<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+underestimated+about+opensource%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 05:41:49 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 05:41:49 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=what+underestimated+about+opensource%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=what+underestimated+about+opensource%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[LUG: LinOs Fürstenfeldbruck]]></title>
<description><![CDATA[Wir sind ein Stammtisch von Linux & OpenSource Freunden, die sich im Regelfall 1x im Monat zusammensetzen und austauschen. 2 weitere Donnerstage im Monat sind für Installationshilfen und OpenSource geplant. Interessierte Menschen und Neulinge sind herzlich willkommen, wir helfen gern beim Umstieg.]]></description>
<link>https://tsecurity.de/de/3693204/it-nachrichten/lug-linos-fuerstenfeldbruck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693204/it-nachrichten/lug-linos-fuerstenfeldbruck/</guid>
<pubDate>Sat, 25 Jul 2026 08:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wir sind ein Stammtisch von Linux &amp; OpenSource Freunden, die sich im Regelfall 1x im Monat zusammensetzen und austauschen. 2 weitere Donnerstage im Monat sind für Installationshilfen und OpenSource geplant. Interessierte Menschen und Neulinge sind herzlich willkommen, wir helfen gern beim Umstieg.]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI bottleneck is not the model. It’s the infrastructure behind it]]></title>
<description><![CDATA[Every enterprise AI conversation seems to begin with the same question: Which model should we use?



I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better r...]]></description>
<link>https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</guid>
<pubDate>Tue, 21 Jul 2026 11:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI conversation seems to begin with the same question: Which model should we use?</p>



<p class="wp-block-paragraph">I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better reasoning. Another offers a larger context window. Another appears faster, cheaper or more specialized.</p>



<p class="wp-block-paragraph">But after years of working around enterprise platforms, integration layers, cloud migration, middleware, production operations and mission-critical systems, I see the AI conversation differently.</p>



<p class="wp-block-paragraph">The model matters. But it is not where most enterprises will struggle next.</p>



<p class="wp-block-paragraph">The next AI bottleneck is the infrastructure behind the model.</p>



<p class="wp-block-paragraph">I do not mean only GPUs, cloud capacity or data storage. I mean the full enterprise operating layer that allows AI to work safely in the real world: data pipelines, identity, APIs, messaging, observability, security controls, deployment automation, cost governance, auditability, support ownership and recovery design.</p>



<p class="wp-block-paragraph">That layer is what determines whether AI remains an exciting experiment or becomes a trusted business capability.</p>



<h2 class="wp-block-heading">Pilots hide the hard part</h2>



<p class="wp-block-paragraph">Most organizations can build an <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">impressive AI pilot</a>. A small team can connect a model to a dataset, create a workflow and show a use case that works well in a controlled setting.</p>



<p class="wp-block-paragraph">The harder part starts when that pilot moves into a <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">real production process</a>.</p>



<p class="wp-block-paragraph">That is when practical questions show up. Who owns the data quality? What systems can the AI access? How do we trace which prompt, policy or retrieval flow produced a specific answer? What happens when an API slows down, a queue backs up or a downstream system is unavailable?</p>



<p class="wp-block-paragraph">To me, these are not model problems. They are infrastructure problems.</p>



<p class="wp-block-paragraph">This is where many enterprises are now headed. The first phase of AI was experimentation. The next phase is operationalization, and that is where the real gap becomes clear.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage">McKinsey</a> has made a similar point in its work on agentic AI, noting that the next phase of value depends less on isolated tools and more on redesigning workflows, operating models and enterprise execution around agents.</p>



<p class="wp-block-paragraph">AI pilots can survive on enthusiasm. Production AI requires architecture.</p>



<h2 class="wp-block-heading">AI is becoming an integration problem</h2>



<p class="wp-block-paragraph">The more I look at enterprise AI, the more it feels like an integration challenge.</p>



<p class="wp-block-paragraph">In large organizations, I have seen how messaging platforms, integration gateways, deployment pipelines, monitoring tools and cloud infrastructure can decide whether a digital capability succeeds or fails. AI will be no different. Even the strongest model will struggle if the data, middleware, identity layer and operational controls around it are weak.</p>



<p class="wp-block-paragraph">AI does not work in isolation. It needs context from systems of record, clean data from different business areas, secure access to APIs, event streams, workflows, knowledge repositories, monitoring tools and legacy systems.</p>



<p class="wp-block-paragraph">That is why the CIO question is changing.</p>



<p class="wp-block-paragraph">It is no longer just, “Which AI tool should we buy?”</p>



<p class="wp-block-paragraph">It is becoming, “Can we safely operationalize intelligence across the business?”</p>



<p class="wp-block-paragraph">This is where agentic AI matters. Autonomous AI only creates real value when the architecture around it can make its actions safe, traceable and useful.</p>



<p class="wp-block-paragraph">A model can generate an answer. Infrastructure determines whether that answer is secure, timely, explainable, governed and connected to the right workflow.</p>



<p class="wp-block-paragraph">For example, an AI assistant that summarizes customer or order information may look like a model use case. But underneath, it depends on access control, fresh data, reliable APIs, logging, encryption, monitoring and policy enforcement.</p>



<p class="wp-block-paragraph">If the answer is wrong, people may blame the model. But the real failure may have started with stale data, weak integration, poor access design, missing observability or an unreliable downstream system.</p>



<p class="wp-block-paragraph">That is why CIOs should not judge AI only by model capability. The enterprise system around the model matters just as much.</p>



<h2 class="wp-block-heading">Latency will become a trust issue</h2>



<p class="wp-block-paragraph">In traditional technology operations, latency is often treated as a performance metric. In AI-enabled workflows, latency becomes a trust issue.</p>



<p class="wp-block-paragraph">When an employee asks an AI assistant for help and the response takes too long, the employee stops using it. When a customer-facing workflow becomes slow, the customer abandons it. When an AI agent waits on multiple backend calls, the entire business process feels unreliable.</p>



<p class="wp-block-paragraph">This becomes even more important as organizations move from simple chat interfaces to agentic workflows. A single AI-driven action may include identity checks, context retrieval, policy validation, model reasoning, API calls, business-rule execution, logging and human approval.</p>



<p class="wp-block-paragraph">Each step adds latency. Each dependency adds a possible failure point.</p>



<p class="wp-block-paragraph">A model may be fast in a benchmark but slow inside an enterprise process. That difference matters.</p>



<p class="wp-block-paragraph">This is where platform engineering becomes essential. Enterprises need reusable patterns for AI workloads: approved connectors, secure retrieval methods, queue-based decoupling, caching strategies, deployment pipelines, monitoring dashboards and standard rollback procedures.</p>



<p class="wp-block-paragraph">Without those patterns, every AI initiative becomes a custom build. Custom builds may work for pilots, but they do not scale across a large enterprise.</p>



<h2 class="wp-block-heading">Observability has to expand</h2>



<p class="wp-block-paragraph">Traditional monitoring tells us whether infrastructure is healthy. Is the server up? Is CPU high? Is memory exhausted? Is the application returning errors?</p>



<p class="wp-block-paragraph">AI needs that, but it also needs more.</p>



<p class="wp-block-paragraph">We need to know what data was retrieved, which model was used, which prompt version was active, which user initiated the request, which policy was applied, how long each step took and whether the output passed validation.</p>



<p class="wp-block-paragraph">We also need to detect new forms of risk: unusual usage patterns, repeated failed tool calls, unexpected cost spikes, sensitive data exposure, weak retrieval results or an AI workflow attempting actions outside its intended boundary.</p>



<p class="wp-block-paragraph">In production AI, observability is not only about uptime. It is about confidence.</p>



<p class="wp-block-paragraph">If a business leader, auditor, regulator or security team asks why an AI system made a recommendation, the answer cannot be, “The model said so.” The enterprise needs traceability. It needs evidence. It needs operational context that engineers, risk teams and business owners can understand.</p>



<p class="wp-block-paragraph">This is one of the biggest gaps I see in AI strategy. Many organizations are investing in models and use cases, but not enough in the control plane required to manage them.</p>



<h2 class="wp-block-heading">Data readiness is still underestimated</h2>



<p class="wp-block-paragraph">AI has exposed an uncomfortable truth: many enterprises are not as data ready as they think.</p>



<p class="wp-block-paragraph">Data is often duplicated across platforms, described differently by each team, governed inconsistently and refreshed on different schedules. Access rules may be clear in one system but unclear in another. Even basic business definitions can change from department to department.</p>



<p class="wp-block-paragraph">AI does not fix that automatically. In many cases, it makes the problem more visible.</p>



<p class="wp-block-paragraph">A bad report may be questioned. A bad AI answer may sound confident enough to be trusted.</p>



<p class="wp-block-paragraph">That is a real risk.</p>



<p class="wp-block-paragraph">Being data-ready for AI is not just about connecting a vector database or indexing documents. It requires clear ownership, lineage, classification, quality checks, retention rules, access boundaries and a shared understanding of which data should be used for which purpose.</p>



<p class="wp-block-paragraph">The same principle applies to resilient cloud-native design. In my IEEE TechRxiv paper, “<a href="https://www.techrxiv.org/doi/full/10.36227/techrxiv.175433366.65304469/v1">Enabling Fault-Tolerant Multicast in Cloud-Native Architectures</a>” I explored how reliability, observability and fault tolerance become foundational requirements when critical workloads stretch across hybrid and multi-cloud environments.</p>



<p class="wp-block-paragraph">CIOs already understand this because they have lived through enterprise resource planning programs, cloud migration, integration modernization, cybersecurity transformation and analytics initiatives. The lesson is familiar: technology cannot outrun data discipline forever.</p>



<h2 class="wp-block-heading">Security cannot be added later</h2>



<p class="wp-block-paragraph">As AI moves from answering questions to acting, security becomes much more important.</p>



<p class="wp-block-paragraph">An assistant that summarizes information carries one level of risk. An agent that can open a ticket, update a record, trigger a workflow, approve a request or contact a customer carries a very different one.</p>



<p class="wp-block-paragraph">The more AI can do, the more identity, authorization, least privilege, separation of duties and human approval matter.</p>



<p class="wp-block-paragraph">Enterprises should be careful not to grant AI broad access just to speed up a pilot. That may seem harmless in development, but it can become dangerous at scale.</p>



<p class="wp-block-paragraph">AI access should be treated like any other privileged enterprise capability: limited, logged, reviewed and easy to revoke.</p>



<p class="wp-block-paragraph">The <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a> AI Risk Management Framework is a useful reference point here because it frames AI risk as something organizations must govern, map, measure and manage continuously rather than something handled only at the end of deployment.</p>



<p class="wp-block-paragraph">Security teams should be involved early, not at the end. The goal is not to slow innovation. The goal is to build a platform where safe innovation becomes repeatable.</p>



<h2 class="wp-block-heading">The CIO has to define the operating model</h2>



<p class="wp-block-paragraph">AI is creating pressure from every direction. Boards want productivity. Business teams want automation. Employees want better tools. Vendors are pushing new features. Security teams are watching risk. Finance teams are watching cost. Customers expect faster, smarter experiences.</p>



<p class="wp-block-paragraph">The CIO sits in the middle of all of it.</p>



<p class="wp-block-paragraph">That is why the CIO’s role cannot stop at choosing tools or approving pilots. The CIO has to define how AI will actually operate across the enterprise.</p>



<p class="wp-block-paragraph">That means answering practical questions. Which architecture is approved? Which data sources can be trusted? How are AI workflows deployed, monitored, supported and governed? How are costs controlled? How do teams reuse common patterns instead of rebuilding the same foundation each time?</p>



<p class="wp-block-paragraph">This work may not be as exciting as a model demo, but it is what separates sustainable AI from short-term experimentation.</p>



<p class="wp-block-paragraph">The winning organizations will not be the ones with the most pilots. They will be the ones with the strongest AI operating layer.</p>



<p class="wp-block-paragraph">They will build reusable platform patterns, strengthen data governance, design access properly, monitor AI behavior end to end and measure success by business improvement, not only model performance.</p>



<p class="wp-block-paragraph">The model still matters. But the enterprise behind the model matters more.</p>



<p class="wp-block-paragraph">A powerful model on weak infrastructure will eventually disappoint the business. A capable model on strong infrastructure can deliver real value because it can be trusted, secured, scaled and improved.</p>



<p class="wp-block-paragraph">That is the shift CIOs need to lead.</p>



<p class="wp-block-paragraph">The next AI bottleneck is not the model. It is whether the enterprise behind the model is ready.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The technology behind every live sports moment]]></title>
<description><![CDATA[When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.



They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbin...]]></description>
<link>https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</guid>
<pubDate>Mon, 20 Jul 2026 16:48:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.</p>



<p class="wp-block-paragraph">They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbing a traffic spike that appeared without warning.</p>



<p class="wp-block-paragraph">They just feel the moment.</p>



<p class="wp-block-paragraph">And that’s exactly how it’s supposed to work.</p>



<p class="wp-block-paragraph">And as live sports viewership pushes into territory that makes previous records look modest (driven by a generation that expects to watch anything, on any device, anywhere, without waiting), the gap between getting that delivery right and getting it wrong has never been more consequential, or more public.</p>



<p class="wp-block-paragraph"><strong>As audiences moved to digital platforms, the margin for error disappeared.</strong><strong></strong></p>



<p class="wp-block-paragraph">There is a version of this conversation that is easy to have: audiences expect more, technology has to keep up. True, but incomplete.</p>



<p class="wp-block-paragraph">Audiences have always expected live sport to work. What changed is what “working” means, and how quickly they find out when it doesn’t.</p>



<p class="wp-block-paragraph">Viewers no longer sit in front of a single screen. During a FIFA World Cup match, a household might have the main feed on the living room television, while someone else streams the highlights on a second TV in the bedroom, all while phones flash with live stats and tablets run separate commentary. From the infrastructure’s perspective, that isn’t just one household watching a game; it’s a chaotic web of concurrent demands triggered by the exact same split-second on the pitch.</p>



<p class="wp-block-paragraph">Multiply that across tens of millions of viewers, and the scale of the challenge becomes clear. Social media raises the stakes further. When a platform fails during a World Cup knockout match, audiences report it in real-time on the same platforms they use to discuss the game. The complaint travels faster than the fix.</p>



<p class="wp-block-paragraph">Broadcasters no longer have the luxury of resolving an incident before people notice. The incident becomes the story, and in many cases, travels further than the match itself.</p>



<h3 class="wp-block-heading"><strong>What these viewership numbers actually mean for infrastructure</strong></h3>



<p class="wp-block-paragraph">The shift in how people watch live sport has moved well beyond trend territory.</p>



<p class="wp-block-paragraph">EMARKETER forecasts that digital live sports audiences in the US will grow to <a href="https://www.emarketer.com/content/100-million-watch-live-sports-digital">114.1 million viewers</a>, while traditional pay TV audiences decline to 82.0 million, highlighting the continued shift toward streaming.</p>



<p class="wp-block-paragraph">The concurrency numbers generated by major sporting events now sit in a territory that would have seemed implausible a decade ago.</p>



<p class="wp-block-paragraph">During the 2026 FIFA World Cup, for instance, streaming platforms shattered every historical ceiling, highlighted by Brazil’s <a href="https://streamscharts.com/news/fifa-world-cup-2026-group-stage-livestreaming">CazéTV</a> repeatedly breaking global YouTube records for concurrent viewership during the group stage. Meanwhile, in the United States, Peacock and <a href="https://www.nbcuniversal.com/article/fifa-world-cup-2026-propels-telemundo-and-peacock-record-viewership">Telemundo’s</a> digital platforms logged an unprecedented 13 million concurrent viewers for a single knockout window. </p>



<p class="wp-block-paragraph">When tens of millions of people tune into the same live stream at the same moment, it’s a challenge unlike regular web traffic.</p>



<p class="wp-block-paragraph">Historically, massive global audiences were insulated by geography. The load was spread across distinct regional networks: antenna signals, satellite downlinks, and physical cable architectures. The physical infrastructure of traditional television inherently absorbed the impact. </p>



<p class="wp-block-paragraph">Digital streaming removes that buffer. Traffic spikes all at once, often at the most critical moment. The tighter the match, the deeper the stoppage time, the sharper the spike. Network infrastructure is forced to handle its heaviest, most volatile traffic exactly when it has zero margin for error.</p>



<p class="wp-block-paragraph">Social media compounds the pressure operationally. The second a crucial goal is scored, a wave of real-time reactions floods the internet, instantly dragging a secondary “curiosity audience” into the app. These are people who weren’t even watching the match, but saw the hype and decided to tune in, meaning the network has to absorb a massive new rush of users precisely while the primary stream is already maxing out its capacity.</p>



<p class="wp-block-paragraph">To survive these surges while satisfying a modern audience, the underlying broadcast playbook has undergone a massive structural shift. It’s no longer just about handling traffic; it’s also about using modern technology like AI to manage it intelligently.</p>



<p class="wp-block-paragraph">According to an <a href="https://www.haivision.com/blog/all/2025-broadcast-transformation-report-key-takeaways/">industry survey</a>, 25% of broadcasters integrated AI into live production workflows in 2025, a massive leap from just 9% the previous year, with 64% identifying AI as the single largest impact driver over the next five years. </p>



<p class="wp-block-paragraph">The network is no longer just delivering content. AI is now generating highlights and short clips in real time, producing millions of videos that keep fans engaged long after the live moment has passed.</p>



<p class="wp-block-paragraph">Ultimately, the technical demand is driven by a shift in what viewers expect. An <a href="https://newsroom.ibm.com/2025-08-18-ibm-study-sports-fans-demand-more-dynamic-digital-content,-powered-by-ai">IBM sports study</a> revealed that 56% of fans now want AI-driven insights layered directly onto their content, while 33% point to real-time, automated translation as the feature that most impacts their experience.</p>



<p class="wp-block-paragraph">Whether it’s one screen or several, viewers don’t notice the edge infrastructure or AI powering the experience. They just expect the game to play without interruption.</p>



<h3 class="wp-block-heading"><strong>The planning mistake most organisations make</strong></h3>



<p class="wp-block-paragraph">Capacity planning is where most organisations spend their time when preparing to stream a major event. Can the system handle a million concurrent streams? Can it scale on demand if the numbers exceed projections? These are real questions. </p>



<p class="wp-block-paragraph">The lesson is not unique to sports streaming. Every digital business now experiences moments where demand, visibility, and customer expectations collide. Peak traffic events such as flash sales, ticket releases, and viral campaigns can drive website traffic <a href="https://aws.amazon.com/blogs/apn/how-to-manage-peak-traffic-on-aws-using-queue-its-virtual-waiting-room/">2 to 25 times above normal levels within seconds</a>. The infrastructure may be different, but the pressure is remarkably similar.<br></p>



<p class="wp-block-paragraph">Large-scale system failures occur when multiple components, each functioning as expected on its own, are overwhelmed by a surge in demand, rising latency, or regional blind spots at the same time.</p>



<p class="wp-block-paragraph">The problem isn’t the individual systems. It’s how they work together.</p>



<p class="wp-block-paragraph">Latency is the factor most consistently underestimated. A few seconds of delay is not a minor inconvenience in live sport. It is a fundamentally broken experience. </p>



<p class="wp-block-paragraph">A viewer whose stream is running four seconds behind will see a notification before the decisive moment appears on screen. Someone watching a service from the privacy of their room may hear a celebration from another room before seeing it on their screen.</p>



<p class="wp-block-paragraph">Geography is another planning gap. Streaming growth is increasingly being driven by emerging markets. In Southeast Asia alone, premium video streaming subscriptions grew <a href="https://avia.org/southeast-asia-premium-vod-accelerates-in-2025-as-subscriber-growth-rebounds-ctv-scales-and-local-content-breaks-through/?utm_source=chatgpt.com">19%</a> in 2025, led by Indonesia, while viewing hours continued to climb across the region. Yet much of the world’s media infrastructure was originally designed around North American and Western European demand. An architecture that looks robust on paper can deliver very different experiences depending on where the viewer is.</p>



<p class="wp-block-paragraph">The reason is simple: physical distance still matters. Every extra hop between the viewer and the content adds latency, making it harder to deliver a consistent experience at global scale.</p>



<p class="wp-block-paragraph">Then there is the timing question. The decisions that determine whether a platform holds during the most-watched minutes of the year are not made on event day. They are made months earlier through choices around architecture, redundancy, testing, and operational readiness.</p>



<p class="wp-block-paragraph">Once an event is underway, it’s too late to redesign the architecture behind it. If your system isn’t designed to handle the pressure before the crowd arrives, it’s already too late.</p>



<h3 class="wp-block-heading"><strong>The hidden chain behind every live event</strong></h3>



<p class="wp-block-paragraph">When a streaming disruption becomes public, people naturally look for a single point of failure: the app, the platform, or the provider.</p>



<p class="wp-block-paragraph">A live event depends on dozens of systems working together, and any one of them can become a problem.</p>



<p class="wp-block-paragraph">And the experience is only as good as the weakest handoff between them.</p>



<p class="wp-block-paragraph">It all starts with the live camera feed moving from the venue to the production studio. This is a real-time stream, not a file download. If you drop even a single packet at the wrong moment, everything down the line breaks, no matter how perfect the rest of your setup is.</p>



<p class="wp-block-paragraph">Remote and cloud-based production workflows have redefined how live sports are produced, enabling broadcasters to operate with greater agility and scale. As production becomes more distributed, success increasingly depends on ensuring every stage of the delivery chain works together seamlessly.</p>



<p class="wp-block-paragraph">Each transition is a potential failure point. Managing them requires visibility that extends across providers, platforms, and networks simultaneously.</p>



<p class="wp-block-paragraph">Behind every live stream, technologies like encoding, transcoding, packaging, rights management, and ad insertion are constantly at work. If any one of them fails, the stream can go down altogether.</p>



<p class="wp-block-paragraph">Global distribution introduces another layer of complexity. Viewers in Asia, Africa, and South America may all be watching the same match, but each stream travels across different networks and infrastructure. That means performance can vary by region, and issues may affect one audience without impacting another. </p>



<p class="wp-block-paragraph">AI is increasingly helping operators detect anomalies in real time, pinpoint affected regions and trigger corrective actions before disruptions become widespread. Combined with point-to-point monitoring, it provides the visibility needed to keep live events running smoothly at global scale.</p>



<p class="wp-block-paragraph">Edge delivery is where the difference between preparation and improvisation becomes most apparent. Bringing content closer to users reduces latency, absorbs local traffic surges, and improves performance in markets with variable connectivity. </p>



<p class="wp-block-paragraph">The value of technology investments such as AI and Edge becomes clearest during the moments when demand is highest.</p>



<p class="wp-block-paragraph">Monitoring is what turns visibility into action. With AI helping analyze telemetry and detect anomalies in real time, operations teams can identify issues sooner and respond before they affect viewers. By the time customers start reporting a problem, the opportunity to prevent it has already passed.</p>



<h3 class="wp-block-heading"><strong>What reliability is actually worth</strong></h3>



<p class="wp-block-paragraph">For most of early broadcast history, audience tolerance provided some buffer. Disruptions happened. People accepted them. There was nowhere else to go, and the story rarely escaped the room.</p>



<p class="wp-block-paragraph">Neither of those things is true now.</p>



<p class="wp-block-paragraph">A streaming failure during a major match becomes public within seconds. Viewers don’t distinguish between a network issue, a processing failure, or a distribution problem; they simply see a service that failed. That single experience can shape the broadcaster’s reputation, credibility and customer loyalty, influencing whether viewers come back for the next event or recommend the service to others.</p>



<p class="wp-block-paragraph">The commercial implications are significant. Global tournaments such as the FIFA World Cup illustrate just how valuable live sports rights have become. Their return depends on reliably reaching the audience that was promised.</p>



<p class="wp-block-paragraph">Advertisers invest in live sport for one reason: to reach a large, engaged audience at the exact moment it matters most. If the stream fails during that window, the opportunity is lost. Those viewers, impressions, and advertising value cannot be recovered once the moment has passed.</p>



<p class="wp-block-paragraph">The same principle increasingly applies outside media. Customers rarely know nor care whether an outage originated in the application, the cloud environment, the network or a third-party dependency. They experience a failure of the brand. In a digital-first economy, reliability has become part of the customer experience itself.</p>



<p class="wp-block-paragraph">For broadcasters and streamers, reliability is no longer just an operational KPI. It directly influences audience trust, advertising revenue, and the long-term value of premium sports rights.</p>



<h3 class="wp-block-heading"><strong>The demands ahead are bigger</strong></h3>



<p class="wp-block-paragraph">AI-assisted production is already changing how live events are created. Broadcasters are using AI to automate highlight generation, camera selection and real-time clip packaging for social media, with new AI-assisted workflows producing sports highlights up to <a href="https://www.statsperform.com/insights/opta-pulse-launch/">80% faster</a> than traditional methods. </p>



<p class="wp-block-paragraph">All of this processing happens within the live delivery chain, where every additional task must be completed without adding latency or compromising the viewing experience.</p>



<p class="wp-block-paragraph">Personalisation at scale is the next significant challenge. Not personalisation in a vague sense, but the specific technical reality of delivering multi-language commentary tracks, different languages, different statistical overlays, and different camera angles to different viewers watching the same event simultaneously. </p>



<p class="wp-block-paragraph">Instead of one stream per event, the infrastructure has to manage a matrix of concurrent variants, each with its own encoding, storage, and delivery requirements. </p>



<p class="wp-block-paragraph">Interactive experiences add bidirectional data flows: real-time polls, integrated second-screen data, live wagering. These move data from the viewer back through infrastructure that was primarily built to push content outward. Managing that at scale is a different engineering problem from managing delivery.</p>



<p class="wp-block-paragraph">Higher-resolution formats (4K now becoming a standard expectation in premium markets, 8K moving into early deployment) are bandwidth-intensive at exactly the scale where bandwidth is already under pressure. Consumer devices are ready. Infrastructure in many high-growth markets is not uniformly there yet.</p>



<p class="wp-block-paragraph">Many of these capabilities are already being deployed for major global sporting events. The organisations investing seriously in technology, innovation, and infrastructure now are building toward a standard that will be the baseline requirement within a few years. Those that are not will be closing the gap under the worst possible conditions.</p>



<h3 class="wp-block-heading"><strong>The technology you never think about</strong></h3>



<p class="wp-block-paragraph">The broadcasters that succeed don’t leave reliability to chance. They plan for it from the outset, designing their infrastructure to handle peak demand long before the audience arrives.</p>



<p class="wp-block-paragraph">This reality hits hardest during massive global events. When a stream glitches, millions of people feel it simultaneously in a matter of seconds. Keeping those streams alive doesn’t happen by accident; it takes massive scale, intense discipline, and deep experience controlling everything from the stadium camera to the viewer’s screen.</p>



<p class="wp-block-paragraph">The lesson extends well beyond live sports. Every enterprise is becoming a real-time digital business, whether it’s delivering AI-powered applications, launching digital products, processing financial transactions, or handling a sudden surge in customer demand. Different industries may face different triggers, but the expectation is the same: the experience has to work, even when demand is at its highest.</p>



<p class="wp-block-paragraph">Delivering that level of reliability is why many of the world’s largest sports brands rely on <a href="https://www.tatacommunications.com/media-entertainment">Tata Communications</a>. Supporting the broadcast, production, and management of 80% of the world’s sporting events, and reaching more than two billion viewers across 190+ countries, Tata Communications operates in the invisible layers that make every live moment possible. We call this the “Virtual Stadium of the World”, the technology and infrastructure that connects fans, broadcasters, rights-holders, and sporting moments at a truly global scale.</p>



<p class="wp-block-paragraph">By managing the critical handoffs across contribution networks, edge processing, and global media infrastructure, we engineer the resilience required to keep 120,000 live events running flawlessly every year.</p>



<p class="wp-block-paragraph">Live sport may be the most visible test of digital infrastructure, but it won’t be the last. As AI, personalisation and real-time experiences become the norm across industries, the ability to deliver reliably at scale will define far more than match day.</p>



<p class="wp-block-paragraph">To learn more, visit us <a href="https://www.tatacommunications.com/sports?utm_source=blog&amp;utm_medium=cio&amp;utm_campaign=mes%20fifa%20campaign">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:46:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:32:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Comic Chat ist Open Source: Microsoft gibt Ursprung von Comic Sans frei]]></title>
<description><![CDATA[Microsoft hat den Quellcode seines fast vergessenen Chatprogramms Comic Chat als Open Source veröffentlicht und damit ein Stück Computergeschichte wieder zugänglich gemacht. Der berühmte Font Comic Sans hat hier seinen Ursprung.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3675512/it-security-nachrichten/comic-chat-ist-open-source-microsoft-gibt-ursprung-von-comic-sans-frei/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675512/it-security-nachrichten/comic-chat-ist-open-source-microsoft-gibt-ursprung-von-comic-sans-frei/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160047.html"><img hspace="5" border="0" align="left" alt="Sicherheit, Sicherheitslücke, Security, Schadsoftware, Cybersecurity, Exploit, Cybercrime, Open Source, Code, Programmierung, Quellcode, Developer, Programmieren, schloss, Sourcecode, Coding, Coder, Development, Opensource, Source Code, Open Source Software, Quelloffen, Lock, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56871.jpg"></a>
			Microsoft hat den Quellcode seines fast vergessenen Chatprogramms Comic Chat als <a href="https://winfuture.de/special/open-source/" title="Open Source Special">Open Source</a> veröffentlicht und damit ein Stück Computergeschichte wieder zugänglich gemacht. Der berühmte Font Comic Sans hat hier seinen Ursprung.			(<a href="https://winfuture.de/news,160047.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵]]></title>
<description><![CDATA[#OpenSource #Technologie #PolitischeMusik     submitted by    /u/Horus_Sirius   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3674910/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674910/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</guid>
<pubDate>Fri, 17 Jul 2026 04:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1uy6n0c/lakandor_systemaktualisierung_solidarit%C3%A4t_als/"> <img src="https://external-preview.redd.it/aThwdWVkdWpzbGRoMe0PXkgdUfecaNq-QqtzWstuZw-6b3__Ki6AL1kwgkUy.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=7c4161b1834e21627e9ff6d7ed8a6a1b886016c7" alt="LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵" title="LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>#OpenSource #Technologie #PolitischeMusik </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://v.redd.it/gkzt6bujsldh1">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1uy6n0c/lakandor_systemaktualisierung_solidarit%C3%A4t_als/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 0x - Views:1 ▶️ *SOZIOÖKONOMISCHE TIEFENANALYSE:* Das System läuft auf Hochtouren – aber für wen eigentlich? Die Fehlermeldungen der Gesellschaft werden systematisch ignoriert 🤯. 

In diesem musikalischen Video-Essay dekonstruieren wir das neoliberale Narra...]]></description>
<link>https://tsecurity.de/de/3674582/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674582/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</guid>
<pubDate>Thu, 16 Jul 2026 22:23:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ECtiBK4MAbg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>▶️ *SOZIOÖKONOMISCHE TIEFENANALYSE:* Das System läuft auf Hochtouren – aber für wen eigentlich? Die Fehlermeldungen der Gesellschaft werden systematisch ignoriert 🤯. <br />
<br />
In diesem musikalischen Video-Essay dekonstruieren wir das neoliberale Narrativ und betrachten unsere Wirtschaft als das, was sie ist: Ein fehlerhafter Programmcode. Wenn Mieten unaufhaltsam steigen und Löhne künstlich klein gehalten werden, ist das kein Versehen. Die reale Datenlage zeigt: Es ist ein eiskalt kalkulierter Architekturfehler 📉.<br />
<br />
Wir analysieren die *strukturellen Ursachen*, die im Hintergrund wirken:<br />
💸 *Die Rendite-Schleife:* Die Rechner laufen heiß, die Produktivität steigt, doch der erarbeitete Reichtum kommt bei den "Zahnrädern" der Gesellschaft nie an. Die Gewinne fließen in geschlossene Systeme.<br />
🔒 *Zentralrechner der Macht:* Wer den Quelltext der Wirtschaft besitzt, kontrolliert die Verteilung. Wenige Monopole und elitäre Netzwerke ziehen die Daten und Ressourcen ab, während die arbeitende Mitte ausbrennt.<br />
🌍 *Die Fragmentierung:* Das System ist darauf programmiert, uns zu vereinzeln ("jeden für sich allein"). Konkurrenzkampf und Abstiegsangst sind keine Naturgesetze, sondern bewusst implementierte Steuerungsmechanismen.<br />
<br />
Statt auf individuelle "Hustle Culture" zu pochen, deckt dieses Video den *Systemfehler des Kapitalismus* auf. Wir fordern einen offenen Quelltext für unsere Welt: Dezentrale Macht, geteiltes Wissen und eine Wirtschaft, bei der Solidarität die *Standardeinstellung* ist 💡🌱.<br />
<br />
---<br />
👇 *WERDE TEIL DER LÖSUNG:*<br />
Abonniere den Kanal für weitere tiefgehende sozioökonomische Analysen und lass uns gemeinsam das System neu programmieren ✊: @vazules <br />
<br />
#Systemkritik #Wirtschaft #Digitalisierung #Gerechtigkeit #Klassenkampf #OpenSource #LaKanDoR #politischemusik #netzpolitik #analyse #technologie<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Routine maintenance as a failure vector in modern networks]]></title>
<description><![CDATA[Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.



Eve...]]></description>
<link>https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.</p>



<p>Every pre-check passed. Device health looked normal. High-availability synchronization was complete. Monitoring showed no obvious concerns. Yet shortly after the change, users began reporting application failures.</p>



<p>The root cause was not a failed upgrade, hardware fault or software defect. The maintenance activity exposed a dependency elsewhere in the traffic path that nobody had considered.</p>



<p>Since then, I have seen similar patterns repeatedly across enterprise environments. The change itself was rarely the problem. The problem was the assumption that the change was isolated.</p>



<p>Planned maintenance is intended to reduce risk, but in practice, it often introduces risk into an otherwise stable network.</p>



<p>Many production incidents result from routine tasks such as firewall updates, DNS changes, certificate renewals, routing adjustments, load balancer failovers, WAF updates, switch upgrades or software patches, rather than dramatic failures.</p>



<p>The reality is that “routine” does not equate to “low risk.” It simply means the activity has been performed before, not that the current environment will respond the same way.</p>



<p>Modern networks have become too interconnected for maintenance to be treated as a simple device-level task. A change to one control point can expose a dependency elsewhere in the traffic path. A firewall update can affect asymmetric return traffic. A DNS change can shift users to a data center where persistence is not aligned. A load balancer failover can expose stale ARP or MAC learning issues. A certificate renewal can cause an inspection or TLS negotiation to fail in the backend. A WAF update can block application behavior that was never visible in testing.</p>



<p>Failures rarely stem from the maintenance activity itself, but rather from the assumption that the change is isolated.</p>



<h2 class="wp-block-heading">Why routine changes still cause outages</h2>



<p>In traditional network operations, the unit of change was often a device: upgrade a switch, modify a router, add a firewall rule, renew a certificate or reboot an appliance. That model worked better when application traffic paths were simpler, and dependencies were easier to understand.</p>



<p>Today, a single user transaction may cross DNS, global traffic management, WAN routing, data center switching, firewalls, load balancers, TLS inspection points, WAF policies, API gateways and backend application tiers. Each layer may make an independent decision about availability, security, routing or session handling.</p>



<p>This creates a risky maintenance pattern. Teams often validate only the component they changed, not the complete traffic flow before and after the change. Devices may appear healthy, configurations may load correctly and all checks may pass, yet users can still experience failures due to a changed dependency somewhere in the end-to-end path.</p>



<p>Google’s Site Reliability Engineering (SRE) guidance highlights that changes remain one of the most common sources of service disruption, which is why mature organizations invest heavily in change validation, rollback planning and observability. <a href="https://sre.google/sre-book/">The SRE book</a> provides extensive discussion of change management, reliability engineering and operational risk in large-scale environments.</p>



<p>For this reason, maintenance windows should be evaluated as both operational events and potential failure vectors.</p>



<h2 class="wp-block-heading">Common failure points during maintenance</h2>



<p>One common issue is state mismatch. Firewalls, load balancers, NAT devices and application delivery controllers often maintain connection or session state. During failover, reboot or path change, existing flows may not survive even if the standby device becomes active as designed. New connections may succeed while long-lived sessions fail. In other cases, traffic may enter through one device and return through another, causing stateful inspection to drop packets that appear invalid.</p>



<p>Asymmetric routing is another frequent cause. A routing change may look harmless from a Layer 3 perspective, but if the forward and return paths traverse different firewalls or inspection zones, applications can fail intermittently. The network may still be “up,” but the security policy no longer sees the full conversation.</p>



<p>Layer 2 behavior is also underestimated. In highly available data center designs, MAC learning, ARP cache behavior, VLAN tagging, port channels and first-hop gateway behavior can determine whether traffic moves cleanly after a failover. A device may successfully assume an active role, but upstream switches or firewalls may still forward traffic toward the old path until tables age out or are refreshed.</p>



<p>DNS and GSLB changes introduce a different class of risk. Teams often test name resolution, but resolution is only the first step. The more important question is where users are being sent and whether that destination is ready to handle production traffic.</p>



<p><a href="https://www.internetsociety.org/resources/deploy360/dns/">DNS resilience guidance published by the Internet Society</a> emphasizes that successful name resolution alone does not guarantee application availability, particularly when multiple infrastructure dependencies exist behind the DNS response.</p>



<p>If global traffic management shifts users from one data center to another, the receiving site must have aligned firewall rules, load balancer configuration, health monitors, certificates, persistence behavior, routing advertisements and backend capacity. Otherwise, DNS sends users to a site that is not actually ready.</p>



<p>Certificate maintenance can also break more than the browser-facing endpoint. In many environments, TLS is terminated, re-encrypted, inspected or validated across multiple hops. Renewing a certificate on the external virtual server may not address backend certificates, intermediate chains, SNI behavior, cipher compatibility or trust stores used by inspection devices. The maintenance task may be described as a certificate renewal, but the real dependency is end-to-end TLS negotiation.</p>



<p>Security policy maintenance creates another risk. WAFs, IPSs, DDoS protection systems, bot defense platforms and firewall policies are designed to block abnormal behavior. But during updates, tuning changes or signature refreshes, they can also block legitimate application traffic if policy enforcement is not validated against real transaction patterns.</p>



<p>This is especially true for APIs, where small differences in headers, methods, payload structure or authentication flows can trigger unexpected enforcement.</p>



<h2 class="wp-block-heading">The test environment problem</h2>



<p>Many teams rely on pre-checks and test environments, but these controls are often less effective than they seem.</p>



<p>Pre-checks confirm device reachability, interface status, route existence, pool member availability and HA health. While necessary, these checks do not ensure production traffic will survive a path change because they focus on infrastructure rather than transaction validation.</p>



<p>Test environments rarely mirror production. Production environments involve real user volume, client diversity, DNS caching behavior, firewall states, certificates, backend latency and complex dependencies. A failover that succeeds in a lab may behave very differently in the real world.</p>



<p>This does not render testing useless, but test results should not be considered proof of production safety. They provide evidence, not a guarantee.<br><br>This challenge aligns with broader <a href="https://www.nist.gov/cyberframework">operational resilience guidance from the NIST Cybersecurity Framework</a>, which emphasizes continuous monitoring, validation and recovery planning as critical operational capabilities.</p>



<p>A stronger maintenance process starts with mapping the traffic path before the window. For critical applications, teams should understand the normal ingress path, egress path, firewall zones, NAT points, load balancer virtual servers, DNS or GSLB decision points, TLS termination points, persistence requirements and backend dependencies.</p>



<p>The next step is defining failure expectations. What happens to existing sessions if a firewall is rebooted? Should source MAC, floating IP, ARP or upstream forwarding behavior change during a load balancer failover? How long will cached clients continue to access the old site after a DNS shift? Which clients and inspection devices validate the certificate chain when a certificate is replaced?</p>



<p>These questions should be addressed before the maintenance window, not during an outage.</p>



<p>Pre-checks should include both control-plane and data-plane evidence. Control-plane checks confirm configuration, synchronization, device health, routing tables, interface status and object availability. Data-plane checks validate real traffic movement: TCP handshakes, TLS negotiation, HTTP status codes, API responses, session persistence, source NAT behavior and return-path consistency.</p>



<p>During the change, monitoring should focus on symptoms that expose traffic failure early. Device CPU and interface status are useful, but they are not enough. Teams should also watch connection resets, denied firewall logs, WAF violation spikes, pool member selection failures, DNS answer changes, TCP retransmissions, backend 5xx errors and synthetic transaction results.</p>



<p>Rollback planning must also be precise. Simply rolling back a configuration is often insufficient. If a DNS record changes, cached clients may continue using the previous answer. If a firewall state table is cleared, restoring the rule does not recover active sessions. If failover alters forwarding behavior, upstream devices may require ARP refresh, route reconvergence or manual validation.</p>



<p>An effective rollback plan should identify lost state, persistent caches and the evidence required to confirm recovery.</p>



<h2 class="wp-block-heading">Treating maintenance as a resilience exercise</h2>



<p>The objective is not to make maintenance overly complex or bureaucratic. The objective is to avoid underestimating its risks.</p>



<p>Every maintenance window is a controlled opportunity to test whether the network behaves as specified by the architecture.</p>



<p>If failover is part of the design, maintenance should verify failover behavior. If a secondary data center is expected to handle traffic, maintenance should demonstrate that it can process real transactions. If security policies are updated, maintenance should prove that legitimate traffic is still allowed. If certificates are renewed, maintenance should validate the complete TLS path, not just the public endpoint.</p>



<p><a href="https://uptimeinstitute.com/resources">Industry outage studies published by the Uptime</a> Institute consistently show that human error and process failures remain significant contributors to downtime. Their annual outage research continues to highlight the role of operational processes and maintenance activities in service disruptions.<br><br>Maintenance windows provide an opportunity to identify those weaknesses before they become customer-facing incidents.</p>



<p>This requires closer collaboration between network, security, application and operations teams. Network engineers may own routing or load-balancing changes, but application teams understand transaction flows. Security teams understand inspection and enforcement behavior. Operations teams often see user-impacting symptoms first.</p>



<p>Treating maintenance as a shared traffic event rather than a device event reduces blind spots.</p>



<p>Routine maintenance will always involve some risk. However, the greatest risk is the false confidence that the term ‘routine’ conveys.</p>



<p>Modern networks fail in the spaces between systems: between DNS and load balancing, between firewalls and routing, between TLS inspection and application behavior, between HA design and actual forwarding state. Maintenance exposes those spaces.</p>



<p>For that reason, network teams should view every maintenance window as more than a checklist. It is a live test of architecture, operational discipline and production resilience.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday MCP]]></title>
<description><![CDATA[I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data.  Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploite...]]></description>
<link>https://tsecurity.de/de/3662627/malware-trojaner-viren/patch-tuesday-mcp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662627/malware-trojaner-viren/patch-tuesday-mcp/</guid>
<pubDate>Sun, 12 Jul 2026 04:18:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data. </p> <p>Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploited, and what needs to be patched first? </p> <p>Ask things like:</p> <p> “Summarize this month’s Patch Tuesday”</p> <p> “Which of these CVEs are on the CISA KEV list?”</p> <p> “Show me CVEs with an exploitation probability above 50%”</p> <p> “What older patches does KB5094123 replace?”</p> <p> “What Critical CVEs hit Windows Server 2022 this month?” </p> <p>What makes it different: most vulnerability tools can look up a CVE, but they have no concept of a monthly Microsoft release, a KB article, or a product family. </p> <p>This server parses the full MSRC CVRF documents, so it can answer the questions Microsoft shops actually ask on the second Tuesday of every month. </p> <p>It is built around the data sources teams already trust:</p> <ul> <li>Official MSRC Security Update Guide API: Microsoft’s source for Security Update Guide and CVRF data</li> <li>EPSS scores from FIRST.org: daily-updated probability each CVE gets exploited in the next 30 days</li> <li>CISA KEV integration: confirmed-exploited CVEs with federal remediation due dates</li> <li>Supersedence chains: walks Microsoft’s “this KB replaces that KB” links so your assistant never recommends a stale patch</li> <li>Results ranked by real-world urgency: KEV/exploited → EPSS → severity → CVSS</li> </ul> <p>Zero API keys, zero accounts: everything comes from public MSRC, <a href="http://first.org/">FIRST.org</a>, and CISA feeds. Run it locally or remotely. Details below: </p> <p> Repo: <a href="https://github.com/jonnybottles/patch-tuesday-mcp">https://github.com/jonnybottles/patch-tuesday-mcp</a> </p> <p> Remote MCP server endpoint:<br> <a href="https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp">https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp</a> </p> <p>If you triage Microsoft updates frequently, I’d love feedback. If there’s a feature you’d use, open an issue. </p> <p>Disclaimer: This is an independent, self-built project and is not an official Microsoft tool or service. </p> <p><a href="https://www.facebook.com/hashtag/patchtuesday?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#PatchTuesday</a> <a href="https://www.facebook.com/hashtag/cybersecurity?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#CyberSecurity</a> <a href="https://www.facebook.com/hashtag/vulnerabilitymanagement?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#VulnerabilityManagement</a> <a href="https://www.facebook.com/hashtag/mcp?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MCP</a> <a href="https://www.facebook.com/hashtag/ai?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#AI</a> <a href="https://www.facebook.com/hashtag/claude?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Claude</a> <a href="https://www.facebook.com/hashtag/microsoft?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Microsoft</a> <a href="https://www.facebook.com/hashtag/msrc?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MSRC</a> <a href="https://www.facebook.com/hashtag/opensource?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#OpenSource</a> <a href="https://www.facebook.com/hashtag/infosec?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#InfoSec</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Active_Pick3975"> /u/Active_Pick3975 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61024 | openlink virtuoso-opensource 7.2.11 sqlo_try_in_loop denial of service (Issue 1227 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability has been found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected is an unknown function of the component sqlo_try_in_loop. This manipulation causes denial of service.

This vulnerability is registered as CVE-2025-61024. Remote exploitation of the attac...]]></description>
<link>https://tsecurity.de/de/3662298/sicherheitsluecken/cve-2025-61024-openlink-virtuoso-opensource-7211-sqlotryinloop-denial-of-service-issue-1227-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662298/sicherheitsluecken/cve-2025-61024-openlink-virtuoso-opensource-7211-sqlotryinloop-denial-of-service-issue-1227-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 20:20:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>sqlo_try_in_loop</em>. This manipulation causes denial of service.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2025-61024">CVE-2025-61024</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61025 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1229 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in openlink virtuoso-opensource 7.2.11. The impacted element is an unknown function. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as CVE-2025-61025. The attack can be launched remotely. No exploit exists.]]></description>
<link>https://tsecurity.de/de/3662297/sicherheitsluecken/cve-2025-61025-openlink-virtuoso-opensource-7211-denial-of-service-issue-1229-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662297/sicherheitsluecken/cve-2025-61025-openlink-virtuoso-opensource-7211-denial-of-service-issue-1229-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 20:20:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. The impacted element is an unknown function. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2025-61025">CVE-2025-61025</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61018 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1224 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in openlink virtuoso-opensource 7.2.11. Affected by this issue is some unknown functionality. Executing a manipulation can lead to denial of service.

This vulnerability is handled as CVE-2025-61018. The attack can be executed remotel...]]></description>
<link>https://tsecurity.de/de/3661998/sicherheitsluecken/cve-2025-61018-openlink-virtuoso-opensource-7211-denial-of-service-issue-1224-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661998/sicherheitsluecken/cve-2025-61018-openlink-virtuoso-opensource-7211-denial-of-service-issue-1224-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. Affected by this issue is some unknown functionality. Executing a manipulation can lead to denial of service.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2025-61018">CVE-2025-61018</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61020 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1225 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in openlink virtuoso-opensource 7.2.11. This vulnerability affects unknown code. The manipulation results in denial of service.

This vulnerability was named CVE-2025-61020. The attack may be performed from remote. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3661997/sicherheitsluecken/cve-2025-61020-openlink-virtuoso-opensource-7211-denial-of-service-issue-1225-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661997/sicherheitsluecken/cve-2025-61020-openlink-virtuoso-opensource-7211-denial-of-service-issue-1225-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This vulnerability affects unknown code. The manipulation results in denial of service.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-61020">CVE-2025-61020</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61022 | openlink virtuoso-opensource 7.2.11 sqlo_tb_col_preds denial of service (Issue 1226 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in openlink virtuoso-opensource 7.2.11. Impacted is an unknown function of the component sqlo_tb_col_preds. Such manipulation leads to denial of service.

This vulnerability is referenced as CVE-2025-61022. It is possible to launch the ...]]></description>
<link>https://tsecurity.de/de/3661996/sicherheitsluecken/cve-2025-61022-openlink-virtuoso-opensource-7211-sqlotbcolpreds-denial-of-service-issue-1226-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661996/sicherheitsluecken/cve-2025-61022-openlink-virtuoso-opensource-7211-sqlotbcolpreds-denial-of-service-issue-1226-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. Impacted is an unknown function of the component <em>sqlo_tb_col_preds</em>. Such manipulation leads to denial of service.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2025-61022">CVE-2025-61022</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[When Your Smart Vacuum Dies]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Many smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely.

Open-source alternatives offer ...]]></description>
<link>https://tsecurity.de/de/3658337/it-security-video/when-your-smart-vacuum-dies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658337/it-security-video/when-your-smart-vacuum-dies/</guid>
<pubDate>Fri, 10 Jul 2026 00:02:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/FocWU7HRrIU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Many smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely.<br />
<br />
Open-source alternatives offer a different model. By running locally and avoiding cloud dependencies, they give users greater control, improved privacy, and longer product lifespans. It's a reminder that convenience and ownership don't always go hand in hand.<br />
<br />
Should more smart home devices be designed to work offline by default, even if it means sacrificing some cloud-powered features?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#IoT #OpenSource #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises using multiple AI models are underestimating failure rates by 2.25x]]></title>
<description><![CDATA[A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. A new study evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceili...]]></description>
<link>https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</guid>
<pubDate>Thu, 09 Jul 2026 21:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. <a href="https://arxiv.org/abs/2606.27288">A new study</a> evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceiling.</p><p>The assumption works like this: as long as two models don't usually fail on the exact same prompts, combining them is supposed to create a safety net against failures.</p><p>The real limit on orchestration is not how often models disagree, but the percentage of prompts where every model in the pool gives the wrong answer at once. By ignoring the co-failure ceiling, enterprises are building complex, expensive routing infrastructure to chase performance gains that do not exist. Fortunately, developers can use this same math to build a cost-free test that determines exactly when multi-model orchestration will actually pay off.</p><h2>The hidden costs of the multi-model strategy</h2><p>To orchestrate multiple language models, developers typically rely on three architectures. <a href="https://venturebeat.com/technology/new-1-5b-router-model-achieves-93-accuracy-without-costly-retraining">Model routers</a> act as traffic cops, sending complex queries to expensive models and simple queries to cheaper ones. Cascades send every prompt to a cheap model first, only escalating to a premium model if the initial system signals low confidence. Finally, approaches like <a href="https://bdtechtalks.com/2025/02/17/llm-ensembels-mixture-of-agents/">Mixture-of-Agents</a> (MoA) fuse multiple models by asking them the same question and generating a synthesized answer from their combined outputs.</p><p>These architectures introduce a "shadow price" to inference costs. Every time a development team implements a router or a cascade, they pay a premium in added system latency, complex infrastructure maintenance, and increased governance risks across multiple API providers.</p><p>To justify these operational costs, engineers rely on “pairwise error correlation” to select their model pool. Imagine a developer has Model A, which writes excellent Python but fails at SQL, and Model B, which writes excellent SQL but fails at Python. Because they fail on different types of prompts, their pairwise error correlation is low. The developer assumes that by placing a routing layer in front of them, they have created a composite system that rarely fails at coding.</p><p>According to the study, throwing diverse models together based on low correlation can actually hurt performance if the models are not equally capable — when you vote across diverse but unequal models, the weaker ones often gang up and outvote the smartest one.</p><p>Josef Chen, author of the paper, told VentureBeat that in their experiments, "Naive majority voting across unequal models had negative mean gain (minus 10 points on our hard mix): diverse-but-weaker members outvote the strong one." The actionable advice for developers is to "combine only models within a matched quality band." If you cannot match quality, take the single-model baseline and spend your budget on the best model available.</p><p>The paper provides one bright spot for this approach regarding MoA architectures. When building ensembles, teams often use "Self-MoA," where they query the same premium model multiple times to generate a synthesized answer. The researchers found that at matched quality, building a diverse ensemble of models with low pairwise correlation beats a high-correlation Self-MoA setup.</p><p>However, when teams use that same pairwise correlation metric to predict the absolute accuracy of their overall system, the math breaks down.</p><p>"So teams pay the orchestration overhead up front (latency, complexity, multi-provider operations) on the assumption that a diversity dividend arrives later," Chen said. "Usually it doesn't, because today's best models agree, and, worse, they fail on the same queries … the prompt simply carries little signal about which model will be the one that's right when the frontier disagrees."</p><h2>Why the math fails: the co-failure ceiling</h2><p>The core finding of the study centers on a metric called the "co-failure rate" — the formal name for the all-wrong scenario described above. No router, voting system, or cascade can ever achieve an accuracy higher than the ceiling it imposes.</p><p>The coding, logic, and generalist pool shows low pairwise correlation on routine prompts — they rarely fail together. But the co-failure ceiling represents the obscure, highly complex edge case that pushes past the limits of current AI architectures. If a prompt is so difficult that all three models hallucinate or fail, it does not matter how intelligently the router distributes the task. The entire pool wipes out at once.</p><p>The researchers tested their 67-model pool, which included GPT-5.5, Claude Opus 4.8, and Gemini 3.1 Pro, on the open-ended MATH-500 math benchmark. Based on standard pairwise correlation, statistical models predicted that the entire pool would wipe out simultaneously on only 2.3% of the questions. In reality, the co-failure rate was 5.2%.</p><p>Standard correlation metrics underestimated the failure rate by roughly 2.25 times. The culprit is not just independent difficulty, but a shared failure point.</p><p>"The driver is what we call a common-mode atom: a slice of queries on which the entire market fails together, which no pairwise statistic can see," Chen said. "Adding a 20th model to your pool doesn't buy tail coverage. The tail is shared."</p><p>The researchers also found that task format directly triggers co-failure. When they took graduate-level science questions from the GPQA benchmark and changed them from multiple-choice to free-response formats, the all-wrong tail expanded to 12.7%.</p><p>Developers can engineer around the ceiling, though. "The engineering implication is uncomfortable: multi-model setups buy the least exactly where teams want them most, on open-ended generation," Chen said. "Anywhere you can convert generation into verification or constrained selection (structured outputs, checkable answers, execution tests), you reopen the ceiling."</p><p>Ultimately, the researchers found this ceiling limits AI applications in two distinct ways, depending on the domain:</p><ul><li><p><b>Ceiling-bound environments (e.g., open-ended math):</b> The co-failure rate is high. The task is too hard, and all models fail simultaneously. No amount of routing can bypass the lack of underlying capability.</p></li><li><p><b>Realizability-bound environments (e.g., graduate-level science):</b> The co-failure rate is near zero, meaning at least one model in the pool usually knows the answer. However, the models disagree so subtly that a routing layer cannot reliably pick the correct answer without an omniscient oracle.</p></li></ul><h2>The $0 pre-deployment sanity check</h2><p>Before dedicating engineering hours to building a router, teams can calculate their absolute performance ceiling for free using a mathematical formula called a Clopper-Pearson bound.</p><p>The Clopper-Pearson bound operates as a worst-case scenario calculator. If you flip a coin ten times and get eight heads, you cannot guarantee the coin will land on heads 80% of the time forever. The bound takes a small sample of test questions and outputs a mathematically guaranteed ceiling.</p><p>Applied to language models, suppose a team tests a pool of five agents on 50 sample queries and finds they all fail together on just two questions. A developer might assume their multi-agent system will achieve 96% accuracy in production. The Clopper-Pearson formula corrects this optimism. It analyzes the small sample size and provides a mathematical guarantee that the true co-failure rate could actually be as high as 12%.</p><p>To use this in practice, enterprises must build a held-out dataset. A fintech company, for example, could take 200 complex customer support tickets from the previous quarter and have human agents write perfect resolutions to serve as a benchmark. While this sounds like a heavy manual project, mature engineering teams can automate the entire ceiling calculation.</p><p>"Integration is trivial: it's a counting job over eval logs teams already produce," Chen notes, "so it runs in the same CI stage as the eval suite and re-triggers whenever the model pool or the workload changes."</p><p>The engineering team then runs its candidate models against these 200 tickets once and records the results. When they want to evaluate multi-model configurations, they can use the co-failure rate measure to predict the maximum accuracy they can get from the system without running extra queries.</p><p>One important conclusion the study draws is that on tasks where answers can be definitively checked, combining models rarely beats using the single best model on the market, unless the team possesses an exceptionally strong query-level routing signal.</p><p>In an enterprise environment, a definitively checked task has an objective, zero-tolerance answer. This includes generating a SQL query that must execute without error, extracting a specific invoice total from a 50-page PDF, or formatting a JSON payload that perfectly matches a strict schema. For these tasks, enterprises are usually better off paying a premium for the smartest frontier model rather than weaving together three cheaper models and hoping a router picks the correct output. The study didn't test subjective, ungraded tasks like drafting marketing copy — the authors note that whether these findings hold outside their verifiable benchmarks remains an open question.</p><p>Because this mathematical check is free, enterprise teams can track their own co-failure rates as new models drop.</p><p>"The measurement costs nothing, so any team can track its own co-failure rate across model generations and watch whether the tail is closing," says Chen. Ultimately, "the lever buyers hold is failure-mode heterogeneity and market churn, not model count."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Communities verbinden! (ds2010)]]></title>
<description><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h...]]></description>
<link>https://tsecurity.de/de/3650084/it-security-video/communities-verbinden-ds2010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650084/it-security-video/communities-verbinden-ds2010/</guid>
<pubDate>Tue, 07 Jul 2026 01:17:50 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h. über Mailinglisten, IRC oder Jabber. 

Um eine stärkere Vernetzung untereinander zu erreichen, wurde von mir 2008 das Regionaltreffen Berlin und dem Berliner Umland ins Leben gerufen. Alle Interessenten aus den verschiedenen OpenSource-Strömungen sind zu 
diesen Treffen eingeladen, um sich dabei persönlich kennenzulernen und um miteinander Wissen und Neuigkeiten auszutauschen.

In diesem Beitrag blicke ich auf zwei Jahre LUG-Treffen zurück, berichte über Erfolge und Erlebnisse und möchte damit zu ähnlichen Treffen in der Region anregen.
about this event: https://datenspuren.de/2010/fahrplan/event/4022.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Communities verbinden! (ds2010)]]></title>
<description><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h...]]></description>
<link>https://tsecurity.de/de/3650068/it-security-video/communities-verbinden-ds2010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650068/it-security-video/communities-verbinden-ds2010/</guid>
<pubDate>Tue, 07 Jul 2026 01:03:26 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h. über Mailinglisten, IRC oder Jabber. 

Um eine stärkere Vernetzung untereinander zu erreichen, wurde von mir 2008 das Regionaltreffen Berlin und dem Berliner Umland ins Leben gerufen. Alle Interessenten aus den verschiedenen OpenSource-Strömungen sind zu 
diesen Treffen eingeladen, um sich dabei persönlich kennenzulernen und um miteinander Wissen und Neuigkeiten auszutauschen.

In diesem Beitrag blicke ich auf zwei Jahre LUG-Treffen zurück, berichte über Erfolge und Erlebnisse und möchte damit zu ähnlichen Treffen in der Region anregen.
about this event: https://datenspuren.de/2010/fahrplan/event/4022.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Big Tech Now Backpedaling on the AI Jobs Wipeout Scenario?]]></title>
<description><![CDATA["A year ago, the message from many business leaders was that AI was going to wipe out jobs," remembers the Wall Street Journal.But "For the past month or so, tech CEOs have been striking a more optimistic tone."


In late May, OpenAI Chief Executive Sam Altman — who has long predicted that AI wil...]]></description>
<link>https://tsecurity.de/de/3648119/it-security-nachrichten/is-big-tech-now-backpedaling-on-the-ai-jobs-wipeout-scenario/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648119/it-security-nachrichten/is-big-tech-now-backpedaling-on-the-ai-jobs-wipeout-scenario/</guid>
<pubDate>Mon, 06 Jul 2026 09:50:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["A year ago, the message from many business leaders was that AI was going to wipe out jobs," remembers the Wall Street Journal.But "For the past month or so, tech CEOs have been striking a more optimistic tone."


In late May, OpenAI Chief Executive Sam Altman — who has long predicted that AI will lead to seismic shifts in the workforce — said during a conference, "We've been roughly right on technological predictions and pretty wrong on the social and economic implications." Soon after, he told CNBC, "Our industry underestimated how much we're going to be able to keep people at the center of everything." 

Anthropic CEO Dario Amodei, who warned in May 2025 that artificial intelligence could eliminate half of entry-level jobs, a year later highlighted more positive scenarios for AI-adopting businesses: "They can do the same thing with less resources, and that leads to things like layoffs, or they can do more with the same amount of resources. But that requires creativity...." 

Is the sunnier outlook a move to win back customers and the public who are souring on AI's world-upending promise? Or is the role of AI in the workplace now just better understood...? 

Collectively, the narrative has shifted from worker-light doomsday scenarios caused by AI to a future in which workers keep their jobs — and get a productivity boost. The sentiment change isn't limited to tech leaders: A survey by EY-Parthenon found that the percentage of CEOs who believe AI investments will result in significant reductions in head count fell from around 46% in January 2025 to just 20% this May.
"They may have noticed that the labor market is genuinely not changing (i.e., imploding) as rapidly as they expected," said David Autor, a professor of economics at the Massachusetts Institute of Technology. "They may have realized it was simply bad business to say that your great new product will destroy the economy." 

The article notes Amazon founder Jeff Bezos "has a history of predicting that AI will create new jobs," and in June said AI could even lead to a labor shortage. "When asked on CNBC in May about people being afraid of AI taking jobs, he said the reason they're afraid is because 'all these smart people keep saying that.'" 
The article then adds that "Fewer people are saying it now."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Is+Big+Tech+Now+Backpedaling+on+the+AI+Jobs+Wipeout+Scenario%3F%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F06%2F0552215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F06%2F0552215%2Fis-big-tech-now-backpedaling-on-the-ai-jobs-wipeout-scenario%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/06/0552215/is-big-tech-now-backpedaling-on-the-ai-jobs-wipeout-scenario?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mecklenburg-Vorpommern streicht jetzt erste Microsoft-Cloud-Dienste]]></title>
<description><![CDATA[Mecklenburg-Vorpommern reduziert seine Abhängigkeit von US-Tech-Konzernen und setzt in der Verwaltung verstärkt auf Open-Source-Lösungen. Während Cloud-Dienste und KI europäisch werden, bleibt ein komplettes Microsoft-Aus vorerst aus.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3645063/it-security-nachrichten/mecklenburg-vorpommern-streicht-jetzt-erste-microsoft-cloud-dienste/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645063/it-security-nachrichten/mecklenburg-vorpommern-streicht-jetzt-erste-microsoft-cloud-dienste/</guid>
<pubDate>Sat, 04 Jul 2026 10:53:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159768.html"><img hspace="5" border="0" align="left" alt="Open Source, Sourcecode, Opensource, Source Code, Open Source Software, Quelloffen, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56862.jpg"></a>
			Mecklenburg-Vorpommern reduziert seine Abhängigkeit von US-Tech-Konzernen und setzt in der Verwaltung verstärkt auf Open-Source-Lösungen. Während <a href="https://winfuture.de/special/cloud/" title="Cloud Special">Cloud-Dienste</a> und KI europäisch werden, bleibt ein komplettes Microsoft-Aus vorerst aus.			(<a href="https://winfuture.de/news,159768.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[As AI capabilities accelerate, it's easy to focus on what the technology can create.]]></title>
<description><![CDATA[Author: PQShield - Bewertung: 2x - Views:50 As AI capabilities accelerate, it's easy to focus on what the technology can create.

But as Eric Amador points out on Shielded: The Last Line of Cyber Defense:
AI is a fantastic tool to put things together, but it's not really good at creating new bric...]]></description>
<link>https://tsecurity.de/de/3643650/videos/as-ai-capabilities-accelerate-its-easy-to-focus-on-what-the-technology-can-create/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643650/videos/as-ai-capabilities-accelerate-its-easy-to-focus-on-what-the-technology-can-create/</guid>
<pubDate>Fri, 03 Jul 2026 15:18:28 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: PQShield - Bewertung: 2x - Views:50 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ukZC1Sn1Uss?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>As AI capabilities accelerate, it's easy to focus on what the technology can create.<br />
<br />
But as Eric Amador points out on Shielded: The Last Line of Cyber Defense:<br />
AI is a fantastic tool to put things together, but it's not really good at creating new bricks.<br />
<br />
Behind every AI-powered innovation are the developers, researchers, standards bodies, and open-source communities creating the foundational building blocks that make progress possible.<br />
<br />
The future of cybersecurity won't be built by AI alone. It will depend on continued investment in open standards, transparent research, quality documentation, and collaborative innovation.<br />
AI might assemble the future.<br />
Open source helps create it.<br />
<br />
What's one open-source project that has had a major impact on your work?<br />
<br />
#OpenSource #AI #CyberSecurity #Technology #Innovation #DeveloperCommunity #CyberDefense #ShieldedPodcast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t waste your next cloud outage]]></title>
<description><![CDATA[In the past year, cloud outages have exposed a hard truth about the modern digital economy: A disruption at one hyperscaler can quickly spread far beyond a single vendor’s platform. Failures in cloud control planes, identity systems, storage layers, and core regions have disrupted business operat...]]></description>
<link>https://tsecurity.de/de/3643145/ai-nachrichten/dont-waste-your-next-cloud-outage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643145/ai-nachrichten/dont-waste-your-next-cloud-outage/</guid>
<pubDate>Fri, 03 Jul 2026 11:33:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the past year, <a href="https://www.infoworld.com/article/4132902/why-cloud-outages-are-becoming-normal.html" data-type="link" data-id="https://www.infoworld.com/article/4132902/why-cloud-outages-are-becoming-normal.html">cloud outages</a> have exposed a hard truth about the modern digital economy: A disruption at one hyperscaler can quickly spread far beyond a single vendor’s platform. Failures in cloud control planes, <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity systems</a>, storage layers, and core regions have disrupted business operations, developer workflows, and consumer services worldwide. From Google Cloud’s internetwide disruption to repeated outages at AWS and Microsoft Azure, the pattern is now impossible to ignore. As organizations deepen their dependence on a small number of providers, resilience, redundancy, and contingency planning are becoming strategic necessities rather than purely technical concerns. Just consider this list of recent sizeable outages in the past year alone:</p>



<ul class="wp-block-list">
<li><strong>Google Cloud, June 12, 2025:</strong> Google Cloud suffered a major outage that disrupted its own services and rippled across the internet, affecting platforms including Spotify and other downstream applications.</li>



<li><strong>AWS, October 20, 2025:</strong> AWS experienced a significant outage linked to a network health monitor issue, disrupting businesses worldwide and, once again, underscoring the concentration risk surrounding its US-East-1 region.</li>



<li><strong>Microsoft Azure, October 29, 2025:</strong> Azure’s global outage generated more than 18,000 user reports at its peak. It was tied to a configuration change in Azure Front Door’s global control plane.</li>



<li><strong>Microsoft Azure, February 2–3, 2026:</strong> Azure endured another major outage lasting more than 10 hours after a misconfiguration in Microsoft-managed storage accounts triggered cascading failures across virtual machine operations and managed identities.</li>



<li><strong>AWS, May 2026:</strong> AWS was hit by a serious US-East-1 outage caused by a thermal event and power loss at a Virginia data center, impairing core services including EC2 and EBS.</li>
</ul>



<p>What once seemed exceptional is now a regular occurrence that organizations must accept as part of doing business in the cloud. This normalization of infrastructure-layer failures should concern every technology leader who has been told that the cloud is the reliable, enterprise-grade foundation for their <a href="https://www.cio.com/article/230425/what-is-digital-transformation-a-necessary-disruption.html">digital transformation</a> initiatives.</p>



<h2 class="wp-block-heading">A staggering financial impact</h2>



<p>The financial impact of these outages on enterprises is substantial and often underestimated. When a cloud platform goes down, companies lose revenue in direct proportion to the outage’s duration and their reliance on the affected services. For large enterprises processing millions of transactions per hour, even a two-hour outage can cost tens of millions of dollars in lost revenue. Beyond direct losses, there are reputational damages, customer churn, and the operational costs of <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">incident response</a> and recovery.</p>



<p>When your e-commerce platform goes down during a peak shopping period, you don’t just lose the sales from that two-hour window. You lose customer trust that extends well beyond the outage itself. When your enterprise collaboration tools become unavailable, productivity grinds to a halt across your entire organization. When your data processing pipeline stalls, downstream analytical capabilities that drive critical business decisions are delayed or entirely compromised. The true cost of a cloud outage extends far beyond the immediate period of unavailability.</p>



<h2 class="wp-block-heading">SLAs don’t help much</h2>



<p>Many enterprise tech leaders are frustrated by their limited recourse during outages. Cloud service-level agreements (SLAs) often offer service credits that are far below actual damages. These agreements also usually absolve providers of responsibility for indirect or consequential damages, subject to a cap that rarely reflects the true cost of an outage.</p>



<p>In essence, enterprises are being asked to trust platforms they don’t control with business-critical operations, while accepting terms that provide minimal protection when things go wrong. This fundamentally imbalanced relationship favors the provider at the customer’s expense.</p>



<h2 class="wp-block-heading">Resilient architecture</h2>



<p>This situation demands a fundamental shift in how enterprises approach cloud architecture and infrastructure planning. The days of simply migrating everything to a single hyperscaler and assuming reliability will follow are over. Organizations need to deliberately build resilience into their platforms by embracing architectural approaches that reduce dependence on any single provider or service.</p>



<p>A hybrid architecture that combines cloud-based and on-premises infrastructure enables organizations to shift workloads during outages while maintaining control of critical systems. Similarly, a multicloud strategy that distributes applications and data across multiple providers reduces the blast radius of any single provider’s failure. These approaches, without question, introduce complexity and require more sophisticated management tools and operational expertise. However, the alternative—accepting that your business continuity depends entirely on the reliability of platforms you cannot control—is increasingly untenable.</p>



<p>The challenge is that achieving resilience through heterogeneity introduces management complexity that many organizations are not prepared to handle. Using multiple cloud providers and on-premises infrastructure requires learning different operational models, maintaining diverse skill sets, and managing different tools across your environment. Licensing costs, integration efforts, and ongoing operational overhead are significant.</p>



<p>However, the organizations that invest in this complexity will be better positioned to maintain business continuity when the next major cloud failure inevitably occurs. The question is not whether you can afford to invest in resilience, but whether you can afford not to.</p>



<h2 class="wp-block-heading">Three things to do now</h2>



<p>The practical reality is that organizations cannot simply wait for cloud providers to solve this problem. The economics of the industry make it unlikely that service-level agreements will become significantly more favorable to customers. The complexity of modern cloud infrastructure means that outages will continue to occur regardless of the investments providers make in reliability. Therefore, enterprises must take responsibility for their own resilience.</p>



<p>Here are the three things enterprises should be doing right now:</p>



<p><strong>First, enterprises should conduct a comprehensive audit</strong> of their cloud dependencies to identify single points of failure across their architecture. This means mapping every application, data store, and integration point to determine exactly what would happen if a specific cloud service went offline. Most organizations discover they have far more dependencies on a single provider than they realized, and many of those dependencies are undocumented. An audit will serve as the foundation for a deliberate resilience strategy that prioritizes redundancy for the most critical systems. </p>



<p><strong>Second, enterprises should implement a hybrid architecture</strong> that incorporates on-premises infrastructure for their most critical workloads. Mission-critical systems must have an alternative path to operation when cloud services fail. The key is to identify which systems truly require this level of protection and which can tolerate cloud-only deployment. A phased approach that starts with the most sensitive workloads and expands over time allows organizations to build expertise with <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid systems</a> and refine their processes as they go.</p>



<p><strong>Third, enterprises must establish formal disaster-recovery testing procedures</strong> that specifically target cloud provider outages rather than traditional site failures. Most organizations test their disaster recovery capabilities against scenarios such as a data center failure or a natural disaster, but they rarely test what happens when a cloud API becomes unresponsive or a cloud region goes dark. Regular testing of these scenarios will expose gaps in the architecture that might otherwise remain hidden until an actual outage occurs.</p>



<p>Here’s the bottom line: Don’t put all your eggs in a single basket. Accept that cloud platforms will continue to fail, and plan your architecture accordingly. The investment in resilience will pay for itself the next time your primary cloud provider experiences an outage. Your competitors will be scrambling while your business continues to operate.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Fable 5, KI-Agenten & Open Source: Die wichtigsten KI-News Q2 2026 | INSIDE AI #37]]></title>
<description><![CDATA[Author: Fraunhofer IEM - Bewertung: 3x - Views:23 In der 37. Episode von Inside AI ordnet KI-Experte Tommy Falkowski die wichtigsten Entwicklungen aus der Welt der Künstlichen Intelligenz im zweiten Quartal 2026 ein.

Im Mittelpunkt stehen das neue Claude-Fable-5-Modell von Anthropic, Diskussione...]]></description>
<link>https://tsecurity.de/de/3643002/videos/claude-fable-5-ki-agenten-open-source-die-wichtigsten-ki-news-q2-2026-inside-ai-37/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643002/videos/claude-fable-5-ki-agenten-open-source-die-wichtigsten-ki-news-q2-2026-inside-ai-37/</guid>
<pubDate>Fri, 03 Jul 2026 10:18:09 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Fraunhofer IEM - Bewertung: 3x - Views:23 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WqrwhtfSsuo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In der 37. Episode von Inside AI ordnet KI-Experte Tommy Falkowski die wichtigsten Entwicklungen aus der Welt der Künstlichen Intelligenz im zweiten Quartal 2026 ein.<br />
<br />
Im Mittelpunkt stehen das neue Claude-Fable-5-Modell von Anthropic, Diskussionen rund um Sicherheitsrisiken und Exportbeschränkungen sowie die Frage, welche Auswirkungen leistungsfähigere KI-Modelle auf Unternehmen und Europa haben. Darüber hinaus geht es um den aktuellen Trend zu Agentic Loops und autonomen KI-Agenten, wirtschaftliche Herausforderungen durch steigende Token-Kosten, die Profitabilität großer KI-Unternehmen sowie neue Open-Source-Modelle als mögliche Alternative zu kommerziellen Angeboten.<br />
<br />
Tommy Falkowski<br />
🔗 LinkedIn: https://www.linkedin.com/in/tommy-falkowski/<br />
<br />
Überblick<br />
<br />
0:00 – Einführung: KI-Druckbetankung Q2 2026<br />
0:30 – Claude Fable 5: Leistungsfähigkeit, Sicherheit und Exportbeschränkungen<br />
5:17 – Agentic Loops: Der neue Trend autonomer KI-Agenten<br />
8:38 – Praxisbeispiele für Loop Engineering und Coding-Agenten<br />
10:03 – Token-Kosten und wirtschaftliche Herausforderungen für Unternehmen<br />
14:35 – Sind OpenAI und Anthropic langfristig profitabel?<br />
17:31 – Neue Open-Source-Modelle: GLM 5.2 und Kimi K2-7<br />
19:31 – Warum Europa eigene KI-Modelle benötigt<br />
21:17 – Fazit und Diskussion: Wie sinnvoll sind autonome KI-Agenten?<br />
<br />
📺 Abonniere unseren YouTube-Kanal:<br />
https://www.youtube.com/@fraunhoferiem<br />
<br />
Mehr erfahren & vernetzen:<br />
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem<br />
📸 Instagram: https://www.instagram.com/fraunhofer.iem<br />
📩 Newsletter: https://www.iem.fraunhofer.de/newsletter<br />
<br />
#KI #Claude #Anthropic #OpenAI #GenerativeAI #AIAgents #OpenSource #FraunhoferIEM<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[You Ruled Yourself Out Too Soon]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 Early interest in technology and cybersecurity didn’t automatically turn into confidence. At eighteen, the assumption was that a career in cyber “probably wasn’t in the cards,” despite the interest already being there.

That minds...]]></description>
<link>https://tsecurity.de/de/3641407/it-security-video/you-ruled-yourself-out-too-soon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641407/it-security-video/you-ruled-yourself-out-too-soon/</guid>
<pubDate>Thu, 02 Jul 2026 16:04:05 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/pb3ZKkwAIc0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Early interest in technology and cybersecurity didn’t automatically turn into confidence. At eighteen, the assumption was that a career in cyber “probably wasn’t in the cards,” despite the interest already being there.<br />
<br />
That mindset is common across industries. People often eliminate themselves from opportunities long before failure ever happens. In fast-moving fields like cybersecurity, curiosity and persistence can matter just as much as traditional credentials or early certainty.<br />
<br />
The bigger risk may not be trying and failing — it may be deciding too early that you were never capable in the first place.<br />
<br />
Leaning into strengths and interests earlier can completely change long-term growth, fulfillment, and career direction.<br />
<br />
How many people walk away from careers they would’ve loved simply because they underestimated themselves too soon?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#CareerGrowth #Motivation #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shadow agents: How IT leaders must govern ‘headless’ AI before it breaks the enterprise]]></title>
<description><![CDATA[Earlier this year, I was running my own local AI agent, a system I built called LaptopAI-Agent, which uses a LangGraph reasoning loop, a local Ollama model and a set of tools that can read files, query my git repositories and monitor system processes, all running entirely on my laptop with no clo...]]></description>
<link>https://tsecurity.de/de/3638078/it-security-nachrichten/shadow-agents-how-it-leaders-must-govern-headless-ai-before-it-breaks-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638078/it-security-nachrichten/shadow-agents-how-it-leaders-must-govern-headless-ai-before-it-breaks-the-enterprise/</guid>
<pubDate>Wed, 01 Jul 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Earlier this year, I was running my own local AI agent, a system I built called LaptopAI-Agent, which uses a LangGraph reasoning loop, a local Ollama model and a set of tools that can read files, query my git repositories and monitor system processes, all running entirely on my laptop with no cloud calls. I had given it a broad task and walked away. When I came back, it had completed the work. Every file it touched was within its allowed paths. Every action was technically correct.</p>



<p>What unsettled me was not what the agent had done. It was that I could not reconstruct the sequence of decisions that led to it. Without the SHA-256 chained audit log I had deliberately built in, I would have had no record of why the agent made each choice, only what it produced. That gap between visible outcomes and invisible reasoning is what I had to engineer around for a single-user personal tool. Enterprises face the same problem at the scale of thousands of agents, with far less instrumentation.</p>



<p>This is what I mean by shadow agents: autonomous AI processes that operate at the API layer, chain tools together and complete multi-step workflows without logging in, generating session records, or waiting for a human to approve. They already run inside enterprise systems today. The governance infrastructure to manage them is, in most cases, far behind.</p>



<p>The question is no longer whether your organization will run these autonomous processes. It already does. The question is whether you can see what they are doing.</p>



<h2 class="wp-block-heading">The economics that opened the door</h2>



<p>The immediate catalyst for this shift is financial. Enterprise teams that embedded frontier AI models from providers like OpenAI and Anthropic into everyday workflows quickly discovered that per-token cloud inference costs compound fast once agents run autonomously, making hundreds of API calls per task rather than one.</p>



<p>The industry response has been a push toward local AI processing. <a href="https://blog.google/innovation-and-ai/technology/developers-tools/introducing-gemma-4-12b/" rel="nofollow">Google’s Gemma 4 12B</a>, released in June 2026, is the clearest signal yet. Designed to run on consumer-grade hardware with just 16GB of VRAM, it brings multimodal AI, covering text, audio and visual processing, fully local to enterprise laptops without any cloud API dependency. Apache 2.0 licensing means any organization can deploy it without per-token fees.</p>



<p>For finance teams, this is cost relief. For IT governance teams, it is a new category of exposure. When inference moves onto thousands of distributed laptops, centralized telemetry disappears. The natural network choke points that monitoring tools rely on vanish with it. Without visibility infrastructure built before rollout, IT has no reliable way to know what those agents are accessing or deciding in the organization’s name.</p>



<h2 class="wp-block-heading">The visibility gap is structural</h2>



<p>Every monitoring tool, security scanner and compliance platform most enterprises rely on was designed to track human behavior: logins, session durations and file accesses triggered by a person at a keyboard. The implicit assumption in all of it is that a human is somewhere in the loop, generating observable signals.</p>



<p>Agentic AI generates none of those signals. It operates at the API layer, bypasses the user interface entirely, retrieves context from data stores, reasons over it and takes action. It does not log in. It produces no session record.</p>



<p>Box’s <a href="https://www.businesswire.com/news/home/20260402112577/en/Box-Unveils-the-Box-Agent-to-Transform-How-Enterprises-Work-With-Content" rel="nofollow">April 2026 launch of the Box Agent</a> shows exactly how fast enterprise software is moving in this direction. The Box Agent works natively on the enterprise content layer, respecting existing permissions and compliance controls while it autonomously searches, summarizes and routes documents. That is solid engineering for business teams. It also means that contract reviews, approval chains and regulatory filings can now be executed by an agent that leaves no login trace in the monitoring systems IT manages.</p>



<p>The compliance consequence is real. An agent can chain tools in ways that move sensitive data from a secured internal store to an external processing endpoint because the agent found the connection useful, all within valid permissions, with no single step appearing suspicious and no record in any system IT is watching. The violation happens in the reasoning layer.</p>



<h2 class="wp-block-heading">A new role: The forward-deployed AI engineer</h2>



<p>Closing the governance gap requires a type of technical talent that most enterprise IT teams have not hired for. I have been calling this the forward-deployed AI engineer, a distinct role from DevOps.</p>



<p>A DevOps engineer asks whether the system is up. A forward-deployed AI engineer asks whether the agent is doing what was intended and only that. Their work covers three areas.</p>



<p>The first is prompt governance. The instructions that drive agent behavior function as code. They need version control, hardening against prompt injection attacks and rigorous re-testing after every model update. A prompt producing correct output in January can behave differently after a model version change in March, with no external indication that anything shifted.</p>



<p>The second is guardrail design: defining in technical terms what each agent is permitted to access, which external systems it may contact and which categories of action, financial transactions, credential access, outbound data transfers require human authorization before the agent can proceed.</p>



<p>The third is RAG pipeline governance. Enterprise agents typically access corporate knowledge through Retrieval-Augmented Generation pipelines. Scoping those pipelines correctly and auditing them on a consistent schedule is one of the most underestimated security responsibilities in agentic deployment. Overly permissive retrieval creates data exposure paths that are hard to detect until something has already gone wrong.</p>



<h2 class="wp-block-heading">Runtime isolation: The right security model for agents</h2>



<p>The architectural shift required here is from perimeter defense to runtime isolation. Perimeter defense assumes you control what enters the environment. When agents run locally, call external APIs dynamically and chain tools based on autonomous reasoning, the perimeter boundary is no longer a meaningful control surface.</p>



<p>Microsoft’s <a href="https://learn.microsoft.com/en-us/agent-framework/workflows/advanced/agent-executor" rel="nofollow">Agent Executor</a>, part of the Microsoft Agent Framework, provides a practical model here. The Agent Executor wraps an agent in a sandboxed runtime that manages session state, conversation context and tool permission boundaries within a controlled envelope. An agent inside a properly configured executor cannot reach unauthorized systems or take unapproved actions regardless of what the model decides to do. The security guarantee shifts from trusting the model’s output to controlling what it is allowed to execute. For any organization under compliance mandates, that distinction between trust and control is not a nuance; it is the design requirement.</p>



<h2 class="wp-block-heading">Governing at scale: The multi-agent challenge</h2>



<p>One sandboxed agent with clear guardrails is manageable. A fleet of coordinating agents with distinct permissions, running simultaneously across cloud, desktop and on-premises environments, is a qualitatively different problem that requires dedicated infrastructure.</p>



<p>Automation Anywhere’s <a href="https://www.prnewswire.com/news-releases/automation-anywhere-collaborates-with-cisco-nvidia-okta-and-openai-launching-enterpriseclaw-to-run-next-generation-ai-agents-inside-enterprise-systems-302775670.html" rel="nofollow">EnterpriseClaw</a>, launched in May 2026 with Cisco, NVIDIA, Okta and OpenAI as partners, is the most comprehensive platform I have seen address this. NVIDIA contributes OpenShell, an open-source runtime for deploying autonomous agents safely, plus NIM microservices with Nemotron models for on-premises customers. Okta handles cross-agent identity management and policy enforcement across the entire agent fleet. Cisco AI Defense provides an agent-specific threat detection layer that conventional network monitoring cannot replicate. OpenAI enables production workflows on its latest models, including GPT-5.5.</p>



<p>The platform gives IT a single governance surface: centralized policy, behavioral monitoring and auditable observability across every agent regardless of where it runs. The core principle is that no agent, cloud-hosted or running locally on a laptop, operates outside a defined policy boundary. EnterpriseClaw is currently in preview, with general availability expected later in 2026.</p>



<h2 class="wp-block-heading">Accountability cannot be an afterthought</h2>



<p>Building governance into LaptopAI-Agent took deliberate effort: a permission guard with path allowlists, blocked commands, manual approval triggers and a chained audit log. That overhead for a personal tool on a single laptop previews what enterprises face at an orders-of-magnitude larger scale, across systems they did not build and agents they did not deploy themselves.</p>



<p>The tools are available. The architectural patterns are documented. What is missing in most organizations is the deliberate decision to build governance in parallel with deployment, not as remediation after the first incident.</p>



<p>Every shadow agent in your environment was approved somewhere, by someone, for a specific purpose. The question is whether you still have a current, verifiable line from that approval to what the agent is doing right now. If the answer is no, or we are not sure, that is exactly where the work needs to start.</p>



<p>Shadow agents are not a future problem. They are in production today, summarizing documents, routing decisions and interacting with systems your monitoring tools cannot observe. IT leaders who build real accountability infrastructure around them will be positioned to harness autonomous AI with confidence. The ones who wait will spend their time explaining, after the fact, how something happened that nobody could see.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is exposing the real limits of enterprise cloud strategy]]></title>
<description><![CDATA[Across the global corporations, I advise, in financial services, healthcare, retail and the public sector, the same crisis surfaces in leadership meetings. Executives approved a bold AI roadmap. Cloud spending climbed 40, 50, even 70 percent. And yet the AI workloads that made perfect sense in th...]]></description>
<link>https://tsecurity.de/de/3635329/it-security-nachrichten/ai-is-exposing-the-real-limits-of-enterprise-cloud-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635329/it-security-nachrichten/ai-is-exposing-the-real-limits-of-enterprise-cloud-strategy/</guid>
<pubDate>Tue, 30 Jun 2026 13:06:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Across the global corporations, I advise, in financial services, healthcare, retail and the public sector, the same crisis surfaces in leadership meetings. Executives approved a bold AI roadmap. Cloud spending climbed 40, 50, even 70 percent. And yet the AI workloads that made perfect sense in the boardroom presentation now stall, overshoot their budgets or collapse under production load before they reach real users.</p>



<p>I am writing this just after the spring 2026 conference season, and the signal from <a href="https://cloud.google.com/blog/topics/google-cloud-next/google-cloud-next-2026-wrap-up" rel="nofollow">Google Cloud Next</a>, <a href="https://news.microsoft.com/build-2026/" rel="nofollow">Microsoft Build</a>, and a run of <a href="https://aws.amazon.com/events/summits/" rel="nofollow">AWS summits</a> only sharpens the point. Over the past several weeks the industry shipped, in production form, the infrastructure to run and govern AI at scale. What most enterprises still lack is the operating model to decide how to use it.</p>



<p>The problem is not the AI models. The models work. The problem is that organizations built their AI ambitions on cloud strategies designed for a world that no longer exists: strategies built for SaaS applications, predictable traffic and linear cost curves. AI workloads break all three assumptions at once.</p>



<h2 class="wp-block-heading">Why AI breaks traditional cloud assumptions</h2>



<p>For a decade, cloud-first served enterprises well. It delivered elasticity, reduced capital expenditure and democratized access to compute, because enterprise workloads were predictable: web applications, ERP systems, databases and analytics pipelines that scaled smoothly and billed in ways finance could model on a spreadsheet. GenAI and agentic AI change every one of those assumptions at once.</p>



<p>When organizations move AI into production, real inference, retrieval pipelines, vector search and real-time decisioning, the cloud equation breaks in at least five ways:</p>



<ol class="wp-block-list">
<li>Training clusters demand power densities far above standard compute.</li>



<li>Inference needs millisecond latency that network geography can defeat.</li>



<li>Vector databases generate cost spikes invisible in standard billing.</li>



<li>Agentic workloads chain hundreds of tool calls with cascading dependencies.</li>



<li>And data-sovereignty rules constrain where any of them can run.</li>
</ol>



<p>In short, what works at the platform level fails at the workload level.</p>



<p>The costs are the first thing to surprise leaders, because they hide. <a href="https://www.cloudzero.com/blog/ai-cost-management/" rel="nofollow">CloudZero’s analysis</a> and the FinOps teams I work with put it plainly: AI spend surfaces as generic compute, storage and instance line items, rarely labeled “AI.” Three layers drive most of the waste:</p>



<ol class="wp-block-list">
<li>The most visible is LLM API cost, where stateless calls re-send the full conversation history on every request, so a deployment with a couple hundred users can burn many times the token budget in the business case.</li>



<li>The biggest is idle GPU: teams’ provision for peak and then run at 10 to 20 percent utilization, and most miss their AI cost forecasts by more than a quarter.</li>



<li>The most underestimated is the vector database and retrieval layer, where storage I/O, query volume and embedding refresh appear nowhere labeled AI until the bill arrives.</li>
</ol>



<h2 class="wp-block-heading">The dimensions leaders underweight resilience and control</h2>



<p>Cost and latency dominate the conversation. Two dimensions rarely get the same rigor until something breaks:</p>



<ol class="wp-block-list">
<li>Resilience, whether an AI-dependent system can survive failure, degrade gracefully and recover predictably.</li>



<li>Control, who can observe, halt and audit it.</li>
</ol>



<p>AI introduces failure modes that traditional architecture never faced: GPU single points of failure under revenue-critical inference, agentic pipelines that fail mid-execution with no rollback, and models that degrade silently from drift or throttling.</p>



<p>I see the pattern repeated across industries. Organizations design resilience for their traditional applications, then deploy AI on top without asking whether the same guarantees hold. In one global financial services firm I advise, a real-time credit-decisioning model running on a single cloud region took a 47-minute outage during a regional availability event. The halted loan approvals cost more than the system’s entire annual infrastructure budget, and the resilience rework that followed cost several times what designing it in from the start would have. The leaders who avoid this should ask four questions before go-live:</p>



<ol class="wp-block-list">
<li>What happens when the network fails?</li>



<li>What happens when the model degrades?</li>



<li>What happens when an agent executes only halfway?</li>



<li>Who holds the authority to halt and audit?</li>
</ol>



<h2 class="wp-block-heading">What the cloud providers signaled this spring</h2>



<p>The major providers are on track to spend <a href="https://www.statista.com/chart/35046/capital-expenditure-of-meta-alphabet-amazon-and-microsoft/" rel="nofollow">close to $700 billion on AI infrastructure in 2026</a>, roughly three and a half times the 2024 level. Their announcements are strategic signals, not just features. Last year they converged on one message: enterprises cannot run everything in public cloud, so all three built ways to bring their infrastructure into your data center and your sovereign environment. This year the signal advanced a step. They stopped talking about where workloads run and started shipping the layer that governs what agents are allowed to do: identity, containment, auditability and rollback.</p>



<p>Microsoft introduced an “Agent Computer” model with execution containers and machine identity for agents. AWS built <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025/" rel="nofollow">Amazon Bedrock AgentCore</a> around runtime, memory, identity and auditability. Google shipped an agent gateway and sovereign controls for cross-cloud traffic. As <a href="https://www.bain.com/insights/google_cloud_next_2026_the_agentic_enterprise_control_plane_comes_into_view/" rel="nofollow">Bain observed</a>, agentic AI is now an economics and operations problem, not just a capability problem. The through-line, captured by Microsoft’s own framing, is that AI alone will not change your business; the system running it will. <a href="https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/the-next-big-shifts-in-ai-workloads-and-hyperscaler-strategies" rel="nofollow">McKinsey’s read</a> is consistent: workloads are becoming more distributed, specialized and operationally demanding, which forces more deliberate infrastructure decisions.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/hyperscaler-convergence-spring-2026.png?w=1024" alt="Hyperscaler convergence, Spring 2026." class="wp-image-4190723" width="1024" height="557" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<h2 class="wp-block-heading">From platform choice to placement decision</h2>



<p>The failure I document most often is not a technology failure; it is a governance failure. Most enterprises lack a clear, repeatable way to decide what runs where, under what conditions and with what tradeoffs. Platform teams make that call informally, under deadline pressure and repeat it hundreds of times as new use cases launch. Workloads then accumulate in public cloud by default, not by design and 30 to 50 percent cost overruns follow, not because public cloud was the wrong choice but because no deliberate choice was ever made.</p>



<p>In one global manufacturer I advise, a predictive-maintenance model went live on public cloud and performed exactly as validated in staging. But real-time inference on the factory floor ran at 80 to 120 milliseconds across the WAN, when the machine-control system needed under ten. Moving the model to edge nodes fixed the latency, but the company lost most of a quarter of the cost, rework and delayed benefits, and the line had run for weeks on stale recommendations: a control failure that could have caused a safety event. The fix was never more AI talent. It was a structured placement decision at the start, weighing six dimensions:</p>



<ul class="wp-block-list">
<li><strong>Latency: </strong>real-time (under 10 ms, edge or on-prem), interactive (50 to 500 ms, cloud) or batch.</li>



<li><strong>Cost and TCO: </strong>token spend, GPU utilization, vector-database queries, egress and unit economics per workload.</li>



<li><strong>Resilience: </strong>failover architecture, degraded-mode behavior, recovery SLA and rollback policy.</li>



<li><strong>Control: </strong>observability, audit trails, governance authority and the ability to halt or reverse.</li>



<li><strong>Data sensitivity: </strong>sovereignty requirements, privacy and compliance rules, and IP protection.</li>



<li><strong>Integration: </strong>legacy system dependencies, pipeline complexity and data-residency constraints.</li>
</ul>



<p>Run consistently, those dimensions produce a placement pattern like this:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Workload</strong></td><td><strong>Latency</strong></td><td><strong>Cost predictability</strong></td><td><strong>Data sovereignty</strong></td><td><strong>Recommended path</strong></td></tr></thead><tbody><tr><td><strong>Customer-facing chatbot</strong></td><td>200-500 ms</td><td>Medium</td><td>Low risk</td><td>Public cloud, reserved instances</td></tr><tr><td><strong>Real-time fraud detection</strong></td><td>Under 10 ms</td><td>Medium</td><td>High</td><td>On-prem or sovereign private cloud</td></tr><tr><td><strong>Clinical decision support</strong></td><td>100-300 ms</td><td>Predictable</td><td>Critical</td><td>Sovereign cloud or dedicated VPC</td></tr><tr><td><strong>Demand forecasting (batch)</strong></td><td>Hours</td><td>High</td><td>Low risk</td><td>Spot instances or scheduled cloud</td></tr><tr><td><strong>Factory-floor vision AI</strong></td><td>Under 5 ms</td><td>Predictable</td><td>Medium</td><td>Edge node (Azure Local, AWS on-prem)</td></tr><tr><td><strong>Internal knowledge assistant</strong></td><td>1-3 sec</td><td>Variable tokens</td><td>High (IP risk)</td><td>Private cloud with on-prem retrieval</td></tr></tbody></table> </div></figure>



<p>This is no longer optional. <a href="https://www.storagenewsletter.com/2026/03/11/enterprise-survey-finds-93-are-repatriating-ai-workloads-or-evaluating-a-move-away-from-public-cloud/" rel="nofollow">Cloudian’s 2026 enterprise AI infrastructure survey</a> found that 79 percent of enterprises have already moved AI workloads out of public cloud, and 93 percent are repatriating or actively evaluating it, driven by data sovereignty, cost overruns and real-time performance. Repatriation is now the norm, not the exception.</p>



<p>The agentic layer makes discipline urgent. An agent chains 20 to 100 tool calls, each with its own latency, cost and failure mode, so the governance model that works for a chatbot does not work for an autonomous agent approving procurement or onboarding a customer. This spring the providers shipped production infrastructure for exactly this, yet <a href="https://www.deloitte.com/global/en/issues/generative-ai/state-of-ai-in-enterprise.html" rel="nofollow">Deloitte’s 2026 survey</a> of more than 3,000 leaders finds only about one in five companies has a mature governance model for autonomous agents. The platforms solved the mechanism. Most enterprises have not yet written the policy.</p>



<h2 class="wp-block-heading">What the leaders do differently</h2>



<p>The organizations extracting compounding value from AI, not just running experiments, share one discipline: they treat workload placement as a repeatable process, and they build resilience and control in from the start rather than after the first production incident. In practice, they do five things:</p>



<ol class="wp-block-list">
<li>Classify every use case at intake across the six dimensions, before any infrastructure is provisioned.</li>



<li>Separate AI budget lines for experiments, production inference and training, so cost is governable.</li>



<li>Treat unit economics, cost per inference, per query and per agent run, as engineering KPIs, not month-end surprises.</li>



<li>Define repatriation triggers in advance, typically 12 to 18 months of stable volume.</li>



<li>Write an explicit resilience contract, and agentic observability and rollback rules, before scaling.</li>
</ol>



<p>The gap between strategy-ready and infrastructure-ready is the remediation backlog, and most enterprises stall moving from proof of concept to production for exactly this reason. <a href="https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2026/ai-infrastructure-compute-strategy.html" rel="nofollow">Deloitte’s tech-trends analysis</a> frames the same shift as the move to inference economics: the bottleneck is infrastructure governance, not model capability.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ai-governance.png?w=1024" alt="AI infrastructure maturity: The governance gap." class="wp-image-4190724" width="1024" height="555" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<p><strong>For CIOs, a 90-day agenda. </strong>Five actions separate the leaders from those managing infrastructure crises:</p>



<ol class="wp-block-list">
<li>Audit every AI workload in production across latency, cost, sovereignty, volume, resilience, control and integration.</li>



<li>Separate AI infrastructure budget lines so each workload type is attributable and governable.</li>



<li>Define unit economics by workload and review them as engineering KPIs.</li>



<li>Set a quantitative repatriation evaluation trigger.</li>



<li>Define observability, cost attribution and rollback policy before scaling agents.</li>
</ol>



<h2 class="wp-block-heading">The strategic reframe</h2>



<p>The organizations making real progress on AI are not distinguished by the sophistication of their models or the size of their cloud contracts. One discipline sets them apart: a clear, repeatable way to decide what runs where, under what conditions, with what tradeoffs and what happens when something fails. That discipline is not an IT problem. It is a strategic capability that requires CIO ownership, CFO alignment and executive accountability.</p>



<p>This spring the cloud providers handed enterprises the infrastructure to run and govern AI, and agents, at every tier of the architecture. The gap is no longer supply. It is the operating model to use deliberately. The companies building that model now build the operating foundation for AI at scale. Everyone else builds a remediation backlog. The infrastructure decisions you make in the next 12 months will decide which of those two you become.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61028 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1233)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in openlink virtuoso-opensource 7.2.11. This impacts an unknown function. The manipulation results in denial of service.

This vulnerability is cataloged as CVE-2025-61028. The attack may be launched remotely. There is no exploit ava...]]></description>
<link>https://tsecurity.de/de/3629760/sicherheitsluecken/cve-2025-61028-openlink-virtuoso-opensource-7211-denial-of-service-issue-1233/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629760/sicherheitsluecken/cve-2025-61028-openlink-virtuoso-opensource-7211-denial-of-service-issue-1233/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This impacts an unknown function. The manipulation results in denial of service.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2025-61028">CVE-2025-61028</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61019 | openlink virtuoso-opensource 7.2.11 sqlo_key_part_best denial of service (Issue 1222)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in openlink virtuoso-opensource 7.2.11. This affects an unknown part of the component sqlo_key_part_best. The manipulation leads to denial of service.

This vulnerability is uniquely identified as CVE-2025-61019. The attack is possible t...]]></description>
<link>https://tsecurity.de/de/3629756/sicherheitsluecken/cve-2025-61019-openlink-virtuoso-opensource-7211-sqlokeypartbest-denial-of-service-issue-1222/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629756/sicherheitsluecken/cve-2025-61019-openlink-virtuoso-opensource-7211-sqlokeypartbest-denial-of-service-issue-1222/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This affects an unknown part of the component <em>sqlo_key_part_best</em>. The manipulation leads to denial of service.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2025-61019">CVE-2025-61019</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61023 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1230)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in openlink virtuoso-opensource 7.2.11. The affected element is an unknown function. Performing a manipulation results in denial of service.

This vulnerability is identified as CVE-2025-61023. The attack can be initiated remotely. There is...]]></description>
<link>https://tsecurity.de/de/3629754/sicherheitsluecken/cve-2025-61023-openlink-virtuoso-opensource-7211-denial-of-service-issue-1230/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629754/sicherheitsluecken/cve-2025-61023-openlink-virtuoso-opensource-7211-denial-of-service-issue-1230/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. The affected element is an unknown function. Performing a manipulation results in denial of service.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2025-61023">CVE-2025-61023</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61021 | openlink virtuoso-opensource 7.2.11 sqlo_natural_join_cond denial of service (Issue 1223)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in openlink virtuoso-opensource 7.2.11. This issue affects some unknown processing of the component sqlo_natural_join_cond. This manipulation causes denial of service.

The identification of this vulnerability is CVE-2025-61021. It is possib...]]></description>
<link>https://tsecurity.de/de/3629753/sicherheitsluecken/cve-2025-61021-openlink-virtuoso-opensource-7211-sqlonaturaljoincond-denial-of-service-issue-1223/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629753/sicherheitsluecken/cve-2025-61021-openlink-virtuoso-opensource-7211-sqlonaturaljoincond-denial-of-service-issue-1223/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This issue affects some unknown processing of the component <em>sqlo_natural_join_cond</em>. This manipulation causes denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2025-61021">CVE-2025-61021</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61027 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1232)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in openlink virtuoso-opensource 7.2.11. This affects an unknown function. The manipulation leads to denial of service.

This vulnerability is listed as CVE-2025-61027. The attack may be initiated remotely. There is no available ...]]></description>
<link>https://tsecurity.de/de/3629752/sicherheitsluecken/cve-2025-61027-openlink-virtuoso-opensource-7211-denial-of-service-issue-1232/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629752/sicherheitsluecken/cve-2025-61027-openlink-virtuoso-opensource-7211-denial-of-service-issue-1232/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This affects an unknown function. The manipulation leads to denial of service.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2025-61027">CVE-2025-61027</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Installation und Einführung von Zorin OS - Tutorial für Anfänger]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 10x - Views:96 In diesem Video zeigt Jean, wie man Zorin OS parallel zu Windows installiert und so optimal mit Linux durchstarten kann.
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!

Links:
---...]]></description>
<link>https://tsecurity.de/de/3627596/linux-tipps/installation-und-einfuehrung-von-zorin-os-tutorial-fuer-anfaenger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627596/linux-tipps/installation-und-einfuehrung-von-zorin-os-tutorial-fuer-anfaenger/</guid>
<pubDate>Fri, 26 Jun 2026 15:40:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 10x - Views:96 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cvTboRfwl3E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean, wie man Zorin OS parallel zu Windows installiert und so optimal mit Linux durchstarten kann.<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
Falls sich die Windows-Partition nicht ausreichend verkleinern lässt, liegt dies oft an der Auslagerungsdatei. Hilfe dazu findet man z.B. in verschiedenen Foren: https://forum.linuxguides.de/index.php?thread/10697-windows-partition-l%C3%A4sst-sich-nicht-verkleinern/<br />
<br />
- ZorinOS herunterladen: https://zorin.com/os/download/<br />
- https://rufus.ie/de/<br />
- ehrenamtliche Hilfe durch die Linux Helden: https://www.linuxguides.de/linux-helden-karte/<br />
- Du suchst eine gute Cloud Lösung? https://www.libre-workspace.org/cloud/<br />
- Linux Assistant: https://www.linux-assistant.org/<br />
<br />
Videoempfehlungen:<br />
- Alles zur Firewall: https://youtu.be/gSq1W3qfKBs<br />
- LibreOffice Writer einrichten wie Microsoft Word: https://youtu.be/Hms467GhynE<br />
- Crashkurs zu Writer (Word Alternative): https://youtu.be/QyakKLNv7Yg<br />
- Crashkurs zu Calc (Excel Alternative): https://youtu.be/ioAxN27CIUA<br />
- Thunderbird Tutorial (Mailclient): https://youtu.be/eAgCsvQV7ZE<br />
- Windows in einer Box: https://youtu.be/CAditqMhYrA<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Begrüßung<br />
00:44 ZorinOS und Rufus herunterladen<br />
02:19 Festplattenkonfiguration ändern<br />
03:41 Abbild auf USB-Stick erstellen<br />
07:10 Hilfe durch Linux Helden<br />
08:33 Vom USB-Stick starten<br />
09:55 Installation<br />
14:14 Willkommensbildschirm<br />
17:48 Treiber, Firewall<br />
20:15 Software installieren<br />
26:20 Einstellungen<br />
30:12 Dateimanager<br />
32:36 Finale Hinweise<br />
37:55 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #zorinos #linux #opensource<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[🚨 Die Milliarden-Lüge des Staates: Wie wir unsere digitale Freiheit an US-Konzerne verkaufen 💸]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 0x - Views:3 *▶️ IT Beschaffung:* Stell dir vor, du mietest eine Wohnung, aber der Vermieter behält alle Schlüssel und baut Kameras ein. Exakt so agiert unser Staat seit Jahrzehnten bei der IT-Beschaffung. Dieses Erklärvideo dekonstruiert die staatliche IT-...]]></description>
<link>https://tsecurity.de/de/3626588/it-security-nachrichten/die-milliarden-luege-des-staates-wie-wir-unsere-digitale-freiheit-an-us-konzerne-verkaufen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626588/it-security-nachrichten/die-milliarden-luege-des-staates-wie-wir-unsere-digitale-freiheit-an-us-konzerne-verkaufen/</guid>
<pubDate>Fri, 26 Jun 2026 09:23:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YEg6CwfVr8M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>*▶️ IT Beschaffung:* Stell dir vor, du mietest eine Wohnung, aber der Vermieter behält alle Schlüssel und baut Kameras ein. Exakt so agiert unser Staat seit Jahrzehnten bei der IT-Beschaffung. Dieses Erklärvideo dekonstruiert die staatliche IT-Infrastruktur aus einer linksprogressiven Perspektive und fordert: "Öffentliches Geld, Öffentlicher Code"!<br />
<br />
*Wir entlarven die Falle der US-Tech-Monopole:* Die Abhängigkeitsfalle geschlossener Systeme zwingt den Staat, den Überwachungskapitalismus des Silicon Valley mit unseren Steuergeldern zu finanzieren (permanenter Abfluss von Telemetriedaten). Durch US-Datengesetze haben ausländische Konzerne faktisch einen "Not-Aus-Schalter" für unsere kritische Infrastruktur.<br />
<br />
*Wir beleuchten das Machtversagen der IT-Sicherheit:* Milliardenkonzerne machen Profit mit kostenloser Basis-Software, während die Sicherheit des Internets auf den Schultern unbezahlter, überarbeiteter freiwilliger Entwickler ruht. Das Resultat sind verheerende Angriffe auf die digitale Lieferkette. <br />
<br />
*Das Jahr 2026 bringt die Wende:* Digitale Zutatenlisten (SBoM) werden rechtlich bindend. Der Staat investiert in digitale Allmendegüter und offene Standards (Open Desk), um die Datensouveränität der Bürger zu garantieren und das Steuergeld endlich in der heimischen Wirtschaft zu halten. Wir fordern den genossenschaftlichen Wohnraum im Netz! ✊<br />
<br />
---Thema:<br />
🛑 DIE CODE-REBELLION: Wem gehört unsere Infrastruktur? 💶<br />
<br />
*Kernaussage:*<br />
<br />
* *📉 Die Monopol-Falle:* Geschlossene Systeme von US-Konzernen schaffen eine massive strukturelle Abhängigkeitsfalle. Behörden funken massenhaft Daten ab – der Steuerzahler finanziert seine eigene Entmündigung.<br />
<br />
* *🧠 Die Souveränitäts-Krise:* Gesetze wie der "US Cloud Act" zwingen Anbieter zur Datenherausgabe. Die EU blockiert dies ab 2026, da kein Drittstaat einen "Not-Aus-Schalter" über europäische Infrastruktur haben darf.<br />
<br />
* *⚖️ Ausbeutung der Freiwilligen:* Das Prinzip "Viele Augen finden jeden Fehler" scheitert an der Profitgier. Milliarden-Konzerne nutzen kostenlose Basis-Software, während die IT-Sicherheit von unbezahlten Freiwilligen getragen wird (Folge: massive Hackerangriffe auf Lieferketten). Ab 2026 investiert der Staat (17 Mio. Euro Budget) in diese Wartung.<br />
<br />
* *🌍 Algorithmen aus der Dunkelkammer:* Geschlossene Codes verhindern die Prüfung auf strukturelle Diskriminierung (Beispiel Sozialleistungen). Vorbilder wie Barcelona zeigen, wie offene Systeme die Bürger schützen.<br />
<br />
* *🛡️ Der Wendepunkt 2026:* Digitale Souveränität wird Vergabekriterium. Durch offene Arbeitsplatz-Suiten (bereits 70.000 Nutzer) amortisieren sich die Kosten nach 12-15 Monaten. Das Steuergeld fließt an lokale Mittelständler statt ins Silicon Valley.<br />
<br />
*1. ✊ GEMEINSAM GEGEN DIE IT-MONOPOLE:*<br />
    KANAL ABONNIEREN: @vazules <br />
<br />
#OpenSource #Systemkritik #ITSicherheit #Politik #Wirtschaft #Digitalisierung #Klassenkampf #LaKanDoR<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61029 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1228)]]></title>
<description><![CDATA[A vulnerability was found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to denial of service.

This vulnerability is documented as CVE-2025-61029. The attack can be executed remotely. There...]]></description>
<link>https://tsecurity.de/de/3623448/sicherheitsluecken/cve-2025-61029-openlink-virtuoso-opensource-7211-denial-of-service-issue-1228/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623448/sicherheitsluecken/cve-2025-61029-openlink-virtuoso-opensource-7211-denial-of-service-issue-1228/</guid>
<pubDate>Thu, 25 Jun 2026 07:38:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. Such manipulation leads to denial of service.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2025-61029">CVE-2025-61029</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM, Red Hat, Palo Alto team to secure open-source software]]></title>
<description><![CDATA[IBM, its RedHat subsidiary, and Palo Alto Networks are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by AI.



The joint effort will rely on Palo Alto’s network-based virtual patching technology,...]]></description>
<link>https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</guid>
<pubDate>Wed, 24 Jun 2026 21:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM, its RedHat subsidiary, and <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">Palo Alto Networks</a> are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">AI</a>.</p>



<p>The joint effort will rely on Palo Alto’s network-based virtual patching technology, which is found in its <a href="https://www.networkworld.com/article/4084195/palo-alto-networks-readies-security-for-ai-first-world.html">Prisma security software</a>, and IBM/Red Hat’s Project Lightwell, a software remediation initiative designed to help enterprises secure open-source software. Vulnerability intelligence from both vendors will also contribute to threat detection and remediation, the companies stated.  </p>



<p>Announced in May, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era">Project Lighthouse</a> is IBM and Red Hat’s $5 billion project to develop what IBM calls a “trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale.”</p>



<p>“The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code,” IBM stated in May. “These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.”</p>



<p>Open-source software (OSS) underpins modern enterprise infrastructure, with more than 90% of Fortune 500 companies relying on OSS, IBM stated, citing a <a href="https://worldmetrics.org/opensource-statistics/">Worldmetric</a> study.</p>



<p>IBM and Red Hat said they are working with a variety of early adopters on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, RBC, State Street, Visa and Wells Fargo.</p>



<p>Key elements of the Palo Alto/IBM/Red Hat initiative include:</p>



<ul class="wp-block-list">
<li><strong>Vulnerability coverage: </strong>Protection across open-source software, commercial applications, operational technology environments, and connected devices.</li>



<li><strong>Preemptive coverage: </strong>Organizations can receive virtual patch protections before official software patches become available, helping reduce exposure while remediation is underway.</li>



<li><strong>Rapid protection</strong>: When a new vulnerability is discovered, network-level protections can be deployed the same day, with a long-term goal of reducing the time from validated discovery to protection.   </li>
</ul>



<p>The companies said they also plan to establish secure processes for sharing vulnerability information across participating software vendors, technology providers, and security teams. The idea is to accelerate protection development and provide anonymized telemetry on real-world exploitation attempts, the companies stated.</p>



<p>“AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace,” said Nikesh Arora, CEO and chairman of Palo Alto Networks, in a statement. “By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients.”</p>



<p>IBM and Palo Alto have a long-running relationship of integrating security and enterprise-class networks. Recently, IBM and Palo Alto said they would combine to offer a service, <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-and-ibm-plan-to-launch-joint-solution-to-accelerate-enterprise-wide-quantum-safe-readiness">Quantum-Safe Readiness</a>, that would let enterprise customers identify cryptographic exposure, understand <a href="https://www.networkworld.com/article/4131660/ibm-research-when-ai-and-quantum-merge.html">quantum-computing</a> related risks, and accelerate their use of quantum-safe security technology.</p>



<p>In addition, the companies <a href="https://www.ibm.com/new/announcements/introducing-the-rapid-ai-security-assessment-secure-your-ai-innovation-with-ibm-and-palo-alto-networks">earlier this year</a> said they would combine to offer a service designed to help enterprises discover, assess, and prioritize security and compliance risks for their artificial intelligence implementations in the cloud.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inklusion bei Digitalen Projekten (tdf2026)]]></title>
<description><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://...]]></description>
<link>https://tsecurity.de/de/3622556/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622556/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AA8XA3/]]></content:encoded>
</item>
<item>
<title><![CDATA[Open source grapples with agentic coding]]></title>
<description><![CDATA[Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. 



The latest area that is catching the attention of devel...]]></description>
<link>https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</guid>
<pubDate>Wed, 24 Jun 2026 11:03:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. </p>



<p>The latest area that is catching the attention of developers is how agentic coding is affecting the open source community. The <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source movement</a> has been defending the rights of folks to use, change, and contribute to software for many years. And of course, agentic coding is starting to become part of that process.</p>



<p>On the one hand, maintainers of open source projects rightfully are frustrated as they become overwhelmed with pull requests of dubious quality and usefulness being submitted by coding agents. On the other hand, <a href="https://world.hey.com/dhh/let-the-agents-democratize-open-source-9fd630a9">as David Heinemeier Hansson notes</a>, maintainers are starting to get a little snooty about accepting AI-written code, viewing it as somehow not worthy of being included. Some organizations have explicitly <a href="https://x.com/LundukeJournal/status/2060344714432241990?s=20" data-type="link" data-id="https://x.com/LundukeJournal/status/2060344714432241990?s=20">banned AI-generated submissions</a>.</p>



<p>I get that they don’t want AI slop overwhelming their input queues. But I think it is a huge mistake to ban AI-written code outright.</p>



<h2 class="wp-block-heading">Whose code?</h2>



<p>Before I dig deeper into that notion, it’s important to look at another issue that arises from all of this: Who actually owns the code that AI writes? </p>



<p>Copyright requires that a human produce the thing being copyrighted. If you prompt Claude Code with “Write me a CMS system” and then Claude writes you a CMS system that you check into a public GitHub repository unchanged, it’s not quite clear if that code is protected by copyright. However, if you prompt Claude Code with a specification and guidelines and then you work with Claude to refine the initial result, reviewing the code and making changes as part of an iterative process, then it could be argued that a human did produce that code. But it is not at all <a href="https://legallayer.substack.com/p/who-owns-the-claude-code-wrote">clear-cut legally</a>. (Please note that I am not a lawyer.)</p>



<p>The current thinking is that the result of accepting verbatim the output of a simple prompt is not copyrightable, and that no one actually owns the code — an interesting notion in and of itself. </p>



<p>But then the ethical question comes into play. If I find a bug in an open source project, I ask GitHub Copilot to fix it, and Copilot writes a clever and effective fix, then who cares who owns the code? Should a maintainer of the project reject such a pull request just because it was AI-generated? That seems silly to me, yet it is happening today. </p>



<h2 class="wp-block-heading">Our code</h2>



<p>There is, too, the issue of license compliance for AI-generated code. As a general rule, LLMs generate code rather than copying it. They don’t copy and paste code directly from repositories. However, there have been cases where AI-produced code has resembled open source code so closely that the claim could be made that it is a copy. If this happens with <a href="https://opensource.org/license/gpl-3.0">GPL</a> code, it could be a violation of the license to use it without the receiving code base being “infected.” Open source maintainers naturally should be concerned about this happening.</p>



<p>In the end, an open source maintainer should care about the quality and license compliance of submissions, not how those submissions were derived. Gatekeeping based on the source of code doesn’t seem like a good path towards project success. Good code is good code, no matter where it comes from.</p>



<p>Agentic coding is here, and the open source community needs to realize — and embrace — that inevitability.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Mistral late or savvy?]]></title>
<description><![CDATA[For the past few years, the most visible corner of the AI market has been easy to caricature: OpenAI gets the consumer attention, Anthropic gets the developer love, Google gets the benefit of the doubt with increasingly capable models and a complementary product suite, and everyone else gets to e...]]></description>
<link>https://tsecurity.de/de/3614975/ai-nachrichten/is-mistral-late-or-savvy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614975/ai-nachrichten/is-mistral-late-or-savvy/</guid>
<pubDate>Mon, 22 Jun 2026 11:19:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past few years, the most visible corner of the AI market has been easy to caricature: OpenAI gets the consumer attention, Anthropic gets the developer love, Google gets the benefit of the doubt with increasingly capable models and a complementary product suite, and everyone else gets to explain why they’re not dead yet.</p>



<p>That’s unfair, of course, but not completely wrong. In AI, attention compounds and it’s leading to outsized revenue, with both <a href="https://www.reuters.com/technology/openai-files-us-ipo-after-anthropic-ai-giants-head-public-markets-2026-06-08/">OpenAI</a> and <a href="https://www.reuters.com/business/ai-giant-anthropic-confidentially-files-us-ipo-2026-06-01/">Anthropic</a> reportedly rushing toward trillion-dollar-sized IPOs on the backs of billions in revenue.</p>



<p>So it’s easy to underrate Mistral AI.</p>



<p>Honestly, I hadn’t thought of the Paris-based company for a year. Maybe longer. But then <a href="https://www.linkedin.com/feed/update/urn:li:activity:7472694983636971520/">Brian Hall announced he’s joining Mistral</a> as CMO, and I had an <a href="https://arresteddevelopment.fandom.com/wiki/Her%3F">Arrested Development “Her?” moment</a>. Hall, a longtime Microsoft exec, hired me at AWS and went on to run product marketing at Google Cloud. His move prompted curiosity because Mistral doesn’t dominate developer chatter in the United States or boast the same seemingly endless compute budgets as Anthropic or OpenAI. If the AI market is simply a race to build the biggest, most magical, most general-purpose model, Mistral isn’t the company to bet on.</p>



<p>But that’s the wrong question, and likely the wrong bet.</p>



<p>The more interesting question is when the enterprise AI market will revert to type and demand that AI deliver the same security, predictability, and control we’re used to from other IT investments. Here Mistral has a real story. As Hall notes, Mistral’s approach is to “prioritize AI for mission-critical environments that need the confidence and self-control to bet for the long term (with open weights and real sovereign capabilities).”</p>



<p>While this might have sounded like an overly hopeful talking point, it became real in June when <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">the US government ordered Anthropic to suspend access</a> for foreign nationals to its most advanced Fable 5 and Mythos 5 models. Anthropic said it would disable the models for all users because of the export-control directive. “Can this vendor be forced to turn us off?” is no longer a theoretical question.</p>



<p>That’s why Mistral’s quiet focus on enterprise control just might work.</p>



<h2 class="wp-block-heading"><a></a>The wrong race</h2>



<p>The enterprise control story is much more compelling than the narrative I used to hear. You know, the “Europe needs its own OpenAI” schtick. There is a market for “patriotic AI,” but it’s relatively small. The far bigger market is comprised of enterprises that just want AI that works, costs less (or delivers more) than expected, and can be customized while fitting their compliance requirements.</p>



<p>Though the company’s <a href="https://web.archive.org/web/20230726224506/https:/mistral.ai/">initial launch page</a> went out of its way to mention that the company was operating out of Europe and headquartered in Paris, since at least <a href="https://web.archive.org/web/20231030012147/https:/mistral.ai/">October 2023 Mistral’s product posture has centered on enterprise control</a>. Scattered throughout its current (and past) website are words like “customize,” “fine-tune,” “open source,” and “complete control.” Mistral pitches Studio for building and running AI apps, Forge for custom model training and alignment, Vibe for agentic work, Vibe for Code for coding workflows, and Compute for training and inference infrastructure. The company talks about observability, evals, guardrails, deployment portability, and running production AI “from edge to cloud.”</p>



<p>In other words, it sounds less like a chatbot company and more like an infrastructure company.</p>



<p>That positioning becomes clearer when you look underneath the product names.<a href="https://mistral.ai/news/ai-studio/"> Mistral AI Studio</a> includes an AI Registry that acts as a system of record for agents, models, data sets, judges, tools, and workflows. It tracks lineage, ownership, and versioning. It enforces access controls and promotion gates before deployment. That’s boring governance plumbing (and “boring” is good in enterprise IT, <a href="https://www.infoworld.com/article/4082782/boring-governance-is-the-path-to-real-ai-adoption.html">as I’ve written</a>).</p>



<p><a href="https://mistral.ai/news/forge/">Forge</a> may be even more important. Mistral describes it as a way for enterprises to train frontier-grade models on proprietary enterprise data. Rather than training on others’ copyrighted information strewn across the web or on a mountain of Reddit posts, Forge goes well beyond <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation</a> (RAG) to not simply “read in” proprietary docs/info/etc., but rather to give an enterprise its own private OpenAI, as it were. </p>



<p>That’s super interesting.</p>



<p>But is it different? I mean, OpenAI and Anthropic can do plenty of this, with greater scale and the benefit of leading frontier models. Both have enterprise products, cloud partnerships, evals, agents, governance tools, and varying forms of model customization. Mistral’s bet with Forge isn’t that the big labs can’t customize models. It’s that some enterprises aren’t interested in customization as a side feature bolted onto a frontier API. It <em>is </em>the product. OpenAI and Anthropic can build everything around Forge but not Forge itself, because the one thing they almost certainly aren’t interested in selling is independence from them.</p>



<p>This is where Mistral may have found a useful seam, one that allows it to ask a different set of questions. What if the best enterprise model isn’t the smartest general-purpose model? What if the best model is the one that’s small enough to run where the customer needs it, open enough to inspect and adapt, cheap enough to use broadly, and specialized enough to do the job? What if “good enough, governable, and your own” beats “slightly smarter, mostly opaque, and rented”?</p>



<p>This won’t matter for every use case, of course. If I’m asking AI to reason through a spreadsheet or write code, I probably want the best model I can get. But for banks, defense agencies, manufacturers, utilities, telcos, and governments, “best” is multidimensional and includes questions like latency, auditability, etc. It’s why banks, for example, still run so many workloads on premises: They want control.</p>



<h2 class="wp-block-heading"><a></a>What about compute?</h2>



<p>None of this makes compute irrelevant. But it may change <em>how</em> compute matters.</p>



<p>If Mistral is trying to be a French version of OpenAI, its lack of hyperscale compute is a fatal weakness. It won’t outspend OpenAI, Oracle, Microsoft, Google, Amazon, SpaceX, or Anthropic. It probably won’t out-recruit them across every frontier research area, either. The AI market is already littered with companies that underestimated how quickly “good model” became “not good enough.”</p>



<p>But if Mistral is trying to become the enterprise-controlled AI layer for organizations that don’t want all intelligence to live behind someone else’s API, compute becomes a more nuanced issue. It still needs infrastructure, and Mistral seems to know it. After all, Mistral <a href="https://www.reuters.com/business/finance/frances-mistral-raises-830-million-debt-ai-data-centre-build-up-2026-03-30/">raised $830 million in debt to buy 13,800 Nvidia chips</a> for a data center near Paris. That’s a rounding error compared to OpenAI and Anthropic, of course, but the real question is whether Mistral can turn relative compute scarcity into a virtue, like <a href="https://www.amazon.jobs/content/en/our-workplace/leadership-principles">Amazon’s Leadership Principle “Frugality”</a> on steroids. If lower compute capacity leads Mistral to deliver smaller, more efficient, and more specialized models, which in turn helps enterprises maintain more control of their data at lower cost, then less really does become more.</p>



<p>Mistral’s compute challenge, then, is not to try and have as much compute as OpenAI. It’s to make customers care less about raw compute scale and more about deployment flexibility, specialization, and control.</p>



<p>That’s a hard sell. But it’s not a dumb one.</p>



<h2 class="wp-block-heading"><a></a>What Mistral must prove</h2>



<p>The bear case remains obvious. OpenAI has consumer distribution, developer mindshare, capital, and a brand that has basically become synonymous with AI. Anthropic has become the developer darling and has an unusually strong enterprise story of its own. Google has the models, the infrastructure, the data, and a bevy of complementary services. AWS, Microsoft, and Oracle have customer relationships and infrastructure.</p>



<p>Mistral has to prove that there’s room for another center of gravity. More specifically, it must prove three things.</p>



<p>First, it has to show that open-weight and controllable AI matter enough to influence buying decisions, not just conference panels. Everyone says they want control, just as most like the idea of open source. But proprietary software and cloud services still dominate the market. Mistral must make control feel like the easy button.</p>



<p>Second, it must prove that specialization beats generality in enough high-value markets. “Our model is almost as good” is not a strategy. “Our model is better for your bank, your government agency, or your retailer” just might be.</p>



<p>Third, it needs to establish a beachhead within enterprise IT before OpenAI and Anthropic become “boring” enough to satisfy the same buyers. This is the real race. The biggest AI companies are hiring enterprise sales teams, building admin controls, and cutting deals with every major cloud. Mistral’s window exists because the market is still young, but that window won’t stay open much longer.</p>



<p>If AI remains a model benchmark race, Mistral likely loses. But if AI keeps evolving to become grown-up enterprise infrastructure, Mistral has a real chance.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why open infrastructure will define the AI era]]></title>
<description><![CDATA[A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.



JetBrains Research found that 74% of developers worldwide use AI tools. Claude Code, available only since Ma...]]></description>
<link>https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</guid>
<pubDate>Mon, 22 Jun 2026 11:19:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.</p>



<p><a href="https://blog.jetbrains.com/research/2026/04/which-ai-coding-tools-do-developers-actually-use-at-work/">JetBrains Research</a> found that 74% of developers worldwide use AI tools. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, available only since May 2025, is now the most popular AI coding tool, followed by <a href="https://www.infoworld.com/article/3829347/review-gemini-code-assist-is-good-at-coding.html">Gemini Code Assist</a> and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, according to Jellyfish’s 2026 <a href="https://jellyfish.co/resources/2026-state-of-engineering-management-report/">State of Engineering Management Report</a>.</p>



<p>The latter study also found that 91% of developers say their productivity has increased in the past 12 months. As coding output <a href="https://leaddev.com/ai/openai-says-there-are-easily-1000x-engineers-now">expectations are rewritten daily</a>, the engineering world is becoming heavily reliant on paid external AI services.</p>



<p><a href="https://www.linkedin.com/posts/markwoneill_how-to-optimize-token-consumption-for-ai-activity-7458329480994992128-AT9m?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAA-8zTABlsmtYe-zC-Uf5z3oD5nm6qXDVVo">Gartner predicts</a> that by 2028 spending on AI coding tokens could exceed developer salaries. Yet, <a href="https://www.infoworld.com/article/4183060/the-tokenmaxxing-backlash-is-coming.html">tokenmaxxing</a> while <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html">vibe coding</a> through a vendor’s cloud-based API feels like a far cry from the open foundations of free programming languages and open models, which many of today’s AI platforms now abstract.</p>



<p>“Open infrastructure will be the backbone of the AI era,” says <a href="https://www.linkedin.com/in/farkasp/">Peter Farkas</a>, CEO of <a href="https://www.percona.com/">Percona</a>, a provider of open-source database solutions. “Right now, too many companies are building their entire AI strategy on top of proprietary platforms because the convenience is seductive.”</p>



<p>“It’s ‘three clicks’ to stand up a database or an AI service in a hyperscaler, and that convenience blinds people to the lock-in they’re signing up for,” he adds. “As AI workloads mature, organizations will realize that depending on one vendor for their data, models, runtime, and pricing is not a strategy.”</p>



<p><a href="https://www.infoworld.com/article/3973969/knowing-when-to-use-ai-coding-assistants.html">AI-assisted coding</a> is democratizing software engineering for non-engineers and <a href="https://leaddev.com/ai/ai-doesnt-create-great-developers-it-amplifies-them">accelerating top performers</a>. But if teams are always working within the confines of how one platform thinks the world should work, it could create locked-in toolsets at scale. And as <a href="https://techcrunch.com/2025/12/29/2025-was-the-year-ai-got-a-vibe-check/">AI platform costs rise</a>, a fundamental question arises: will software developers consume AI on their own terms, or on someone else’s?</p>



<p>There’s a strong case that the long-term winners in tech will be built on open-source standards and foundations, similar to the history of cloud-native computing and the internet itself.</p>



<p>“Open always wins,” says <a href="https://www.linkedin.com/in/brianalvey/">Brian Alvey</a>, CTO at <a href="https://wpvip.com/">WordPress VIP</a>, a managed WordPress hosting platform. “Not because it’s a fancy ideology, but because it gives you total freedom to adapt, evolve, and stay in control.”</p>



<p>Open infrastructure avoids a future where developers perpetually rent. “For AI to be useful to people at large, it can’t be something you’re paying rent for the rest of your life,” says <a href="https://www.linkedin.com/in/maniksurtani/">Manik Surtani</a>, CTO and co-founder of the <a href="https://aaif.io/">Agentic AI Foundation</a> (AAIF), a vendor-neutral home for open-source agentic AI technologies. “And it can’t be concentrated in one particular corporation or a small handful of corporations, because we know how that goes.”</p>



<h2 class="wp-block-heading">Pricey, closed, proprietary AI</h2>



<p>AI development today is traveling two parallel paths. On one path, <a href="https://leaddev.com/technical-direction/be-careful-open-source-ai">open-source AI</a> is thriving and fueling tremendous growth in the number and variety of AI models and tools. Just take the thousands of open-weight models on <a href="https://huggingface.co/">HuggingFace</a>, the community around the <a href="https://openclaw.ai/">OpenClaw</a> AI agent, or the many academic institutions publishing <a href="https://thenewstack.io/llms-can-now-trace-their-outputs-to-specific-training-data/">new breakthroughs</a>.</p>



<p>“Open-source models and tooling are hot on the heels of state-of-the-art, with interesting and boundary-pushing work being shared by labs and researchers across the world,” says Austin Parker, director of AI strategy at <a href="https://www.honeycomb.io/">Honeycomb</a>, an observability platform provider, citing frontier open-source models like <a href="https://mistral.ai/">Mistral</a>, <a href="https://github.com/deepseek-ai/deepseek-v3">DeepSeek</a>, and <a href="https://allenai.org/olmo2">Ai2’s OLMo</a> as examples.</p>



<p>Others agree. “There’s unprecedented openness at the model and tooling layer, with open-source models, frameworks, and orchestration advancing at remarkable speed,” says <a href="https://www.linkedin.com/in/markcollier/">Mark Collier</a>, general manager of AI and infrastructure at the <a href="https://www.linuxfoundation.org/">Linux Foundation</a>.</p>



<p>On the other path, we’re seeing heavy reliance on proprietary AI systems controlled by Anthropic, Cursor, Google, Microsoft, OpenAI, and others. As Collier says, “Many platforms are wrapping those open components in closed, opinionated interfaces that trade short-term speed for long-term constraints.”</p>



<p><a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">Open source</a> and the AI tooling market don’t always mix well. LangChain’s <a href="https://github.com/langchain-ai/open-agent-platform">Open Agent Platform</a>, for instance, was open-sourced to much fanfare in 2025, but by 2026 had been deprecated, with the repository now recommending fully managed alternatives.</p>



<p>For <a href="https://www.linkedin.com/in/shaposhnik/">Roman Shaposhnik</a>, co-founder and CTO of <a href="https://nekko.ai/">Ainekko</a>, provider of an open-source, composable AI stack, the current AI platform landscape is reminiscent of <a href="https://devops.com/demystifying-the-low-code-category/">low-code and no-code platforms</a>, which promised democratization of software development but often <a href="https://www.infoworld.com/article/3958483/7-reasons-low-code-and-no-code-tools-fail-to-deliver.html">failed to deliver</a>, becoming synonymous with platform lock-in and inflexibility.</p>



<p>“Honestly, it feels familiar,” Shaposhnik says. “We have incredibly powerful AI tools right now, but most of them come bundled as tightly controlled platforms.” This is a risk for AI, he says, because the infrastructure, models, and hardware are tightly coupled. “If those layers are closed, you lose flexibility fast.”</p>



<p>Some abstractions that sit on top of models, like routing and agent frameworks, tend to be tightly coupled and optimized for certain models. Other platforms take the walled garden concept quite literally. Anthropic, for instance, has repeatedly made headlines for blocking access to its Claude models over <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic-nuked-a-companys-access-to-claude-stopping-60-employees-dead-in-their-tracks-support-via-google-form-is-the-only-recourse-for-vague-usage-policy-violation">vague policy violations</a>. The company recently shut off <a href="https://venturebeat.com/technology/anthropic-cracks-down-on-unauthorized-claude-usage-by-third-party-harnesses">competitor xAI’s use</a> and <a href="https://thenewstack.io/anthropic-agent-sdk-confusion/">stonewalled OpenCode</a>, drawing community backlash.</p>



<p>Moves toward increasingly closed systems don’t bode well for an AI economy already built on shaky economics. As <a href="https://www.linkedin.com/in/vikramsrivats/">Vikram Srivats</a>, head of product experience at <a href="https://www.wavemaker.com/">WaveMaker</a>, provider of an agentic application development platform, adds, “Given the unit economics of AI tooling and pace of accelerated change to keep up, it seems obvious that some will evolve to more of a closed system to be able to monetize and gain ROI.”</p>



<h2 class="wp-block-heading">Why openness matters in the AI era</h2>



<p>Reliance on proprietary AI platforms can create long-term operational dependencies. As systems become less interoperable, organizations may be forced to standardize on a single stack across data pipelines, models, and decision logic, says the Linux Foundation’s Collier.</p>



<p>“As infrastructure consolidates, enterprises become more exposed when platforms change direction, raise prices, or fall behind technically,” he says. “If you can’t change platforms without re-architecting your AI systems, you’ve already given up too much control.”</p>



<p>“When you build on someone else’s platform, you have to live by their rules and those rules always change,” adds WordPress VIP’s Alvey. “We’ve all seen this before, businesses wasting time and money building to serve Google, Facebook, YouTube, and the App Store, instead of building to serve their customers.”</p>



<p><a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">Platform lock-in</a> can also create direct business risk. As Ainekko’s Shaposhnik says, “It usually shows up as higher costs, fragile systems, and growing risk when it’s time to change direction.”</p>



<p>At Ainekko, an internal group called the <a href="https://www.eejournal.com/article/do-you-want-to-be-an-ai-plumber/">AI Plumbers</a> focuses on back-end AI infrastructure like inference, scheduling, memory, and hardware integration. “Their view is simple,” says Shaposhnik. “If those layers are closed, everything above them becomes fragile.”</p>



<p>Open standards, interfaces, and infrastructure provide a necessary hedge against closed systems to prevent this sort of fragility. “In the AI era, open infrastructure gives enterprises control, portability, and choice at exactly the time they need it most,” says Percona’s Farkas.</p>



<p>It can cost upwards of $100,000 to migrate enterprise software, <a href="https://cloudaware.com/blog/cloud-migration-costs/">according to Cloudaware</a>, making portability a major enterprise concern. From this perspective, procuring closed systems can become a costly architectural dependency.</p>



<p>Others argue that openness is a critical hedge against vendor concentration risks at large, especially if AI replaces human labor en masse. “If all of that economic value is now being concentrated in the hands of one or two companies,” says the AAIF’s Surtani, “that’s an order of magnitude bigger problem than we’ve seen in any other wave of computing.”</p>



<p>Instead, open foundations allow adaptability to evolving conditions so enterprises can swap out models, agents, data, hardware, and orchestration, as needed. “Open standards let those components change independently without breaking the system,” says Collier. </p>



<p>Openness can also help future-proof businesses against economic upheaval. “Open everything will help build a cushion for businesses and users to survive and thrive after the almost-certain correction in the current hype cycle,” says WaveMaker’s Srivats.</p>



<h2 class="wp-block-heading">Momentum toward open AI infrastructure</h2>



<p>At the industry level, momentum toward open AI infrastructure is growing. The <a href="https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation">establishment</a> of the <a href="https://aaif.io/author/aaif/">Agentic AI Foundation</a>, Anthropic’s donation of <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP), and Block’s donation of its <a href="https://aaif.io/projects/goose/">Goose agent</a> are significant ecosystem-wide moves toward openness. Other advances include the donation of <a href="https://thenewstack.io/llm-d-cncf-kubernetes-inference/">llm-d</a>, a <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a> framework for LLM inference, to the Cloud Native Computing Foundation (CNCF).</p>



<p>For Parker, donations like this help ensure long-term support and care. “Open standards aren’t just the foundation of the internet, they’re the foundation of the AI space,” he says. “I predict that we’ll see these practices continue, especially as enterprise adoption increases in earnest,” he adds.</p>



<p>Still, some question whether this level of stewardship is enough for a rapidly evolving ecosystem. “The internet benefited early on from groups that helped keep vendors aligned,” says Shaposhnik. “In AI infrastructure, we don’t really have that yet.”</p>



<p>“All of us open source veterans are hopeful,” he says, “but we also need to adapt to this new reality in what we do regarding AI infrastructure.”</p>



<p>Beyond industry governing bodies, companies themselves are also spearheading open AI initiatives. Warp, an agentic development environment, recently <a href="https://thenewstack.io/warp-open-source-client/">went open source</a> amid closed-source rivals. Arcade.dev, meanwhile, is pushing an open-source <a href="https://www.arcade.dev/blog/agent-library/">Agent Library</a> for agentic memory.</p>



<h2 class="wp-block-heading">Where openness matters most in the AI stack</h2>



<p>While AI infrastructure can be open in many ways, a few layers stand out as especially important. First is the openness of the model itself. “Open-source models must be the foundation of future trust and value,” says WaveMaker’s Srivats.</p>



<p>“The forms of open infrastructure that reduce integration friction and accelerate adoption stand out,” adds <a href="https://www.linkedin.com/in/neeraj-abhyankar-9040141/">Neeraj Abhyankar</a>, VP of data and AI at <a href="https://www.rsystems.com/">R Systems</a>, a global digital solutions provider. For him, open model representation formats, open orchestration and execution layers, open agentic protocols, and open governance and metadata standards are all essential for enterprise flexibility.</p>



<p>Others place more value on the connective tissue between AI components. “The most important forms of open infrastructure are the ones that connect systems together,” says Collier. “That includes open APIs, metadata standards, identity and policy frameworks, and protocols for how models and agents communicate.” </p>



<p>Arguably, <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">MCP</a> has become the connective tissue between AI agents and the <a href="https://thenewstack.io/how-to-prepare-your-api-for-ai-agents/">broader API ecosystem</a>. “If we get MCP right we unlock the same level of interoperability between entities on the web and models driving them as we came to enjoy during the Web 2.0 era and the API-first boom,” says Shaposhnik. “If we don’t we risk massive proprietary lock-ins.”</p>



<p>Parker agrees that open protocols will underlie future AI progress. “We’ll see continued development and progress on AI agents which will rely on protocols like MCP and ACP [<a href="https://www.infoworld.com/article/4007686/a-developers-guide-to-ai-protocols-mcp-a2a-and-acp.html">Agent Client Protocol</a>] to interoperate with various clients and each other,” he says. Yet a gap remains around API conventions for models. “It would be nice if we could get a commitment from model providers to use a standard here.”</p>



<p>For the AAIF’s Surtani, opening up the protocol layer is the most important aspect. “I think it’s really important for interoperability, for choice,” he says. “It means you can bring your own agent, you can bring your own framework, you can bring your own harness, and pick what model you want.”</p>



<p>Open standards may also play a significant role within <a href="https://www.infoworld.com/article/4117620/edge-ai-the-future-of-ai-inference-is-smarter-local-compute.html">inference architecture</a>. “As AI expands to the edge, developers need visibility into how models run, how memory is used, and how performance scales,” says Shaposhnik. Open systems could make it easier to optimize, debug, and adapt while helping enterprises avoid observability fragmentation.</p>



<p>Lastly, <a href="https://www.infoworld.com/article/3498485/the-future-of-kubernetes-and-cloud-infrastructure.html">cloud-native architectural standards</a> are a key ingredient for open AI infrastructure. “We’re seeing Kubernetes become the missing link for people who want the hyperscaler-style convenience without hyperscaler lock-in,” says Percona’s Farkas. For him, Kubernetes has become the de facto hybrid enterprise deployment option for data, workloads, and AI components.</p>



<h2 class="wp-block-heading">History repeats itself</h2>



<p>The <a href="https://opensource.org/blog/the-2026-state-of-open-source-report">2026 State of Open Source Report</a> found avoiding vendor lock-in to be the primary driver of open source adoption. But beyond being a strategic decision for a single company, open infrastructure provides a layer for entire industries to be built upon.</p>



<p>Arguably, the internet itself is evidence of this, where groups like the <a href="https://www.ietf.org/">IETF</a> and the <a href="https://www.ieee.org/">IEEE</a> were instrumental in defining the fundamental protocols. “Without open protocols we would’ve been in telco hell and without phenomenons like Google or Facebook,” says Shaposhnik.</p>



<p>Or, take the <a href="https://www.infoworld.com/article/2335646/thirty-two-years-of-linux-and-its-community.html">history of Linux</a> as a parallel. “Linux became the default operating system because it offered a common, vendor-neutral foundation that everyone could build on,” says Collier. “In the AI era, open infrastructure will define the layers that organizations rely on for long-term continuity.”</p>



<p>At the infrastructure level, open standards have repeatedly underpinned major platform shifts, from <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> to <a href="https://www.infoworld.com/article/3812622/will-kubernetes-ever-get-easier.html">Kubernetes</a>. The question now is whether AI will develop a similarly durable standards layer.</p>



<p>For Parker, it’s too early to say, but the current growth of AI mirrors the early cloud. “Remember that it took many years before we saw the development and popularization of the open source cloud-native ecosystem,” he says. “I think it would be a mistake to extrapolate from the current trajectory towards a closed, proprietary future.”</p>



<p>Others agree the future must be rooted in openness. “I see open infrastructure becoming the foundation of enterprise AI,” says R Systems’s Abhyankar. “As systems become more distributed and agent‑driven, closed ecosystems simply won’t scale.”</p>



<p>The groundwork is being laid through open agentic protocols, open frameworks, and industry support intended to reduce fragmentation around proprietary standards.</p>



<p>“Ironically, the AI movement has mostly seemed to learn from the mistakes of the past and is starting off on a more open foot,” says Parker. “Over time, I believe we’ll see innovation and openness thrive.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Soure braucht DEINE Hilfe - Petition für Open Source im Ehrenamt]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 40x - Views:108 Open Source Software hält die digitale Welt am Laufen, doch die Arbeit wird oft von unbezahlten Hobbyentwicklern getan. Eine Anerkennung als Ehrenamt würde diese Arbeit endlich mit der Jugendarbeit oder dem Engagement in einem Sportverein gleichse...]]></description>
<link>https://tsecurity.de/de/3610654/linux-tipps/open-soure-braucht-deine-hilfe-petition-fuer-open-source-im-ehrenamt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610654/linux-tipps/open-soure-braucht-deine-hilfe-petition-fuer-open-source-im-ehrenamt/</guid>
<pubDate>Fri, 19 Jun 2026 16:25:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 40x - Views:108 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oeigSqbvBOQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Open Source Software hält die digitale Welt am Laufen, doch die Arbeit wird oft von unbezahlten Hobbyentwicklern getan. Eine Anerkennung als Ehrenamt würde diese Arbeit endlich mit der Jugendarbeit oder dem Engagement in einem Sportverein gleichsetzen.<br />
<br />
Unterschreibe für die Anerkennung von Open-Source-Arbeit als Ehrenamt: https://www.openpetition.de/petition/online/anerkennung-von-open-source-arbeit-als-ehrenamt-in-deutschland<br />
<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Direkt unterschreiben: https://www.openpetition.de/petition/online/anerkennung-von-open-source-arbeit-als-ehrenamt-in-deutschland<br />
- Über die Petition: https://www.ehrenamt-opensource.de/<br />
- Verbreitung von Open Source in kommerziellen Codebasen: https://www.intel.com/content/www/us/en/developer/articles/guide/the-careful-consumption-of-open-source-software.html<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Ehrenamt ist wichtig<br />
01:15 Was bedeutet Open Source Software?<br />
03:25 Zur Petition<br />
05:50 Digitale Souveränität für alle<br />
09:08 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #petition #opensource #ehrenamt<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an opensource tool that turns rooted Androids into physical exploit platforms HID, DuckyScript, C2]]></title>
<description><![CDATA[Hey fam. I got sick of carrying dedicated microcontrollers for proximity engagements, so I built chimera.  ​ It interacts directly with the Android kernel to HID keyboards, mount virtual flash drives, and drop payloads natively from the phone.  ​ I’d love for you to test it on your setups and giv...]]></description>
<link>https://tsecurity.de/de/3609229/malware-trojaner-viren/i-built-an-opensource-tool-that-turns-rooted-androids-into-physical-exploit-platforms-hid-duckyscript-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609229/malware-trojaner-viren/i-built-an-opensource-tool-that-turns-rooted-androids-into-physical-exploit-platforms-hid-duckyscript-c2/</guid>
<pubDate>Fri, 19 Jun 2026 04:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey fam. I got sick of carrying dedicated microcontrollers for proximity engagements, so I built chimera. </p> <p>​</p> <p>It interacts directly with the Android kernel to HID keyboards, mount virtual flash drives, and drop payloads natively from the phone. </p> <p>​</p> <p>I’d love for you to test it on your setups and give me some brutal feedback pls.</p> <p>​</p> <p>Repo: <a href="https://github.com/cipher-attack/Chimera">https://github.com/cipher-attack/Chimera</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok_Rhubarb_6783"> /u/Ok_Rhubarb_6783 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u8lp3h/i_built_an_opensource_tool_that_turns_rooted/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u8lp3h/i_built_an_opensource_tool_that_turns_rooted/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steve Ballmer called Google Chrome a "rounding error" — 17 years later, Internet Explorer is dead, and Microsoft Edge can barely catch up]]></title>
<description><![CDATA[Former Microsoft CEO Steve Ballmer underestimated Google Chrome. Seventeen years later, Edge is still trying to catch up, and Internet Explorer is gone with the wind.]]></description>
<link>https://tsecurity.de/de/3608064/windows-tipps/steve-ballmer-called-google-chrome-a-rounding-error-17-years-later-internet-explorer-is-dead-and-microsoft-edge-can-barely-catch-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608064/windows-tipps/steve-ballmer-called-google-chrome-a-rounding-error-17-years-later-internet-explorer-is-dead-and-microsoft-edge-can-barely-catch-up/</guid>
<pubDate>Thu, 18 Jun 2026 16:26:07 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Former Microsoft CEO Steve Ballmer underestimated Google Chrome. Seventeen years later, Edge is still trying to catch up, and Internet Explorer is gone with the wind.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why agentic architecture is still so puzzling]]></title>
<description><![CDATA[Many IT leaders looking to capitalize on the promise of agentic AI still struggle with a basic step — building out their agentic architecture — even as they roll out dozens or hundreds of agents.



AI agent deployment is expected to skyrocket over the next year, with IDC predicting a tenfold inc...]]></description>
<link>https://tsecurity.de/de/3607339/it-nachrichten/why-agentic-architecture-is-still-so-puzzling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607339/it-nachrichten/why-agentic-architecture-is-still-so-puzzling/</guid>
<pubDate>Thu, 18 Jun 2026 12:18:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many IT leaders looking to capitalize on the promise of agentic AI still struggle with a basic step — building out their agentic architecture — even as they roll out dozens or hundreds of agents.</p>



<p>AI agent deployment is expected to skyrocket over the next year, with IDC predicting a <a href="https://www.idc.com/resource-center/blog/agent-adoption-the-it-industrys-next-great-inflection-point/">tenfold increase</a> in agent use by large enterprises by the end of this year. But in some cases, CIOs haven’t focused on the building blocks needed to run a huge team of agents, experts say.</p>



<p>Many CIOs have underestimated the <a href="https://www.cio.com/article/4159773/your-ai-agent-is-ready-to-go-is-your-infrastructure.html?utm=hybrid_search">infrastructure work</a> required to get agents to scale responsibly, says <a href="https://www.linkedin.com/in/hilarypacker/" rel="nofollow">Hilary Packer</a>, EVP and head of enterprise data and AI at American Express.</p>



<p>“There’s a tendency to focus on what an agent can do and then move quickly to deployment before the underlying infrastructure is in place,” she says. “It is essential to first build the enterprise capabilities that allow agents to operate consistently across systems, data sources, and workflows.”</p>



<p>IT leaders must also set up well-governed data foundations, but many companies still operate with fragmented systems, inconsistent data definitions, and siloed ownership structures, Packer adds.</p>



<p>“Before deploying increasingly sophisticated models and agents, organizations need confidence that the underlying data is accurate, accessible, and fit for purpose,” she says. “That requires investments in governance, lineage, and modern data infrastructure that allows information to move efficiently across the enterprise.”</p>



<h2 class="wp-block-heading">More than an IT challenge</h2>



<p>Packer sees agentic AI as much a governance and operating model challenge as a technology challenge. In some cases, IT teams are reinventing the wheel with each agent pilot, she suggests.</p>



<p>“As organizations experiment, teams often end up rebuilding the same capabilities repeatedly — for example, identity management, access controls, monitoring, and observability,” she says. “That may be sufficient for isolated pilots, but it becomes difficult to manage and scale across the enterprise.”</p>



<h2 class="wp-block-heading">What agentic architecture really requires</h2>



<p>CIOs need to take a wholistic approach to <a href="https://www.cio.com/article/4129620/agentic-ai-fails-without-an-architecture-of-flow-to-eliminate-the-friction-tax.html?utm=hybrid_search">agentic architecture</a>. While some IT leaders think of architecture as the AI model powering agents, it goes much deeper.</p>



<p>Agentic architecture includes several elements, and in some cases, CIOs have underinvested in some functionality, says <a href="https://www.linkedin.com/in/saurabhpitkar/" rel="nofollow">Saurabh Pitkar</a>, director of product management for agentic commerce at Dell Technologies.</p>



<p>Agentic architecture, Pitkar says, includes an <a href="https://www.cio.com/article/4138739/21-agent-orchestration-tools-for-managing-your-ai-fleet.html">orchestrator</a>, the brain that controls subagents; subagents themselves, which have specialized functions; APIs and other tools; memory to maintain context of an agent session and overall behavior over a longer period; and guardrails to set boundaries for agents</p>



<p>Many organizations are now building <a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html?utm=hybrid_search">agentic architecture</a>, but those still struggling have failed to make the right investments in areas such as building memory and creating <a href="https://www.cio.com/article/4035003/mcp-explained-the-ai-gamechanger.html?utm=hybrid_search">MCP tool</a> standardizations, Pitkar says.</p>



<p>A lack of data access and integration can be a huge barrier to agent deployments despite heavy investments in data modernization, he adds.</p>



<p>In addition, IT leaders struggling to deploy agents have often failed to manage organizational changes to account for a faster, agent-driven delivery cycle, he says. Adoption can slow down considerably if teams aren’t ready to engage with agent-speed outputs.</p>



<p>“AI does not care about org structure when it comes to accessing data,” he says.</p>



<h2 class="wp-block-heading">Use cases determine the details</h2>



<p>While the elements of agentic architecture are fairly standard, CIOs may need to focus more on different functionality depending on the use case, according to Pitkar. The devil is in the details.</p>



<p>“Customer support may need higher investments in dynamic intent mappings, memory, effective UX as these are emotionally charged conversations with human users who need a problem solved to continue their job,” Pitkar adds. “Agentic commerce may focus on deterministic APIs with machine readable data, guardrails, and compliance to securely process transactions with real money.”</p>



<p>Another way to look at agentic architecture is to think about four layers:</p>



<ul class="wp-block-list">
<li><strong>System of context</strong>, including unified, semantically enriched data</li>



<li><strong>System of work</strong>, or composable application services agents can act on</li>



<li><strong>System of agency</strong>, where planning, coordination, and governance live</li>



<li><strong>System of engagement</strong>, the interfaces that enable agents to interact with employees and customers</li>
</ul>



<p>Most organizations have these four functions happening in other enterprise software packages, but they are built for human-paced orchestration instead of machine-speed agents, says <a href="https://www.linkedin.com/in/shibaniahujasalesforce/" rel="nofollow">Shibani Ahuja</a>, SVP for enterprise IT strategy at Salesforce.</p>



<p>“Agentic architecture is the enterprise foundation that allows AI agents to autonomously reason and act — not just respond — in a way that’s governed and secure,” she says. “It’s the difference between an AI that drafts an email and an AI that closes tickets, triggers payments, and updates records, without waiting for a human to pass the baton.”</p>



<p>Ahuja sees organizations struggling to even define agentic architecture, much less deploy it. Throughout 2025, she heard CIOs describing how they implemented AI on a scale.</p>



<p>“If you listened carefully, one was describing predictive AI, one generative AI, and one an agentic workflow that was really just a sophisticated chatbot,” she says. “We were using the same word for fundamentally different things. When the ROI didn’t materialize, organizations didn’t know what had actually failed.”</p>



<p>Agent deployment struggles, meanwhile, have been less about capability and more about where organizations focus their energy, Ahuja says. Many IT leaders focus on the agent, including the use case, the prompt, and the model, but it’s just as important to ask whether the organization’s architecture actually supports its agentic goals, she adds.</p>



<p>“Can agents access real-time, governed data across your entire business?” she says. “Can they act across systems with minimal human input to reconcile inconsistencies? In most enterprises, the honest answer is not yet, and no amount of prompt tuning fixes that.”</p>



<h2 class="wp-block-heading">Setup is only the first step</h2>



<p>It’s now trivial to set up an agent, with most organizations able to do it in days, if not hours. But the work doesn’t stop there, says <a href="https://www.linkedin.com/in/adamfield/" rel="nofollow">Adam Field</a>, chief AI officer at workflow automation provider Tungsten Automation.</p>



<p>Good agentic architecture allows agents to operate reliably inside real business processes, not just in isolation, he says. For the past 30 years, enterprise systems were built for humans to navigate UIs, but agents work silently on the inside by calling APIs and requiring action-level permissions rather than login access.</p>



<p>The underestimated piece of agentic architecture is the governance controls that define what agents can do autonomously and when they must stop and hand off control to a human, Field says.</p>



<p>“Deploying an agent on a discrete task is straightforward,” he adds. “The hard part is that businesses don’t run on discrete tasks.”</p>



<p>Instead, enterprises operate on end-to-end, regulated processes with exceptions, dependencies, compliance requirements, and humans in the loop at specific moments, he notes.</p>



<p>“Designing agentic architecture that works across an entire process, not just a single step, is a fundamentally different challenge,” Field adds. “Traditional software fails obviously. Agents fail silently, confidently, at scale.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Weibo’s tiny VibeThinker-3B has the AI world arguing over benchmarks again]]></title>
<description><![CDATA[On Sunday, a team of nine researchers at Sina Weibo — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a 14-page technical report to arXiv that sent shockwaves through the AI research community. Their claim: ...]]></description>
<link>https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</guid>
<pubDate>Wed, 17 Jun 2026 03:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On Sunday, a team of nine researchers at <a href="https://weibo.com/">Sina Weibo</a> — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a <a href="https://arxiv.org/pdf/2606.16140">14-page technical report</a> to arXiv that sent shockwaves through the AI research community. Their claim: a language model with just 3 billion parameters can match or exceed the reasoning performance of flagship systems from <a href="https://deepmind.google/">Google DeepMind</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, and <a href="https://chat.deepseek.com/">DeepSeek</a> that are hundreds of times larger.</p><p>The model, called <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>, scored 94.3 on <a href="https://aime26.aimedicine.info/">AIME 2026</a> — the American Invitational Mathematics Examination, one of the most demanding standardized math competitions in the world. That figure places it alongside <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a>, a model with 671 billion parameters, and ahead of <a href="https://blog.google/products-and-platforms/products/gemini/gemini-3/">Gemini 3 Pro</a>, Google's high-performance flagship reasoning system, which scored 91.7. With a test-time scaling technique the team calls Claim-Level Reliability Assessment, the score climbs to 97.1, edging past virtually every system in the public record.</p><p>Within hours of publication, the paper had drawn 62 upvotes on <a href="https://huggingface.co/papers/2606.16140">Hugging Face's daily papers</a> feed, the model repository had accumulated 130 likes, and the <a href="https://github.com/WeiboAI/VibeThinker">GitHub repository</a> had reached 685 stars. But the reaction on social media was not uniformly celebratory. It was, in many cases, deeply skeptical.</p><p>"WHAT THE HELL is happening in AI?" wrote the user <a href="https://x.com/orcus108/status/2066876960073281582">@orcus108</a> on X, in a post that accumulated over 161,000 views. "A 3B parameter model just put up coding benchmark scores in the same league as Claude Opus 4.5… I genuinely don't know if this is a breakthrough or if the benchmarks are broken."</p><p>That tension — between genuine scientific advancement and the growing suspicion that AI benchmarks have become gameable to the point of meaninglessness — sits at the heart of the <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> story. And the answer matters enormously, not just for academic bragging rights, but for the multibillion-dollar question of whether the AI industry's relentless push toward ever-larger models is the only path to intelligence.</p><div></div><h2><b>Benchmark scores that defy the scaling laws of modern AI</b></h2><p>The results reported in the technical report are, by any conventional standard, extraordinary.</p><p>On the mathematics side, <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> achieved 91.4 on <a href="https://artificialanalysis.ai/evaluations/aime-2025">AIME 2025</a>, 94.3 on <a href="https://llm-stats.com/benchmarks/aime-2026">AIME 2026</a>, 89.3 on <a href="https://huggingface.co/datasets/MathArena/hmmt_feb_2025">HMMT 2025</a> (the Harvard-MIT Mathematics Tournament), 93.8 on <a href="https://huggingface.co/datasets/MathArena/brumo_2025">BruMO 2025</a> (the Brown University Math Olympiad), and 76.4 on <a href="https://huggingface.co/datasets/Hwilner/imo-answerbench">IMO-AnswerBench</a>, a benchmark comprising 400 problems at the level of the International Mathematical Olympiad. In coding, it posted an 80.2 Pass@1 on <a href="https://www.kaggle.com/benchmarks/open-benchmarks/livecodebench-release-v6">LiveCodeBench v6</a>, a benchmark designed to test executable code generation, and achieved a 96.1 percent acceptance rate on unseen <a href="https://leetcode.com/contest/">LeetCode weekly</a> and biweekly contests from late April through late May 2026. On instruction following, it scored 93.4 on <a href="https://huggingface.co/datasets/google/IFEval">IFEval</a>.</p><p>To put the parameter disparity in perspective: <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a> has 671 billion parameters — roughly 224 times the size of <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>. <a href="https://huggingface.co/zai-org/GLM-5">GLM-5</a>, from Zhipu AI, has 744 billion parameters. <a href="https://huggingface.co/moonshotai/Kimi-K2.5">Kimi K2.5</a>, from Moonshot AI, exceeds 1 trillion. VibeThinker-3B's 3 billion parameters could run on a consumer laptop.</p><p>The researchers frame this result not as an anomaly but as evidence for a broader theoretical claim. They introduce what they call the "<a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a>," which argues that different types of AI capability have fundamentally different relationships to model size. Verifiable reasoning — the kind tested by math competitions and coding challenges, where answers can be definitively checked — is what the paper calls a "parameter-dense" capability: one that can be compressed into a compact core. Open-domain knowledge, by contrast, is "parameter-expansive," requiring broad coverage across facts, concepts, and edge cases that inherently demands more parameters.</p><p>The paper acknowledges this distinction directly. On <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-Diamond</a>, a graduate-level science knowledge benchmark, VibeThinker-3B scored just 70.2 — well behind the 91.9 achieved by Gemini 3 Pro and the 87.0 scored by Claude Opus 4.5. The authors write that this gap "is consistent with our claim rather than a contradiction to it: the main finding is not that a 3B model has fully replaced leading general-purpose models, but that a small model can reach first-tier performance on many verifiable reasoning tasks."</p><div></div><h2><b>Inside the four-stage training pipeline that powers a tiny reasoning engine</b></h2><p><a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> is not built from scratch. It is post-trained on top of <a href="https://huggingface.co/Qwen/Qwen2.5-Coder-3B">Qwen2.5-Coder-3B</a>, a compact foundation model from Alibaba's Qwen team, through what the Weibo AI researchers call the "Spectrum-to-Signal Principle" — a multi-stage pipeline first introduced in the team's earlier VibeThinker-1.5B work in November 2025.</p><p>The training unfolds in four major phases. The first is a two-stage supervised fine-tuning process that uses curriculum learning: the model first trains on a broad mixture of math, code, STEM reasoning, general dialogue, and instruction-following data, then shifts to a curated subset of harder, longer-horizon reasoning problems. In the second stage, samples with reasoning traces shorter than 5,000 tokens are discarded, and problems that <a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a> can solve more than 75 percent of the time are filtered out, forcing the model to focus on genuinely difficult challenges.</p><p>The second phase applies reinforcement learning across multiple domains — mathematics, code, and STEM — using the team's <a href="https://www.emergentmind.com/topics/maxent-guided-policy-optimization-mgpo">MaxEnt-Guided Policy Optimization</a> algorithm, or MGPO, which prioritizes training on problems at the model's current capability boundary rather than problems it already solves easily or finds impossible. Notably, the team found that a strategy that worked well at the 1.5B scale — progressively expanding the context window during RL training — actually hurt performance at 3B. They hypothesize that the stronger starting checkpoint meant that truncating reasoning traces during warm-up was no longer removing noise but disrupting valid reasoning patterns. The solution was to train with a single 64,000-token context window throughout.</p><p>Within the math RL phase, the team also introduces what it calls "<a href="https://arxiv.org/pdf/2606.16140">Long2Short Math RL</a>," a secondary optimization stage that redistributes rewards to favor shorter correct solutions over longer ones, reducing verbosity without sacrificing accuracy. The technique uses a zero-sum reward redistribution that avoids biasing the overall reward signal while nudging the model toward more efficient reasoning.</p><p>The third phase extracts high-quality reasoning trajectories from the RL-trained checkpoints and distills them back into a unified model through supervised fine-tuning. The team uses a "learning-potential score" — essentially the student model's perplexity on each teacher trajectory — to prioritize traces that are correct but that the student has not yet internalized. The final phase, called Instruct RL, applies reinforcement learning on instruction-following tasks using a combination of rule-based validators for format constraints and rubric-based reward models for open-ended quality assessment.</p><p><a href="https://x.com/f14bertolotti/status/2066752828505288902">Francesco Bertolotti</a>, an AI researcher who flagged the paper early on X, described the approach succinctly: "These results were achieved primarily through post-training refinements on Qwen2.5-Coder. The paper doesn't provide many details, but it appears they distill from RL ckpts and then do a final RL-based instruct RL." His post drew over 161,000 views.</p><div></div><h2><b>Real-world testing reveals the gap between benchmark scores and practical AI performance</b></h2><p>For every enthusiastic reaction, the paper drew an equally forceful objection. The AI research community in mid-2026 has grown deeply wary of benchmark-driven claims, and <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> arrived in an environment primed for suspicion.</p><p>"The benchmarks are literal pattern matching single file coding," wrote <a href="https://x.com/BigMoonKR/status/2066950583941214698">@BigMoonKR</a> on X. "It has no relation to actual coding work. I don't know how people still don't get this."</p><p>"Benchmaxxing," declared @<a href="https://x.com/oflu_bedirhan/status/2066883558388404717">oflu_bedirhan</a>, using a term that has become shorthand in the AI community for models that appear optimized specifically for benchmark performance at the expense of real-world utility.</p><p>The most pointed criticism came from users who actually downloaded and tested the model. "Just tried the full precision," wrote <a href="https://x.com/politilols/status/2066901234091438132">@politilols</a>. "It doesn't even know what a uv script (so the most popular Python dev tool) is. Haven't seen that in a single LLM in at least a year now. Benchmaxxed." When Bertolotti responded that the model seemed more focused on mathematical reasoning than practical coding, the user countered: "They include a livecodebench score. Zero chance that is reflective of the model."</p><p><a href="https://x.com/Itsdotdev/status/2066961630521385166">@Itsdotdev</a> raised a structural criticism: "Look into the benchmarks themselves and it probably won't be so shocking. Why no DeepSWE? Why none of the standard benchmarks SOTA providers use?" The user @AvenirReym posed a more diagnostic question: "If it holds on a benchmark made after the model's training cutoff, it's real. If it only wins on AIME-style sets that have been circulating for years, it's leakage."</p><p>The paper's authors appear to have anticipated these objections. The technical report states that training sets "have undergone strict benchmark decontamination," including n-gram-based filtering to remove "n-gram overlaps with evaluation sets."</p><p>The LeetCode contest evaluation — which covers contests from April 25 to May 31, 2026, dates that postdate any plausible training data cutoff — represents the most robust guard against data contamination concerns. On those contests, VibeThinker-3B passed 123 out of 128 first-attempt submissions, a 96.1 percent rate that exceeded GPT-5.2, Doubao Seed 2.0 Pro, Kimi K2.5, and Claude Opus 4.6 under identical evaluation conditions.</p><p>Still, real-world user reports suggest a significant gap between benchmark performance and practical utility — a phenomenon that has become familiar across the industry. "In LM Studio it only responds well to first question, next questions reply to the first question," reported <a href="https://x.com/luismolinaab/status/2066980744220528940">@luismolinaab</a>.</p><div></div><h2><b>Why a social media company may have found a crack in the scaling hypothesis</b></h2><p>Even the sharpest critics acknowledged that achieving these benchmark numbers at 3 billion parameters — regardless of how transferable they are to production use cases — is a meaningful engineering achievement. "Even if it's benchmaxxing doing so with 3B parameters is fascinating, goes to show how fast this field is progressing," wrote <a href="https://x.com/rohityin/status/2066913806287327302">@rohityin.</a></p><p>The observation cuts to a question that has consumed the AI industry since the advent of the scaling hypothesis: Is bigger always better? The conventional wisdom, articulated most famously in the Chinchilla scaling laws and reinforced by the commercial dominance of ever-larger foundation models, holds that more parameters and more training data reliably yield better performance. The economic corollary is stark: training and deploying frontier models costs tens or hundreds of millions of dollars, creating enormous barriers to entry.</p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> challenges that consensus — but only partially. The paper is careful to draw a boundary around its claims, distinguishing between tasks with "clear verification signals" and those that require broad factual knowledge. The Parametric Compression-Coverage Hypothesis explicitly argues that small models cannot replace large ones across the board.</p><p>"The true significance of VibeThinker-3B does not lie in proving that a 3B model can replace large-scale generalists," the paper states, "but rather in providing a concrete empirical signal: the development of compact models is no longer merely a passive compromise for deployment efficiency or cost control; it emerges as a promising research trajectory that is fundamentally complementary to the traditional parameter scaling paradigm."</p><p>Perhaps the most surprising element of the work is its provenance. Sina Weibo — publicly traded on Nasdaq and Hong Kong, with a market capitalization that fluctuates in the single-digit billions — is not a company typically associated with frontier AI research. Yet the VibeThinker series is Weibo's second major open-source AI contribution in seven months. </p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a>, released in November 2025, demonstrated that a model with just 1.5 billion parameters could outperform the original DeepSeek R1 on several math benchmarks — a result the team achieved for what it claimed was a post-training cost of just $7,800, compared to the $294,000 estimated for DeepSeek R1.</p><p>The research team is compact — nine authors, all listed as Sina Weibo Inc. employees. The model is released under the <a href="https://opensource.org/license/mit">MIT License</a>, one of the most permissive open-source licenses available, and the weights are freely downloadable from both <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">Hugging Face</a> and <a href="https://modelscope.cn/models/WeiboAI/VibeThinker-3B">ModelScope</a>. Within the first day of release, community members had already created GGUF quantizations and derivative models.</p><h2><b>Small models, big implications, and the question the AI industry can no longer avoid</b></h2><p>The most honest assessment of <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> may be that it is simultaneously less and more than what the benchmarks suggest. Less, because a model that struggles with basic knowledge of popular developer tools is unlikely to replace any production-grade coding assistant anytime soon. More, because the underlying insight — that reasoning ability and factual knowledge are partially decoupled, and that the former can be compressed far more aggressively than previously assumed — has profound implications for how the industry thinks about model design, deployment economics, and the accessibility of advanced AI capabilities.</p><div></div><p>If the <a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a> holds, it suggests a future in which small, specialized reasoning engines operate alongside large knowledge-rich models in hybrid architectures — a vision where a 3-billion-parameter model handles the logical heavy lifting while a larger system supplies the factual grounding. Such an architecture could dramatically reduce the cost of deploying AI reasoning capabilities, potentially bringing competition-level mathematical and coding performance to devices with modest hardware.</p><p>"The interesting part is that we're starting to separate knowledge from reasoning," wrote <a href="https://x.com/RealLambdaFlux/status/2066924260724265463">@RealLambdaFlux</a> on X. "A small model with strong post-training can punch way above its size on tasks with clear feedback."</p><p><a href="https://x.com/cmitsakis/status/2066850007693578352">@cmitsakis</a> suggested the practical endgame: "I think small models are the future for agents because they can use tools to get the knowledge and they can run fast and cheap."</p><p>Whether that future arrives through <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> specifically, or through the dozens of teams now racing to reproduce and extend these results, the paper has already accomplished something that no benchmark score can fully capture.</p><p>It has forced the AI community to confront an uncomfortable possibility: that for years, the industry may have been spending billions of dollars scaling up parameters to improve a kind of intelligence that could have fit, all along, on a laptop. The weights are public. The code is open. And the most important test isn't on any leaderboard — it's whether anyone can make a model this small actually useful in the real world.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inklusion bei Digitalen Projekten (tdf2026)]]></title>
<description><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://...]]></description>
<link>https://tsecurity.de/de/3597153/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597153/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 15:47:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AA8XA3/]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - Inklusion bei Digitalen Projekten]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:4 https://media.ccc.de/v/tdf5-205-inklusion-bei-digitalen-projekten

Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verb...]]></description>
<link>https://tsecurity.de/de/3597150/it-security-video/tdf-2026-inklusion-bei-digitalen-projekten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597150/it-security-video/tdf-2026-inklusion-bei-digitalen-projekten/</guid>
<pubDate>Sun, 14 Jun 2026 15:47:49 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tbrmiiETYlQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-205-inklusion-bei-digitalen-projekten<br />
<br />
Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.<br />
<br />
Borys Sobieski<br />
<br />
https://cfp.cttue.de/tdf5/talk/AA8XA3/<br />
<br />
#tdf2026 #DigitalLiteracyandEmpowerment<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Open Policy & Advocacy Blog: A Handful of Companies Control the Web. AICOA Can Change That.]]></title>
<description><![CDATA[Mozilla Champions the Reintroduction of the American Innovation and Choice Online Act (AICOA)
Today, only a handful of tech companies shape the online experience for the more than 300 million internet users in America. This concentration of power is exactly why we need legislation that advances c...]]></description>
<link>https://tsecurity.de/de/3590865/tools/mozilla-open-policy-advocacy-blog-a-handful-of-companies-control-the-web-aicoa-can-change-that/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590865/tools/mozilla-open-policy-advocacy-blog-a-handful-of-companies-control-the-web-aicoa-can-change-that/</guid>
<pubDate>Thu, 11 Jun 2026 16:24:26 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Mozilla Champions the Reintroduction of the American Innovation and Choice Online Act (AICOA)</strong></p>
<p>Today, only a handful of tech companies shape the online experience for the more than 300 million internet users in America. This concentration of power is exactly why we need legislation that advances competition and user choice.  It’s all the more urgent as AI transforms not just the tools that people use, but also <a href="https://blog.mozilla.org/en/mozilla/rewiring-mozilla-ai-and-web/">magnifies the competitive inequities</a> underlying the web itself.</p>
<p>The American Innovation and Choice Online Act (AICOA) is bipartisan legislation designed to curb harmful gatekeeper behaviors of the biggest tech platforms. The bill does so by prohibiting dominant platforms from unfairly preferencing their own products, discriminating against tech competitors, and preventing interoperability — all practices that stop the best product winning and stifle consumer control. The goal is straightforward: companies should compete based on the quality of their products, not by leveraging anticompetitive tactics.</p>
<p>As the builder and operator of the Firefox browser and the browser engine <a href="https://blog.mozilla.org/netpolicy/2026/03/23/competition-innovation-and-the-future-of-the-web/">Gecko</a>, Mozilla has firsthand experience with the impact of the exclusionary practices AICOA seeks to prevent. For example, <a href="https://research.mozilla.org/browser-competition/over-the-edge-the-use-of-design-tactics-to-undermine-browser-choice/">deceptive design tactics</a> deployed by operating systems make it difficult for people to install and keep Firefox as their preferred browser. Browsers are the portal through which people access the open web, and users should define that interaction. AICOA would help limit the ability of operating systems to steer users toward affiliated products through deceptive design choices. Ensuring meaningful user choice online is not just about variety; it reflects values and individual preferences. Openness and innovation thrives when the web is built around platforms that serve people, not the other way round.</p>
<p>Browser engines, while lesser-known, are among the most complex and consequential pieces of infrastructure on the modern internet, impacting user-focused innovations in privacy, security, speed, and more. Gecko is one of only three widely used engines and the only independent browser engine. The importance of that competitive counterweight cannot be underestimated. When platform owners favor their own vertically integrated products, independent challengers face barriers that have nothing to do with product quality and everything to do with a monopolized market.</p>
<p>It’s important to recognize that antitrust reform can make the internet <i>more</i> private and secure than it is today, as we’ve consistently <a href="https://blog.mozilla.org/en/mozilla/calling-for-antitrust-reform/">emphasized</a>. For example, in 2021, Firefox was <a href="https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/">at the forefront of developing technology against cross-site tracking</a>, but could not release the technology to Firefox users on iOS because of app store rules preferring Apple’s own browser engine, blocking alternatives like<a href="https://blog.mozilla.org/netpolicy/2026/03/23/competition-innovation-and-the-future-of-the-web/"> Gecko</a>.</p>
<p>We’re champions of AICOA and look forward to working with members of Congress to push this legislation forward and tackle longstanding anticompetitive practices. Mozilla thanks Senators Grassley and Klobuchar for their leadership in advancing competition. A thriving tech ecosystem requires an open, fair, and competitive market where innovative services can compete on merit and people can control their own experiences online.</p>
<p>The post <a href="https://blog.mozilla.org/netpolicy/2026/06/11/a-handful-of-companies-control-the-web-aicoa-can-change-that/">A Handful of Companies Control the Web. AICOA Can Change That.</a> appeared first on <a href="https://blog.mozilla.org/netpolicy">Open Policy &amp; Advocacy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security "a real challenge" – The underestimated danger of the World Cup - YouTube]]></title>
<description><![CDATA[It detects and targets enemy drones. The drone is disabled with a net ... 2026 World Cup: Security "a real challenge" – The underestimated danger of the ...]]></description>
<link>https://tsecurity.de/de/3582355/it-security-nachrichten/security-a-real-challenge-the-underestimated-danger-of-the-world-cup-youtube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582355/it-security-nachrichten/security-a-real-challenge-the-underestimated-danger-of-the-world-cup-youtube/</guid>
<pubDate>Mon, 08 Jun 2026 19:54:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>It</b> detects and targets enemy drones. The drone is disabled with a net ... 2026 World Cup: <b>Security</b> "a real challenge" – The underestimated danger of the ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (php:8.2 and php:8.3), Debian (gst-plugins-good1.0, symfony, and yelp), Fedora (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), Mageia (assimp, libcaca, sdl2_sound, and tar), Slackware (kernel)...]]></description>
<link>https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 02 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (php:8.2 and php:8.3), <b>Debian</b> (gst-plugins-good1.0, symfony, and yelp), <b>Fedora</b> (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), <b>Mageia</b> (assimp, libcaca, sdl2_sound, and tar), <b>Slackware</b> (kernel), <b>SUSE</b> (alloy, apache-commons-lang3, apache-commons-text,, apache2, bubblewrap, busybox, chromium, cups, docker-stable, ffmpeg-8, google-osconfig-agent, gsasl, ignition, java-26-openjdk, kernel, libsolv-demo, libsoup, libzypp, localsearch, openjpeg2, postgresql-jdbc, putty, python-mistune, python-Pillow, python-python-multipart, python-Twisted, python3-Twisted, re, roundcubemail, vim, wireshark, and xz), and <b>Ubuntu</b> (evolution-data-server, exim4, gsasl, haveged, lcms2, libreoffice, linux-aws, linux-lts-xenial, linux-lowlatency, linux-nvidia-tegra, nginx, nncp, qtdeclarative-opensource-src, sslh, sssd, and xz-utils).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), Debian (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), Fedora (chromium, dj...]]></description>
<link>https://tsecurity.de/de/3563159/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563159/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 01 Jun 2026 15:09:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), <b>Debian</b> (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), <b>Fedora</b> (chromium, djvulibre, docker-compose, giflib, haveged, libsoup3, libssh2, mingw-objfw, netatalk, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, objfw, pdns, perl-Crypt-PasswdMD5, perl-libwww-perl, python-urllib3, suricata, and xrdp), <b>Mageia</b> (perl-Template-Toolkit and vim), <b>Oracle</b> (.NET 8.0, cockpit, firefox, flatpak, freerdp, kernel, and libexif), <b>Red Hat</b> (containernetworking-plugins, libsoup, libsoup3, multiple packages, php:8.2, php:8.3, podman, rhc, and skopeo), <b>SUSE</b> (amazon-ecs-init, amazon-ssm-agent, apptainer, azure-storage-azcopy, bind, chromium, csync2, cups, docker-stable, frr, gdk-pixbuf-loader-libheif, gnutls, hauler, helm, helm3, ignition, java-1_8_0-ibm, kernel, libBasicUsageEnvironment2, libredwg-devel, localsearch, memcached, openexr, perl-Net-CIDR-Lite, perl-YAML-Syck, postgresql14, python-mistune, python-pillow, python-pytest-html, python-urllib3, python311-Authlib, strongswan, trivy, vim, and xz), and <b>Ubuntu</b> (gdal, python-pip, qtwebengine-opensource-src, rsync, and texmaker).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2018-25411 | M-Gb MGB OpenSource Guestbook 0.7.0.2 email.php ID sql injection (Exploit 45665 / EUVD-2018-21933)]]></title>
<description><![CDATA[A vulnerability has been found in M-Gb MGB OpenSource Guestbook 0.7.0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file email.php. The manipulation of the argument ID leads to sql injection.

This vulnerability is listed as CVE-2018-25411. The at...]]></description>
<link>https://tsecurity.de/de/3559935/sicherheitsluecken/cve-2018-25411-m-gb-mgb-opensource-guestbook-0702-emailphp-id-sql-injection-exploit-45665-euvd-2018-21933/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559935/sicherheitsluecken/cve-2018-25411-m-gb-mgb-opensource-guestbook-0702-emailphp-id-sql-injection-exploit-45665-euvd-2018-21933/</guid>
<pubDate>Sun, 31 May 2026 03:22:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/m-gb:mgb_opensource_guestbook">M-Gb MGB OpenSource Guestbook 0.7.0.2</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the file <em>email.php</em>. The manipulation of the argument <em>ID</em> leads to sql injection.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2018-25411">CVE-2018-25411</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[LibreOffice Writer - einrichten wie Microsoft Word]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 398x - Views:4097 In diesem Video zeigt Jean, wie man den Libre Office Writer so einrichten kann wie Microsoft Word, um in vertrauter Umgebung mit einer sehr guten Office-Alternative arbeiten zu können.
Wenn Du das Video unterstützen willst, dann gib bitte eine B...]]></description>
<link>https://tsecurity.de/de/3557943/linux-tipps/libreoffice-writer-einrichten-wie-microsoft-word/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557943/linux-tipps/libreoffice-writer-einrichten-wie-microsoft-word/</guid>
<pubDate>Sat, 30 May 2026 01:19:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 398x - Views:4097 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Hms467GhynE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean, wie man den Libre Office Writer so einrichten kann wie Microsoft Word, um in vertrauter Umgebung mit einer sehr guten Office-Alternative arbeiten zu können.<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
Schriftarten: Paket "Ttf-mscorefonts-installer" für die klassischen Microsoft-Schriftarten (Arial, Times New Roman etc.)<br />
Paket "Fonts-crosextra-carlito" für eine Calibri-Alternative<br />
Paket "Fonts-crosextra-caladea" für eine Cambria-Alternative<br />
<br />
Wichtigste Tastenkombinationen in MS Word: https://www.heise.de/hintergrund/Word-Tastenkuerzel-69-Shortcuts-im-Ueberblick-4108214.html<br />
<br />
- Libre Office Writer (Word) Crashkurs: https://youtu.be/QyakKLNv7Yg<br />
- Libre Office Calc (Excel) Crashkurs: https://youtu.be/ioAxN27CIUA<br />
- Briefe schreiben mit Libre Office Writer: https://youtu.be/wL971SdRVkY<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Begrüßung<br />
00:51 Oberfläche<br />
03:08 Microsoft-Schriftarten<br />
07:22 Speichern als .docx<br />
09:19 Tastenkombinationen (Shortcuts)<br />
11:28 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #libreoffice #libreofficewriter #msword #opensource<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, cockpit, firefox, flatpak, httpd, kernel, and kernel-rt), Debian (kernel, kitty, lemonldap-ng, nagios4, python-flask-httpauth, and roundcube), Fedora (CImg, gmic, haveged, jpegxl, kernel, libpng, mapserver, mingw-qt6-qtsvg, openb...]]></description>
<link>https://tsecurity.de/de/3557942/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557942/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Sat, 30 May 2026 01:19:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 8.0, .NET 9.0, cockpit, firefox, flatpak, httpd, kernel, and kernel-rt), <b>Debian</b> (kernel, kitty, lemonldap-ng, nagios4, python-flask-httpauth, and roundcube), <b>Fedora</b> (CImg, gmic, haveged, jpegxl, kernel, libpng, mapserver, mingw-qt6-qtsvg, openbao, perl-Sereal, perl-Sereal-Decoder, perl-Sereal-Encoder, and podofo), <b>Mageia</b> (bind, graphicsmagick, microcode, nginx, packages, perl-Catalyst-Plugin-Authentication, perl-HTTP-Daemon, perl-IO-Compress, and thunderbird(-l10n)), <b>SUSE</b> (alloy, apache2, beets, bubblewrap, cups, docker-stable, ffmpeg-4, ffmpeg-7, firefox, google-osconfig-agent, patterns-glibc-hwcaps, podman, samba, thunderbird, trivy, xdg-desktop-portal, and xz), and <b>Ubuntu</b> (apache2, libreoffice, multipart, openjdk-17, openjdk-17-crac, openjdk-21, openjdk-21-crac, openjdk-25, openjdk-25-crac, openjdk-26, openjdk-8, openjdk-lts, php8.1, php8.3, php8.4, php8.5, pyopenssl, python-pip, qtsvg-opensource-src, sed, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM und Red Hat investieren Milliarden in Open-Source-Sicherheit]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Leistungsfähige KI-Modelle wie Claude Mythos bedrohen den Open-Source-Ansatz. IBM und Red Hat wollen den Fortbestand sichern. Norman Chan / Shutterstock



Open-Source-Code ist in Unternehmen allgegenwärtig; Schätzungen zuf...]]></description>
<link>https://tsecurity.de/de/3557739/it-security-nachrichten/ibm-und-red-hat-investieren-milliarden-in-open-source-sicherheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557739/it-security-nachrichten/ibm-und-red-hat-investieren-milliarden-in-open-source-sicherheit/</guid>
<pubDate>Sat, 30 May 2026 01:13:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Leistungsfähige KI-Modelle wie Claude Mythos bedrohen den Open-Source-Ansatz. IBM und Red Hat wollen den Fortbestand sichern. </figcaption></figure><p class="imageCredit">Norman Chan / Shutterstock</p></div>



<p>Open-Source-Code ist in Unternehmen allgegenwärtig; Schätzungen zufolge nutzen <a href="https://worldmetrics.org/opensource-statistics/" target="_blank" rel="noreferrer noopener">mehr als 90 Prozent</a> der Fortune-500-Unternehmen ihn in ihren Software-Lieferketten. Open-Source-Code ist jedoch bekanntermaßen voller Schwachstellen und das Aufspüren und Beheben dieser Fehler kann für Sicherheitsteams zu einem endlosen Kampf werden.</p>



<p>IBM und Red Hat setzen darauf, dass eine neue Initiative, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era" target="_blank" rel="noreferrer noopener">Project Lightwell</a>, dazu beitragen kann, diesen Prozess zu beschleunigen. Im Rahmen des Projekts wollen die beiden Unternehmen fünf Milliarden Dollar sowie 20.000 Ingenieure von IBM und Red Hat bereitstellen, um eine Art „Clearingstelle“ für Unternehmen aufzubauen.</p>



<p>Den Unternehmen zufolge soll diese als KI-gestützte „Sicherheits-Koordinierungsebene“ dienen und Unternehmen die Möglichkeit geben, Patches direkt in ihre bestehenden Software-Lieferketten zu integrieren.</p>



<p>„Project Lightwell“ befindet sich derzeit in der Konzeptphase mit einer Gruppe von elf Finanzpartnern und soll später als kommerzielles Abonnement angeboten werden.</p>



<p>„Die Fortschritte bei KI-Tools haben die Patching-Landschaft revolutioniert – also die Fähigkeit, Schwachstellen in Software zu entdecken, ohne dabei an Behebungsgeschwindigkeit einzubüßen“, erklärt <a href="https://www.redhat.com/en/about/company/leadership/ashesh-badani" target="_blank" rel="noreferrer noopener">Ashesh Badani</a>, Senior Vice President und Chief Product Officer bei Red Hat, gegenüber CSOonline. „Jeder nutzt Open-Source-Software und die Herausforderung besteht darin, Schwachstellen nicht schnell genug beheben zu können.“</p>



<h2 class="wp-block-heading">Die Lücke bei der Behebung von Schwachstellen schließen</h2>



<p>Die Sicherheitsprobleme bei Open-Source-Software sind gut dokumentiert: Fast 50.000 Common Vulnerabilities and Exposures (CVEs) <a href="https://www.cve.org/about/Metrics">wurden im Jahr 2025 veröffentlicht</a>, und das Project Glasswing von Anthropic, das auf dem <a href="https://www.computerwoche.de/article/4156536/wie-claude-mythos-die-it-sicherheit-veraendert.html">Mythos Preview</a>-Modell basiert, fand kurz nach dem Start rund 3.900 bisher unentdeckte Schwachstellen mit hohem oder kritischem Schweregrad in Open-Source-Software.</p>



<p>IBM betreibt eines der größten kommerziellen Open-Source-Ökosysteme und nutzt mehr als 62<strong>.</strong>000Softwarepakete in Umgebungen wie Linux, Kubernetes, Kafka, Terraform und Java. Das Unternehmen bietet dort bereits Lebenszyklusmanagement, Validierung und Patching an.</p>



<p>Mit Project Lightwell sollen diese Prinzipien nun auf KI-Frameworks, unabhängige Bibliotheken, Sprach-Toolchains und Daten-Streaming-Plattformen ausgeweitet werden. Ziel ist es, validierte Sicherheitskorrekturen für Open-Source-Code bereitzustellen, der bereits in Unternehmensumgebungen eingesetzt wird – ohne Stabilität, Zertifizierungen oder Compliance-Anforderungen zu beeinträchtigen.</p>



<p>IBM zufolge sind dafür keine Upgrades oder der Zugriff auf den Quellcode erforderlich. Project Lightwell werde Sicherheitskorrekturen auf genau die Abhängigkeitsversionen zurückportieren, die bereits getestet und bereitgestellt wurden. Die Lösung arbeitet auf Basis von Konfigurationsdateien wie <em>pom.xml</em>, sodass der Code innerhalb der kontrollierten Unternehmensumgebung verbleibt. Der anfängliche Fokus liegt auf Java/Maven, später sollen auch PyPI, npm, Go und weitere Plattformen unterstützt werden.</p>



<h2 class="wp-block-heading">Diskrete Fehlerbehebung möglich</h2>



<p>Unternehmen sollen zudem die Möglichkeit erhalten, sensible Schwachstellen unter Embargo über ein „sicheres Vermittlermodell“ zu teilen und validierte Patches zu erhalten, die Red Hat-Plattformen und unabhängigen Community-Code abdecken. Darüber hinaus können sie Korrekturen über Abhängigkeitsketten hinweg bereitstellen, Probleme in aktiven Produktionsumgebungen melden und beheben sowie Korrekturen an die Upstream-Community weitergeben, damit diese sie integrieren kann.</p>



<p>„Wir wollen sicherstellen, dass alle Korrekturen, die wir den Unternehmen über die Clearingstelle zur Verfügung stellen, auch wieder ihren Weg zurück in die Open-Source-Projekte finden, die [den Code] entwickelt haben“, erklärt Badani. „Wenn beispielsweise ein Stück Python-Code gepatcht wurde, soll die Korrektur schnell an die Python-Community zurückgeliefert werden.“</p>



<p>Mithilfe fortschrittlicher KI und in Zusammenarbeit mit führenden Open-Source-Mitwirkenden werden sich die Ingenieure von IBM und Red Hat darauf konzentrieren, Upstream- und Downstream-Umgebungen besser zu verbinden, damit die Korrekturen sofort für Unternehmen nutzbar sind. Zudem sollen sie Patches entwickeln, große Mengen an Schwachstellen analysieren und priorisieren sowie Abhängigkeiten absichern.</p>



<p>Badami zufolge stammen die 20.000 Ingenieure aus den bestehenden Teams von IBM und Red Hat. Bei Bedarf sollen weitere Fachkräfte hinzugezogen werden. Die Unternehmen wollen sowohl moderne Foundation-Modelle führender KI-Labore als auch eigene KI-Werkzeuge und Frameworks einsetzen. Die fünf Milliarden Dollar werden in KI-Werkzeuge und den Aufbau der erforderlichen Infrastruktur investiert.</p>



<p>Zu den frühen Unterstützern von Project Lightwell zählen unter anderem Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa und Wells Fargo. Nach der Designphase soll das Angebot schrittweise weiteren Kunden über ein Abonnementmodell zugänglich gemacht werden.</p>



<h2 class="wp-block-heading">Ein Aufruf zum Handeln?</h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> von Beauceron Security bezeichnet die Initiative als „dringend notwendig“, wenn Unternehmen Open Source langfristig erhalten wollen. Die Zeit, in der Billionenwerte auf der Arbeit freiwilliger Entwickler beruhten, sei mit Claude Mythos abrupt zu Ende gegangen. Nun müssten Unternehmen ihren Beitrag leisten, um Open Source zu unterstützen.</p>



<p>„Wenn wir keinen Weg finden, in Open Source zu investieren, besteht die Alternative darin, dass jeder seinen eigenen maßgeschneiderten Code mithilfe von KI entwickelt“, erklärt Shipley. Das wäre aus Rechen- und Umweltperspektive „enorm verschwenderisch“.</p>



<h2 class="wp-block-heading">Menschen bleiben unverzichtbar</h2>



<p>Red-Hat-Manager Badani betont, dass KI zwar hervorragend darin sei, Sicherheitsprobleme in Open-Source-Code aufzudecken, der Prozess der Fehlerbehebung jedoch nach wie vor mühsam sein kann. Korrekturen müssten zunächst an die Entwickler weitergeleitet, an die Open-Source-Community verteilt und dann an Kunden und Nutzer zurückgespielt werden.</p>



<p>„Den Fehler zu finden ist eine Sache“, so Badani. „Die eigentliche Herausforderung sind die vielen Schritte, die erforderlich sind, um ihn tatsächlich zu beheben. Genau diesen zusätzlichen Zeitaufwand wollen wir verkürzen.“</p>



<p>Während die öffentliche Diskussion häufig davon geprägt sei, menschliche Entwickler durch KI zu ersetzen, verfolge Project Lightwell den gegenteiligen Ansatz, fügte der Red-Hat-CPO an „Wir können das Problem mit einer Kombination aus KI-Tools und menschlichem Wissen und Fachkompetenz angehen. Die Verbindung beider Aspekte führt zu einem besseren Ergebnis als ausschließlich das eine oder das andere zu nutzen.“ (mb)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s open-source toolkit for controlling out-of-control AI agents]]></title>
<description><![CDATA[The rapid uptake of agentic AI has exposed a range of issues with our non-deterministic helpers. That’s mainly because AI agents are not people and don’t behave like people, even though they generally use the same APIs as humans. For one thing, they make many more queries than a human would, as t...]]></description>
<link>https://tsecurity.de/de/3557522/ai-nachrichten/microsofts-open-source-toolkit-for-controlling-out-of-control-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557522/ai-nachrichten/microsofts-open-source-toolkit-for-controlling-out-of-control-ai-agents/</guid>
<pubDate>Sat, 30 May 2026 01:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The rapid uptake of <a href="https://www.infoworld.com/article/4120858/agentic-ai-exposes-what-were-doing-wrong.html" data-type="link" data-id="https://www.infoworld.com/article/4120858/agentic-ai-exposes-what-were-doing-wrong.html">agentic AI</a> has exposed a range of issues with our non-deterministic helpers. That’s mainly because AI agents are not people and don’t behave like people, even though they generally use the same APIs as humans. For one thing, they make many more queries than a human would, as they build the necessary context to deliver a response.</p>



<p>Anecdotal data from companies that have worked with agents or who have users who access services through agents indicate that this can mean <a href="https://github.blog/news-insights/company-news/an-update-on-github-availability/">massive increases in API usage</a>, which have affected availability. This increase is the result of automated requests flooding in and blocking calls and responses from APIs that worked perfectly well a year or so ago but now are struggling to cope with the load.</p>



<p>A fundamental redesign of our APIs is necessary, but budgets, resourcing, and capacity make this hard to deliver overnight. What’s needed, then, is a way to manage agent interactions with APIs, treating agents as a new class of user, providing and enforcing the policies that are needed to manage agent life cycles. The use of <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) as a standard wrapper for agent access to APIs helps here, as it gives us a common environment where we can implement the governance layer needed to keep agents under control.</p>



<p>Microsoft recently <a href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/" data-type="link" data-id="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/">launched a public preview</a> of its <a href="https://github.com/microsoft/agent-governance-toolkit" data-type="link" data-id="https://github.com/microsoft/agent-governance-toolkit">open-source Agent Governance Toolkit</a> (AGT), which is intended to wrap policy-based enforcement around agents, ensuring that calls are evaluated before they’re made. You can think of the toolkit as a way to manage agent actions, rather than controlling the inputs and outputs of the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs) your agents use. Figures from Microsoft suggest that this method of securing agents is far safer than relying on rules in prompts. However, in practice it’s a good idea to run a capability tool like Agent Governance Toolkit alongside traditional filters to trap user errors and prompt-based attacks.</p>



<p>AGT is <a href="https://microsoft.github.io/agent-governance-toolkit/">a set of tools</a> designed to cover OWASP’s list of agentic risks, building on Microsoft’s experience securing its own agents and AI platforms, with more than 13,000 tests built into the toolkit. It works by evaluating actions before they’re run, checking them against your policies, before allowing or denying the action and logging the results. Microsoft expects policy evaluation to take less than 0.1ms per operation, keeping overheads to a minimum.</p>



<h2 class="wp-block-heading">Policies for agents</h2>



<p><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP’s top 10 agent risks</a> lists the most significant issues that can disrupt agent operations resulting from user prompts and bad application design. These risks include agent goal hijacking, uncontrolled code execution, insecure output handling, and agents going rogue. Features in the toolkit are designed to protect agentic applications from these and other issues, using isolation and sandboxing, as well as validating outputs using content policies.</p>



<p>You can use declarative programming techniques to build the policies that <a href="https://devblogs.microsoft.com/dotnet/governing-mcp-tool-calls-in-dotnet-with-the-agent-governance-toolkit/" data-type="link" data-id="https://devblogs.microsoft.com/dotnet/governing-mcp-tool-calls-in-dotnet-with-the-agent-governance-toolkit/">define the limits of your agents’ operations</a>. As the policies are human-readable, you can share them with colleagues and refine them across projects to produce a common set of AGT rules for all agents running inside your organization.</p>



<p>The resulting authorization model is intent-based, with agents declaring their intent, which AGT approves or denies. The policy then determines what operations are allowed, whether they’re permitted with an alert, or blocked. This approach allows your code to check orchestrated operations for drift from the top-level intent. When your code is running a harness for multiple parallel agents, this helps keep the application on track and reduces the risk of unwanted operations and using too many tokens.</p>



<p>Agent behavior often results in using more tokens than expected, so keeping spend under control is another role for AGT. As platforms move to new pricing and budgeting models, the ability to control the number of tokens that can be spent on an agent interaction will become very important indeed, and the ability to set a token budget in an AGT policy will allow developers to prevent users from significant unintended spend. AGT’s budget management tools can be used to throttle activities as agents approach preset limits, and to reject actions if they look likely to use excessive tokens.</p>



<h2 class="wp-block-heading">Monitoring and manag agents in action</h2>



<p>You can even use AGT to manage API calls, something that’s becoming increasingly important as agent context-seeking activities can quickly overwhelm APIs designed for human interactions. By building rules that limit the number of calls in a set amount of time, you can now have your agent framework manage throttling for you rather than implementing complex API management tools.</p>



<p>One key feature of AGT is the ability to use its mix of declarative policies to find agents that are drifting from your set baselines, helping spot issues before they cost money or affect operations. AGT also can be used to apply kill switches where necessary. Logging and observability capabilities include a way to provide a root cause analysis of issues, along with what Microsoft calls a “decision bill of materials” that keeps track of governance decisions with an audit chain and the details of the trust levels associated with agents.</p>



<p>A toolkit like AGT needs to be vendor neutral, as your agents could be working with models running in any environment. AGT is designed to work with Azure Foundry, Amazon Bedrock, and Google ADK, as well as with most common agent orchestration frameworks. AGT supports five different programming languages: Python, TypeScript, .NET, Rust, and Go. While capabilities vary between the different implementations, the Python version has the full set.</p>



<p>Microsoft has made some interesting architectural decisions in AGT. Perhaps the most important is that it treats agents as code running on a secure operating system, using concepts from hypervisors to isolate agents from the underlying platform. You can see this in the way the underlying components and packages are named; the core governance package is called Agent OS.</p>



<h2 class="wp-block-heading">Building AGT into your code</h2>



<p><a href="https://microsoft.github.io/agent-governance-toolkit/quickstart/">Getting started with AGT</a> can be as simple as installing the complete toolkit using standard package manager of your language of choice. You don’t need to install the whole thing. You have the option of installing specific packages when you don’t need all the features, or when you only want to use a single function. You could download only AGT’s software reliability engineering tools, for example, when you want to put your agents through chaos testing.</p>



<p>You can define policies inside your code or as external policy documents. Policies are focused on key security and governance goals, such as blocking dangerous tools from running, looking for PII in messages, and showing users what action has been taken and why. External policy documents are recommended for use with production AGT implementations, as they let you author policies in YAML. The toolkit provides a single call to load all the policy files in a directory, so it’s a good idea to store only production policies in that location to avoid issues.</p>



<p>Adding support for AGT in existing code is a matter of adding evaluations before your agent framework makes a call. This can be handled using refactoring tools in your editor, finding the call and wrapping the evaluator and decision results around it. This way you can develop agents without using AGT, adding its tools when you’re confident you have a working agent. Microsoft provides <a href="https://microsoft.github.io/agent-governance-toolkit/packages/#framework-integrations-19" data-type="link" data-id="https://microsoft.github.io/agent-governance-toolkit/packages/#framework-integrations-19">custom adapters for 19 different frameworks</a>, tuned to work with them. These can be loaded alongside the rest of the toolkit.</p>



<p>AGT is a sign of growing maturity in our agent landscape, applying enterprise rigor to what has been something of a Wild West free-for-all. It addresses many of the concerns associated with using agents at scale, helping control both agent behavior and costs. Autonomous software needs to be kept on a leash, and AGT’s declarative approach to building and applying policies — along with the rest of its suite of tools — gives you the ability to quickly build and apply the necessary controls.</p>



<p>With companies looking to control costs and regulators wanting to ensure that agentic software doesn’t violate compliance requirements, tools like the Agent Governance Toolkit will likely become an essential part of our modern agent development environment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM·레드햇, 기업용 오픈소스 보안 컨트롤타워 구축 나서]]></title>
<description><![CDATA[기업 환경에서 오픈소스 코드는 사실상 필수 요소가 됐다. 포춘 500대 기업의 90% 이상이 소프트웨어 공급망에 오픈소스 코드를 포함하고 있는 것으로 추정된다. 그러나 오픈소스는 수많은 보안 취약점을 안고 있는 경우가 많아, 이를 찾아내고 패치하는 작업은 보안팀의 끝없는 과제로 꼽힌다.



IBM과 레드햇은 이러한 문제를 해결하기 위해 새로운 프로젝트인 ‘프로젝트 라이트웰(Project Lightwell)’을 추진한다.



29일 공개된 프로젝트 라이트웰은 50억 달러(약 6조 8,000억 원)와 IBM 및 레드햇 엔지니어...]]></description>
<link>https://tsecurity.de/de/3556101/it-nachrichten/ibm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556101/it-nachrichten/ibm/</guid>
<pubDate>Fri, 29 May 2026 07:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>기업 환경에서 오픈소스 코드는 사실상 필수 요소가 됐다. 포춘 500대 기업의 90% 이상이 소프트웨어 공급망에 오픈소스 코드를 포함하고 있는 것으로 <a href="https://worldmetrics.org/opensource-statistics/" target="_blank" rel="nofollow">추정된다</a>. 그러나 오픈소스는 수많은 보안 취약점을 안고 있는 경우가 많아, 이를 찾아내고 패치하는 작업은 보안팀의 끝없는 과제로 꼽힌다.</p>



<p>IBM과 레드햇은 이러한 문제를 해결하기 위해 새로운 프로젝트인 ‘<a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era" target="_blank" rel="nofollow">프로젝트 라이트웰</a>(Project Lightwell)’을 추진한다.</p>



<p>29일 공개된 프로젝트 라이트웰은 50억 달러(약 6조 8,000억 원)와 IBM 및 레드햇 엔지니어 2만 명을 투입해 오픈소스 소프트웨어의 취약점 발견과 대응을 가속화하는 새로운 ‘엔터프라이즈 클리어링하우스(Enterprise Clearinghouse)’를 구축하는 것이 목표다. 양사는 이 클리어링하우스가 AI 기반 ‘보안 조정 계층(Security Coordination Layer)’ 역할을 수행해 기업이 기존 소프트웨어 공급망에 패치를 직접 통합할 수 있도록 지원할 것이라고 밝혔다.</p>



<p>프로젝트 라이트웰은 현재 11개 금융기관과 함께 설계 단계에 있으며, 향후 구독형 상용 서비스로 제공될 예정이다.</p>



<p>레드햇의 수석부사장 겸 최고제품책임자(CPO) <a href="https://www.redhat.com/en/about/company/leadership/ashesh-badani" target="_blank" rel="nofollow">아셰시 바다니</a>는 “AI 도구의 발전으로 취약점을 발견하면서도 대응 속도를 유지할 수 있는 환경이 마련됐다”라며 “대부분의 기업이 오픈소스 소프트웨어를 사용하고 있지만, 취약점을 충분히 빠르게 해결하지 못하는 것이 가장 큰 과제”라고 CSO온라인에 설명했다.</p>



<h2 class="wp-block-heading">취약점 대응 격차 해소 나선 IBM·레드햇</h2>



<p>오픈소스 보안 문제는 이미 널리 알려져 있다. <a href="https://www.cve.org/about/Metrics" target="_blank" rel="nofollow">2025년 한 해 동안</a> 공개된 공통 취약점 및 노출(CVE)은 약 5만 건에 달했다. 또한 앤트로픽의 미토스 프리뷰(Mythos Preview) 모델 기반 ‘프로젝트 글래스윙(Project Glasswing)’은 출시 직후 오픈소스 소프트웨어에서 약 3,900건의 미발견 고위험 및 치명적 취약점을 찾아냈다.</p>



<p>IBM은 업계에서 가장 폭넓은 상용 오픈소스 생태계를 보유한 기업 가운데 하나로 평가받는다. 현재 6만 2,000개 이상의 패키지를 활용하고 있으며, 리눅스(Linux), 쿠버네티스(Kubernetes), 카프카(Kafka), 테라폼(Terraform), 자바(Java) 등 다양한 플랫폼에서 운영·검증·패치 및 라이프사이클 관리 서비스를 제공하고 있다.</p>



<p>IBM은 프로젝트 라이트웰을 통해 이러한 엔지니어링 원칙을 AI 프레임워크, 독립 라이브러리, 언어 툴체인, 데이터 스트리밍 플랫폼 등으로 확대 적용할 계획이다. 이를 통해 기업 환경에서 이미 사용 중인 오픈소스 코드에 검증된 수정 사항을 제공하고, 시스템 안정성이나 인증, 규제 준수에 영향을 주지 않으면서 취약점을 해결할 수 있도록 지원한다는 설명이다.</p>



<p>프로젝트 라이트웰은 소스코드 접근 권한이나 버전 업그레이드를 요구하지 않는다. 이미 테스트와 배포가 완료된 정확한 의존성 버전에 맞춰 수정 사항을 역이식(backport)하는 방식으로 운영된다. 또한 pom.xml과 같은 구성 매니페스트를 기반으로 작동해 패치된 아티팩트가 배포되더라도 코드는 기업의 통제된 운영 환경 내에 그대로 유지된다. 초기에는 자바·메이븐(Java/Maven) 생태계에 집중하지만, 향후 PyPI, npm, Go 등으로 지원 범위를 확대할 예정이다.</p>



<p>기업은 ‘보안 중개 모델(Secure Intermediary Model)’을 통해 공개 전 단계의 민감한 취약점 정보를 안전하게 공유할 수 있으며, 레드햇 플랫폼은 물론 독립 오픈소스 커뮤니티 코드에 대한 검증된 패치도 받을 수 있다. 또한 의존성 체인 전반에 걸쳐 수정 사항을 배포하고, 운영 환경에서 발견된 문제를 보고·해결하며, 수정 사항을 다시 업스트림에 공유해 오픈소스 커뮤니티 전체가 활용할 수 있도록 지원한다.</p>



<p>레드햇의 수석부사장 겸 최고제품책임자(CPO) 아셰시 바다니는 “클리어링하우스를 통해 기업에 제공하는 수정 사항이 해당 코드를 개발한 오픈소스 커뮤니티에도 다시 전달되도록 하는 것이 중요하다”라며 “예를 들어 파이썬 코드의 취약점을 수정했다면 그 결과가 신속하게 파이썬 커뮤니티에도 공유돼야 한다”고 설명했다. 이어 “프로젝트 라이트웰은 이러한 과정을 안전하게 연결하는 ‘보안 지도(Secure Map)’ 역할을 수행할 것”이라고 덧붙였다.</p>



<p>IBM과 레드햇 엔지니어들은 첨단 AI 기술과 주요 오픈소스 기여자들과의 협력을 바탕으로 업스트림과 다운스트림 환경을 연결해 기업 환경에 바로 적용할 수 있는 패치를 개발할 계획이다. 이와 함께 대규모 취약점 검토 및 분류 작업, 의존성 강화 작업도 수행한다.</p>



<p>바다니는 “프로젝트에 투입되는 2만 명의 엔지니어는 IBM과 레드햇이 보유한 기존 인력으로 구성되며, 필요에 따라 추가 인력을 배치할 예정”이라고 설명했다. 양사는 최첨단 AI 연구소들이 개발한 파운데이션 모델과 자체 개발한 AI 도구 및 프레임워크를 함께 활용할 계획이다. 50억 달러(약 6조 8,000억 원)의 투자금은 AI 도구 도입과 내부 운영 인프라 구축에 사용된다.</p>



<p>프로젝트 라이트웰의 초기 참여 기업으로는 뱅크오브아메리카(Bank of America), BNY, 씨티(Citi), 골드만삭스(Goldman Sachs), JP모건체이스(JPMorganChase), 마스터카드(Mastercard), 모건스탠리(Morgan Stanley), 캐나다왕립은행(Royal Bank of Canada), 스테이트스트리트(State Street), 비자(Visa), 웰스파고(Wells Fargo) 등이 포함됐다. IBM과 레드햇은 초기 설계 단계가 마무리되면 구독형 모델을 통해 더 많은 고객으로 프로젝트를 확대할 계획이다.</p>



<h2 class="wp-block-heading">오픈소스 생태계를 위한 투자 촉구</h2>



<p>보서론 시큐리티(Beauceron Security)의 <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="nofollow">데이비드 십리</a>는 기업이 오픈소스 생태계를 지속 가능하게 유지하려면 이와 같은 프로젝트가 “절실히 필요하다”고 평가했다.</p>



<p>십리는 미토스(Mythos)의 등장으로 막대한 규모의 디지털 자산이 자원봉사자들의 노력에 의존하던 시대는 사실상 막을 내렸다고 지적했다. 이제 오픈소스 생태계 유지 비용을 기업이 부담해야 할 시점이 왔으며, 그렇지 않으면 결국 그 혜택을 잃게 될 것이라는 설명이다.</p>



<p>십리는 “오픈소스에 투자할 방법을 찾지 못한다면, 오랫동안 이어져 온 형평성 문제도 해결할 수 없게 된다”라며 “그 대안은 모든 기업이 AI를 활용해 각자 맞춤형 코드를 개발하는 것뿐”이라고 말했다. 이어 “이는 컴퓨팅 자원과 환경 측면에서 매우 비효율적이고 낭비가 큰 방식”이라고 지적했다.</p>



<p>또한 “이번 프로젝트가 다른 기업들의 행동을 촉발하는 계기가 되기를 기대한다”고 밝혔다.</p>



<h2 class="wp-block-heading">인간의 역할은 여전히 중요</h2>



<p>바다니는 AI가 오픈소스 코드의 보안 취약점을 발견하는 데는 뛰어난 성능을 발휘하지만, 실제 패치 과정은 여전히 복잡하고 시간이 많이 소요된다고 강조했다.</p>



<p>취약점이 발견되면 수정 사항을 업스트림 프로젝트에 전달해야 하고, 이후 오픈소스 커뮤니티 전체에 배포된 뒤 다시 고객과 사용자 환경으로 전달되는 과정을 거쳐야 한다.</p>



<p>바다니는 “버그를 발견하는 것과 실제로 이를 해결하는 것은 전혀 다른 문제”라며 “실제 수정 작업에는 수많은 절차가 필요하며, 그 과정에서 발생하는 시간 지연이 우리가 줄이고자 하는 격차”라고 설명했다.</p>



<p>문제의 심각성을 보여주듯 프로젝트 라이트웰 발표 이후 IBM과 레드햇에는 관련 문의와 참여 요청이 쇄도하고 있는 것으로 알려졌다.</p>



<p>바다니는 “이 문제는 가까운 시일 내에 사라지지 않을 것”이라며 “초기 과제를 성공적으로 해결하더라도 기업은 이러한 지원을 지속적이고 반복적으로 필요로 하게 될 것”이라고 전망했다.</p>



<p>최근 AI가 인간 엔지니어를 대체할 것이라는 논의가 확산되고 있지만, 프로젝트 라이트웰은 오히려 AI와 인간의 협업에 초점을 맞추고 있다.</p>



<p>바다니는 “AI 도구와 인간의 지식, 전문성을 결합하면 이 문제를 훨씬 효과적으로 해결할 수 있다”라며 “둘 중 하나만 사용하는 것보다 두 요소를 함께 활용할 때 더 나은 결과를 얻을 수 있다”고 강조했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise]]></title>
<description><![CDATA[Open source code is everywhere in the enterprise; it’s estimated that upwards of 90% of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle for security teams...]]></description>
<link>https://tsecurity.de/de/3555858/ai-nachrichten/ibm-and-red-hat-want-to-become-the-security-clearinghouse-for-open-source-applications-in-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555858/ai-nachrichten/ibm-and-red-hat-want-to-become-the-security-clearinghouse-for-open-source-applications-in-the-enterprise/</guid>
<pubDate>Fri, 29 May 2026 04:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Open source code is everywhere in the enterprise; it’s estimated that <a href="https://worldmetrics.org/opensource-statistics/" target="_blank" rel="noreferrer noopener">upwards of 90%</a> of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle for security teams.</p>



<p>IBM and Red Hat are betting that a new initiative, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era" target="_blank" rel="noreferrer noopener">Project Lightwell</a>, can help accelerate this process.</p>



<p>Announced today, the project will commit $5 billion and 20,000 IBM and Red Hat engineers to build a new ‘enterprise clearinghouse’ to accelerate discovery and remediation of vulnerabilities in open source software. The companies say the clearinghouse will serve as an AI-powered  “security coordination layer,” giving enterprises the ability to integrate patches directly into their existing software supply chains.</p>



<p>Now in the design phase with a group of 11 financial partners, Project Lightwell will eventually be offered as a commercial subscription.</p>



<p>“The advancement in AI tools has broken the patching map, which is the ability to discover vulnerabilities in software without losing the speed of remediation,” <a href="https://www.redhat.com/en/about/company/leadership/ashesh-badani" target="_blank" rel="noreferrer noopener">Ashesh Badani</a>, Red Hat SVP and CPO, told CSOonline. “Everyone’s running open source software, and the challenge is not being able to fix vulnerabilities quickly enough.”</p>



<h2 class="wp-block-heading">Closing the remediation gap</h2>



<p>Open source security issues have been well documented: Almost 50,000 common vulnerabilities and exposures (CVEs) <a href="https://www.cve.org/about/Metrics" target="_blank" rel="noreferrer noopener">were published in 2025</a>, and Anthropic’s Project Glasswing, powered by its <a href="https://www.computerworld.com/article/4160021/anthropics-latest-model-is-deliberately-less-powerful-than-mythos-and-thats-the-point.html" target="_blank">Mythos Preview</a> model, found <a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">roughly 3,900</a> previously undiscovered high or critical severity vulnerabilities in open source software shortly after launch.</p>



<p>IBM is considered one of the broadest commercial open source ecosystems, using more than 62,000 packages and operating across Linux, Kubernetes, Kafka, Terraform, Java and other platforms, and providing lifecycle management, validation, and patching for elements within those environments.</p>



<p>The company says Project Lightwell will now apply those same engineering principles to broader AI frameworks, independent libraries, language toolchains, and data streaming platforms, to deliver validated fixes to open-source code already in use in enterprise environments. This can support remediation without disruption of stability, certification, or compliance.</p>



<p>No upgrades or access to source code are required; Project Lightwell will backport fixes to exact dependency versions that have already been tested and deployed. It operates on fundamental configuration manifests like pom.xml so code remains in controlled enterprise environments when patched artifacts are rolled out. Initial focus will be on Java/Maven, but the project will eventually expand to PyPI, npm, Go, and others.</p>



<p>Enterprises will have the ability to share <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html" target="_blank">sensitive vulnerabilities</a> under embargo through a “secure intermediary model” and receive validated patches spanning Red Hat platforms and independent community code. They will also be able to deliver fixes across dependency chains; report and address issues across active production environments; and share fixes upstream so the wider open-source community can incorporate them.</p>



<p>“We want to make sure that whatever fixes we provide to the enterprises through the clearinghouse also find their way back into the open source community that developed [the code],” Badani explained. For instance, if a piece of Python code was patched, the fix should be quickly delivered back to the Python community. With Project Lightwell, that process can be achieved through a “secure map.”</p>



<p>Using advanced AI, and working with leading open source contributors, IBM and Red Hat engineers will focus on connecting upstream and downstream environments so fixes are enterprise-ready. They will also develop patches and perform “high volume” vulnerability review and triage, and dependency hardening.</p>



<p>The network of 20,000 engineers will come from IBM’s and Red Hat’s existing pools of talent, and the companies will augment those teams as needed, Badani explained. The companies will take advantage of foundation models coming out of frontier labs, as well as their own internally-built AI tools and frameworks. The $5 billion will be used to equip teams with AI tools and build out internal operational infrastructure.</p>



<p>Early Project Lightwell adopters include Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo. Following the initial design period, IBM and Red Hat will phase more customers onto Project Lightwell via a subscription model.</p>



<h2 class="wp-block-heading">A call to action?</h2>



<p>This type of initiative is “desperately needed” if enterprise is to save open source, noted <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<p>The days of trillions in wealth depending on volunteers “ended violently” with Mythos, he noted, and the bill has ultimately come due for open source. Enterprises will need to pay up, or lose it.</p>



<p>“If we don’t find a way to invest in open source, which will close a long-standing equity issue, the alternative is everyone building their own bespoke code using AI,” Shipley said. That would be “massively wasteful” from a compute and environmental perspective.</p>



<p>“I hope this drives others to act,” he said.</p>



<h2 class="wp-block-heading">Keeping humans in the loop for an ongoing battle</h2>



<p>Badani emphasized that, while AI is great at discovering <a href="https://www.csoonline.com/article/4177903/ai-models-more-vulnerable-than-claimed-when-faced-with-iterative-attacks.html" target="_blank">security issues</a> in open-source code, the patching process can still be cumbersome. Fixes have to be sent upstream, distributed to the open source community, then flow back to customers and users.</p>



<p>“Finding the bug is one thing,” said Badani. “The other is all the steps that it takes to actually go and remediate it. That extra amount of time is the gap that we’re trying to help close.”</p>



<p>Underscoring the severity of the problem, IBM and Red Hat have already had an “onslaught of incoming requests” since Project Lightwell was announced.</p>



<p>“This isn’t going to stop any time soon,” Badani said. “Even if we were to very successfully solve the initial set of challenges that come to us, this will be something that companies are going to need on an ongoing or recurring basis.”</p>



<p>And, while the narrative has focused on cutting human engineers in favor of AI, Project Lightwell is focused on the opposite: “We can address [the problem] with a mixture of AI tools and human knowledge and expertise,” Badani said. “Coupling the two gives you a better outcome than just using one or the other.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise]]></title>
<description><![CDATA[Open source code is everywhere in the enterprise; it’s estimated that upwards of 90% of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle for security teams...]]></description>
<link>https://tsecurity.de/de/3555829/it-security-nachrichten/ibm-and-red-hat-want-to-become-the-security-clearinghouse-for-open-source-applications-in-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555829/it-security-nachrichten/ibm-and-red-hat-want-to-become-the-security-clearinghouse-for-open-source-applications-in-the-enterprise/</guid>
<pubDate>Fri, 29 May 2026 03:07:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Open source code is everywhere in the enterprise; it’s estimated that <a href="https://worldmetrics.org/opensource-statistics/" target="_blank" rel="noreferrer noopener">upwards of 90%</a> of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle for security teams.</p>



<p>IBM and Red Hat are betting that a new initiative, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era" target="_blank" rel="noreferrer noopener">Project Lightwell</a>, can help accelerate this process.</p>



<p>Announced today, the project will commit $5 billion and 20,000 IBM and Red Hat engineers to build a new ‘enterprise clearinghouse’ to accelerate discovery and remediation of vulnerabilities in open source software. The companies say the clearinghouse will serve as an AI-powered  “security coordination layer,” giving enterprises the ability to integrate patches directly into their existing software supply chains.</p>



<p>Now in the design phase with a group of 11 financial partners, Project Lightwell will eventually be offered as a commercial subscription.</p>



<p>“The advancement in AI tools has broken the patching map, which is the ability to discover vulnerabilities in software without losing the speed of remediation,” <a href="https://www.redhat.com/en/about/company/leadership/ashesh-badani" target="_blank" rel="noreferrer noopener">Ashesh Badani</a>, Red Hat SVP and CPO, told CSOonline. “Everyone’s running open source software, and the challenge is not being able to fix vulnerabilities quickly enough.”</p>



<h2 class="wp-block-heading">Closing the remediation gap</h2>



<p>Open source security issues have been well documented: Almost 50,000 common vulnerabilities and exposures (CVEs) <a href="https://www.cve.org/about/Metrics" target="_blank" rel="noreferrer noopener">were published in 2025</a>, and Anthropic’s Project Glasswing, powered by its <a href="https://www.computerworld.com/article/4160021/anthropics-latest-model-is-deliberately-less-powerful-than-mythos-and-thats-the-point.html" target="_blank">Mythos Preview</a> model, found <a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">roughly 3,900</a> previously undiscovered high or critical severity vulnerabilities in open source software shortly after launch.</p>



<p>IBM is considered one of the broadest commercial open source ecosystems, using more than 62,000 packages and operating across Linux, Kubernetes, Kafka, Terraform, Java and other platforms, and providing lifecycle management, validation, and patching for elements within those environments.</p>



<p>The company says Project Lightwell will now apply those same engineering principles to broader AI frameworks, independent libraries, language toolchains, and data streaming platforms, to deliver validated fixes to open-source code already in use in enterprise environments. This can support remediation without disruption of stability, certification, or compliance.</p>



<p>No upgrades or access to source code are required; Project Lightwell will backport fixes to exact dependency versions that have already been tested and deployed. It operates on fundamental configuration manifests like pom.xml so code remains in controlled enterprise environments when patched artifacts are rolled out. Initial focus will be on Java/Maven, but the project will eventually expand to PyPI, npm, Go, and others.</p>



<p>Enterprises will have the ability to share <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html" target="_blank">sensitive vulnerabilities</a> under embargo through a “secure intermediary model” and receive validated patches spanning Red Hat platforms and independent community code. They will also be able to deliver fixes across dependency chains; report and address issues across active production environments; and share fixes upstream so the wider open-source community can incorporate them.</p>



<p>“We want to make sure that whatever fixes we provide to the enterprises through the clearinghouse also find their way back into the open source community that developed [the code],” Badani explained. For instance, if a piece of Python code was patched, the fix should be quickly delivered back to the Python community. With Project Lightwell, that process can be achieved through a “secure map.”</p>



<p>Using advanced AI, and working with leading open source contributors, IBM and Red Hat engineers will focus on connecting upstream and downstream environments so fixes are enterprise-ready. They will also develop patches and perform “high volume” vulnerability review and triage, and dependency hardening.</p>



<p>The network of 20,000 engineers will come from IBM’s and Red Hat’s existing pools of talent, and the companies will augment those teams as needed, Badani explained. The companies will take advantage of foundation models coming out of frontier labs, as well as their own internally-built AI tools and frameworks. The $5 billion will be used to equip teams with AI tools and build out internal operational infrastructure.</p>



<p>Early Project Lightwell adopters include Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo. Following the initial design period, IBM and Red Hat will phase more customers onto Project Lightwell via a subscription model.</p>



<h2 class="wp-block-heading">A call to action?</h2>



<p>This type of initiative is “desperately needed” if enterprise is to save open source, noted <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<p>The days of trillions in wealth depending on volunteers “ended violently” with Mythos, he noted, and the bill has ultimately come due for open source. Enterprises will need to pay up, or lose it.</p>



<p>“If we don’t find a way to invest in open source, which will close a long-standing equity issue, the alternative is everyone building their own bespoke code using AI,” Shipley said. That would be “massively wasteful” from a compute and environmental perspective.</p>



<p>“I hope this drives others to act,” he said.</p>



<h2 class="wp-block-heading">Keeping humans in the loop for an ongoing battle</h2>



<p>Badani emphasized that, while AI is great at discovering <a href="https://www.csoonline.com/article/4177903/ai-models-more-vulnerable-than-claimed-when-faced-with-iterative-attacks.html" target="_blank">security issues</a> in open-source code, the patching process can still be cumbersome. Fixes have to be sent upstream, distributed to the open source community, then flow back to customers and users.</p>



<p>“Finding the bug is one thing,” said Badani. “The other is all the steps that it takes to actually go and remediate it. That extra amount of time is the gap that we’re trying to help close.”</p>



<p>Underscoring the severity of the problem, IBM and Red Hat have already had an “onslaught of incoming requests” since Project Lightwell was announced.</p>



<p>“This isn’t going to stop any time soon,” Badani said. “Even if we were to very successfully solve the initial set of challenges that come to us, this will be something that companies are going to need on an ongoing or recurring basis.”</p>



<p>And, while the narrative has focused on cutting human engineers in favor of AI, Project Lightwell is focused on the opposite: “We can address [the problem] with a mixture of AI tools and human knowledge and expertise,” Badani said. “Coupling the two gives you a better outcome than just using one or the other.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4178451/ibm-and-red-hat-want-to-become-the-security-clearinghouse-for-open-source-applications-in-the-enterprise.html" target="_blank">InfoWorld</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MITRE Couldn’t Scale Caldera Alone]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 MITRE is transferring the Caldera cybersecurity platform to the Apache Foundation to encourage broader open source collaboration and long-term project support.

Caldera is widely used for testing systems against the MITRE ATT&CK f...]]></description>
<link>https://tsecurity.de/de/3555664/it-security-video/mitre-couldnt-scale-caldera-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555664/it-security-video/mitre-couldnt-scale-caldera-alone/</guid>
<pubDate>Fri, 29 May 2026 00:17:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JapDvzrae8U?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>MITRE is transferring the Caldera cybersecurity platform to the Apache Foundation to encourage broader open source collaboration and long-term project support.<br />
<br />
Caldera is widely used for testing systems against the MITRE ATT&CK framework and simulating adversary behavior across enterprise environments.<br />
<br />
As cybersecurity projects grow in complexity and adoption, maintaining them requires sustained engineering resources, governance, and community involvement. Moving projects into larger open source foundations can improve longevity and development speed, but it also introduces new coordination and security challenges.<br />
<br />
The shift reflects a broader trend in cybersecurity: important defensive tooling increasingly depends on shared ecosystems rather than single organizations.<br />
<br />
Are major cybersecurity projects becoming too large for individual organizations to realistically maintain alone?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#OpenSource #MITRE #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MariaDB Foundation as Part of the MySQL Ecosystem]]></title>
<description><![CDATA[Author: MariaDB Foundation - Bewertung: 0x - Views:4 MariaDB Foundation Executive Chairman Kaj Arnö speaks at the Oracle MySQL Contributor Summit 26 May 2026 about MariaDB’s role within the broader MySQL ecosystem.

The talk explores interoperability, ecosystem cooperation, vendor lock-in, extens...]]></description>
<link>https://tsecurity.de/de/3554498/videos/mariadb-foundation-as-part-of-the-mysql-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554498/videos/mariadb-foundation-as-part-of-the-mysql-ecosystem/</guid>
<pubDate>Thu, 28 May 2026 16:33:27 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: MariaDB Foundation - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gYWSDEV4vkw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>MariaDB Foundation Executive Chairman Kaj Arnö speaks at the Oracle MySQL Contributor Summit 26 May 2026 about MariaDB’s role within the broader MySQL ecosystem.<br />
<br />
The talk explores interoperability, ecosystem cooperation, vendor lock-in, extensibility, and the realities of long-term open source forking. It argues for viewing MariaDB not as something outside the MySQL world, but as one of several “same-same but different” implementations sharing common roots, operational culture, and user communities.<br />
<br />
Topics include:<br />
MySQL ecosystem cooperation<br />
MariaDB as a long-term MySQL fork<br />
Interoperability and migration paths<br />
Vendor lock-in and user trust<br />
Extensibility and plugin architecture<br />
Vector search and AI-related capabilities<br />
Open source governance and ecosystem dynamics<br />
PostgreSQL competition and developer mindshare<br />
Why “forking is hard”<br />
<br />
The presentation was delivered remotely during the MySQL Contributor Summit 2026.<br />
<br />
References mentioned:<br />
Monty Says: “Celebrating 15 years of MariaDB”<br />
https://monty-says.blogspot.com/2024/10/celebrating-15-years-of-mariadb.html <br />
Monty Says: “The concepts of forking”<br />
https://monty-says.blogspot.com/2026/01/the-concepts-of-forking.html <br />
MariaDB skills: https://github.com/MariaDB/skills<br />
#MySQL #MariaDB #OpenSource #Database #SQL #Interoperability #AI #VectorSearch #Replication #HA #DevOps<br />
Timestamps<br />
00:00 Introduction slide<br />
00:02 MariaDB Foundation as part of the MySQL ecosystem<br />
00:50 Listening first: understanding how MariaDB can contribute<br />
01:29 “Same-same but different” — MariaDB among MySQL forks<br />
02:42 Shared roots, shared operational culture, shared ecosystem<br />
03:08 MariaDB’s evolution over 15 years<br />
03:51 “Forking is hard” — long-term maintenance realities<br />
05:18 Monty’s blog posts on forking and MariaDB history<br />
07:09 Vector search, AI and MariaDB skills<br />
08:38 Oracle compatibility mode and plugins<br />
09:32 Storage engines, InnoDB and ecosystem diversity<br />
10:27 MySQL culture: performance, stability and ease of use<br />
11:20 Plugin development and developer mindshare<br />
12:21 Interoperability and avoiding vendor lock-in<br />
13:08 PostgreSQL competition and ecosystem cooperation<br />
14:02 Migration paths, tooling compatibility and operational familiarity<br />
14:48 Constructive participation in the ecosystem<br />
15:20 Discussions with Oracle, AWS and Percona<br />
15:51 ProxySQL becomes MariaDB Foundation Silver Sponsor<br />
16:06 “A rising tide lifts all boats”<br />
16:45 Closing remarks<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OSBA warnt: „Buy European“ ist keine Souveränität]]></title>
<description><![CDATA[Eine deutsch-französische Taskforce arbeitet an einer verbindlichen Definition digitaler Souveränität. Der größte Open-Source-Verband Europas fürchtet, dass dabei Abschottung mit Unabhängigkeit verwechselt wird.

Tags: #digitale Souveränität | #EU | #OpenSource]]></description>
<link>https://tsecurity.de/de/3553611/it-security-nachrichten/osba-warnt-buy-european-ist-keine-souveraenitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553611/it-security-nachrichten/osba-warnt-buy-european-ist-keine-souveraenitaet/</guid>
<pubDate>Thu, 28 May 2026 11:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920.jpg" class="attachment-full size-full wp-post-image" alt="EU" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/05/EU-Shutterstock-2760997387-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title='OSBA warnt: "Buy European" ist keine Souveränität 1'></p>
    Eine deutsch-französische Taskforce arbeitet an einer verbindlichen Definition digitaler Souveränität. Der größte Open-Source-Verband Europas fürchtet, dass dabei Abschottung mit Unabhängigkeit verwechselt wird.

<p>Tags: <a href="https://www.it-daily.net/thema/digitale-souveraenitaet">#digitale Souveränität</a> | <a href="https://www.it-daily.net/thema/eu">#EU</a> | <a href="https://www.it-daily.net/thema/opensource">#OpenSource</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An open-source toolkit for controlling out-of-control AI agents]]></title>
<description><![CDATA[The rapid uptake of agentic AI has exposed a range of issues with our non-deterministic helpers. That’s mainly because AI agents are not people and don’t behave like people, even though they generally use the same APIs as humans. For one thing, they make many more queries than a human would, as t...]]></description>
<link>https://tsecurity.de/de/3553485/ai-nachrichten/an-open-source-toolkit-for-controlling-out-of-control-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553485/ai-nachrichten/an-open-source-toolkit-for-controlling-out-of-control-ai-agents/</guid>
<pubDate>Thu, 28 May 2026 11:03:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The rapid uptake of <a href="https://www.infoworld.com/article/4120858/agentic-ai-exposes-what-were-doing-wrong.html" data-type="link" data-id="https://www.infoworld.com/article/4120858/agentic-ai-exposes-what-were-doing-wrong.html">agentic AI</a> has exposed a range of issues with our non-deterministic helpers. That’s mainly because AI agents are not people and don’t behave like people, even though they generally use the same APIs as humans. For one thing, they make many more queries than a human would, as they build the necessary context to deliver a response.</p>



<p>Anecdotal data from companies that have worked with agents or who have users who access services through agents indicate that this can mean <a href="https://github.blog/news-insights/company-news/an-update-on-github-availability/">massive increases in API usage</a>, which have affected availability. This increase is the result of automated requests flooding in and blocking calls and responses from APIs that worked perfectly well a year or so ago but now are struggling to cope with the load.</p>



<p>A fundamental redesign of our APIs is necessary, but budgets, resourcing, and capacity make this hard to deliver overnight. What’s needed, then, is a way to manage agent interactions with APIs, treating agents as a new class of user, providing and enforcing the policies that are needed to manage agent life cycles. The use of <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) as a standard wrapper for agent access to APIs helps here, as it gives us a common environment where we can implement the governance layer needed to keep agents under control.</p>



<p>Microsoft recently <a href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/" data-type="link" data-id="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/">launched a public preview</a> of its <a href="https://github.com/microsoft/agent-governance-toolkit" data-type="link" data-id="https://github.com/microsoft/agent-governance-toolkit">open-source Agent Governance Toolkit</a> (AGT), which is intended to wrap policy-based enforcement around agents, ensuring that calls are evaluated before they’re made. You can think of the toolkit as a way to manage agent actions, rather than controlling the inputs and outputs of the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs) your agents use. Figures from Microsoft suggest that this method of securing agents is far safer than relying on rules in prompts. However, in practice it’s a good idea to run a capability tool like Agent Governance Toolkit alongside traditional filters to trap user errors and prompt-based attacks.</p>



<p>AGT is <a href="https://microsoft.github.io/agent-governance-toolkit/">a set of tools</a> designed to cover OWASP’s list of agentic risks, building on Microsoft’s experience securing its own agents and AI platforms, with more than 13,000 tests built into the toolkit. It works by evaluating actions before they’re run, checking them against your policies, before allowing or denying the action and logging the results. Microsoft expects policy evaluation to take less than 0.1ms per operation, keeping overheads to a minimum.</p>



<h2 class="wp-block-heading">Policies for agents</h2>



<p><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP’s top 10 agent risks</a> lists the most significant issues that can disrupt agent operations resulting from user prompts and bad application design. These risks include agent goal hijacking, uncontrolled code execution, insecure output handling, and agents going rogue. Features in the toolkit are designed to protect agentic applications from these and other issues, using isolation and sandboxing, as well as validating outputs using content policies.</p>



<p>You can use declarative programming techniques to build the policies that <a href="https://devblogs.microsoft.com/dotnet/governing-mcp-tool-calls-in-dotnet-with-the-agent-governance-toolkit/" data-type="link" data-id="https://devblogs.microsoft.com/dotnet/governing-mcp-tool-calls-in-dotnet-with-the-agent-governance-toolkit/">define the limits of your agents’ operations</a>. As the policies are human-readable, you can share them with colleagues and refine them across projects to produce a common set of AGT rules for all agents running inside your organization.</p>



<p>The resulting authorization model is intent-based, with agents declaring their intent, which AGT approves or denies. The policy then determines what operations are allowed, whether they’re permitted with an alert, or blocked. This approach allows your code to check orchestrated operations for drift from the top-level intent. When your code is running a harness for multiple parallel agents, this helps keep the application on track and reduces the risk of unwanted operations and using too many tokens.</p>



<p>Agent behavior often results in using more tokens than expected, so keeping spend under control is another role for AGT. As platforms move to new pricing and budgeting models, the ability to control the number of tokens that can be spent on an agent interaction will become very important indeed, and the ability to set a token budget in an AGT policy will allow developers to prevent users from significant unintended spend. AGT’s budget management tools can be used to throttle activities as agents approach preset limits, and to reject actions if they look likely to use excessive tokens.</p>



<h2 class="wp-block-heading">Monitoring and manag agents in action</h2>



<p>You can even use AGT to manage API calls, something that’s becoming increasingly important as agent context-seeking activities can quickly overwhelm APIs designed for human interactions. By building rules that limit the number of calls in a set amount of time, you can now have your agent framework manage throttling for you rather than implementing complex API management tools.</p>



<p>One key feature of AGT is the ability to use its mix of declarative policies to find agents that are drifting from your set baselines, helping spot issues before they cost money or affect operations. AGT also can be used to apply kill switches where necessary. Logging and observability capabilities include a way to provide a root cause analysis of issues, along with what Microsoft calls a “decision bill of materials” that keeps track of governance decisions with an audit chain and the details of the trust levels associated with agents.</p>



<p>A toolkit like AGT needs to be vendor neutral, as your agents could be working with models running in any environment. AGT is designed to work with Azure Foundry, Amazon Bedrock, and Google ADK, as well as with most common agent orchestration frameworks. AGT supports five different programming languages: Python, TypeScript, .NET, Rust, and Go. While capabilities vary between the different implementations, the Python version has the full set.</p>



<p>Microsoft has made some interesting architectural decisions in AGT. Perhaps the most important is that it treats agents as code running on a secure operating system, using concepts from hypervisors to isolate agents from the underlying platform. You can see this in the way the underlying components and packages are named; the core governance package is called Agent OS.</p>



<h2 class="wp-block-heading">Building AGT into your code</h2>



<p><a href="https://microsoft.github.io/agent-governance-toolkit/quickstart/">Getting started with AGT</a> can be as simple as installing the complete toolkit using standard package manager of your language of choice. You don’t need to install the whole thing. You have the option of installing specific packages when you don’t need all the features, or when you only want to use a single function. You could download only AGT’s software reliability engineering tools, for example, when you want to put your agents through chaos testing.</p>



<p>You can define policies inside your code or as external policy documents. Policies are focused on key security and governance goals, such as blocking dangerous tools from running, looking for PII in messages, and showing users what action has been taken and why. External policy documents are recommended for use with production AGT implementations, as they let you author policies in YAML. The toolkit provides a single call to load all the policy files in a directory, so it’s a good idea to store only production policies in that location to avoid issues.</p>



<p>Adding support for AGT in existing code is a matter of adding evaluations before your agent framework makes a call. This can be handled using refactoring tools in your editor, finding the call and wrapping the evaluator and decision results around it. This way you can develop agents without using AGT, adding its tools when you’re confident you have a working agent. Microsoft provides <a href="https://microsoft.github.io/agent-governance-toolkit/packages/#framework-integrations-19" data-type="link" data-id="https://microsoft.github.io/agent-governance-toolkit/packages/#framework-integrations-19">custom adapters for 19 different frameworks</a>, tuned to work with them. These can be loaded alongside the rest of the toolkit.</p>



<p>AGT is a sign of growing maturity in our agent landscape, applying enterprise rigor to what has been something of a Wild West free-for-all. It addresses many of the concerns associated with using agents at scale, helping control both agent behavior and costs. Autonomous software needs to be kept on a leash, and AGT’s declarative approach to building and applying policies — along with the rest of its suite of tools — gives you the ability to quickly build and apply the necessary controls.</p>



<p>With companies looking to control costs and regulators wanting to ensure that agentic software doesn’t violate compliance requirements, tools like the Agent Governance Toolkit will likely become an essential part of our modern agent development environment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Winbox server/client reverse engineered is opensource]]></title>
<description><![CDATA[submitted by    /u/wantasticd   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3552814/reverse-engineering/winbox-serverclient-reverse-engineered-is-opensource/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552814/reverse-engineering/winbox-serverclient-reverse-engineered-is-opensource/</guid>
<pubDate>Thu, 28 May 2026 04:20:46 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/wantasticd"> /u/wantasticd </a> <br> <span><a href="https://github.com/WantasticApp/WantasticCore">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1tpp53l/winbox_serverclient_reverse_engineered_is/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bayern lenkt ein: Doch Open Source statt Millionen-Deal mit Microsoft]]></title>
<description><![CDATA[Der Freistaat Bayern vollzieht eine Kehrtwende in seiner IT-Strategie. Statt den Einsatz von Microsoft 365 massiv auszuweiten, rückt nun der Aufbau einer unabhängigen, souveränen Lösung für die Verwaltung in den Fokus.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3551965/it-security-nachrichten/bayern-lenkt-ein-doch-open-source-statt-millionen-deal-mit-microsoft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551965/it-security-nachrichten/bayern-lenkt-ein-doch-open-source-statt-millionen-deal-mit-microsoft/</guid>
<pubDate>Wed, 27 May 2026 19:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158957.html"><img hspace="5" border="0" align="left" alt="Open Source, Sourcecode, Opensource, Source Code, Open Source Software, Quelloffen, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56862.jpg"></a>
			Der Freistaat Bayern vollzieht eine Kehrtwende in seiner IT-Strategie. Statt den Einsatz von <a href="https://winfuture.de/special/office/" title="Office Special">Microsoft 365</a> massiv auszuweiten, rückt nun der Aufbau einer unabhängigen, souveränen Lösung für die Verwaltung in den Fokus.			(<a href="https://winfuture.de/news,158957.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Trust Is Collapsing]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Doug White talks about manually vetting software downloads from GitHub, NPM, and PyPI before allowing them onto a normal machine.

That process included sandboxing the code in a Linux VM, reviewing it manually, and even using mult...]]></description>
<link>https://tsecurity.de/de/3551954/it-security-video/open-source-trust-is-collapsing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551954/it-security-video/open-source-trust-is-collapsing/</guid>
<pubDate>Wed, 27 May 2026 19:03:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4mD02Pbfcbo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Doug White talks about manually vetting software downloads from GitHub, NPM, and PyPI before allowing them onto a normal machine.<br />
<br />
That process included sandboxing the code in a Linux VM, reviewing it manually, and even using multiple AI models to inspect the files before installation.<br />
<br />
The clip highlights a growing supply-chain security problem inside open-source ecosystems.<br />
<br />
Developers increasingly worry that packages, updates, or dependencies could contain malware, hidden payloads, or compromised code paths — forcing users to treat even routine downloads with suspicion.<br />
<br />
Are software repositories becoming too risky to trust by default, or is this simply the new normal for secure development?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#OpenSource #SupplyChainSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] MOT: a tool to fight openwashing in AI]]></title>
<description><![CDATA[Many large language models (LLMs) are described as open source, but
if one looks a bit deeper it turns out that is not actually so; the
model may be free to download, it may be "open weight", but it
does not fit the Open Source
Initiative (OSI) Open Source
Definition (OSD). Assessing the actual o...]]></description>
<link>https://tsecurity.de/de/3551740/linux-tipps/mot-a-tool-to-fight-openwashing-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551740/linux-tipps/mot-a-tool-to-fight-openwashing-in-ai/</guid>
<pubDate>Wed, 27 May 2026 17:55:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Many large language models (LLMs) are described as open source, but
if one looks a bit deeper it turns out that is not actually so; the
model may be free to download, it may be "<a href="https://opensource.org/ai/open-weights">open weight</a>", but it
does not fit the <a href="http://opensource.org/">Open Source
Initiative</a> (OSI) <a href="https://opensource.org/osd">Open Source
Definition</a> (OSD). Assessing the actual openness of models is not
easy, as Arnaud Le Hors explained in his talk about the <a href="https://mot.isitopen.ai/">Model Openness Tool</a> (MOT) at <a href="https://events.linuxfoundation.org/open-source-summit-north-america/">Open
Source Summit North America</a> 2026. The tool is designed to help
users of LLMs understand to what degree a model is (or is not) open,
and to combat the <a href="https://openwashing.org/">openwashing</a>
that is prevalent with LLMs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meist heruntergeladene OpenSource Software 1990 - 2026]]></title>
<description><![CDATA[Von den 1990er Jahren bis 2026 spiegelt die Geschichte der am häufigsten heruntergeladenen Open-Source-Software wider, wie sich das Computing selbst entwickelt hat. In den 1990er Jahren wurden frühe Open-Source-Giganten wie der Linux-Kernel und Vim zu unverzichtbaren Tools für Programmierer und S...]]></description>
<link>https://tsecurity.de/de/3549585/it-security-nachrichten/meist-heruntergeladene-opensource-software-1990-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549585/it-security-nachrichten/meist-heruntergeladene-opensource-software-1990-2026/</guid>
<pubDate>Wed, 27 May 2026 03:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1toizb8/meist_heruntergeladene_opensource_software_1990/"> <img src="https://external-preview.redd.it/emK-FpZXmhgwmijvmyStHw_N9ozLov47SBbwz67u1kQ.jpeg?width=320&amp;crop=smart&amp;auto=webp&amp;s=be1dbe6bef89c85c655001a07e3a615ec079bfdb" alt="Meist heruntergeladene OpenSource Software 1990 - 2026" title="Meist heruntergeladene OpenSource Software 1990 - 2026"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Von den 1990er Jahren bis 2026 spiegelt die Geschichte der am häufigsten heruntergeladenen Open-Source-Software wider, wie sich das Computing selbst entwickelt hat. In den 1990er Jahren wurden frühe Open-Source-Giganten wie der Linux-Kernel und Vim zu unverzichtbaren Tools für Programmierer und Serveradministratoren und halfen, das frühe Internet zu betreiben. In den späten 1990er und 2000er Jahren dominierte Software wie Apache HTTP Server das Web, während Firefox Hunderte von Millionen von Nutzern als beliebten alternativen Browser gewann. In den 2010er Jahren trat Open-Source-Software in den Mainstream ein, als Chromium die Basis für viele moderne Browser wurde, LibreOffice eine kostenlose Büroalternative anbot und VLC-Media-Player Milliarden von Downloads weltweit erreichte. Bis 2026 ist Open Source keine Nische mehr – ein Großteil des Internets, Cloud-Systeme, Smartphones und alltägliche Apps sind darauf angewiesen, wobei Linux-basierte Systeme Server, Android-Geräte und einen Großteil der digitalen Infrastruktur der Welt leise antreiben.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Altruistic_Level9640"> /u/Altruistic_Level9640 </a> <br> <span><a href="https://youtu.be/dCwN29NxQeQ?si=0ykDrf68QylXuQrN">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1toizb8/meist_heruntergeladene_opensource_software_1990/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most Downloaded OpenSource Software 1990 - 2026]]></title>
<description><![CDATA[Author: Stats Media - Bewertung: 104x - Views:5173 From the 1990s to 2026, the story of the most downloaded open-source software reflects how computing itself evolved. In the 1990s, early open-source giants like the Linux kernel and Vim became essential tools for programmers and server administra...]]></description>
<link>https://tsecurity.de/de/3548143/it-security-nachrichten/most-downloaded-opensource-software-1990-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548143/it-security-nachrichten/most-downloaded-opensource-software-1990-2026/</guid>
<pubDate>Tue, 26 May 2026 15:25:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Stats Media - Bewertung: 104x - Views:5173 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/dCwN29NxQeQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>From the 1990s to 2026, the story of the most downloaded open-source software reflects how computing itself evolved. In the 1990s, early open-source giants like the Linux kernel and Vim became essential tools for programmers and server administrators, helping power the early internet. By the late 1990s and 2000s, software such as Apache HTTP Server dominated the web, while Firefox gained hundreds of millions of users as a popular alternative browser. In the 2010s, open-source software entered the mainstream as Chromium became the base for many modern browsers, LibreOffice offered a free office alternative, and VLC media player reached billions of downloads worldwide. By 2026, open source is no longer niche—much of the internet, cloud systems, smartphones, and everyday apps rely on it, with Linux-based systems quietly powering servers, Android devices, and much of the world’s digital infrastructure.<br />
<br />
Music: <br />
 'Convergence' by Scott Buckley - released under CC-BY 4.0. www,scottbuckley,com,au<br />
 'Wildflowers' by Scott Buckley - released under CC-BY 4.0. www,scottbuckley,com,au<br />
<br />
To support the channel ➡    / @StatsMedia<br />
SUBSCRIBE ➡    / statsmedia<br />
Thanks for watching. Have a nice day !!<br />
<br />
#usa #canada  #spain <br />
<br />
=====<br />
Sources: Google Trends, Stack Overflow Surveys, Git Hub Articles, JetBrains Developer Ecosystem Report, Kaggle, Google Books, industry DBs and early tech articles.<br />
=====<br />
<br />
Disclaimer:<br />
Stats Media relies on third-party data collected and published by a selection of trusted organizations. We publish the data source in the description and in the video itself.<br />
Most of the data in this channel comes directly from third-party providers and is published “as is”. Stats Media channel is not responsible for the accuracy of this data.<br />
<br />
=====<br />
SUPPORT THE CHANNEL ➡    / @StatsMedia<br />
SUBSCRIBE ➡    / StatsMedia<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs are enlisting business users to vibe code their own apps]]></title>
<description><![CDATA[Vibe coding is expanding beyond the realm of software development teams into a variety of business units at a range of enterprises, and technology leaders are not only supporting these efforts but in some cases leading the charge.



This democratization of software development, buoyed by vibe co...]]></description>
<link>https://tsecurity.de/de/3547568/it-nachrichten/cios-are-enlisting-business-users-to-vibe-code-their-own-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547568/it-nachrichten/cios-are-enlisting-business-users-to-vibe-code-their-own-apps/</guid>
<pubDate>Tue, 26 May 2026 12:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vibe coding is expanding beyond the realm of software development teams into a variety of business units at a range of enterprises, and technology leaders are not only supporting these efforts but in some cases leading the charge.</p>



<p>This democratization of software development, buoyed by <a href="https://www.cio.com/article/4165921/19-vibe-coding-tools-for-democratizing-app-development.html">vibe coding tools</a>, including chatbots and agents that generate code via prompts, has made vibe coding a thing in departments such as human resources and marketing.</p>



<p>With guidance from IT, such efforts can cut down development backlogs, move solution-building closer to business problems, and open opportunities not previously pursued. But <a href="https://www.cio.com/article/4148288/vibe-coding-your-own-enterprise-apps-is-edgy-business.html">vibe coding can be edgy business</a>. IT leaders interested in unleashing the power of vibe coding in the hands of business users must establish the governance and guardrails necessary to ensure secure results.</p>



<p>Here is a look at how several IT leaders are deploying vibe coding beyond IT and the challenges they’ve faced.</p>



<h2 class="wp-block-heading">Feeling the vibe</h2>



<p>At financial services technology provider EnFi, everyone in the organization, including the C-suite, is actively encouraged to use Claude Code to build their own sub-agents and then get the rest of their teams to use their creations.</p>



<p>“The results have surprised us,” says <a href="https://www.linkedin.com/in/sweller/" rel="nofollow">Scott Weller</a>, CTO. “What started as an engineering productivity initiative has become a company-wide capability, where anyone from the CEO to a customer success manager can turn an idea into a working prototype in hours, not weeks.”</p>



<p>Vibe coding using the tool quickly expanded when non-engineering employees realized they could participate directly in building applications, Weller says. “Product leadership, customer success, and executive stakeholders now routinely initiate development work through the same system,” he says. “Every branch, regardless of who initiates [coding projects], passes through the same automated quality gates, architectural checks, and human code review before anything reaches production.”</p>



<p>When an AI agent writes code, “it follows the same rules as a senior engineer,” Weller says. “AI-powered code review catches architectural violations, security issues, and pattern inconsistencies before a human reviewer sees it. This means the output from a product manager’s Slack request meets the same quality bar as an engineer’s pull request.”</p>



<p>Enabling everyone in the company to come up with an idea and see it running by simply asking a bot to build it “has fundamentally changed who participates in building the product,” Weller says.</p>



<p>Making AI-assisted coding broadly available has shortened the time to completing some projects from weeks to hours, Weller notes. “It has dramatically increased the number of experiments we can run, on [user experience] improvements, feature explorations, and workflow alternatives,” he says.</p>



<p>The most significant benefit is that new development ideas are no longer bottlenecked by lack of engineering capacity. “When anyone in the company can describe what they want and see it built, the rate of experimentation goes up dramatically,” Weller says.</p>



<h2 class="wp-block-heading">The momentum of building solutions to business problems</h2>



<p>Skillsoft, a provider of technology training services and products, is also pushing vibe coding outside its software development teams.</p>



<p>“While it initially emerged within IT teams, we’ve been intentional about encouraging this mindset beyond traditional software development,” says <a href="https://www.linkedin.com/in/orla-daly-ma/" rel="nofollow">Orla Daly</a>, CIO. “We see real value in enabling teams across the organization to explore, experiment, and problem‑solve using AI in ways that are directly connected to their day‑to‑day work.”</p>



<p>Within Skillsoft’s infrastructure and operations organization non-development individuals are building new products and capabilities or leveraging the principles of vibe coding to troubleshoot production issues, Daly says.</p>



<p>“We’ve seen this show up through cross‑functional experimentation such as prototyping customer intelligence solutions for our go-to-market teams and rapid development of a customer portal,” Daly says. “When people are learning and applying AI to solve a real business problem, it creates purpose and momentum.”</p>



<p>With vibe coding, teams are not just learning new concepts, “they’re developing judgment, curiosity, and a better understanding of how AI can elevate their role and the business more broadly,” Daly says. “The benefits show up in very tangible ways. Teams learn faster because they’re applying AI directly to their work. Engagement increases when people feel trusted to explore and contribute ideas. And as an organization, we gain better visibility into where skills already exist and how they’re evolving.”</p>



<p>More broadly, vibe coding supports adaptability, Daly says. “It helps people move from seeing AI as something abstract or intimidating to something they can work with thoughtfully, using judgment and collaboration rather than relying on rigid processes,” she says. “The solutions created as a result of vibe coding have filled capability gaps and delivered solutions to production in shorter timeframes, producing real value.”</p>



<h2 class="wp-block-heading">Emphasizing experimentation</h2>



<p>At Corevist, an ecommerce platform provider, broad use of vibe coding didn’t start as a formal initiative. “It showed up in different parts of the business, mostly in sales and customer-facing teams, because people were trying to move faster and make ideas easier to communicate,” says <a href="https://www.linkedin.com/in/terrystahler/">Terry Stahler</a>, CIO and chief customer officer.</p>



<p>It also didn’t spread purely on its own. “Without leadership pushing for experimentation, it likely would have moved at a much slower, consensus-driven pace,” Stahler says. “Instead, there was clear encouragement to try things, along with budget behind it.”</p>



<p>Today, Corevist uses vibe coding mainly as a prototyping tool. “It helps people get to something concrete faster, which makes conversations a lot clearer,” Stahler says. “That has been the biggest benefit. We are not using it as a shortcut to production software. Anything that is going to live beyond a prototype goes through our normal engineering and security process.”</p>



<p>Sales was the first place where Stahler saw use cases emerge. One was live prototyping during the sales process. “In a normal B2B conversation, a prospect explains what they need, the account team takes notes, and then everyone goes back and tries to interpret it later,” he says. “What changed here was the ability to turn an idea into something visible much faster, sometimes even while the conversation was still happening.”</p>



<p>That gave the prospect something concrete to react to and made it easier to tell whether a sales rep was actually understanding the request correctly. “It cut down on ambiguity early, which is valuable in any complex sales cycle,” Stahler says.</p>



<p>Marketing has also used vibe coding, for an update of its website. “The value there has been speed in the early creative and planning stages,” Stahler says. “They can generate rough versions of pages and flows much faster than they could through written direction or static mockups alone. That has made it easier to align on direction and has reduced some of the usual back-and-forth that comes with a website rebuild.”</p>



<h1 class="wp-block-heading">Supplementing the engineering queue</h1>



<p>Business growth platform provider ZenBusiness encourages vibe coding “across the board,” says <a href="https://www.zenbusiness.com/alex-victoria/">Alex Victoria</a>, CTO. “The way we think about it is pretty simple: If AI tools can help you go from idea to something working without waiting in an engineering queue, we want you to do that,” he says.</p>



<p>Vibe coding began within the product and engineering teams but has spread to other departments.</p>



<p>“We’ve seen people on the data side building their own query tools, product managers creating interactive prototypes with no design background, and teams across the company using AI to handle tasks they used to outsource to specialists,” Victoria says. “The culture we’ve tried to build is one where experimentation isn’t reserved for engineers. If you’re willing to learn and use the tools we have, anyone can code to improve their workflows on their own.”</p>



<p>Although Victoria has been using agentic coding tools for years, he says the “real unlock” of benefits came in 2025, with the release of Claude Code.</p>



<p>“I’ve seen a huge impact since then, and also with Cursor and Codex,” he says. “When someone can build their own tool or prototype in an afternoon instead of waiting weeks in an engineering queue, it changes what’s worth doing.”</p>



<p>The bigger benefit is how it’s changed the relationship between roles, Victoria says. “People who know how to build software can now produce far more value than ever before,” he says. “There’s still a gap between a vibe-coded idea and a running product. If you know how to ship a running product, you’re very valuable in this world.”</p>



<h2 class="wp-block-heading">Facing down challenges</h2>



<p>Embracing more widespread use of vibe coding in the enterprise comes with its own set of challenges.</p>



<p>One of these is maintaining quality when everyone can build. “When you open development to non-engineers, the risk is code that works but doesn’t follow project conventions, creating technical debt faster than manual development,” Weller says.</p>



<p>EnFi has addressed this by investing heavily in the rules and skills layer of coding. More than 40 custom skills impact AI output to match pre-determined architectural patterns.</p>



<p>“The agent doesn’t just write code; it writes code that passes the same review criteria we apply to human engineers,” Weller says. “Every branch, whether initiated by the CEO or a junior engineer, goes through the same automated quality gates and human code review.”</p>



<p>For business software provider Agiloft, “the biggest challenge isn’t technical, it’s organizational,” says <a href="https://www.linkedin.com/in/noe-ramos-psyd-3a1808178/" rel="nofollow">Noe Ramos</a>, vice president of AI operations. Agiloft is building an AI-native development capacity across every business function, embedding it into processes such as finance, human resources, and professional services.</p>



<p>“Most companies, including ours, are still learning where work actually happens versus where they think it happens,” Ramos says. “Before you can extend AI into a business function, you have to understand the real workflow, not the documented one. That discovery work is underestimated almost everywhere.”</p>



<p>The company also had to work through “the natural friction of trust and adoption,” Ramos says. “The human variable, though critically important to AI, is always the rate-limiting factor in this case, not the technology.”</p>



<p>On the governance side, Agiloft has had to address issues such as access controls, identity management, and data handling. “We built a formal approval process and a structured use-case lifecycle to manage this, so AI doesn’t get introduced into business teams in ways that create technical debt or compliance exposure,” Ramos says.</p>



<p>The primary challenge for healthcare technology provider iCore was creating confidence among non-technical users rather than technical barriers, says <a href="https://www.linkedin.com/in/thiago-soares-060938b5/" rel="nofollow">Thiago Soares</a>, COO. The company has actively supported AI-assisted development outside its engineering team, including operations and client success functions that are building automated reporting tools, internal workflow templates, and client onboarding checklists that previously required developer time to produce.</p>



<p>“Staff unfamiliar with AI-assisted development needed structured onboarding before adoption felt natural,” Soares says. “We addressed that through peer-led sessions, where early adopters demonstrated practical use cases relevant to each team’s specific workflows.</p>



<p>Uneven confidence levels can slow progress, especially when people worry about getting it wrong, Daly says. “Creating a safe space to learn is important,” she says. “Creating small teams to work together with peer-to-peer support and encouraging shared learning has also been helpful to support progress through practical application, which is where we see people learn best.”</p>



<p><a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html">Governance</a> is another key consideration, particularly in regulated industries with strict data handling protocols, such as healthcare. “Successful organizations set out explicit boundaries within which machine-generated code can be developed outside of formal development pathways,” Soares says.</p>



<p>IT leadership at iCore has built the guardrails needed to make expansion of vibe coding safe, “defining data access boundaries and compliance checkpoints that align with our commitment to trust and security,” Soares says. “That governance foundation is what allows cloud-driven innovation to move forward without creating the regulatory exposure healthcare environments cannot afford.”</p>



<h2 class="wp-block-heading">The future of coding</h2>



<p>Organizations that are moving vibe coding beyond software development teams are aiming to expand these efforts further.</p>



<p>At iCore, expansion of vibe coding into marketing and human resources functions is already under way, Soares says, focused on content workflows and documentation automation. These are “areas where vibe coding delivers efficiency without touching sensitive clinical or compliance infrastructure,” he says.</p>



<p>Agiloft plans to expand vibe coding further and make it into a standard practice “carefully and iteratively,” Ramos says, moving from isolated use cases toward a cohesive AI operating model with a shared infrastructure and AI-literate teams across functions, rather than just AI-enabled tools scattered across departments.</p>



<p>“That said, expansion for us means scaling what works, not scaling the toolset,” Ramos says. “We track every AI initiative through a structured lifecycle, from intake through decommission, precisely to avoid accumulating a stack of underutilized capabilities. Every function will eventually have embedded AI, but the goal is for those capabilities to be connected, governed, and [properly] used, not just deployed.”</p>



<p>EnFi is expanding from engineering-adjacent roles, such as product development and customer success, to other functions. “The same pattern — describe what you want, see it built, review and decide — applies to internal tooling, reporting, operational workflows, and documentation,” Weller says.</p>



<p>Organizations that master AI-assisted development internally “will be the ones capable of deploying AI-assisted workflows to their customers with the quality, governance, and reliability that regulated industries demand,” Weller says. “The internal practice is the proof point.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Freie Software-Alternativen für Synchronisation und Backups]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 21x - Views:176 Das bekannte FreeFileSync hat seine Lizenz geändert und ist daher nicht mehr "Freie Software" im Sinne der Free Software Foundation (FSF). In diesem Video zeige ich Dir fünf wirklich freie Programme für Backups und zur Ordner-Synchronisation (soga...]]></description>
<link>https://tsecurity.de/de/3539702/linux-tipps/freie-software-alternativen-fuer-synchronisation-und-backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539702/linux-tipps/freie-software-alternativen-fuer-synchronisation-und-backups/</guid>
<pubDate>Fri, 22 May 2026 15:26:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 21x - Views:176 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/y1MgeXW955M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Das bekannte FreeFileSync hat seine Lizenz geändert und ist daher nicht mehr "Freie Software" im Sinne der Free Software Foundation (FSF). In diesem Video zeige ich Dir fünf wirklich freie Programme für Backups und zur Ordner-Synchronisation (sogar Zwei-Wege-Synchronisation).<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Die vier Freiheiten von Open-Source: https://www.gnu.org/philosophy/free-sw.de.html <br />
- Pika Backups: https://youtu.be/kgaOQ3pLZaI<br />
- Syncthing: https://youtu.be/PwjgUlo8HEQ<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Begrüßung<br />
02:07 Grsync<br />
12:37 Pika Backup<br />
16:12 Luckybackup<br />
21:22 Syncthing<br />
22:54 Unison (in beide Richtungen)<br />
28:58 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linux #freesoftware #opensource #foss #synchronization<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Launch time! Turning early momentum into real growth]]></title>
<description><![CDATA[Launching a new product is hard enough, but the work doesn’t stop once a product is officially on the market. Often, a new and more complex challenge begins: Turning early excitement into sustained growth.



Launches are deceptive. They create visibility, energy and, if you’re lucky, a surge of ...]]></description>
<link>https://tsecurity.de/de/3528435/it-security-nachrichten/launch-time-turning-early-momentum-into-real-growth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528435/it-security-nachrichten/launch-time-turning-early-momentum-into-real-growth/</guid>
<pubDate>Tue, 19 May 2026 11:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Launching a new product is hard enough, but the work doesn’t stop once a product is officially on the market. Often, a new and more complex challenge begins: Turning early excitement into sustained growth.</p>



<p>Launches are deceptive. They create visibility, energy and, if you’re lucky, a surge of initial demand. But they don’t guarantee long-term success. Many products generate strong early interest only to stall when that interest doesn’t convert into repeatable revenue or sustained engagement.</p>



<p>The period immediately after launch is where outcomes diverge. This is where organizations move from building to selling, from internal validation to external validation, and from potential to proof.</p>



<h2 class="wp-block-heading">The real goal: Learning that converts into revenue</h2>



<p>A successful launch is not about perfection. It’s about progress. By the time a product is launched, it should be what I call a “minimum lovable product” — something that delivers clear value, even if incomplete. Waiting for perfection delays learning, and in fast-moving markets, delayed learning is often fatal.</p>



<p>Once a product is live, the focus must shift quickly. The goal is no longer to just validate that the product works. Instead, it’s to validate that customers will pay for it — or, in the case of free products, use it consistently enough to support a viable business model. This requires deliberate effort. </p>



<p>Organizations must build a pipeline of early customers or users. If an organization has a sales team, this means enabling them with a clear message centered on a compelling differentiator. Those without a formal sales organization should work closely with early adopters who are willing to engage and provide honest feedback. These early customers are critical — they aren’t just buyers; they’re partners in shaping the product’s future. Their usage, patterns, feedback and willingness to pay provide signals that are far more valuable than internal metrics alone. One of the simplest and most effective tests is to ask directly: Would you pay for this?</p>



<p>Another area that must be pursued in these early phases is a deep understanding of tomorrow and the day after tomorrow’s ideal customer profile (ICP). This is hard work, requires a lot of customer conversations at varying levels of detail, both buyers and users. It might just make sense to have a team dedicated to doing this; it’s not sales, it’s not pure prioritization, it’s not engineering, it’s a sales and product management skill that goes hand in hand and must be rewarded because this lays the groundwork for what will build a strong revenue stream.  Far too often, this step is overlooked or conducted spuriously, leading to pain later when the product does not sell to later adopters.</p>



<p>Research consistently demonstrates that stated interest and actual willingness to pay are very different. <a href="https://www.library.hbs.edu/working-knowledge/what-customers-want-from-your-products" rel="nofollow">Studies</a> from Harvard Business Review highlight that customer behavior, not intent, is the most reliable indicator of product value.</p>



<h2 class="wp-block-heading">Balancing ambition with realism in early commitments</h2>



<p>One of the most challenging aspects of the post-launch phase is deciding what to promise. On one hand, it’s important to lean forward. Early customers often require additional support, customization or roadmap commitments to get started. Going above and beyond for a small number of initial customers can be the difference between traction and stagnation. On the other hand, overpromising creates risk. Committing to features that don’t exist or unreasonable timelines risks damaging trust — not just with customers, but internally. Engineering teams become overextended, priorities become unclear and execution suffers.</p>



<p>The balance lies in informed ambition. Having a clear view of where a product is headed and what is realistic to deliver. This requires close alignment between product, engineering and go-to-market teams. It also requires discipline in prioritization. Not everything matters equally. Product differentiation, the core reason customers care, is what should drive the roadmap and messaging. Other features, while important, are secondary. Overinvesting in completeness too early can dilute focus and slow progress.</p>



<p>This is a contrarian point for many organizations. The instinct is to make a product as comprehensive as possible before scaling. The most successful products often win by being significantly better at one thing, rather than marginally better at many.</p>



<h2 class="wp-block-heading">Creating a repeatable go-to-market motion</h2>



<p>Launching a product is a moment. Building a go-to-market engine is a process. One of the biggest mistakes organizations make is treating marketing as a one-time event rather than an ongoing system. Messages alone don’t drive growth; distribution does. Build a funnel that consistently brings the message to the right audience.</p>



<p>This includes:</p>



<ul class="wp-block-list">
<li>Clear positioning based on the differentiator</li>



<li>Targeted outreach to the right customer segments</li>



<li>Feedback loops to refine messaging and approach</li>



<li>Metrics to understand what’s working and what isn’t</li>
</ul>



<p>Frameworks like HubSpot’s <a href="https://www.hubspot.com/inbound-marketing" rel="nofollow">inbound methodology</a> emphasize the importance of aligning content, distribution and engagement to create sustained demand. Regardless of the framework used, the principle is the same: consistency matters more than perfection. The initial approach won’t be perfect — it shouldn’t be. The goal is to start with a strong hypothesis and iterate based on real-world results.</p>



<p>At the same time, internal alignment is critical. The organization’s sales team — or equivalent customer-facing function — needs to feel confident and energized. They need to understand not just what the product does, but why it matters and how to position it effectively. Energy is contagious: if the organization believes in the product, that belief translates into better execution.</p>



<h2 class="wp-block-heading">Why ease of use matters more than you think</h2>



<p>Beyond differentiation, one of the most underestimated factors in post-launch success is ease of adoption. Even if the product delivers significant value, friction in getting started can slow growth dramatically. Users are busy. They have alternatives. If a product requires too much effort to understand or implement, adoption will suffer. This is especially important in enterprise environments, where implementation complexity can be a major barrier. </p>



<p>In one of my experiences, we built a product that was loved by many early adopters. Our product gave varying levels of users and stakeholders insights into their IT systems operations well beyond what they had before. But the setup required to get them to that level of visibility required a lot of hand-holding. While we had the differentiator, our product was too difficult to get started with and that stood out as one of the reasons our sales slowed at that time.</p>



<p>Research from <a href="https://www.gartner.com/en/customer-service-support/topics/customer-service-experience" rel="nofollow">Gartner</a> consistently highlights that customer experience, including ease of use, is a key driver of technology adoption. Ideally, the product should be both differentiated and easy to use. In practice, achieving both on day one is difficult. Given the choice to prioritize, differentiation comes first — but ease of use should follow quickly. Products that combine the two create a powerful foundation for growth.</p>



<h2 class="wp-block-heading">What happens immediately post-launch</h2>



<p>One of the most overlooked aspects of launching a product is what comes next internally. Leading up to launch, teams often operate in a state of focus. There’s a clear goal, a defined timeline and a shared sense of urgency. Once the product is released, that structure often disappears.</p>



<p>Without proper preparation, this can create a void. The solution is to have a near-term roadmap ready before launch. The post-launch period is when organizations receive their most valuable insights. Customers will share what’s working, what isn’t and what they need next. The ability to respond quickly can significantly influence a product’s trajectory.</p>



<p>Launching a product is a major milestone. Taking the time to recognize that achievement reinforces team morale and sets the tone for the next phase. It’s not just about acknowledging past effort. Instead, prepare the organization for what comes next.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Ultimately, the goal of the post-launch phase is to move toward product-market fit.</p>



<p>This is where many products stall. They generate initial interest but fail to translate that into sustained usage or revenue. The reasons vary, but they often come back to the same fundamentals:</p>



<ul class="wp-block-list">
<li>Lack of a clear differentiator that really solves a problem</li>



<li>Insufficient understanding of customer needs, both early adopters and later ones</li>



<li>Weak go-to-market execution</li>



<li>Overly complex setup experience</li>



<li>Failure to iterate based on feedback</li>
</ul>



<p>The good news is that this phase offers the fastest learning cycle. If customers are using the product, they will tell you what they value. If they aren’t, that signal is just as important. Either way, you gain clarity. The key is to act on that clarity.</p>



<p>A launch is a beginning, not an endpoint. The organizations that succeed are those that treat it as the start of a continuous process of learning, refining and scaling. They focus on what matters most, align their teams around a clear vision and build systems that support sustained growth.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuerungen im GeoServer (fossgis2016)]]></title>
<description><![CDATA[Der GeoServer ist ein bekannter und mächtiger OpenSource Kartenserver. Er
          ermöglicht die Veröffentlichung von Geodiensten aus zahlreichen Datenquellen auf Basis
          offener Standards.

          Die sehr aktive GeoServer Community arbeitet laufend an Erweiterungen und Verbesserung...]]></description>
<link>https://tsecurity.de/de/3527041/it-security-video/neuerungen-im-geoserver-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527041/it-security-video/neuerungen-im-geoserver-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 20:16:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der GeoServer ist ein bekannter und mächtiger OpenSource Kartenserver. Er
          ermöglicht die Veröffentlichung von Geodiensten aus zahlreichen Datenquellen auf Basis
          offener Standards.

          Die sehr aktive GeoServer Community arbeitet laufend an Erweiterungen und Verbesserungen
          der Kernsoftware. Dieser Vortrag wird sich einigen (Neu-)Entwicklungen der jüngeren
          Vergangenheit widmen und an praktischen Beispielen den Nutzen vorstellen. Hierunter fallen
          u.a.:

          <ul>
          <li>Die Importer Extension zum Hinzufügen von Geodaten in den GeoServer über das
          Webinterface.</li>
          <li>Die CSS Extension zum Stylen von Layern über Cascading Style Sheets.</li>
          <li>Der WFS (Web Feature Service) Datenspeicher zur Kaskadierung entfernter
          WFS-Server.</li>
          <li>Die Darstellung von Curved Geometries.</li>
          <li>Die GeoFence Integration.</li>
          </ul>

          Der Vortag wird mit einem Ausblick auf geplante und zukünftige Entwicklungen abschließen.


about this event: https://fossgis-konferenz.de/2016/programm/event5077.html]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoExt3 (fossgis2016)]]></title>
<description><![CDATA[Der Vortrag stellt GeoExt 3 [1] vor und wird auch die Vater-Bibliotheken ExtJS [2]
          und OpenLayers [3] erläutern. Schwerpunkte werden hier zunächst allgemeine Features der
          Bibliotheken / Frameworks sein, bevor der Fokus auf der Erstellung von 'universalen'
          WebGIS-Appl...]]></description>
<link>https://tsecurity.de/de/3526970/it-security-video/geoext3-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526970/it-security-video/geoext3-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 19:48:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Vortrag stellt GeoExt 3 [1] vor und wird auch die Vater-Bibliotheken ExtJS [2]
          und OpenLayers [3] erläutern. Schwerpunkte werden hier zunächst allgemeine Features der
          Bibliotheken / Frameworks sein, bevor der Fokus auf der Erstellung von 'universalen'
          WebGIS-Applikationen liegt. Unter 'universal' verstehen wir hierbei eine GeoExt3-basierte
          Applikation, die sowohl auf klassischen Desktop-Browsern aber auch auf mobilen Endgeräten
          wie Tablets und Smartphones funktioniert und ein ansprechendes Benutzererlebnis
          ermöglicht.

          Insbesondere seit der GeoExt3 zugrundeliegenden Version 6 von ExtJS kann man aus einer
          einzigen Codebasis solche Applikationen erstellen, ohne jede Funktionialität doppelt
          entwickeln zu müssen. OpenLayers 3 verfolgt bereits seit den ersten Entwicklungen die
          Unabhängigkeit vom gewählten Webbrowser und Endgerät.

          Im Vortrag wird also die OpenSource-Bibliothek GeoExt3 vorgestellt und ein konkretes
          Anwendungsbeispiel beleuchtet. Der Vortrag wird die Rahmenbedingungen von universalen
          WebGIS-Applikationen nennen und zeigen, wie die Bibliotheken und Entwicklungstools (etwa
          Sencha Cmd [4]) helfen, die konkreten Anforderungen an die jeweiligen Gegebenheiten zu
          erfüllen.

          Die Vortragenden Christian Mayer (meggsimum) und Marc Jansen (terrestris) sind beide
          Kernentwickler und Mitglieder des Projektsteuerungskommitees von GeoExt.

          [1] http://geoext.github.io/geoext3/, https://github.com/geoext/geoext3
          [2] https://www.sencha.com/products/extjs/
          [3] http://openlayers.org/
          [4] https://www.sencha.com/products/sencha-cmd/


about this event: https://fossgis-konferenz.de/2016/programm/event5057.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Automatische Erkennung der Projektion von Geodaten (fossgis2016)]]></title>
<description><![CDATA[Auch heutzutage gibt es Geodatenlieferungen mit unbekannter oder falscher
          Projektion. Sehr gute Kenntnisse über Koordinatensysteme sind nötig, um die gelieferten
          Geodaten rasch in ein bestehendes GIS-Projekt lagerichtig zu integrieren. Für
          GIS-Fachunkundige bedeuten ...]]></description>
<link>https://tsecurity.de/de/3526835/it-security-video/automatische-erkennung-der-projektion-von-geodaten-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526835/it-security-video/automatische-erkennung-der-projektion-von-geodaten-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 19:03:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Auch heutzutage gibt es Geodatenlieferungen mit unbekannter oder falscher
          Projektion. Sehr gute Kenntnisse über Koordinatensysteme sind nötig, um die gelieferten
          Geodaten rasch in ein bestehendes GIS-Projekt lagerichtig zu integrieren. Für
          GIS-Fachunkundige bedeuten solche Unklarheiten immer wieder erneuten enormen
          Einarbeitungsaufwand.
          In dieser Einreichung wird ein GIS-Programm aufbauend auf einem OpenSource GIS-Testservice
          von Aaron Racicot als Lösungsvorschlag der beschriebenen Problematik vorgestellt. Das
          Programm mit dem Namen SHAPEFILE PROJECTIONFINDER wertet ein ausgewähltes Shapefile mit
          unbekannter Projektion (ohne PRJ-Datei) in Kombination mit einer geographischen
          Referenzkoordinate aus und erhält automatisch nach Anfrage beim bestehenden
          GIS-Testservice von Aaron Racicot eine Liste möglicher zutreffender Projektionen. Nach
          händischer Auswahl wird für jede ausgewählte Projektion eine Kopie des Shapefiles mit
          entsprechender PRJ-Datei erstellt. Der GIS-Anwender muss nun die erstellten Kopien in sein
          GIS-Projekt laden und entscheidet nach visueller Prüfung über die richtige Projektion.
          Nach Darstellung der Lösung werden im Detail vorhandene Problembereiche präsentiert. Dabei
          wird vor allem auf den Unterschied zwischen geographischen und projizierten Koordinaten
          eingegangen. In diesem Zusammenhang werden auch Projektionen, welche unterschiedliche
          Referenzellipsoide (z.B. UTM 32 N : WGS84 und ETRS98) verwenden, in Fallbeispielen
          diskutiert.
          Abschließend werden Ausbaumöglichkeiten und Alternativen wie eine reine Desktopanwendung
          dargestellt.

Das GIS-Tool SHAPEFILE PROJECTIONFINDER wird als Lösungsvorschlag in
          Zusammenhang mit Geodaten und unbekannter Projektion präsentiert.

          Zielgruppe dieses Programms sind vor allem Anwender, die mit geringen Fachkenntnissen zu
          Koordinatensystemen ohne Aufwand gelieferte Daten in GIS-Projekte lagerichtig integrieren
          möchten.
about this event: https://fossgis-konferenz.de/2016/programm/event5013.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues in Metador 2.1 (fossgis2016)]]></title>
<description><![CDATA[Metador2 ist eine OpenSource Lösung zum einfachen Erstellen und Bearbeiten von
          Metadaten. Dabei unterstützt Metador2 die Aufnahme von Metadaten gemäß der INSPIRE
          Technical Guidelines und der Richtlinien der GDI-DE, kann aber auch einfach an völlig
          unterschiedliche un...]]></description>
<link>https://tsecurity.de/de/3526682/it-security-video/neues-in-metador-21-fossgis2016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526682/it-security-video/neues-in-metador-21-fossgis2016/</guid>
<pubDate>Mon, 18 May 2026 18:19:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Metador2 ist eine OpenSource Lösung zum einfachen Erstellen und Bearbeiten von
          Metadaten. Dabei unterstützt Metador2 die Aufnahme von Metadaten gemäß der INSPIRE
          Technical Guidelines und der Richtlinien der GDI-DE, kann aber auch einfach an völlig
          unterschiedliche und beliebige Metadatenprofile angepasst werden. Die Webanwendung bietet
          Importfunktionen, wie z.B. aus WMS-Capabilities an und kann die Metadaten als XML, PDF
          oder HTML exportieren. Metador2 bringt selbst keine CSW-Schnittstelle mit, sondern wird
          dafür durch CSW-Software wie Geonetwork oder deegree erweitert.

          Metador 2.1 bringt ein neues Plugin-System mit, das die Erweiterung der Software um neue
          Funktionen einfacher und übersichtlicher macht. Plugins können dabei u.a. unterschiedliche
          Metadatenprofile sein. Während im INSPIRE und GDI-DE-Kontext die Metadatenprofile recht
          ähnlich sind, können z.B. für interne Metadaten unterschiedliche Profile für
          unterschiedliche Datentypen genutzt werden. Ist ein Metadatenprofil in einem Plugin
          umgesetzt, können auch weitere, von diesem abhängige Plugins entwickelt werden,
          beispielsweise für den Import von Metadaten in dieses Profil. Eine weitere
          Einsatzmöglichkeit von Plugins kann die Anpassung des Themas sein, d.h. der Farben, des
          Logos, etc.

          Der Vortrag stellt die Neuerungen in der kommenden Version 2.1 vor, mit Live-Beispielen.
          Metador ist verfügbar unter: https://github.com/WhereGroup/metador2/

Metador2 ist eine OpenSource Lösung zum einfachen Erstellen und Bearbeiten von
          Metadaten. Metador 2.1 enthält ein neues Plugin-System, mit dem beispielsweise
          unterschiedliche Metadatenprofile einfacher und übersichtlicher erstellt und mit Import-
          und Exportfunktionen unterstützt werden können. Der Vortrag stellt die Neuerungen in der
          kommenden Version 2.1 vor, mit Live-Beispielen. Metador ist verfügbar unter:
          https://github.com/WhereGroup/metador2/
about this event: https://fossgis-konferenz.de/2016/programm/event5069.html]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI deployment gap enterprises can’t afford to ignore]]></title>
<description><![CDATA[Enterprises are moving quickly to explore artificial intelligence. New pilots are being launched across functions, from customer service chatbots to predictive analytics and automated workflows. Early results are often encouraging. Models perform well, demonstrations impress stakeholders, and mom...]]></description>
<link>https://tsecurity.de/de/3525422/it-security-nachrichten/the-ai-deployment-gap-enterprises-cant-afford-to-ignore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525422/it-security-nachrichten/the-ai-deployment-gap-enterprises-cant-afford-to-ignore/</guid>
<pubDate>Mon, 18 May 2026 11:22:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises are moving quickly to explore artificial intelligence. New pilots are being launched across functions, from customer service chatbots to predictive analytics and automated workflows. Early results are often encouraging. Models perform well, demonstrations impress stakeholders, and momentum builds around the promise of AI-led transformation.</p>



<p>Yet a more difficult reality is emerging. Most AI initiatives do not make it into production.<br>While adoption is widespread, with 88% of organizations using AI, nearly <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="sponsored">two-thirds</a> are still in pilot or early-stage deployments, highlighting the gap between experimentation and enterprise-scale impact.</p>



<p>A majority of pilots fail to scale beyond experimentation. The challenge is rarely the model itself. In controlled settings, it usually works. The problem begins when organizations try to translate those results into systems that can operate reliably at scale.</p>



<p>This gap between experimentation and production is not just slowing adoption. It is delaying value, increasing costs, and creating a growing divide between organizations that can operationalize AI and those that remain stuck in cycles of pilots and rework.</p>



<h2 class="wp-block-heading">Why pilots succeed and production struggles</h2>



<p>Pilot projects are designed for controlled outcomes. Teams work with curated datasets. Infrastructure is temporary, usage is limited, and performance issues are resolved manually. Success is measured by model accuracy or proof of concept, not business impact.</p>



<p>Production systems face a very different reality. They must handle real-world data that is inconsistent and constantly changing. They need to integrate with existing enterprise systems, comply with regulations, and deliver consistent performance under variable demand. Once deployed, they are expected to run continuously without constant expert intervention.</p>



<p>This shift exposes fundamental gaps. Infrastructure that performs well under limited load can struggle at scale. Models trained on curated data may degrade when exposed to real-world variability. Bridging this gap requires more than improving algorithms. It requires rethinking how AI is built, deployed, and managed end to end.</p>



<h2 class="wp-block-heading">Infrastructure readiness is often underestimated</h2>



<p>One of the most common barriers to scaling AI is infrastructure that was never designed for it. Traditional enterprise environments are built for predictable workloads. AI introduces variability, intensity, and data complexity that these systems were not designed to handle.</p>



<p>Compute demand can fluctuate significantly, making static provisioning inefficient and expensive. Data presents an even larger challenge. It remains a fundamental constraint – over 50% of organizations cite data quality and availability as the biggest barrier to scaling AI. AI models rely on large volumes of distributed data, and moving this data to centralized locations introduces latency, cost, and compliance risks. Production AI requires architectures that allow data to be accessed where it resides.</p>



<p>Storage and networking also become critical constraints. AI workloads generate high-volume read and write patterns that conventional systems struggle to support. At the same time, production environments must enforce security and regulatory requirements consistently and at scale. Governance that was relaxed during pilots must now be embedded into the system.</p>



<h2 class="wp-block-heading">Rethinking the talent challenge through platforms</h2>



<p>The challenge of scaling AI is often described as a shortage of skilled talent. While expertise is limited, the issue is also about how effectively teams can work.</p>



<p>In many organizations, data scientists spend a large portion of their time on tasks such as data preparation, environment setup, and infrastructure troubleshooting. This approach may work for a few pilots, but it does not scale as use cases grow. In practice, highly skilled teams remain underutilized; studies suggest data scientists spend over 40% of their time on data preparation rather than building models.</p>



<p>Organizations that move successfully into production take a different approach. They invest in shared platforms that reduce complexity. Standardized environments, automated pipelines, and repeatable workflows allow teams to focus on solving business problems rather than managing infrastructure.</p>



<p>This shift also broadens participation. Domain experts can engage more directly in building AI solutions when tools are easier to use, enabling adoption beyond specialist teams and embedding AI into business processes.</p>



<h2 class="wp-block-heading">Governance becomes foundational</h2>



<p>Governance is often treated as a secondary consideration during experimentation. In production, it becomes essential.</p>



<p>AI systems depend on data that evolves over time. Without continuous monitoring and validation, model performance can decline. In customer-facing or regulated environments, this creates real risk.</p>



<p>Enterprises also need transparency and traceability. They must understand how models make decisions, what data was used, and whether outputs meet regulatory and ethical standards. These capabilities must be built into systems from the start. Retrofitting governance later is costly and disruptive.</p>



<h2 class="wp-block-heading">From isolated projects to platform thinking</h2>



<p>A clear pattern is emerging among enterprises that successfully scale AI. They are moving away from isolated projects and adopting platform-led approaches that unify development, deployment, and governance.</p>



<p>In siloed environments, teams use different tools and workflows. This works initially, but becomes difficult to manage as adoption grows. Data fragmentation increases, governance becomes inconsistent, and operational complexity rises.</p>



<p>Platform-led approaches address this by integrating key capabilities into a single system. Data pipelines become repeatable, model development is standardized, and deployment follows consistent processes. This reduces friction and enables scale.</p>



<p>This is where our platform, <a href="https://www.tatacommunications.com/cloud/cloud-ai/ai-studio" rel="sponsored">Tata Communications’ Vayu AI Studio,</a> is becoming relevant. Instead of requiring enterprises to assemble multiple tools, these environments bring together infrastructure, data pipelines, model development, and governance into a unified system designed for production. This simplifies development and creates a more stable foundation for scaling AI.</p>



<p>The platform also improves how data is handled. Integrated pipelines reduce the effort required to move from raw data to production-ready models, while capabilities such as real-time processing and model customization support faster development without sacrificing control.</p>



<p>At the deployment stage, integrated model hosting, low-latency inference, and lifecycle automation enable reliable scaling. Governance is embedded within workflows, with controls for data lineage, access, and monitoring. At the same time, simplified interfaces allow a broader set of users to participate, accelerating adoption across the enterprise.</p>



<h2 class="wp-block-heading">Closing the gap</h2>



<p>The AI deployment gap is not just a technical issue. It is a reflection of how organizations approach AI as part of their operating model.</p>



<p>Enterprises that address this deliberately, by investing in production-ready platforms, strengthening governance, and aligning teams, are able to move beyond isolated pilots. They build systems that scale, adapt, and deliver consistent value.</p>



<p>The question is no longer whether AI will move into production. It is whether organizations can bridge the gap between experimentation and execution in a way that is sustainable and aligned with long-term business outcomes.</p>



<p><a href="https://www.tatacommunications.com/cloud/cloud-ai/ai-studio" rel="sponsored">Click here</a> to know more about Tata Communications Vayu AI Studio.</p>



<p>Yet a more difficult reality is emerging. Most AI initiatives do not make it into production.<br>While adoption is widespread,  with 88% of organizations using AI: nearly <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="sponsored">two-thirds</a> are still in pilot or early-stage deployments, highlighting the gap between experimentation and enterprise-scale impact.</p>



<p>A majority of pilots fail to scale beyond experimentation. The challenge is rarely the model itself. In controlled settings, it usually works. The problem begins when organizations try to translate those results into systems that can operate reliably at scale.</p>



<p>This gap between experimentation and production is not just slowing adoption. It is delaying value, increasing costs, and creating a growing divide between organizations that can operationalize AI and those that remain stuck in cycles of pilots and rework.</p>



<p><strong>Why pilots succeed and production struggles</strong></p>



<p>Pilot projects are designed for controlled outcomes. Teams work with curated datasets. Infrastructure is temporary, usage is limited, and performance issues are resolved manually. Success is measured by model accuracy or proof of concept, not business impact.</p>



<p>Production systems face a very different reality. They must handle real-world data that is inconsistent and constantly changing. They need to integrate with existing enterprise systems, comply with regulations, and deliver consistent performance under variable demand. Once deployed, they are expected to run continuously without constant expert intervention.</p>



<p>This shift exposes fundamental gaps. Infrastructure that performs well under limited load can struggle at scale. Models trained on curated data may degrade when exposed to real-world variability. Bridging this gap requires more than improving algorithms. It requires rethinking how AI is built, deployed, and managed end to end.</p>



<p><strong>Infrastructure readiness is often underestimated</strong></p>



<p>One of the most common barriers to scaling AI is infrastructure that was never designed for it. Traditional enterprise environments are built for predictable workloads. AI introduces variability, intensity, and data complexity that these systems were not designed to handle.</p>



<p>Compute demand can fluctuate significantly, making static provisioning inefficient and expensive. Data presents an even larger challenge. It remains a fundamental constraint – over 50% of organizations cite data quality and availability as the biggest barrier to scaling AI. AI models rely on large volumes of distributed data, and moving this data to centralized locations introduces latency, cost, and compliance risks. Production AI requires architectures that allow data to be accessed where it resides.</p>



<p>Storage and networking also become critical constraints. AI workloads generate high-volume read and write patterns that conventional systems struggle to support. At the same time, production environments must enforce security and regulatory requirements consistently and at scale. Governance that was relaxed during pilots must now be embedded into the system.</p>



<p><strong>Rethinking the talent challenge through platforms</strong></p>



<p>The challenge of scaling AI is often described as a shortage of skilled talent. While expertise is limited, the issue is also about how effectively teams can work.</p>



<p>In many organizations, data scientists spend a large portion of their time on tasks such as data preparation, environment setup, and infrastructure troubleshooting. This approach may work for a few pilots but does not scale as use cases grow. In practice, highly skilled teams remain underutilized, studies suggest data scientists spend over 40% of their time on data preparation rather than building models.</p>



<p>Organizations that move successfully into production take a different approach. They invest in shared platforms that reduce complexity. Standardized environments, automated pipelines, and repeatable workflows allow teams to focus on solving business problems rather than managing infrastructure.</p>



<p>This shift also broadens participation. Domain experts can engage more directly in building AI solutions when tools are easier to use, enabling adoption beyond specialist teams and embedding AI into business processes.</p>



<p><strong>Governance becomes foundational</strong></p>



<p>Governance is often treated as a secondary consideration during experimentation. In production, it becomes essential.</p>



<p>AI systems depend on data that evolves over time. Without continuous monitoring and validation, model performance can decline. In customer-facing or regulated environments, this creates real risk.</p>



<p>Enterprises also need transparency and traceability. They must understand how models make decisions, what data was used, and whether outputs meet regulatory and ethical standards. These capabilities must be built into systems from the start. Retrofitting governance later is costly and disruptive.</p>



<p><strong>From isolated projects to platform thinking</strong></p>



<p>A clear pattern is emerging among enterprises that successfully scale AI. They are moving away from isolated projects and adopting platform-led approaches that unify development, deployment, and governance.</p>



<p>In siloed environments, teams use different tools and workflows. This works initially but becomes difficult to manage as adoption grows. Data fragmentation increases, governance becomes inconsistent, and operational complexity rises.</p>



<p>Platform-led approaches address this by integrating key capabilities into a single system. Data pipelines become repeatable, model development is standardized, and deployment follows consistent processes. This reduces friction and enables scale.</p>



<p>This is where our platforms <a href="https://www.tatacommunications.com/cloud/cloud-ai/ai-studio" rel="sponsored">Tata Communications’ Vayu AI Studio</a> is becoming relevant. Instead of requiring enterprises to assemble multiple tools, these environments bring together infrastructure, data pipelines, model development, and governance into a unified system designed for production. This simplifies development and creates a more stable foundation for scaling AI.</p>



<p>The platform also improves how data is handled. Integrated pipelines reduce the effort required to move from raw data to production-ready models, while capabilities such as real-time processing and model customization support faster development without sacrificing control.</p>



<p>At the deployment stage, integrated model hosting, low-latency inference, and lifecycle automation enable reliable scaling. Governance is embedded within workflows, with controls for data lineage, access, and monitoring. At the same time, simplified interfaces allow a broader set of users to participate, accelerating adoption across the enterprise.</p>



<p><strong>Closing the gap</strong></p>



<p>The AI deployment gap is not just a technical issue. It is a reflection of how organizations approach AI as part of their operating model.</p>



<p>Enterprises that address this deliberately, by investing in production-ready platforms, strengthening governance, and aligning teams, are able to move beyond isolated pilots. They build systems that scale, adapt, and deliver consistent value.</p>



<p>The question is no longer whether AI will move into production. It is whether organizations can bridge the gap between experimentation and execution in a way that is sustainable and aligned with long-term business outcomes.</p>



<p><a href="https://www.tatacommunications.com/cloud/cloud-ai/ai-studio" rel="sponsored">Click here</a> to know more about Tata Communications Vayu AI Studio.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Added an LLM-Based Grammar Checking + TeX Math Import To LibreOffice]]></title>
<description><![CDATA[Former Microsoft programmer Keith Curtis "wrote and self-published After the Software Wars to explain the caliber of free and open source software," according to his entry on Wikipedia, "and why he believes Linux is technically superior to any proprietary OS." 

He's also KeithCu (long-time Slash...]]></description>
<link>https://tsecurity.de/de/3522733/it-security-nachrichten/how-i-added-an-llm-based-grammar-checking-tex-math-import-to-libreoffice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522733/it-security-nachrichten/how-i-added-an-llm-based-grammar-checking-tex-math-import-to-libreoffice/</guid>
<pubDate>Sat, 16 May 2026 23:49:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Former Microsoft programmer Keith Curtis "wrote and self-published After the Software Wars to explain the caliber of free and open source software," according to his entry on Wikipedia, "and why he believes Linux is technically superior to any proprietary OS." 

He's also KeithCu (long-time Slashdot reader #925,649), and has written a blog post on "How I added an LLM-based grammar checking + TeX math import to LibreOffice."



:


At Microsoft, I spent five years working on the text components RichEdit and Quill, and came to understand the "physics" of word processing: the file formats, data structures, and algorithms that provided fast access to text and properties, independent of the length of the file. Selecting one million characters to make them bold took about the same time as changing one character, because of the clever data structures (piece tables) and algorithms in these engines... 

When I decided to add a real-time AI grammar checker to [LibreOffice plugin] WriterAgent, I knew what I was getting into, but I underestimated the trickery of LibreOffice's UNO. 

His site shares the surprises he encountered, one by one. (Starting with "the office suite throws a bunch of initialization variables at your constructor. If your Python __init__ method doesn't handle them, the code fails to map the call, the stack misaligns, and the program dies.") There's sentence casing issues, duplicate words, and foreign-language syntax — all culminating in new features for "a LibreOffice extension (Python + UNO) that adds generative AI editing to Writer, Calc, and Draw..." 
"If you want to try it out, the repo is here... Let's make LibreOffice and the free desktop AI-native!"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+I+Added+an+LLM-Based+Grammar+Checking+%2B+TeX+Math+Import+To+LibreOffice%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F16%2F2047205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F16%2F2047205%2Fhow-i-added-an-llm-based-grammar-checking--tex-math-import-to-libreoffice%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/16/2047205/how-i-added-an-llm-based-grammar-checking--tex-math-import-to-libreoffice?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Mint 23 verzögert sich - Auch in 2026 noch das beste Linux?!]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 27x - Views:350 In diesem Video erklärt Jean, was hinter dem angepassten Release-Zyklus von Linux Mint steckt und wie die Verzögerung von Mint 23 einzuordnen ist. Ist Mint auch in 2026 noch eine empfehlenswerte Linux-Distro?
Wenn Du das Video unterstützen willst,...]]></description>
<link>https://tsecurity.de/de/3519903/linux-tipps/linux-mint-23-verzoegert-sich-auch-in-2026-noch-das-beste-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519903/linux-tipps/linux-mint-23-verzoegert-sich-auch-in-2026-noch-das-beste-linux/</guid>
<pubDate>Fri, 15 May 2026 15:41:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 27x - Views:350 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/_xWf9TfRpjM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video erklärt Jean, was hinter dem angepassten Release-Zyklus von Linux Mint steckt und wie die Verzögerung von Mint 23 einzuordnen ist. Ist Mint auch in 2026 noch eine empfehlenswerte Linux-Distro?<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Meine Probleme mit CachyOS: https://youtu.be/7aJTAGnFHCI https://youtu.be/gr0iAHYkqpg<br />
- Ubuntu 26.04 angeschaut: https://youtu.be/N86gHr5Z3Ng<br />
- Linux Mint News Blog: https://blog.linuxmint.com/?p=5019<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Intro<br />
01:34 Änderung im Release-Zyklus<br />
06:48 Mint mit neuer Hardware<br />
10:15 Wayland-Problematik<br />
16:11 Highlights und Schwächen von Mint<br />
20:38 Blick zur Konkurrenz<br />
25:13 Empfehlung für Linux-Einsteiger<br />
28:05 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linuxmint #opensource #linuxdistro<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Southeast Asia’s AI boom has a power problem — and it’s being underestimated]]></title>
<description><![CDATA[Southeast Asia’s AI surge is accelerating but power constraints may define its limits.]]></description>
<link>https://tsecurity.de/de/3517040/it-nachrichten/southeast-asias-ai-boom-has-a-power-problem-and-its-being-underestimated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517040/it-nachrichten/southeast-asias-ai-boom-has-a-power-problem-and-its-being-underestimated/</guid>
<pubDate>Thu, 14 May 2026 16:32:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Southeast Asia’s AI surge is accelerating but power constraints may define its limits.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026]]></title>
<description><![CDATA[In 2026, opportunistic assaults and isolated breaches will no longer characterize Australia's cyber risk environment. Industrialized data theft, in which stolen data is packaged, repackaged, and marketed on underground marketplaces, is influencing it. 


Threat actors are already combining Austra...]]></description>
<link>https://tsecurity.de/de/3516243/it-security-nachrichten/why-australian-dark-web-data-is-now-being-sold-in-bundles-and-what-it-means-for-organizational-exposure-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516243/it-security-nachrichten/why-australian-dark-web-data-is-now-being-sold-in-bundles-and-what-it-means-for-organizational-exposure-in-2026/</guid>
<pubDate>Thu, 14 May 2026 11:35:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1440" height="720" src="https://cyble.com/wp-content/uploads/2026/05/Australian-dark-web-data.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Australian dark web data" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/05/Australian-dark-web-data.png 1440w, https://cyble.com/wp-content/uploads/2026/05/Australian-dark-web-data-300x150.png 300w, https://cyble.com/wp-content/uploads/2026/05/Australian-dark-web-data-1024x512.png 1024w, https://cyble.com/wp-content/uploads/2026/05/Australian-dark-web-data-768x384.png 768w" sizes="(max-width: 1440px) 100vw, 1440px" title="Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026 1"></p>
<p><!-- wp:paragraph --></p>
<p>In 2026, opportunistic assaults and isolated breaches will no longer characterize Australia's cyber risk environment. Industrialized data theft, in which stolen data is packaged, repackaged, and marketed on underground marketplaces, is influencing it. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Threat actors are already combining Australian data into composite "breach packages," increasing both its commercial worth and its downstream danger, as opposed to single-company breaches occurring in isolation. This trend is also intensifying concerns around <a href="https://cyble.com/blog/australian-dark-web-cybercrime-threats-2025/" target="_blank" rel="noreferrer noopener">Australian dark web</a> data, where aggregated breach packages are increasingly traded and monetized. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This move has a direct impact on how exposed enterprises will be in 2026 and is not merely cosmetic; rather, it represents a structural shift in how <a href="https://cyble.com/knowledge-hub/who-is-a-cybercriminal/" target="_blank" rel="noreferrer noopener">cybercriminal</a> ecosystems monetize stolen information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why are Australian dark web data breaches increasing?</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Australian cyber events have sharply increased, according to Cyble <a href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noreferrer noopener">cyber threat intelligence</a> monitoring. 71 publicly reported data breaches involving Australian companies were found between January and early October 2025. Compared to the 48 breaches that were reported at the same time in 2024, that is a 48% increase. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The overall trend is even more telling: 71 breaches in 2025 have already surpassed the 66 Australian breaches that were reported in 2024. This suggests that the year is structurally exceeding previous standards rather than just drifting upward. The rapid escalation in both the number and severity of every major data breach Australia has experienced indicates a maturing underground economy centered on stolen information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble reported 1,684 occurrences of reported data breaches worldwide in 2025, an 18% increase. In light of this, Australia's more rapid growth stands out as being disproportionately severe rather than a component of a global increase. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It is crucial to remember that these numbers only include occurrences that have been reported to the public. Since many breaches never appear on forums or leak sites, the actual exposure baseline is probably much greater. This means the scale of the current Australian data breach landscape may still be underestimated. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why “Bundled Data” Has Become the New Trade Standard</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The packaging of stolen Australian data into bundled datasets is one of the most significant developments in underground markets. <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noopener" title="What is a Cyber Threat Actor? Types of Threat Actors" data-wpil-keyword-link="linked" data-wpil-monitor-id="32378">Threat actors</a> are progressively combining several datasets into composite offerings rather than selling a single breach per victim organization. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Bundled data is easier to monetize, which provides a straightforward economic explanation for this practice. It enables cybercriminals to: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Combine data from several organizations to increase resale value  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Attract a larger range of purchasers (ransomware affiliates, fraud groups, and access brokers)  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Cut down on the time spent promoting specific violations  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Bundling also indicates maturity in the <a href="https://cyble.com/knowledge-hub/what-is-a-supply-chain-attack/" target="_blank" rel="noreferrer noopener">supply chain</a> for cybercrime from an operational perspective. Data is now curated rather than just stolen. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This implies that an organization's security posture is no longer the only factor influencing exposure. One vendor or partner's data may unintentionally be included in a larger selling bundle with unrelated victims due to a breach. This is one reason why modern <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark web</a> data breach operations are becoming more difficult to contain once information is leaked. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Ransomware Groups Are Driving the Acceleration</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The prevalence of ransomware-related entities is a significant contributing element to Australia's breach rise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Ransomware groups were responsible for around half of the 71 breaches that were discovered in 2025. This indicates a change in attribution from around 42% of Australian violations in 2024 to approximately 71% in 2025. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This modification shows how ransomware tactics have evolved. Data theft is becoming more important to groups than encryption. Even if encryption is never used, attackers exfiltrate sensitive data before using it for extortion or resale, rather than depending only on locking measures. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This dual-use approach feeds directly into the bundling ecosystem. Stolen datasets become modular assets that can be repackaged across multiple campaigns, contributing to the growing volume of dark web <a href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noreferrer noopener">data breaches</a> impacting Australian organizations. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Supply Chain Attacks Expand the Blast Radius</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The increase in supply chain compromise is another significant factor. Attackers are taking advantage of third-party providers' laxer security measures rather than going after companies directly. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This has a domino effect: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Numerous downstream companies may be exposed by a single hacked vendor  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unintentionally, data from unrelated victims is combined  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Attack surfaces extend beyond the impacted enterprise's direct control  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This is one of the main ways that bundled data sales are made possible. Multi-organization datasets are inevitably created by supply chain breaches, consolidated, and resold. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Sector Exposure: No Industry Left Untouched</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Australian breaches in 2025 have impacted a wide range of industries, including: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Professional services  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Information technology  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Healthcare  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Energy and utilities  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Banking and financial services  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Education  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Construction and real estate  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Telecommunications  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Transportation and hospitality  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Manufacturing  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of targeting highlights a key reality: attackers are no longer selecting industries solely based on prestige or financial value. Instead, any organization with usable data, operational leverage, or weak third-party dependencies becomes a viable target. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Notable Incidents Highlight the Scale of Exposure</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Several incidents in 2025 illustrate the depth and variety of compromised data: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A threat actor operating via a private Telegram channel claimed access to approximately 2TB of sensitive documents allegedly belonging to a major Australian airline  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A telecommunications-related database containing around 236,000 records reportedly included names, emails, passwords, phone numbers, billing details, and payment data  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A SaaS provider offering loan management and digital signing tools reportedly had its source code exposed, including authentication systems, APIs, and administrative modules  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>An ICT and telecommunications provider breach allegedly exposed financial records and internal databases, claimed by an extortion group  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>In construction, 71GB of engineering and infrastructure files were advertised, including geotechnical reports and safety documentation  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A trading platform breach reportedly exposed 27,000 records containing KYC data, user identities, and transaction histories  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Pension funds were impacted through credential reuse attacks that enabled unauthorized account access and financial losses  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Energy and logistics systems were affected by leaks involving millions of operational files from petroleum distribution and internal logistics networks  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Across these incidents, one pattern stands out: attackers are extracting structured, high-value data sets that can be reused, recombined, and resold. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why Australia Is in the Crosshairs</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The increase in targeting can be explained by several structural factors: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>First, <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> and data extortion groups find Australian companies appealing because they are very data-driven and technologically advanced. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Second, systemic exposure is increased by reliance on outside service providers. One provider's security flaws can spread throughout large ecosystems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Third, the cost of starting large-scale campaigns is being reduced by attackers using sophisticated tools, such as automation and AI-assisted phishing. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lastly, Australia's widespread use of digital technology raises the attack surface and data accessibility. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Defensive Shifts Required for 2026</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Organizations are being forced to adopt intelligence-driven security solutions due to the shifting threat landscape. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Risk-based vulnerability management, which concentrates remedial efforts on actively exploited vulnerabilities rather than theoretical problems, is becoming important. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>To protect against credential-based assaults, which are commonly employed in supply chain and ransomware incursions, multi-factor authentication is becoming a standard requirement. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>To identify vulnerability outside of their immediate surroundings, organizations are also improving their supply chain risk assessments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>To combat contemporary threats like AI-generated phishing, deepfake impersonation, and automated <a href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noreferrer noopener">social engineering</a> efforts, security awareness programs are changing. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Behavioral analytics and AI-driven detection systems are becoming more and more important at the infrastructure level to find anomalies that conventional monitoring tools overlook. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lastly, as businesses shift from implicit trust to continuous verification models, Zero Trust architectures are becoming more popular. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Role of Intelligence-Led Defense Platforms</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Platforms such as those developed by Cyble reflect a broader shift toward real-time, intelligence-led security operations. Their approach combines <a href="https://cyble.com/solutions/dark-web-monitoring/" target="_blank" rel="noreferrer noopener">dark web monitoring</a>, <a href="https://cyble.com/knowledge-hub/what-is-external-attack-surface-management/" target="_blank" rel="noreferrer noopener">external attack surface</a> visibility, <a href="https://cyble.com/knowledge-hub/vulnerability-intelligence-explained/" target="_blank" rel="noreferrer noopener">vulnerability intelligence</a>, and <a href="https://cyble.com/en-eu/endpoint-security-solutions-in-europe/" target="_blank" rel="noreferrer noopener">endpoint compromise</a> detection. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While such systems vary in implementation, the broader trend is clear: security teams are moving away from static defense models toward continuous monitoring of external threat ecosystems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This shift is especially relevant in environments where stolen data is rapidly aggregated and resold, making early detection of exposure more valuable than post-incident response. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Bundling Is the New Exposure Multiplier</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The 48% increase in Australian data breaches highlights a major shift in cybercrime operations. Stolen data is no longer traded in isolation — cybercriminals are bundling, repackaging, and reselling Australian dark web data across larger underground ecosystems, increasing exposure for multiple organizations at once.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For the upcoming years, organizations must focus not only on preventing breaches but also on understanding how stolen data is reused and monetized after exfiltration. With AI-native threat intelligence, dark web monitoring, and <a class="wpil_keyword_link" href="https://cyble.com/solutions/attack-surface-management/" target="_blank" rel="noopener" title="Attack Surface Management" data-wpil-keyword-link="linked" data-wpil-monitor-id="32377">attack surface management</a>, Cyble helps organizations identify exposed data, detect emerging threats, and strengthen cyber resilience.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Want to see the intelligence behind the data in this report or learn how Cyble can help protect your organization?</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Schedule a <strong><a href="https://cyble.com/request-demo/">personalized demo</a></strong> with Cyble today.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/australian-dark-web-data-breaches/">Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nach LiMux: München wagt zweiten Anlauf mit Open-Source-Software]]></title>
<description><![CDATA[Die neue Münchner Regierung plant einen umfassenden IT-Umbau. Nach Jahren der Microsoft-Nutzung soll Open Source wieder der Standard in der Verwaltung werden. Der Fokus liegt dabei auf digitaler Unabhängigkeit aber auch auf Kostensenkungen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3516242/it-security-nachrichten/nach-limux-muenchen-wagt-zweiten-anlauf-mit-open-source-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516242/it-security-nachrichten/nach-limux-muenchen-wagt-zweiten-anlauf-mit-open-source-software/</guid>
<pubDate>Thu, 14 May 2026 11:35:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158694.html"><img hspace="5" border="0" align="left" alt="Open Source, Sourcecode, Opensource, Source Code, Open Source Software, Quelloffen, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56865.jpg"></a>
			Die neue Münchner Regierung plant einen umfassenden IT-Umbau. Nach Jahren der Microsoft-Nutzung soll <a href="https://winfuture.de/special/open-source/" title="Open Source Special">Open Source</a> wieder der Standard in der Verwaltung werden. Der Fokus liegt dabei auf digitaler Unabhängigkeit aber auch auf Kostensenkungen.			(<a href="https://winfuture.de/news,158694.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Fired employee sought AI help to hide deletion of hosting firm’s customer data]]></title>
<description><![CDATA[The apparent revenge deletion of US federal databases after the dismissal of twin brothers from an online hosting company is another reminder to IT and HR leaders that tough off-boarding procedures have to be implemented to prevent insider attacks.



Destructive attacks either from disgruntled c...]]></description>
<link>https://tsecurity.de/de/3515306/it-security-nachrichten/fired-employee-sought-ai-help-to-hide-deletion-of-hosting-firms-customer-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515306/it-security-nachrichten/fired-employee-sought-ai-help-to-hide-deletion-of-hosting-firms-customer-data/</guid>
<pubDate>Thu, 14 May 2026 01:37:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The apparent revenge deletion of US federal databases after the dismissal of twin brothers from an online hosting company is another reminder to IT and HR leaders that tough off-boarding procedures have to be implemented to prevent insider attacks.</p>



<p>Destructive attacks either from disgruntled current or former employees <a href="https://www.csoonline.com/article/4143393/the-insider-threat-rises-again.html" target="_blank">aren’t new</a>. But the <a href="https://www.justice.gov/opa/pr/federal-jury-convicts-virgina-man-charges-relating-deletion-us-government-databases" target="_blank" rel="noreferrer noopener">conviction by a Virginia jury last week</a> of one of the brothers raises a number of issues that IT pros and CEOs have to keep in mind.</p>



<p>A federal jury convicted Sohaib Akhter, 34, of Alexandria, Virgina, on charges of conspiracy to commit computer fraud, password trafficking, and possession of a firearm by a prohibited person. He will be sentenced in September. And last month his brother, Muneeb, signed an agreed statement of facts about the siblings’ activities in response to several charges against him. But according to <a href="https://www.courtlistener.com/docket/71989485/united-states-v-akhter/" target="_blank" rel="noreferrer noopener">documents from the case</a> provided on the Free Law Project’s archive of court data, The Court Listener, Muneeb is now trying to have the charges dismissed.</p>



<p>Still, the incident has led one expert, <a href="https://www.linkedin.com/in/rob-enderle-03729/" target="_blank" rel="noreferrer noopener">Robert Enderle</a> of the Enderle Group, to say, “it should serve as a wake-up call: Organizations must not only tighten their internal controls, but also begin accounting for how AI tools can be weaponized against them, and these AI tools need far stronger guardrails than they currently have.”</p>



<h2 class="wp-block-heading">The statement of facts</h2>



<p>According to the statement of facts Muneeb agreed to, but now disputes, he and his brother, Sohaib, worked for an unnamed company in Washington, DC that provided software and services to more than 45 US government agencies, including hosting data for some federal clients. They included the US Equal Employment Opportunity Commission (EEOC), Homeland Security, and the Internal Revenue Service (IRS).</p>



<p>On Feb 18, 2025, both brothers were terminated by the company after it discovered Sohaib had been convicted nine years earlier of a felony. After the firing, they both allegedly tried to harm their former employer by accessing computers without authorization, deleting databases and destroying evidence of their work. In his statement of facts this year, Muneeb admitted to deleting 96 databases.</p>



<p>How? While five minutes after they were fired in 2025, Sohaib’s VPN was disconnected and he lost access to the hosting provider, his brother still had access. The brothers also still had their company-issued laptops. They went to work.</p>



<p>As part of their alleged destructive work, when Muneeb didn’t know the database commands necessary to accomplish his goals, he used an AI tool to help him, asking “how do I clear system logs from SQL servers after deleting databases” and later, “how do you clear all event and application logs from Microsoft Windows Server 2012.” The agreed statement of facts doesn’t make it clear, but presumably the AI tool was a public chatbot.</p>



<p>In the statement of facts, Muneeb agreed he stole copies of IRS information on a virtual machine that included federal tax information of 450 people.</p>



<p>Muneeb also admitted that between May and December 2025, he committed fraud and stole credentials for the EEOC public portal in an attempt to access email and other online accounts of 4,500 people. In hundreds of instances, he successfully logged into victims’ email accounts without their authorization.</p>



<h2 class="wp-block-heading">State of insider attacks</h2>



<p>According to the <a href="https://www.mimecast.com/resources/ebooks/state-of-human-risk/" target="_blank" rel="noreferrer noopener">State of Human Risk Report</a> from Mimecast, 42% of organizations have experienced an increase in malicious insider incidents over the past year, with 42% also reporting a rise in negligent incidents for the first time.</p>



<p><a href="https://ponemon.dtex.ai/" target="_blank" rel="noreferrer noopener">A report this year</a> by the Ponemon Institute on the costs of insider risks, commissioned by insider threat detection provider DTEX, estimated incidents cost organizations an average of $19.5 million last year, up from $17.4 million in 2024.</p>



<p>The biggest cause of losses last year (53%) was negligence and mistakes, it said. The second biggest cause, however, was malicious activity (27%).</p>



<p><a href="https://www.linkedin.com/in/musa-ishaq-a21007b4/" target="_blank" rel="noreferrer noopener">Musa Ishaq</a>, senior principal insider threat analyst at DTEX, said last week’s conviction “is a clear and sobering reminder that termination is not the end of risk. In many cases, it is the beginning of it.”</p>



<p>The off-boarding moment “is one of the most dangerous windows in any organization’s security posture,” he said, “and it remains one of the most underestimated. Every departing employee, whether they leave willingly or are terminated, represents a live risk event that must be treated in real time. That means immediate access revocation, active session termination, and active monitoring, not a checklist completed the following day. When those steps fail, or when even a single access pathway is left open, the consequences can be catastrophic, as this case demonstrates.”</p>



<h2 class="wp-block-heading">‘AI didn’t give attackers a new capability’</h2>



<p>Equally important, he added, is what this case reveals about AI’s role in accelerating insider threats. “AI did not give them a new capability; they already had the access and the intent. What it did was compress their decision cycle, turning what might have taken several minutes of research into seconds of execution. The new threat reality is that AI does not create malicious insiders, but it dramatically amplifies what they can accomplish before defenders are able to respond.”</p>



<p>As a result, organizations have to shift to proactive and risk-adaptive security approaches, Ishaq said. A privileged user querying an AI tool through a company owned or controlled computer for log evasion techniques while simultaneously executing destructive commands on production servers is an escalation signal, he said. “Behavioral visibility, not just technical controls, is what enables security teams to detect that pattern and act before deletion becomes destruction,” he said.</p>



<p>“This case is a preview of what insider threats look like in an AI-enabled world in terms of being faster, harder to trace, and far more consequential when governance gaps exist,” he said. “As such, the fundamentals, including strict access control, real-time off-boarding protocols, and layered monitoring of privileged users, have never been more critical.”</p>



<h2 class="wp-block-heading">‘Textbook example’ of need to re-think processes</h2>



<p>Enderle agreed. He said this incident “is a textbook example of why we need to rethink the speed and process of our off-boarding processes. The fact that a former employee was able to access and delete government databases post-termination highlights a massive failure in basic access control. In a modern enterprise, access revocation needs to be instantaneous, automatic, and comprehensive; any gap between a firing and a lockout is a window for significant liability.”</p>



<p>The most disturbing aspect, he added, is the role AI played. “Using an AI tool to solicit instructions on clearing system logs is a clear signal that the barrier to entry for sophisticated digital sabotage is dropping,” Enderle said. “We are entering an era where AI can act as a force multiplier for malicious intent, making it easier for individuals to cover their tracks. Even AI protections can be bypassed. I saw a demonstration on YouTube the other day where a user just re-asked a question to a public AI site on preparing a bomb until the AI gave up saying ‘No,’ and provided the answer.”</p>



<p>Queries like ‘How to clear SQL logs’ have legitimate administrative purposes, he acknowledged. But, he added, AI providers must move beyond simple keyword filtering and implement intent-aware guardrails that can identify attack chains.</p>



<p>“When a sequence of prompts moves from technical curiosity to a roadmap for destroying evidence and obfuscating logs, the AI should recognize the malicious context and refuse the request, Enderle argued.</p>



<p>“Ultimately,” he warned, “if AI providers don’t take responsibility for preventing their platforms from becoming a ‘How-to’  manual for criminal activity, they risk a regulatory backlash and potential civil and criminal liability that could stifle the very innovation they are trying to promote.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cesium - der 3D-Globus im Web (fossgis2015)]]></title>
<description><![CDATA[Cesium ist ein performantes und interoperables Tool für die Visualisierung von Daten im dreidimensionalen Kontext. Stichworte zum Vortrag: 3D - JavaScript - Open Source - WebGL - Zeitabhängige Darstellung - OGC Standards - Openlayers 3 API - Demos und Beispiele.

Mit der JavaScript Programmbiblio...]]></description>
<link>https://tsecurity.de/de/3515193/it-security-video/cesium-der-3d-globus-im-web-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515193/it-security-video/cesium-der-3d-globus-im-web-fossgis2015/</guid>
<pubDate>Thu, 14 May 2026 00:17:51 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cesium ist ein performantes und interoperables Tool für die Visualisierung von Daten im dreidimensionalen Kontext. Stichworte zum Vortrag: 3D - JavaScript - Open Source - WebGL - Zeitabhängige Darstellung - OGC Standards - Openlayers 3 API - Demos und Beispiele.

Mit der JavaScript Programmbibliothek Cesium kann ein 3D-Globus für das Web erstellt werden, ohne dass für die Visualisierung Plugins gebraucht werden. Cesium benutzt WebGL und unterstützt ausserdem OGC-Standards wie WMS oder WMTS. Dies macht es zu einem performanten und interoperablen Tool für die Visualisierung von Daten im dreidimensionalen Kontext.

Die Präsentation stellt das Cesium.js Projekt vor und möchte folgende Fragen beantworten:
- Ein Opensource 3D Globus - was kann Cesium?
- Performante mehrdimensionale Visualisierung im Web - was steckt dahinter?
- 3D ist überall - wo wird Cesium eingesetzt?

Ausserdem wird die Kombination von Openlayers3 mit Cesium vorgestellt und ein Ausblick über die nächsten Entwicklungen gegeben.
about this event: https://fossgis-konferenz.de/2015/programm/events/857.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[3D GIS Stack aus OpenSource Komponenten (fossgis2015)]]></title>
<description><![CDATA[In den letzten Jahren hat die dritte Dimension auch Einzug in den gängigen FOSSGIS Lösungen (PostGIS, QGIS, OpenLayers etc.) gehalten, so dass mittlerweile ein kompletter 3D-GIS-Stack aus OpenSource Lösungen realisiert werden kann. Das wichtigste Ziel der hier vorgestellten Projekte ist die Inter...]]></description>
<link>https://tsecurity.de/de/3515192/it-security-video/3d-gis-stack-aus-opensource-komponenten-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515192/it-security-video/3d-gis-stack-aus-opensource-komponenten-fossgis2015/</guid>
<pubDate>Thu, 14 May 2026 00:17:50 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In den letzten Jahren hat die dritte Dimension auch Einzug in den gängigen FOSSGIS Lösungen (PostGIS, QGIS, OpenLayers etc.) gehalten, so dass mittlerweile ein kompletter 3D-GIS-Stack aus OpenSource Lösungen realisiert werden kann. Das wichtigste Ziel der hier vorgestellten Projekte ist die Interaktion mit 3D-Webkarten. Der Anwender soll in der Lage sein, mit den 3D-Modellen über das Web arbeiten zu können und sie nicht nur zu betrachten.

Derzeit gibt es einen kleinen Hype um 3D Web-Viewer mit WebGL-Unterstützung. Immer mehr Softwarefimen bieten eigene Lösungen an, die häufig auf offen verfügbaren Engines wie etwa Cesium [1] oder OpenWebGlobe [2] basieren. WebGL-Viewer benötigen keine clientseitigen Plugins und funktionieren auf vielen Endgeräten. Sie laufen auch ohne High-End-Ausstattung sehr schnell und erlauben ein flüssiges interaktives Bewegen durch eine 3D Szene. 

Plattformen mit vielen detaillierten volltexturierten Objekten, wie etwa 3D-Stadtmodelle (damit sind keine texturierten Oberflächenmodelle von Städten gemeint), müssen zwar derzeit noch mit stärkeren Performanceeinschränkungen leben, durch die rasant steigende Anzahl an Entwicklern und Anwendern von WebGL sollte dieser Engpass aber bald der Vergangenheit angehören. Aus demselben Grund dürften zunehmend auch freie Viewer in den derzeit von prorietären Angeboten dominierten Markt drängen. 

Einen Anfang macht Cuardo [3] – eine OpenSource JavaScript-Bibliothek basierend auf THREE.js und WebGL. Cuardo wird von der französischen Firma Oslandia entwickelt, die sich auch verantwortlich zeigt für den 3D-Support in PostGIS und ein 3D-Plugin für QGIS namens Horao [4]. Oslandia hat das Ziel einen kompletten 3D-GIS-Stack von der Datenbank bis zur Webvisualisierung zu realisieren. Datenbank-seitig wird u.a. die 3D City Database [5] eingesetzt, eine OpenSource-Lösung zum Speichern von CityGML-basierten 3D Stadt- und Landschaftsmodellen in PostGIS. 

Seit der neusten Version der 3D City Database steht eine WFS-Schnittstelle (Simple) zur Verfügung, die Viewern wie Cuardo die Möglichkeit bietet, Inhalte der Datenbank abzurufen, ohne das spezifische Abfragen gegen das zugrunde liegende Datenbankschema notwendig sind. Der Client muss nur den WFS 2.0-Standard des OGC unterstützen. Für die Zukunft ist geplant, das neben einer vollen Unterstützung des OGC Filter Encoding auch Transaktionen mit dem WFS möglich sein werden. 

Das wichtigste Ziel der hier vorgestellten Projekte ist die Interaktion mit 3D-Webkarten. Der Anwender soll in der Lage sein, mit den 3D-Modellen über das Web arbeiten zu können und sie nicht nur zu betrachten. Der momentane Wirbel um WebGL erhöht nicht nur die Aufmerksamkeit für 3D-Webmapping, er schürt auch Erwartungen an ein 3D-WebGIS, das seinem 2D-Pendant in nichts nach steht.
about this event: https://fossgis-konferenz.de/2015/programm/events/868.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Der schwere Werdegang zu einem FOSSGIS-Open Source Projekt (fossgis2015)]]></title>
<description><![CDATA[OpenSource machen ist einfach. Ein bisschen Code geschrieben, einen schicken Lizenz-Header oben drüber gepastet und ab damit auf Git oder eine andere hippe Plattform. Aber damit ist es dann meistens doch nicht getan. Der Vortrag beschreibt warum.

OpenSource-Projekte, natürlich nicht nur im FOSSG...]]></description>
<link>https://tsecurity.de/de/3515146/it-security-video/der-schwere-werdegang-zu-einem-fossgis-open-source-projekt-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515146/it-security-video/der-schwere-werdegang-zu-einem-fossgis-open-source-projekt-fossgis2015/</guid>
<pubDate>Thu, 14 May 2026 00:03:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenSource machen ist einfach. Ein bisschen Code geschrieben, einen schicken Lizenz-Header oben drüber gepastet und ab damit auf Git oder eine andere hippe Plattform. Aber damit ist es dann meistens doch nicht getan. Der Vortrag beschreibt warum.

OpenSource-Projekte, natürlich nicht nur im FOSSGIS Umfeld, leben von Ihrer aktiven Community, sie leben davon, dass sie möglichst wenig „Stallgeruch“ einer Firma haben, dass sie an vielen Stellen zum Einsatz kommen und in aller Munde sind. Dies alles sind Schritte, die ein Projekt durchlaufen muss. Dazu kommt die Co-Existenz und eine Art von positivem Wettstreit mit anderen Projekten, die vielleicht sehr ähnliches tun. Weiterhin zu nennen wären auch unbezahlte Aufwände für Homepage, Dokumentation, Übersetzungen, PSC und und und…

Der Vortrag widmet sich dem Prozess hin zu einem „echten“ OpenSource-Projekt. Aufgezeigt wird dies an verschiedenen Beispielen. Oft fangen Open Source Projekte auf Basis von mehreren Entwicklungen an und werden langsam zu einem OpenSource-Projekt entwickelt. Warum das schwierig ist, wird im Vortrag erläutert. Dazu wird das Dilemma dargestellt, in das eine Firma zwangsläufig hineinläuft, nämlich die Balance zwischen Projektarbeit und OpenSource-Projekt zu finden. In diesem Zusammenhang werden auch strategische Entscheidungen, die in den vorgestellten Beispiel-Projekten gelaufen sind, vorgestellt und Ihre Wirkung auf das OpenSource-Projekt projiziert.
about this event: https://fossgis-konferenz.de/2015/programm/events/849.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Automatisiertes Geodatenmanagement mit  GeoKettle (fossgis2015)]]></title>
<description><![CDATA[Dieser Vortrag stellt verschiedene Einsatzmöglichkeiten der freien ETL-Software GeoKettle vor. GeoKettle ist die Open Source-Alternative zur verbreiteten Software "FME" und kann nicht nur Geodatenformate konvertieren, sondern beispielsweise auch Objekte verteilen und zusammenfassen, redundante Da...]]></description>
<link>https://tsecurity.de/de/3515078/it-security-video/automatisiertes-geodatenmanagement-mit-geokettle-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515078/it-security-video/automatisiertes-geodatenmanagement-mit-geokettle-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:31:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dieser Vortrag stellt verschiedene Einsatzmöglichkeiten der freien ETL-Software GeoKettle vor. GeoKettle ist die Open Source-Alternative zur verbreiteten Software &quot;FME&quot; und kann nicht nur Geodatenformate konvertieren, sondern beispielsweise auch Objekte verteilen und zusammenfassen, redundante Daten finden oder Prozesse in einer grafischen Oberfläche modellieren.

WhereGroup GmbH &amp; Co. KG 

Abstract

GeoKettle
GeoKettle ist ein ETL-Programm für räumliche Daten. ETL steht für Extract, Load und Transform. GeoKettle basiert auf der OpenSource Software Pentaho Data Integration (Kettle) und ist mit der LPGL lizensiert. GeoKettle unterstützt dabei u.a. die OpenSource Bibliotheken GeoTools, Degree und gdal/ogr und sextante. Es kann als OpenSource-Alternative für die FME eingesetzt werden und bietet vielfältige Einsatzmöglichkeiten.
Während des Vortrags werden einige Einsatzmöglichkeiten und Funktionen von GeoKettle vorgestellt, um dem Auditorium einen Einblick in die Leistungsfähigkeit von Geokettle zu geben. Zu den Funktionalitäten gehören:
Import verschiedener (Geo-)Datenformate
Verteilen von Objekten in einem Shapefile auf mehrere Tabellen
Zusammenfassen von Objekte aus mehreren Shapefiles mit unterschiedlichen Attributfeldern in einer Tabelle
Veränderung von Attributen
Entfernen von redundanten Daten
Benutzten des graphischen Benutzeroberfläche zur Modellierung von Prozessen.
Benutzen der Shellskripte zur automatisierten Verwendung von GeoKettle über cronjobs
...
about this event: https://fossgis-konferenz.de/2015/programm/events/856.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[WPS, GeoServer und SHOGun (fossgis2015)]]></title>
<description><![CDATA[Der Vortrag stellt die Erweiterung des SHOgun Frameworks als WPS-CLient dar. Als WPS Server kommt der GeoServer-WPS zum Einsatz. Der Vortrag wird zum einen kurz die Mechanismen des WPS erläutern, die Einbindung in das SHOGun Framework an praktischen Beispielen zeigen und am Ende die Möglichkeiten...]]></description>
<link>https://tsecurity.de/de/3515075/it-security-video/wps-geoserver-und-shogun-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515075/it-security-video/wps-geoserver-und-shogun-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:31:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Vortrag stellt die Erweiterung des SHOgun Frameworks als WPS-CLient dar. Als WPS Server kommt der GeoServer-WPS zum Einsatz. Der Vortrag wird zum einen kurz die Mechanismen des WPS erläutern, die Einbindung in das SHOGun Framework an praktischen Beispielen zeigen und am Ende die Möglichkeiten, die sich daraus für ein WebGIS ergeben, vorstellen. Das Prinzip eines WPS wird vorgestellt und die Umsetzung innerhalb von SHOGun gezeigt, Stärken, Potentiale, aber auch Schwächen oder mögliche Begrenzungen werden gezeigt.

SHOGun ist ein OpenSource WebGIS Framework, das bereits auf den letzten FOSSGIS Konferenzen vorgestellt wurde.

In der derzeitigen Version bietet SHOGun die Möglichkeit aus einer Installation Layer aus verschiedenen Kartendiensten, WebGIS-Oberflächen und Benutzer zu verwalten, WMS und WFS-Dienste abzusichern sowie darüber hinaus viele Webschnittstellen über Mittel des Frameworks Java Spring zur Verfügung zu stellen. SHOGun ist somit eine mächtige, datenbankunabhängige Middleware, die in großen Verwaltungen ein komplettes GIS ersetzt.

Der WebGIS-Client zeichnet sich durch eine Fülle an Funktionen aus, die weit über den normalen Funktionsumfang eines WebGIS hinaus gehen. Dennoch erfordert jede funktionale Erweiterung bisher eine entsprechende Programmierung in SHOGun. Aus diesem Grunde wurde für die Wasserwirtschafts-Verwaltung Rheinland-Pfalz SHOGun um eine Web Processing Service (WPS) Client-Schnittstelle erweitert. Da SHOGun ohnehin in der Lage ist, GeoServer über seine REST-API anzusprechen, wurde auch der GeoServer WPS verwendet. Über die Verwaltungsoberfläche von SHOGun lassen sich einzelne oder verkettete WPS-Prozesse in einen WebGIS-Clienten einbinden. Damit ist eine funktionale Erweiterung mittels Konfiguration über die Oberfläche möglich. Zur Ergebnisverarbeitung stellt SHOGun wiederum verschiedene Methoden und Funktionen bereit. 
Selbstverständlich hat die Implementierung Einschränkungen, dies alleine aufgrund der de facto unbegrenzten Möglichkeiten, die die WPS-Spezifikaiton bietet.

Der Vortrag stellt das Prinzip eines WPS vor und die Umsetzung innerhalb von SHOGun, zeigt Stärken, Potentiale, aber auch Schwächen oder mögliche Begrenzungen auf.
about this event: https://fossgis-konferenz.de/2015/programm/events/848.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoServer in action (fossgis2015)]]></title>
<description><![CDATA[GeoServer in action - Der Vortrag fokussiert sich weniger auf die "Out-of-the-box"-Verwendung des GeoServers, sondern beleuchtet vielmehr fortgeschrittene Möglichkeiten beim Einsatz dieser Software. Es geht um Kompilieren, Schnittstellenverwendung, Extensions, Performance-Tuning, GeoWebCache-Eins...]]></description>
<link>https://tsecurity.de/de/3515058/it-security-video/geoserver-in-action-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515058/it-security-video/geoserver-in-action-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:18:06 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GeoServer in action - Der Vortrag fokussiert sich weniger auf die &quot;Out-of-the-box&quot;-Verwendung des GeoServers, sondern beleuchtet vielmehr fortgeschrittene Möglichkeiten beim Einsatz dieser Software. Es geht um Kompilieren, Schnittstellenverwendung, Extensions, Performance-Tuning, GeoWebCache-Einsatz, Troubleshooting und Stolperfallen.

Der GeoServer ist ein weithin bekannter und mächtiger OpenSource Kartenserver. Sofern man die Umgebung eingerichtet hat, ist sowohl die Installation als auch die Konfiguration von ersten WMS- und WFS-Layern sehr einfach. In diesem Vortrag wird auf die typischen Anforderungen eines &quot;GeoServers in action&quot; eingegangen. Der Vortrag fokussiert sich also weniger auf die &quot;Out-of-the-box&quot;-Verwendung des GeoServers, sondern beleuchtet vielmehr fortgeschrittene Möglichkeiten beim Einsatz dieser Software.

In diesem Rahmen werden u.a. folgende Themen behandelt:
* GeoServer auf Basis des Source-Codes selber kompilieren
* Verwendung der REST-Schnittstelle
* Einsatz des GeoWebCache (GWC)
* GeoServer Extensions
* Performance-Tuning für den Produktiveinsatz auf verschiedenen Ebenen
* Typische Stolperfallen und Troubleshooting

Der Vortrag richtet sich an Entwickler, Anwender und Interessierte.
about this event: https://fossgis-konferenz.de/2015/programm/events/842.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Mapnik oder MapServer (fossgis2015)]]></title>
<description><![CDATA[Mit Mapnik und MapServer stehen zwei OpenSource Kartenrenderer zur Verfügung, die in Geschwindigkeit, Funktionsumfang und Bildqualität kaum Wünsche übrig lassen. Aber welche Software nehme ich für mein Projekt?

Mit Mapnik und MapServer stehen zwei OpenSource Kartenrenderer zur Verfügung, die in ...]]></description>
<link>https://tsecurity.de/de/3515008/it-security-video/mapnik-oder-mapserver-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515008/it-security-video/mapnik-oder-mapserver-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:03:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Mapnik und MapServer stehen zwei OpenSource Kartenrenderer zur Verfügung, die in Geschwindigkeit, Funktionsumfang und Bildqualität kaum Wünsche übrig lassen. Aber welche Software nehme ich für mein Projekt?

Mit Mapnik und MapServer stehen zwei OpenSource Kartenrenderer zur Verfügung, die in Geschwindigkeit, Funktionsumfang und Bildqualität kaum Wünsche übrig lassen. Aber welche Software nehme ich für mein Projekt?

Der Vortrag geht auf die kleinen und großen Unterschiede zwischen Mapnik und MapServer ein.
Für welche Einsatzzwecke ist MapServer besser geeignet? Was kann Mapnik besonders gut? Wie können die Renderer in Anwendungen und Server integriert werden? Gibt es überhaupt nennenswerte Unterschiede?

Der Vortrag zeigt ausserdem anhand von Beispielen, welche Software das bessere Kartenbild liefert und welche Verbesserungen von den zukünftigen Versionen Mapnik 3 und MapServer 7 zu erwarten sind.
about this event: https://fossgis-konferenz.de/2015/programm/events/851.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoExt (fossgis2015)]]></title>
<description><![CDATA[Der Vortrag stellt die neueste Version von GeoExt vor und zeigt auf, welches Handwerkszeug dem Entwickler hier bereitsgestellt wird. Unterschiede zwischen ExtJS und anderen Bibliotheken werden benannt, dies kann als Diskussionsgrundlage für die Wahl einer Bibliothek dienen. Schwerpunkt ist die Be...]]></description>
<link>https://tsecurity.de/de/3515006/it-security-video/geoext-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515006/it-security-video/geoext-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 23:03:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Vortrag stellt die neueste Version von GeoExt vor und zeigt auf, welches Handwerkszeug dem Entwickler hier bereitsgestellt wird. Unterschiede zwischen ExtJS und anderen Bibliotheken werden benannt, dies kann als Diskussionsgrundlage für die Wahl einer Bibliothek dienen. Schwerpunkt ist die Betrachtung der zukünftigen Entwicklung von GeoExt.

GeoExt [1] ist eine auf den JavaScript-Bibliotheken OpenLayers (für interaktive Karten im Web und Verarbeitung einer Fülle von OGC-konformen Formaten, [2]) und ExtJS (Framework zur Erstellung von Desktop-ähnlichen Webanwendungen mit nativem Look and Feel, [3]) aufbauende OpenSource JavaScript-Bibliothek, die es vereinfacht, Kartenmaterial in ansprechenden und komplexen Oberflächen zu präsentieren, so genannte &quot;Rich Webmapping Applications&quot;.

Neben ExtJS bietet der Markt eine Vielzahl weiterer JavaScript-Frameworks und Bibliotheken an, die sich ebenfalls der Herausforderung angenommen haben, die Entwicklung von webbasierten JavaScript Clients zu vereinfachen und zu harmonisiseren. Hier sind -- und das ist nur eine willkürliche Auswahl -- etwa AngularJS ([4]) und EmberJS ([5]) zu nennen. Eben jene Frameworks sind derzeit in der Entwicklergemeinschaft sehr beliebt, es werden viele klare Vorzüge dieser modernen Frameworks gelobt und die Art und Weise der Problemlösung spricht viele Developer an.

Der Vortrag wird die neueste Version von GeoExt vorstellen und aufzeigen, welches Handwerkszeug dem Entwickler hier bereitsgestellt wird. Wir werden Unterschiede zwischen ExtJS und den vorgenannten Bibliotheken benennen und Diskussionsgrundlage für die Wahl einer Bibliothek geben. Hierbei können wir als Kernentwickler von GeoExt nie vollständig neutral vorgehen, wir wollen jedoch versuchen jeweilige Vor- und Nachteile der jeweiligen Bibliotheken herauszustellen.

Zum Zeitpunkt der Abstract-Einreichung wird an GeoExt massiv weiterentwickelt: Es stehen die Unterstützung von ExtJS 5 und (später) OpenLayers 3 an. Ein weiterer Schwerpunkt wird dementsprechend auf der Betrachtung dieser und der zukünftigen Entwicklung von GeoExt liegen.
about this event: https://fossgis-konferenz.de/2015/programm/events/834.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Herausforderungen bei der Umsetzung der INSPIRE-Richtlinie (fossgis2015)]]></title>
<description><![CDATA[Von Datenspezifikationen, komplexen Feature-Modellen, Open Source Softwareprodukten für INSPIRE und Darstellungs- und Dounloaddiensten.

Seit 2012 stehen die ersten INSPIRE-Downloaddienste bereit. Konforme, aber nicht interoperable Dienste stellen hierbei INSPIRE-relevante Daten in einem vom Date...]]></description>
<link>https://tsecurity.de/de/3514915/it-security-video/herausforderungen-bei-der-umsetzung-der-inspire-richtlinie-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514915/it-security-video/herausforderungen-bei-der-umsetzung-der-inspire-richtlinie-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 22:18:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Von Datenspezifikationen, komplexen Feature-Modellen, Open Source Softwareprodukten für INSPIRE und Darstellungs- und Dounloaddiensten.

Seit 2012 stehen die ersten INSPIRE-Downloaddienste bereit. Konforme, aber nicht interoperable Dienste stellen hierbei INSPIRE-relevante Daten in einem vom Datenanbieter definierten Datenmodell bereit. Meist werden hierfür einfach strukturierte Feature-Modelle eingesetzt. Das GML-Schema eines einfachen Feature-Modells (GML SF-0) kann automatisiert aus der Struktur der verwendeten Datenquelle (z. B. Datenbanktabelle) abgeleitet werden. Für jede durch den WFS-Server unterstützte GML-Version (2.1, 3.1, 3.2) kann ein korrespondierendes GML-Schema erzeugt werden.

Bei den INSPIRE-Datenmodellen handelt es sich komplexe Feature-Modelle (GML-Anwendungsschemata). Gelegentlich wird das Problem bei der Bereitstellung von Daten gemäß INSPIRE-Datenspezifikationen auf das Thema Datenmodelltransformation reduziert. Eine weitere große Herausforderung ergibt sich jedoch bei der anschließenden Bereitstellung der transformierten Daten über Darstellungs- und Downloaddienste.

Daher werden im Vortrag folgende Fragestellungen erläutert und diskutiert:
• Wie unterscheiden sich einfache und komplexe Feature-Modelle?
• Welche Lösungsansätze gibt es bei der Bereitstellung von komplexen Feature-Modellen?
• Mit welchen OpenSource-Softwareprodukten ist die Bereitstellung von INSPIRE-konformen Daten möglich?

Weiterhin wird am Beispiel QGIS auf vorhandene Einschränkungen bei der Verwendung von Geodaten auf Grundlage von GML-Anwendungsschemata eingegangen.
about this event: https://fossgis-konferenz.de/2015/programm/events/860.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Softwarewartung für OpenSource. Ein Widerspruch? (fossgis2015)]]></title>
<description><![CDATA[In meinem Vortrag möchte ich ein Thema diskutieren, das sowohl die Open Source Welt, als auch die kleine, heile FOSSGIS-Welt und damit natürlich auch uns bei terrestris seit einiger Zeit umtreibt:
Softwarewartung für Open Source!

Der Inhalt des Vortrags Talks widmet sich der Software-Wartung bzw...]]></description>
<link>https://tsecurity.de/de/3514912/it-security-video/softwarewartung-fuer-opensource-ein-widerspruch-fossgis2015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514912/it-security-video/softwarewartung-fuer-opensource-ein-widerspruch-fossgis2015/</guid>
<pubDate>Wed, 13 May 2026 22:18:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In meinem Vortrag möchte ich ein Thema diskutieren, das sowohl die Open Source Welt, als auch die kleine, heile FOSSGIS-Welt und damit natürlich auch uns bei terrestris seit einiger Zeit umtreibt:
Softwarewartung für Open Source!

Der Inhalt des Vortrags Talks widmet sich der Software-Wartung bzw. Betriebssicherheit. Wenn es darum geht, Open Source Software einzusetzen, wird dem oft das Argument entgegengesetzt, das ja keiner verantwortlich sei, das es keine Betriebsgarantie gibt und die Entwickler ja „morgen schon was anderes machen könnten“. Ich sehe dies als letzte Bastion der proprietären Hersteller im kürzlich als zu Ende erklärtem Glaubenskrieg zwischen Proprietärer und Open Source Software-Verfechtern.

Ich möchte in meinem Vortrag nicht diskutieren, inwieweit Architekturwechsel proprietärer Hersteller in der Vergangenheit dazu geführt haben, das Unsummen an investiertem Geld trotz sogenannter Betriebssicherheit unwiderbringlich den Rhein herabgeflossen sind (Stichwort ArcView GIS, Windows XP u.v.m.). Trotzdem wird solchen Anbietern eher zugetraut, das eine angebotene Softwarewartung zu Betriebs- und damit Investitionssicherheit beiträgt. Im Vortrag steht vielmehr die Frage im Raum, ob es eine Verletzung des Open Source Grundsatzes ist, wenn eine Firma, die maßgeblich hinter der Entwicklung einer oder mehrerer Open Source (GIS-)Projekten steht, eine solche Wartung nach proprietärem Geschäftsmodell zu einem jährlichen Fixpreis anbietet? Kann das Angebot von Betriebssicherheit und auch Support dazu führen, das Open Source eher eingesetzt wird? Würde ein solches Angebot überhaupt Chancen beim Kunden haben - da sie ja anders als beim proprietären Geschäftsmodell nicht obligatorisch wäre (sein kann!)? De Fakto bieten Firmen solche Modelle bereits an, es stellt sich die Frage, ob der Markt reif ist für diese nächste „Professionalisierungsstufe“?

All dies sind Fragen die ich in meinem Vortrag behandeln und anschließend gerne auch diskutieren möchte.
about this event: https://fossgis-konferenz.de/2015/programm/events/826.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Commemorative US Mint Steve Jobs coin sells out in just 11 minutes]]></title>
<description><![CDATA[The American Innovation $1 coin bearing a vague likeness of Steve Jobs went on sale from the U.S. Mint on Tuesday. It sold out in 11 minutes.Image Credit: United States MintThe United States Mint put up a collection of new designs of American Innovation coin rolls and bags on May 12, representing...]]></description>
<link>https://tsecurity.de/de/3511451/ios-mac-os/commemorative-us-mint-steve-jobs-coin-sells-out-in-just-11-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511451/ios-mac-os/commemorative-us-mint-steve-jobs-coin-sells-out-in-just-11-minutes/</guid>
<pubDate>Tue, 12 May 2026 19:43:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The American Innovation $1 coin bearing a vague likeness of <a href="https://appleinsider.com/inside/steve-jobs" title="Steve Jobs" data-kpt="1">Steve Jobs</a> went on sale from the U.S. Mint on Tuesday. It sold out in 11 minutes.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67624-142486-67613-142454-chorbs-xl-xl.jpg" alt="Bronze commemorative coin showing Steve Jobs sitting crosslegged on grass before rolling hills, surrounded by text: Make Something Wonderful, United States of America, Steve Jobs, California, 2026"><br><span>Image Credit: United States Mint</span></div><br>The United States Mint put up a collection of new designs of American Innovation coin rolls and bags on May 12, representing four states. It seems that the U.S. Mint underestimated the demand for the set, especially for one Apple-related item.<br><br>The <a href="https://appleinsider.com/articles/25/10/15/steve-jobs-featured-on-american-innovation-1-gold-coin-for-2026">2026 set</a> represents innovation in four states: Iowa, Wisconsin, Minnesota, and California. For the California coin, an image of a young Steve Jobs is used to represent innovation.<br><br><br> <a href="https://appleinsider.com/articles/26/05/12/commemorative-us-mint-steve-jobs-coin-sells-out-in-just-11-minutes?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244322?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoExt2 (fossgis2014)]]></title>
<description><![CDATA[Referenten: Marc Jansen, terrestris & Christian Mayer, ISB AG

GeoExt [1] ist eine auf den JavaScript-Bibliotheken OpenLayers (für interaktive Karten im Web und Verarbeitung einer Fülle von OGC-konformen Formaten, [2]) 
und ExtJS (Framework zur Erstellung von Desktop-ähnlichen Webanwendungen mit ...]]></description>
<link>https://tsecurity.de/de/3508092/it-security-video/geoext2-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508092/it-security-video/geoext2-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 20:19:05 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Referenten: Marc Jansen, terrestris &amp; Christian Mayer, ISB AG

GeoExt [1] ist eine auf den JavaScript-Bibliotheken OpenLayers (für interaktive Karten im Web und Verarbeitung einer Fülle von OGC-konformen Formaten, [2]) 
und ExtJS (Framework zur Erstellung von Desktop-ähnlichen Webanwendungen mit nativem Look and Feel, [3]) aufbauende OpenSource JavaScript-Bibliothek, die es vereinfacht, Kartenmaterial in ansprechenden und komplexen Oberflächen zu präsentieren, so genannte &quot;Rich Webmapping Applications&quot;.

Seit Oktober 2013 liegt GeoExt in der Version 2.0.0 vor, welche auf den neuesten stabilen Version der Basisbibliotheken aufbaut: OpenLayers 2.13.1 und ExtJS 4.2.1.

Der Vortrag wird die aktuelle Version präsentieren, und anhand von beeindruckenden Beispielen die Möglichkeiten von GeoExt darstellen. Hierbei werden insbesondere folgende Aspekte beleuchtet werden:

* Änderungen für Anwender im Vergleich zur Vorgängerversion
* Kompatibilität mit dem Single-File Build-Tool von Sencha (Automatisierte Erzeugung einer komprimierten JS-Datei für den Produktivbetrieb)
* Integration in den ExtJS MVC (Model-View-Controller) Architekturansatz
* Verbesserte API-Dokumentation und Präsentation
* Vereinfachte &quot;themeability&quot; (Einfachere grafische Ausgestaltung der resultierenden Anwendung)

Außerdem wird ein kurzer Blick auf die Entwicklungsgeschichte und die Hintergründe von GeoExt 2 geworfen werden: Weite Teile der Codebasis wurden bei einem gesponserten internationalen Codesprint gelegt, warum dauerte es bis zur finalen Version 2.0 anschließend vergleichbar lange?

Weiterer Fokus wird auf der Darstellung der zukünftig geplanten Entwicklung des Projektes liegen. Insbesondere wird der Vortrag aktuelle Überlegungen zur Unterstützung verschiedener Kartenbibliotheken wie OpenLayers 3 [4] oder Leaflet [5] behandeln.

[1] http://geoext.github.io/geoext2/
[2] http://openlayers.org
[3] http://www.sencha.com/products/js/
[4] http://ol3js.org/
[5] http://leafletjs.com/
about this event: https://fossgis-konferenz.de/2014/programm/events/697.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenLayers 3 (fossgis2014)]]></title>
<description><![CDATA[Referenten: Marc Jansen, terrestris & Andreas Hocevar, Boundless

OpenLayers ist eine OpenSource JavaScript Kartenbibliothek mit sehr großer Verbreitung, sowohl innnerhalb von OSGeo-Projekten als auch in privaten wie öffentlichen Webseiten und Internet-/Intranet-Applikationen. Die 2.x-er Versione...]]></description>
<link>https://tsecurity.de/de/3508087/it-security-video/openlayers-3-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508087/it-security-video/openlayers-3-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 20:18:57 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Referenten: Marc Jansen, terrestris &amp; Andreas Hocevar, Boundless

OpenLayers ist eine OpenSource JavaScript Kartenbibliothek mit sehr großer Verbreitung, sowohl innnerhalb von OSGeo-Projekten als auch in privaten wie öffentlichen Webseiten und Internet-/Intranet-Applikationen. Die 2.x-er Versionen der Software werden bis zum heutigen Tage weiterentwickelt und gepflegt. Doch natürlich nagt der Zahn der Zeit auch an OpenLayers: Entwickler und Anwender haben 2014 verständlicherweise andere Ansprüche an digitale Kartenbibliotheken, als dies vor 8 Jahren der Fall war.

Bereits seit einiger Zeit wird daher von der Entwicklergemeinde an OpenLayers 3 gearbeitet, zum Zeitpunkt der Einreichung des Abstracts ist die aktuellste Version 3.0.0.beta.1.

Der Vortrag zweier OpenLayers Kernentwickler wird in die Verwendung der neuen Version einführen. Die Zuhörer werden erfahren, was sich geändert hat (kurz: fast alles) und was gleich bleibt (kurz: die zahllosen Anwendungsmöglichkeiten). Hierbei werden wir viele Verwendungsbeispiele (Quellcode und Ergebnis) aufzeigen. Auch die Erläuterung der Architektur hinter OpenLayers 3 wird beleuchtet werden. Besonders werden hierbei einige technische Highlights (wie die Verwendung von WebGL, Vektor-API, kleine Dateigröße, Build-Prozess) vorgestellt.

Auch die Roadmap der weiteren Entwicklung des Projektes wird angesprochen werden.
about this event: https://fossgis-konferenz.de/2014/programm/events/698.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[opencaching.de (fossgis2014)]]></title>
<description><![CDATA[Erfahren Sie, wie Sie mit dem GPS auf Schatzsuche gehen können. Das facettenreiche Hobby Geocaching spricht verschiedenste Zielgruppen an und die freie Plattform Opencaching.de ermöglicht jedem Interessierten die aktive Mitgestaltung und Weiterentwicklung dieses Hobbys.

Praämbel: Angeregt durch ...]]></description>
<link>https://tsecurity.de/de/3508085/it-security-video/opencachingde-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508085/it-security-video/opencachingde-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 20:18:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erfahren Sie, wie Sie mit dem GPS auf Schatzsuche gehen können. Das facettenreiche Hobby Geocaching spricht verschiedenste Zielgruppen an und die freie Plattform Opencaching.de ermöglicht jedem Interessierten die aktive Mitgestaltung und Weiterentwicklung dieses Hobbys.

Praämbel: Angeregt durch den OSM-Podcast Nr. 24 wurde zwischen uns, Peter Körner und den anderen Anwesenden im Mumble-Chat ein kleines &quot;Interview&quot; zum Thema Opencaching abgehalten. Nach dem Interview war man sich einig, dass &quot;wir&quot; uns bei der FOSGISS mit einem Beitrag bewerben sollten und unser Hobby, unsere Plattform und die dabei verwendete Technik des OSM Kartenmaterials vorstellen sollten. Darüber hinaus stellte man fest, dass die so genannten &quot;Mapping-Partys&quot; themenbezogen auch gut als Event auf unserer Plattform gelistet und &quot;organisiert&quot; werden können. Ein früherer Versuch bei der Plattform geocaching.com schlug fehl, da die Nutzungsbedingungen ein solchen Event nicht zulassen würden. &quot;Wir&quot; als OpenSource-Projekt stehen dafür aber dahinter und möchten uns im Rahmen der FOSSGIS einmal vorstellen. Wir hoffen, dass unsere Einreichung, die erst kurzfristig zusammengestellt wurde, ausreicht, um das Interesse für einen Vortrag von uns zu wecken. Daher stellen wir hier, uns und unsere Bereiche, die wir anreißen wollen schon mal vor. Die FOSSGIS als Konferenz haben wir bislang leider nicht wahrgenommen und sind daher bemüht unseren Vortrag passend und interessant vorzubereiten.

Geocaching

Geocaching ist DIE Form der modernen Schatzsuche. Während man früher auf den Boden schaute um sich an Papierschnipsel o.ä. zu orientieren, läuft man heute auf der Suche nach dem &quot;Schatz&quot; mit einem GPS-Gerät durch Stadt und Land.
Um etwas weiter auszuholen: Geocaching entstand im Jahr 2000 und wurde erst dadurch möglich, dass die USA die Genauigkeit des GPS-Signals für Jedermann deutlich verbesserte, wodurch es auch Privatpersonen möglich wurde, einen konkreten Punkt zielgenau zu finden. Am Ende der Suche steht fast immer ein verschieden großer Behälter, der immer ein Logbuch, in das sich der Finder einträgt, und je nach Größe noch weitere Gegenstände enthält. Die Größen variieren von Nano, einem sehr kleinen Behälter mit einem etwa centgroßen Durchmesser, bis sehr groß, was Tonnen, Fässer, oder noch größere Verstecke bezeichnet.

Nachdem man den ersten versteckten Cache, der sich in Oregon, USA befand, heute als Traditional Cache bezeichnen würde, bei dem die Zielposition von vornherein angegeben ist, haben sich mit der Zeit verschiedene andere Arten von Caches entwickelt. So gibt es Mystery-Caches, bei denen meist im Vorfeld Rätsel zu lösen sind, um die Position des Cachebehälters zu ermitteln. Außerdem gibt es Multi-Caches, bei denen auf einer mehr oder weniger langen Wanderung verschiedene Stationen angelaufen werden müssen, an denen man die Koordinaten der nächsten Station entweder erhält oder errätseln muss. Eine Sonderform stellen virtuelle Caches dar, bei denen kein Behälter zu suchen ist, sondern meist Informationen eingeholt werden müssen, um ein Logpasswort zu ermitteln. 


Plattformen

Natürlich haben sich in der Zeit auch verschiedene Plattformen entwickelt, die den Geocachern die Möglichkeit geben, die zu den Cache gehörenden Listings online zu erstellen. Als erstes war da die US-amerikanische Plattform Geocaching.com, auf der heute auch weltweit die meisten Caches gelistet sind. Ohne eine (kostenfreie) Anmeldung ist das Angebot nicht nutzbar. Für über die Grundfunktionen hinausgehende Features muss jedoch eine kostenpflichtige Mitgliedschaft abgeschlossen werden.
Dem gegenüber stehen verschiedene weitere Plattformen, darunter speziell für den deutschsprachigen Raum Opencaching.de. Im Kern unterscheidet sich Opencaching.de zunächst dadurch von geocaching.com, dass den Besuchern/Nutzern der Plattform nahezu alle Dienste auch ohne eine Registrierung angeboten werden. So ist bspw. das Einsehen der Listings und auch der Download als aufbereitete Datei für das GPS-Gerät jedermann möglich. Lediglich für das Loggen der Caches sowie das Einstellen eigener Listings ist eine kostenfreie Registrierung notwendig, da hier nutzerbezogene Daten hinterlegt werden.


Opencaching.de

Opencaching.de entstand im Jahr 2005, zunächst als privates Projekt. Für die verschiedenen Aufgaben wie Entwicklung, Technik und Support bildeten sich Teams aus Freiwilligen. Die Plattform wurde von den Cachern gut angenommen. Schon nach drei Jahren war eine Anzahl von etwa 10.000 Listings verfügbar. Um die Plattform rechtlich auf sichere Beine zu stellen übernahm Ende 2006 die Deutsche Wanderjugend (DWJ) die Betreiberschaft. Außerdem stellte die DWJ auch finanzielle Mittel zur Weiterentwicklung und für den Betrieb bereit. Die Deutsche Wanderjugend betrieb zu diesem Zeitpunkt bereits die Infoplattform Geocaching.de. 

Etwa 5 Jahre später, im November 2011, war es dann soweit, dass Opencaching.de wieder auf eigene Beine gestellt werden sollte, um die Entwicklung voranzutreiben und einige andere notwendige Vorhaben umzusetzen. Es begann eine Phase, in der intern ausgelotet wurde, wer aus dem alten Team auch in Zukunft dabei sein würde. Anschließend wurde der Community das Vorhaben vorgestellt und auch dort nach neuen Unterstützern gesucht. Zeitgleich begann auch die Suche nach einer geeigneten Rechtsform. Nach einiger Zeit formte sich dann das neue Team und der Verein kristallisierte sich als optimale Rechtsform heraus. Im Mai 2012 gründeten dann 15 Cacher den Verein Opencaching Deutschland e.V., der seitdem die Website betreibt. Wieder formierten sich neue Teams aus Freiwilligen, die seitdem für den laufenden Betrieb und die Weiterentwicklung des Webangebots sorgen.

Seitdem hatte der Verein Zulauf und zählt derzeit 26 Mitglieder. Für die Mitarbeit an der Plattform ist die Vereinsmitgliedschaft aber keine Pflicht. Daher arbeiten an der Plattform auch zahlreiche weitere Helfer mit, die jedoch nicht Vereinsmitglieder sind. Aufgabengebiete sind unter anderem der User-Support oder die Erweiterung des Wikis. Besonders wichtig sind allerdings die Bereiche Systemadministration und Softwareentwicklung, schon allein weil sie den Kern des Plattformbetriebes darstellen. Wie bei vielen Communityprojekten bestehen hier die meisten Engpässe, weshalb Opencaching.de immer auf der Suche nach ambitionierten PHP-Entwicklern ist. Neben der Umsetzung der von der Community gewünschten Funktionen haben Entwickler bei Opencaching.de sehr viele Freiheiten um auch eigene Ideen zu verwirklichen.

Opencaching.de ist Teil des Internationalen Opencaching-Netzwerkes. So werden weltweit noch 7 weitere Opencaching-Knoten in Europa und Nordamerika betrieben. Ein japanischer Knoten stellte nach dem Tōhoku-Erdbeben 2011 seinen Betrieb ein. Besonders nennenswert ist der Erfolg des polnischen Knotens, der in Polen mit großem Abstand Marktführer ist. Sowohl die spanische als auch die italienische Opencaching-Plattform sind in die deutsche Plattform integriert und greifen auf dieselbe Datenbank zurück. Durch die komplette Übersetzung in diese drei Sprachen sowie in die englische Sprache erreicht Opencaching.de einen erweiterten Nutzerkreis außerhalb Deutschlands. Alle diese Plattformen sind aus früheren Versionen des Quellcodes von Opencaching.de entstanden, mittlerweile haben sich die Quelltexte aber in zwei wesentliche Zweige auseinanderentwickelt. 


OpenSource

Nach der Übernahme der Betreiberschaft durch den Verein wurde das open durch verschiedene Maßnahmen noch weiter vorangetrieben. So wurde etwa beschlossen, Diskussionen im Forum, soweit möglich, komplett öffentlich zu führen. Der wohl wichtigste Schritt war aber die komplette Offenlegung des Quellcodes auf GitHub und damit verbunden, die Neulizenzierung des Quellcodes unter GNU GPL. In diesem Rahmen erfolgte auch die schon lange geplante Lizenzierung aller Inhalte unter CC BY-NC-ND 3.0. Insgesamt war die Neulizenzierung nur der letzte logische Schritt, nachdem Opencaching.de selbst komplett frei nutzbar war und viel Opensource-Software Verwendung findet. So kommt bspw. als Templatesystem Smarty zum Einsatz, das unter LGPL lizenziert ist. Aber auch das wichtigste visuelle Werkzeug innerhalb der Listingplattform, die Geocachekarte, die Anfang 2013 eine vollständige Überarbeitung erfahren hat, sei hier zu nennen. 

Wo bisher auf Google Maps gesetzt wurde, steht nun das Kartenmaterial von OpenStreetMap an erster Stelle (erwähnt im OSM Podcast 16 - &quot;Flopps tolle Karte&quot;), einerseits weil die OSM als freies Communityprojekt vom Wesen her ähnlich ist, andererseits aber auch, weil viele Geocacher die Trackaufzeichnungen ihrer Cachetouren sowie ihre Ortskenntnis dafür nutzen, das Kartenmaterial von OpenStreetMap mit eigenen Beiträgen zu ergänzen oder zu vervollständigen. Gerade in entlegenen Gegenden, in touristisch weniger erschlossenen Bereichen stellt man als Geocacher immer wieder fest, das zumindest der &quot;Weg zur Dose&quot; eingezeichnet ist, ein deutliches Zeichen für den &quot;Datenrücklauf&quot; zum OpenStreetMap-Projekt.

Unterstützung der Mapping-Partys

Aus dem Podcast Team heraus wurden wir angesprochen, ob man die Mapping-Partys nicht bei Opencaching.de listen kann um hier die Kommunikation und Organisation zu vereinfachen. Gerne stehen wir mit der Plattform bereit und bieten diese Möglichkeiten. Denn auch interessierte Cacher, die durch ihre Wanderschaften in entlegenden Gebieten Wege/Daten sammeln könnten sich anschließen um zu erfahren wie man neue Pfade in die richtigen Kanäle steckt. Eine Synergie, in der zwei Plattformen interagieren und sich unterstützen können.

Wir freuen uns auf die Teilnahme und sagen wie bei uns üblich &quot;bis bald - im Wald!&quot;...
about this event: https://fossgis-konferenz.de/2014/programm/events/669.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[GDA Wasser – ein praktisches Beispiel für das komplexe SHOGun-WebGIS Framework (fossgis2014)]]></title>
<description><![CDATA[Das Projekt GDA Wasser wurde Ende des Jahres 2011 durch die Wasserwirtschaft Rheinland-Pfalz zur Ausschreibung gestellt. Ziel war es, eine moderne, umfassende GIS-Architektur auf OpenSource-Basis umzusetzen, um die bestehende, auf älteren Technologien beruhende GDI abzulösen.

Aufbauend auf dem V...]]></description>
<link>https://tsecurity.de/de/3508041/it-security-video/gda-wasser-ein-praktisches-beispiel-fuer-das-komplexe-shogun-webgis-framework-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508041/it-security-video/gda-wasser-ein-praktisches-beispiel-fuer-das-komplexe-shogun-webgis-framework-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 20:04:17 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Projekt GDA Wasser wurde Ende des Jahres 2011 durch die Wasserwirtschaft Rheinland-Pfalz zur Ausschreibung gestellt. Ziel war es, eine moderne, umfassende GIS-Architektur auf OpenSource-Basis umzusetzen, um die bestehende, auf älteren Technologien beruhende GDI abzulösen.

Aufbauend auf dem Vortag der FOSSGIS 2013 „Das SHOGun-WebGIS Framework“ von Till Adams wird in diesem Vortrag die praktische Anwendung der entwickelten Lösung im Rahmen des Projektes GDA Wasser dargestellt.

Die im Projekt verwendete Architektur setzt sich im Wesentlichen aus einem soliden Backend, aufsetzend auf oben erwähntem SHOGun (Java EE, Kernkomponenten Hibernate, Spring3) und einem Verwaltungs- und GIS-Client unter anderem auf Basis der JavaScript Bibliotheken Ext JS, OpenLayers und GeoExt2 zusammen.

Das Backend stellt folgende Kernfunktionalitäten bereit: Erstellung, Verwaltung und Editierung von GIS-Oberflächen inklusive Rechteverwaltung und Absicherung mittels Spring-Security sowie Anlegen und Verwalten von Kartendiensten. Dabei können Layer durch Hochladen von Geodaten in GeoServer angelegt und auch mit Tabellen, Zeitreihen und Bildern verknüpft werden.

Das Frontend besteht neben dynamisch erzeugten GIS-Applikationen aus breit gefächerten Konfigurationsoberflächen.

Ein Einsatzfeld der Architektur GDA Wasser ist die dynamische Erstellung und Konfiguration von thematischen Kartenanwendungen. Die Funktionalitäten einer solchen GIS-Applikation erstrecken sich über ein weites Feld: Von der reinen Anzeige spezifischer Themen, deren dynamischer grafischer Ausgestaltung, Anlage neuer Layer, Digitalisierungs- und Annotierungsfunktionen, über Druckfunktionen, individuelle Abfrage-, Such- und Selektionswerkzeuge, Exportfunktionalitäten und Speicherung von Arbeitsständen, um nur einen kleinen Teil zu nennen. Ebenfalls stehen Schnittstellen für externe Applikationen bzw. Fachanwendungen bereit, um eine Interaktion mit diesen zu gewährleisten.

Der Vortrag soll einleitend einen kurzen architektonischen Überblick geben und die verwendeten Komponenten beleuchten. Ein Großteil des Vortrages soll sich auf die praktische Anwendung konzentrieren und zeigen, welche Funktionalitäten und Möglichkeiten durch das Gesamtsystem gegeben werden.
about this event: https://fossgis-konferenz.de/2014/programm/events/703.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[PostGIS in real :-) action (fossgis2014)]]></title>
<description><![CDATA[In einem deutschlandweiten Projekt wurden Geodaten zu nutzungsfreien Waldflächen in PostgreSQL/PostGIS aufbereitet. Arbeitsschritte waren die Transformation in ein einheitliches Koordinatensystem, eine Überlagerungsanalyse und die Abbildung von überregionalen Daten mit Hilfe von PL/pgSQL-Funktion...]]></description>
<link>https://tsecurity.de/de/3508001/it-security-video/postgis-in-real-action-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508001/it-security-video/postgis-in-real-action-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 19:49:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In einem deutschlandweiten Projekt wurden Geodaten zu nutzungsfreien Waldflächen in PostgreSQL/PostGIS aufbereitet. Arbeitsschritte waren die Transformation in ein einheitliches Koordinatensystem, eine Überlagerungsanalyse und die Abbildung von überregionalen Daten mit Hilfe von PL/pgSQL-Funktionen.

Für ein Forschungsvorhaben wurden von einer Vielzahl von Waldbesitzern aus ganz Deutschland Geo- und Sachinformationen zu nutzungsfreien Wäldern bereitgestellt. Diese umfangreiche Datengrundlage enthält detaillierte Informationen zu ca. 400.000 Hektar Waldfläche in etwa 90 verschiedenen Datenlieferungen. Hierbei lagen die einzelnen Lieferungen in einer z.T. sehr heterogenen Form vor.
Die Haltung, Bearbeitung und Bereitstellung aller Daten wurde in der Datenbank PostgreSQL mit der Erweiterung PostGIS durchgeführt. Wesentliche Arbeitsschritte bezüglich der Geoinformationen waren die Transformation in ein einheitliches Koordinatensystem, eine Überlagerungsanalyse der einzelnen Datenlieferungen, die Abbildung von überregionalen Daten auf die Waldflächen und die Identifizierung von zusammenhängenden oder benachbarten Flächenkomplexen. Hierbei wurden eine Reihe von Funktionen (PL/pgSQL) geschrieben, die die Grundfunktionalitäten von PostGIS zu spezialisierten Werkzeugen kombinieren. Beispielsweise wurde für die Verschneidung der Waldflächen mit deutschlandweit vorliegenden sehr großen Daten wie dem Digitalen Landbedeckungsmodell DLM-DE Funktionen entwickelt, die quadrantenweise eine sukzessive Abarbeitung der Gesamtfläche der Bundesrepublik ermöglichen. Auf diese Weise konnte eine übermäßige Auslastung des Arbeitsspeichers vermieden werden.
Die Realisierung des Projektes wurde möglich durch die Nutzung von OpenSource Werkzeugen. Die verwendeten Werkzeuge stellen eine professionelle und höchst aktuelle Arbeitsumgebung dar, welche in dieser Form als kostenpflichtige Variante keines Falls hätte hergestellt werden können.
Hintergrund: Die Bundesregierung hat das Ziel formuliert bis zum Stichjahr 2020 5 % der Waldfläche in Deutschland einer natürlichen Entwicklung zu überlassen. Da bisher keine verlässliche Bilanzierungsgrundlage existierte, wurde vom Bundesministerium für Umwelt, Naturschutz und Reaktorsicherheit ein Vorhaben beauftragt, welches die entsprechende Grundlage erarbeitet. Das Vorhaben ist weitgehend abgeschlossen.
about this event: https://fossgis-konferenz.de/2014/programm/events/724.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoKettle – FME für Geizige? (fossgis2014)]]></title>
<description><![CDATA[GeoKettle
GeoKettle ist ein ETL-Programm für räumliche Daten. ETL steht für Extract, Load und Transform. GeoKettle basiert auf der OpenSource Software Pentaho Data Integration (Kettle) und ist mit der LPGL lizensiert. GeoKettle unterstützt dabei u.a. die OpenSource Bibliotheken GeoTools, Degree u...]]></description>
<link>https://tsecurity.de/de/3507999/it-security-video/geokettle-fme-fuer-geizige-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507999/it-security-video/geokettle-fme-fuer-geizige-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 19:49:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GeoKettle
GeoKettle ist ein ETL-Programm für räumliche Daten. ETL steht für Extract, Load und Transform. GeoKettle basiert auf der OpenSource Software Pentaho Data Integration (Kettle) und ist mit der LPGL lizensiert. GeoKettle unterstützt dabei u.a. die OpenSource Bibliotheken GeoTools, Degree und gdal/oge und sextante. 
Ausgangslage
Bei der Werraenergie, einem Energiedienstleister in Thüringen, stand aufgrund eines Systemwechsels im Bereich des CAD auch ein Umzug der Geodaten von einer Oracle-Datenbank in eine PostgreSQL Datenbank mit PostGIS an. Die Daten der Werraenergie lagen in einem nicht dokumentierten Datenmodell vor und konnten nur mit einem CAD als Shapedateien exportiert werden. Nach dem Export lagen 247 verschiedene Shapefiles vor. Das Versorgungsgebiet der Werraenergie ist allerdings so groß, dass der Export nur in 40 sich zum Teil überlagernden räumlichen Einheiten durchgeführt werden konnte, was in insgesamt 11.000 Shapefiles resultierte. Die Inhalte der Shapedateien ware zudem nicht eindeutig,  sodass in einem Shapefile für Leitungen, sowohl die Leitungen mit Ihren Attributen als auch Hilfslinien für die Beschriftungen mit den gleichen Attributen beinhalten konnten.

GeoKettle in action
Beim Import der Daten in die PostgreSQL-Datenbank mussten folgende  Arbeiten vorgenommen werden:
Import der 11.000 Shapefile mussten in zwei verschiedene Datenbanken (Gas und Grundkarte)
Verteilen von Objekten in einem Shapefile auf mehrere Tabellen
Zusammenfassen von Objekte aus mehreren Shapefiles mit unterschiedlichen Attributfeldern in einer Tabelle
Veränderung von Attributen
Entfernen von redundanten Daten
…
Fazit
Ohne den Einsatz von GeoKettle wäre die Datenmigration bei der Werraenergie kaum zu stemmen gewesen. Dabei hat sich GeoKettle als gut dokumentierte und leicht zu erlernende Software heraus gestellt, die eine echte Alternative zur FME darstellt.
about this event: https://fossgis-konferenz.de/2014/programm/events/716.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Ernährungsfläche einer Agglomeration (fossgis2014)]]></title>
<description><![CDATA[Wie gross ist die Fläche, die eine durchschnittliche Schweizer Person braucht, um sich zu ernähren? Wie könnte diese optimiert werden? Wo läge sie und wie gross wäre diese Fläche für die Bevölkerung einer bestimmten Agglomeration, wenn alle Nahrungsmittel lokal und in der Schweiz produziert würde...]]></description>
<link>https://tsecurity.de/de/3507998/it-security-video/ernaehrungsflaeche-einer-agglomeration-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507998/it-security-video/ernaehrungsflaeche-einer-agglomeration-fossgis2014/</guid>
<pubDate>Mon, 11 May 2026 19:49:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie gross ist die Fläche, die eine durchschnittliche Schweizer Person braucht, um sich zu ernähren? Wie könnte diese optimiert werden? Wo läge sie und wie gross wäre diese Fläche für die Bevölkerung einer bestimmten Agglomeration, wenn alle Nahrungsmittel lokal und in der Schweiz produziert würden? Es geht also um eine Visulisierung der für die Ernährung einer Region benötigten Fläche.
Um diese Fragen zu beantworten, muss zuerst der Flächenbedarf einer Person für deren Ernährung ermittelt werden. Dabei sollen nur die Produkte, die in der Schweiz anbaubar sind, berücksichtigt werden. Die Berechnungen stützen sich auf die Erträge der jeweiligen landwirtschaftlichen Primärprodukte. 
Für die Zuteilung der Flächen auf die verfügbare landwirtschaftliche Nutzfläche wird ein auf Geodaten und Methoden der Geoinformatik beruhendes Berechnungsmodell entwickelt. Dieses basiert hauptsächlich auf den Daten der Arealstatistik. Die Flächen werden distanzabhängig zugeteilt, um die Transportdistanzen zu minimieren. Das Modell ist so konzipiert, dass es auch übertragbar auf andere Regionen ist.
In einem weiteren Teil wird versucht die heutige Diät zu optimieren. Dabei steht der Flächenver-brauch im Mittelpunkt, aber auch ernährungsphysiologische Aspekte werden berücksichtigt. Es resultieren zwei unterschiedliche Szenarien. 
Mit dem entwickelten Modell können Karten generiert werden, welche darstellen, wie gross die Ernährungsfläche einer Agglomeration wäre und wie sich Veränderungen in der Diät auf diese auswirken. Mit den Karten können auch andere Aspekte aufgezeigt werden. Es wird sofort ersichtlich, warum Futtermittelimporte in der Schweiz nötig sind. 
Die gesamte Analyse einschliesslich der Visualisierung wurde mit Opensource Komponenten erstellt. Diese Arbeit zeigt anschaulich das Potenzial und die Kapazität von Opensource Software im GIS Bereich.
about this event: https://fossgis-konferenz.de/2014/programm/events/625.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Convenience: Exposing the Risks of VMware vSphere Active Directory Integration]]></title>
<description><![CDATA[Written by: Stuart Carrera, Brian Meyer

Executive Summary
Broadcom's VMware vSphere product continues to be a top choice for private cloud virtualization, underpinning important systems and critical infrastructure. Far from losing its appeal, organizations still rely heavily on vSphere for its s...]]></description>
<link>https://tsecurity.de/de/3504175/it-security-nachrichten/beyond-convenience-exposing-the-risks-of-vmware-vsphere-active-directory-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504175/it-security-nachrichten/beyond-convenience-exposing-the-risks-of-vmware-vsphere-active-directory-integration/</guid>
<pubDate>Sun, 10 May 2026 08:09:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Stuart Carrera, Brian Meyer</p>
<hr></div>
<div class="block-paragraph_advanced"><h2><span>Executive Summary</span></h2>
<p><span>Broadcom's VMware vSphere product continues to be a top choice for private cloud virtualization, underpinning important systems and critical infrastructure. Far from losing its appeal, organizations still rely heavily on vSphere for its stability and control. Mandiant is also observing a clear trend where critical workloads are moving back from public cloud services to these on-premises vSphere environments, often driven by strategies that balance innovation with stability and the desire for more direct operational oversight.</span></p>
<p><span>The common practice of directly integrating vSphere with Microsoft Active Directory (AD), while simplifying administration tasks, creates an attack path frequently underestimated due to a misunderstanding of the inherent risks presented today. This configuration extends the AD attack surface directly to the hypervisor. From a threat actor's perspective, this integration constitutes a high-value opportunity. It transforms the relatively common task of compromising AD credentials into a potential high value scenario, granting access to the underlying infrastructure hosting the servers and in turn allowing them to gain privileged administrative control over ESXi hosts and vCenter and ultimately seize complete command of the virtualized infrastructure.</span></p>
<p><span>Ransomware aimed at vSphere infrastructure, including both ESXi hosts and vCenter Server, poses a uniquely severe risk due to its capacity for immediate and widespread infrastructure paralysis. With the end of general support for vSphere 7.x approaching in October 2025—the version Mandiant has observed to be running by a large majority of organizations—the threat of targeted ransomware has become urgent. As recovering from such an attack requires substantial time and resources, proactive defense is paramount. It is therefore critical for organizations to understand the specific threats against these core components and implement effective, unified countermeasures to prevent their compromise, especially before support deadlines introduce additional risk.</span></p>
<p><span>This blog post will logically break down the inherent risks and misunderstandings with integrating vSphere with Microsoft AD. Using Mandiant's deep experience of both vSphere ransomware incidents and proactive assessments of both AD and vSphere, we will provide a directive for understanding risk and increasing security posture aligned with today's threats in respect of enterprise vSphere management.</span></p>
<p><span>After learning about the risks, our next blog post contains <a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944" rel="noopener" target="_blank">actionable guidance on how to defend your VMware vSphere estate</a>. Additionally, register for our <a href="https://www.brighttalk.com/webcast/7451/648354?utm_source=blog" rel="noopener" target="_blank">upcoming webinar to learn these strategies directly from Mandiant experts</a>.</span></p>
<h2><span>vSphere Infrastructure Overview</span></h2>
<p><span>To understand the security risks in a vSphere environment, it's essential to understand its architecture. A compromise at one layer can have cascading effects throughout the entire virtualized environment.</span></p>
<p><span>At its core, vSphere is a platform that pools physical datacenter resources like compute, storage, and networking into a flexible layer of virtual infrastructure, a task primarily accomplished by two key components, ESXi and vCenter, as shown in the following diagram:</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/vmware-architecture-overview.max-1000x1000.png" alt="vmware architecture overview">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><strong>ESXi (The Hypervisor):</strong><span> This is the foundational layer of vSphere. ESXi is a bare metal hypervisor, meaning it installs directly onto the physical server hardware without requiring an underlying operating system. Its core job is to partition that server into multiple, isolated virtual machines (VMs). Each VM, which is essentially just a collection of files, runs its own operating system and applications, acting like an independent computer. The hypervisor's minimal design is intentional, aiming to reduce its own attack surface while efficiently managing the server's resources.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>vCenter (The Control Plane):</strong><span> If ESXi hosts are the workers, the vCenter Server is the "brain" or control plane for the entire environment. It provides a single web-based interface to manage all connected ESXi hosts and the VMs they run. ESXi hosts are registered with vCenter, which uses agents on each host to manage operations and enable advanced features like automatic workload balancing and high availability for failover protection.</span></p>
</li>
</ul>
<p><span>Integrating vSphere with AD creates a flexible environment that simplifies identity management, yet it introduces profound security risks. This direct link can turn an AD compromise into a significant threat against the entire vSphere deployment. </span></p>
<h2><span>An Outdated Blueprint: Re-examining Foundational vSphere Security</span></h2>
<p><span>Virtualization has been a cornerstone of enterprise IT for nearly two decades, solving server sprawl and delivering transformative operational agility. Alongside it, AD remains a pillar of enterprise IT. This has led to a long-standing directive that all enterprise technology, including critical infrastructure like vSphere, must integrate with AD for centralized authentication. The result is a risky dependency—the security of foundational infrastructure is now directly tied to the security of AD, meaning any compromise within AD becomes a direct threat to the entire virtualization environment.</span></p>
<p><span>In the past, vSphere security was often approached in distinct, siloed layers. Perimeter security was stringent, and threats were typically viewed as internal, such as configuration errors, rather than from external threat actors. This, combined with the newfound ease of image-based backups, often led to security efforts becoming primarily focused on robust business continuity and disaster recovery capabilities over proactive defense. As environments expanded, managing local user accounts created significant administrative overhead, so support for AD integration was introduced for centralized identity management.</span></p>
<p><span>Mandiant’s observation, based on extensive incident response engagements, is that many vSphere environments today still operate on this foundational architecture, carrying forward security assumptions that haven't kept pace with the evolving threat landscape. As Mandiant’s assessments frequently identify, these architectures often prioritize functionality and stability over a security design grounded in today's threats.</span></p>
<p><span>So what’s changed? Reliance solely on perimeter defenses is an outdated security strategy. The modern security boundary focuses on the user and device, typically protected by agent-based EDR solutions. But here lies the critical gap: The ESXi hypervisor, a purpose-built appliance, which, contrary to what many people believe, is not a standard Linux distribution. This specialized architecture inherently prevents the installation of external software, including security tools like EDR agents. vSphere documentation explicitly addresses this, stating:</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>“</span><span>The ESXi hypervisor is a specialized, purpose-built solution, similar to a network router’s firmware. While this approach has several advantages, it also makes ESXi unable to run “off-the-shelf” software, including security tools, designed for general-purpose operating systems as the ESXi runtime environment is dissimilar to other operating systems.</span></p>
<p><span>The use of Endpoint Detection and Response (EDR) and other security practices inside third-party guest operating systems is supported and recommended."</span></p>
<p><span>Source: <a href="https://knowledge.broadcom.com/external/article?legacyId=80768" rel="noopener" target="_blank">Broadcom</a></span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>Consequently, most organizations focus their security efforts and EDR deployment inside the guest operating systems. This leaves the underlying ESXi hypervisor—the foundation of the entire virtualization environment—as a significant blind spot for security teams.</span></p>
<h2><span>The vSphere Threat Landscape</span></h2>
<p><span>The security gap at the hypervisor layer, which we detailed in the previous section, has not gone unnoticed by threat actors. As security for Windows-based operating systems matured with advanced EDR solutions, threat actors have pivoted to a softer, higher-value target—the ESXi hypervisor itself.</span></p>
<p><span>This pivot is amplified by common operational realities. The critical role of ESXi hosts often leads to a hesitancy to apply patches promptly for fear of disruption. Many organizations face a rapidly closing window to mitigate risks; however, threat actors aren't just relying on unpatched vulnerabilities. They frequently leverage compromised credentials, a lack of MFA, and simple misconfigurations to gain access.</span></p>
<h2><span>The Rise of Hypervisor-Aware Ransomware</span></h2>
<p><span>Ransomware targeting vSphere is fundamentally more devastating than its traditional Windows counterpart. Instead of encrypting files on servers or end user computers, these attacks aim to cripple the entire infrastructure by encrypting virtual disk files (VMDKs), disabling dozens of VMs at once.</span></p>
<p><span>This is not a theoretical threat. According to Google Threat Intelligence Group (GTIG), the focus on vSphere is rapidly increasing. Of the new ransomware families observed, the proportion specifically tailored for vSphere ESXi systems grew from ~2% in 2022 to over 10% in 2024. This demonstrates a clear and accelerating trend that threat actors are actively dedicating resources to build tooling that specifically targets the hypervisor. In incidents investigated by GTIG, threat actors most frequently deployed REDBIKE, RANSOMHUB, and LOCKBIT.BLACK variants.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/ransomware-os-trends.jpg" alt="ransomware os trends chart">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>GTIG analysts have also noted a recent trend for threat actors to gain persistence to vSphere environments via reverse shells deployed on Virtual center. This enables a foothold to be obtained within the vSphere control plane and thus complete control over all infrastructure. This would typically manifest in into a two-pronged approach: a tactical data exfiltration such as an AD database (NTDS.dit) and then the deployment of ransomware and mass encryption of all VMs.</span></p>
<h2><span>Understanding the Active Directory Integration in vSphere</span><strong> </strong></h2>
<p><span>The decision to integrate vSphere with AD often overlooks the specifics of how this connection actually works. To properly assess the risk, we must look beneath the surface at the technical components that enable this functionality. This analysis will deconstruct those key pieces: the legacy agent responsible for authentication, its inherent inability to support modern security controls like multi-factor authentication (MFA), and the insecure default trust relationships it establishes. By examining these foundational mechanisms, we can expose the direct line from a credential compromise to an infrastructure takeover.</span></p>
<h2><span>vSphere’s Likewise Agent</span></h2>
<p><span>When discussing vSphere's integration with AD, it's essential to distinguish between two separate components: vCenter Server and the ESXi hosts. Their respective AD integration options are independent and possess different capabilities. This connection is entirely facilitated by the Likewise agent.</span></p>
<p><span>The Likewise agent was originally developed by Likewise Software to allow Linux and Unix-based systems to join AD environments, enabling centralized identity management using standard protocols like Kerberos, NTLM, and LDAP/(S). The open-source edition, Likewise Open, included tools such as </span><code>domainjoin-cli</code><span> and system daemons like </span><code>lsassd</code><span>, which are still found under the hood in ESXi and the vCenter Server Appliance (VCSA). vSphere embedded this agent starting with ESX 4.1 (released in 2010) to facilitate Integrated Windows Authentication (IWA). However, its function differs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In </span><strong>ESXi</strong><span>, the Likewise agent actively handles AD user authentication when configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In </span><strong>vCenter</strong><span>, it is only used for the initial domain join when Integrated Windows Authentication (IWA) is selected as the identity source—all actual authentication is then handled by the vCenter Single Sign On (SSO) subsystem.</span></p>
</li>
</ul>
<p><span>The original Likewise Software was eventually absorbed by BeyondTrust, and the open-source edition of the agent is no longer actively maintained publicly. The </span><a href="http://github.com/vmware/likewise-open" rel="noopener" target="_blank"><span>Likewise OSS project is now archived</span></a><span> and marked as inactive. It is understood the codebase is only maintained internally. </span><strong>Note:</strong><span> The agent's build version remains identical at </span><code>Likewise Version 6.2.0</code><span> across both ESXi 7 and 8.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/esxi-likewise-agent-versions.max-1000x1000.png" alt="ESXi Likewise Agent versions">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="jbm7h">Figure 1: ESXi Likewise Agent versions</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The following table lists comparisons between native AD connection methods for both Virtual Center and ESXi.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Feature / Capability</strong></p>
</td>
<td>
<p><strong>ESXi Host</strong></p>
</td>
<td>
<p><strong>vCenter Server (VCSA)</strong></p>
</td>
</tr>
<tr>
<td>
<p><strong>AD Integration Method</strong></p>
</td>
<td>
<p><span>Integrated Windows Authentication (IWA) only</span></p>
</td>
<td>
<p><span>IWA and LDAP/LDAPS</span></p>
<p><span>Federated Identity (SAML, OIDC)</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Likewise Agent Used</strong></p>
</td>
<td>
<p><span>Yes – exclusively for IWA domain join and authentication</span></p>
</td>
<td>
<p><span>Yes – Used for IWA domain join only</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Authentication Protocols Supported</strong></p>
</td>
<td>
<p><span>Kerberos (via IWA only)</span></p>
</td>
<td>
<p><span>Kerberos (IWA), LDAP(S), SAML, OIDC</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Modern Auth Support (OIDC, SAML, FIDO2)</strong></p>
</td>
<td>
<p><span>Not supported </span></p>
</td>
<td>
<p><span>Not supported via AD</span></p>
<p><span>Supported only</span><strong> </strong><span>when using federated IdPs</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>MFA Support</strong></p>
</td>
<td>
<p><span>Not supported</span></p>
</td>
<td>
<p><span>Not supported via</span><strong> </strong><span>AD DS</span></p>
<p><span>Supported via Identity Federation (ADFS, Azure AD, etc.)</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Granular Role-Based Access Control (RBAC)</strong></p>
</td>
<td>
<p><span>Limited (via host profile or CLI only)</span></p>
</td>
<td>
<p><span>Advanced RBAC with vCenter SSO</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2><span>Why Not to Use Likewise-Based AD Integration (ESXi/vCenter)</span></h2>
<p><span>The following list contains considerations when using AD-based connections managed by the vSphere Likewise agent:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Deprecated software</strong><span>: Likewise is legacy software, no longer maintained or supported upstream.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>No support for modern authentication</strong><span>: Likewise only supports Integrated Windows Authentication (Kerberos) and offers no support for SAML, OIDC, or FIDO2.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>No MFA</strong><span>: Likewise cannot enforce contextual policies such as MFA, geolocation restrictions, or time-based access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Credential material stored locally</strong><span>: Kerberos keytabs and cached credentials are stored unencrypted on disk.</span></p>
</li>
</ul>
<p><span>VMware recommends leveraging identity federation with modern identity providers</span><strong>, </strong><span>bypassing the limitations of the legacy Likewise-based stack. Broadcom announced on March 25 that </span><a href="https://knowledge.broadcom.com/external/article/314324/removal-of-integrated-windows-authentica.html" rel="noopener" target="_blank"><span>IWA will be removed</span></a><span> in the next major release. </span></p>
<h2><span>The MFA Gap</span></h2>
<p><span>While AD integration offers administrative convenience, it introduces significant security limitations, particularly regarding MFA. Traditional AD authentication methods, including Kerberos and NTLM, are inherently single-factor. These protocols do not natively support MFA, and the vCenter Likewise integration does not extend AD MFA enforcement to vCenter or ESXi.</span></p>
<p><span>Critically, ESXi does not support MFA in any form, nor does it support identity federation, SAML, or modern protocols such as OIDC or FIDO2. Even for vCenter, MFA can only be applied to users within the vSphere.local domain (using mechanisms like RSA SecurID or RADIUS), but not to AD-joined users authenticated through IWA or LDAP/S.</span></p>
<p><span>Ancillary solutions can offer proxy-based MFA that integrate with AD to enforce MFA to vSphere. AuthLite extends the native AD login process by requiring a second factor during Windows authentication, which can indirectly secure vCenter access when Integrated Windows Authentication is used. Silverfort operates at the domain controller level, enforcing MFA on authentication flows in real time without requiring agents on endpoints or changes to vCenter. Both solutions can help enforce MFA into vSphere environments that lack native support for it, but they can also introduce caveats such as added complexity and potential authorization loops if AD becomes dependent on the same infrastructure they protect and the need to treat their control planes or virtual appliances as Tier 0 systems within the vSphere environment.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>As a result, in organizations that integrate vSphere with traditional Active Directory, all access to critical vSphere infrastructure (ESXi and Virtual Center) remains protected by password alone and no MFA.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>While it is technically possible to enforce MFA in vSphere through Active Directory Federation Services (ADFS), this approach requires careful consideration. It is important to note that ADFS is still a feature included in Windows Server 2025 and is not on any official deprecation list with an end-of-life date. However, the lack of significant new feature development compared to the rapid innovation in Microsoft Entra ID speaks to its status as a legacy technology. This is underscored by the extensive migration resources Microsoft now provides to move applications away from AD FS and into Entra ID.</span></p>
<p><span>Therefore, while ADFS remains a supported feature, for the purposes of securing vSphere it is a complex workaround that doesn't apply to direct ESXi access and runs contrary to Microsoft's clear strategic direction toward modern, cloud-based identity solutions.</span></p>
<p><span>Another common approach involves Privileged Access Management (PAM). While a PAM-centric strategy offers benefits like centralized control and session auditing, several caveats warrant consideration. PAM systems add operational complexity, and the vCenter session itself is typically not directly federated with the primary enterprise identity provider (like Entra ID or Okta). Consequently, context-aware conditional access policies are generally applied only at the initial PAM logon, not within the vCenter session itself.</span></p>
<p><span>Ultimately, these workarounds do not address the core issue: vSphere’s reliance on the Likewise agent and traditional AD protocols prevents native MFA enforcement for AD users, leaving the environment vulnerable.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>There is a reliance on a delegated logon based on AD password complexity, and any MFA would have to be at the network access layer or workstation login, not at the vCenter login prompt for those users.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2><span>The 'ESX Admins' Problem Is Not an ESXi Issue, It's a Trust Issue</span><strong> </strong></h2>
<p><span>In July 2024, </span><a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/" rel="noopener" target="_blank"><span>Microsoft published a blog post on CVE-2024-37085</span></a><span>, an "ESXi vulnerability" that was considered a critical issue, and one that vSphere promptly addressed in a patch release. The CVE, present in vSphere ESXi for many years, involved several ESXi advanced settings utilizing insecure default configurations. Upon joining an ESXi host to an AD domain, the "ESX Admins" AD group is automatically granted an ESXi Admin role, potentially expanding the scope of administrative access beyond the intended users.</span></p>
<p><span>These settings are configured by the following ESXi controls:</span></p>
<ol>
<li><strong>Config.HostAgent.plugins.hostsvc.esxAdminsGroupAutoAdd</strong>
<ul>
<li><strong>What it does</strong><span>: This setting controls whether users from a designated administrators group are automatically added to the host’s local administrative group.</span></li>
</ul>
</li>
<li><strong>Config.HostAgent.plugins.vimsvc.authValidateInterval</strong>
<ul>
<li><strong>What it does</strong><span>: This setting defines the time interval at which the host’s management services validate the authentication credentials (or tickets) of connected clients.</span></li>
</ul>
</li>
<li><strong>Config.HostAgent.plugins.hostsvc.esxAdminsGroup</strong>
<ul>
<li><strong>What it does:</strong><span> This parameter specifies the name (or identifier) of the group whose members are to be automatically considered for host administrative privileges (when auto-add is enabled by the first setting).</span></li>
</ul>
</li>
</ol>
<p><span>vSphere produced a manual workaround for <a href="https://knowledge.broadcom.com/external/article/369707/" rel="noopener" target="_blank">prior versions of vSphere ESXi 8.0 Update 3</a></span><span> based on the following settings:</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroupAutoAdd from true to </span><strong>false</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Config.HostAgent.plugins.vimsvc.authValidateInterval from 1440 to </span><strong>90</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroup from "ESX Admins" to </span><strong>""</strong><span> </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>The following is a configuration fix to default settings in vSphere ESXi 8.0 Update 3:</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroupAutoAdd from true to </span><strong>false</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Config.HostAgent.plugins.vimsvc.authValidateInterval from 1440 to </span><strong>90</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroup </span><strong>no change </strong><span>"ESX Admins"  </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>Integrating an ESXi host with Microsoft AD introduces a fundamental security issue that is often overlooked—the IdP's administrators effectively gain administrative control over the ESXi host and any other system relying on that trust. While a common perception, sometimes reinforced by narratives focusing on the endpoint, suggests the ESXi host itself is the primary vulnerability, the more critical security concern is the implicit, far-reaching administrative power wielded by the administrators of the trusted IdP, particularly when using AD authentication with ESXi.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>Administrators of Active Directory implicitly become administrators of any ESXi host that trusts it.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>Consequently, neither workarounds nor configuration fixes, which only adjust default settings, resolve this core problem when an ESXi host is joined to AD. The issue transcends specific CVEs; it stems from the inherent security implications of the implicit trust model itself, particularly when it involves systems like ESXi and AD, which already possess their own security vulnerabilities and are frequent targets for threat actors.</span></p>
<p><span>In respect of ESXi, context should be applied to the following: </span></p>
<ul>
<li role="presentation"><strong>Automatic full administrative access</strong><span>: When ESXi hosts are joined to AD, a default (or custom configured) AD group (e.g., "ESX Admins") is granted full root-level administrative privileges on the ESXi hosts. Any member of this AD group instantly gains unrestricted control of the ESXi host.</span></li>
<li role="presentation"><strong>Group name</strong><span>: If AD is compromised, threat actors can manipulate </span><strong>any</strong><strong> </strong><span>group name used for via the the </span><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroup </span><span>advanced setting, This is not limited to the group name “ESX Admins.”</span></li>
<li role="presentation"><strong>Lack of security identifier (SID) tracking:</strong><span> AD group names (not limited to “ESX Admins”) added to ESXi are not tracked by their SIDs. This means that a threat actor could rename or recreate a deleted AD group such as “ESX Admins” maintaining the same name in ESXi via Config.HostAgent.plugins.hostsvc.esxAdminsGroup and retain the elevated privileges. This is a limitation of the Likewise ESXi agent.</span></li>
<li role="presentation"><strong>Active Directory group management. </strong><span>Any threat actor looking to access a domain-joined ESXi host would need to simply require sufficient permissions to add themselves to the AD group defined via </span><span>Config.HostAgent.plugins.hostsvc.esxAdminsGroup.</span></li>
</ul>
<p><span>Recent discussions around vulnerabilities like CVE-2024-37085 have brought this security issue to the forefront: the inherent dangers of joining vSphere ESXi hosts directly to an AD domain. While such integration offers perceived management convenience, it establishes a level of trust that can be easily exploited.</span></p>
<h2><span>Why Your ESXi Hosts Should Never Be Active Directory Domain Joined</span></h2>
<p><span>Based on previous discussions we can confidently establish that joining an ESXi host to AD carries substantial risk. This is further endorsed where there is an absence of comprehensive ESXi security controls such as Secure Boot, TPM, execInstalledOnly, vCenter integration, comprehensive logging and SIEM integration. Compromised AD credentials tied to an ESXi-joined group will allow remote threat actors to readily exploit the elevated privileges, executing actions such as virtual machine shutdown and ransomware deployment via SSH. These risks can be summarized as follows:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>No MFA support: </strong><span>ESXi does not support MFA for AD users. Domain joining exposes critical hypervisor access to single-factor password-based authentication.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Legacy authentication protocols: </strong><span>ESXi relies on IWA and Kerberos / NTLM / Windows Session Authentication (SSPI)—outdated protocols vulnerable to various attacks, including pass-the-hash and credential relay.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Likewise agent is deprecated: </strong><span>The underlying Likewise agent is a discontinued open-source project. Continued reliance on it introduces maintenance and security risks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>No modern authentication integration: </strong><span>ESXi does not support federated identity, SAML, OIDC, FIDO2, or conditional access. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>AD policy enforcement is absent: </strong><span>Group Policy Objects (GPOs), conditional access, and login time restrictions do not extend to ESXi via AD join, undermining centralized security controls.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Complexity without benefit: </strong><span>Domain joining adds administrative overhead without offering meaningful security gains — especially when using vCenter as the primary access point.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Limited role mapping granularity: </strong><span>Group-based role mappings on ESXi are basic and cannot match the RBAC precision available in vCenter, reducing access control fidelity.</span></p>
</li>
</ul>
<p><span>To securely remove ESXi hosts from AD, a multistep process is required to shift access management explicitly to vCenter. This involves assessing current AD usage, designing granular vCenter roles, configuring vCenter's RBAC, removing hosts from the domain via PowerCLI, and preventing future AD re-integration. All management then moves to vCenter, with direct ESXi access minimized. This comprehensive approach prioritizes security and efficiency by moving away from AD reliance for ESXi authentication and authorization towards a vCenter-centric, granular RBAC model. vSphere explicitly discourages joining ESXi hosts to AD:</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>“</span><span>ESXi can be joined to an Active Directory domain as well, and that functionality continues to be supported. We recommend directing all configuration &amp; usage through the Role-Based Access Controls (RBAC) present in vCenter Server, though."</span></p>
<p><span>Source: <a href="https://blogs.vsphere.com/vsphere/2020/05/vsphere-7-integrated-windows-authentication-iwa-ldap.html" rel="noopener" target="_blank">VMware</a></span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2><span>vSphere Virtual Center — The Primary Target</span></h2>
<p><span>vSphere vCenter Server represents a strategic objective for threat actors due to its authoritative role as the centralized management for virtualized infrastructure. A compromised vCenter instance effectively cedes comprehensive administrative control over the entire virtual estate, encompassing all connected ESXi hypervisors, virtual machines, datastores, and virtual network configurations. </span></p>
<p><span>Through its extensive Application Programming Interfaces (APIs), adversaries can programmatically manipulate all managed ESXi hosts and their resident virtual machines, enabling actions such as mass ransomware deployment, large-scale data exfiltration, the provisioning of rogue virtual assets, or the alteration of security postures to evade detection and induce widespread operational disruption. </span></p>
<p><span>Furthermore, the vCenter Server appliance itself can be subverted by implanting persistent backdoors, thereby establishing covert command-and-control (C2) channels that allow for entrenched persistence and continued malicious operations. Consequently, its critical function renders vCenter a high-value target. The following should be considered:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Coupled security dependency (compromise amplification risk): </strong><span>Directly linking vCenter to AD makes vSphere security dependent on AD's integrity. As AD is a prime target, compromising privileged AD accounts mapped to vCenter grants immediate, potentially unrestricted administrative access to the virtual infrastructure, bypassing vSphere-specific security layers. Insufficient application of least privilege for AD accounts in vSphere magnifies this risk.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Single-factor authentication weakness (credential compromise risk): </strong><span>Relying solely on AD password validation makes vCenter highly vulnerable to common credential compromise methods (phishing, brute-force, spraying, stuffing, malware). Without mandatory MFA, a single stolen password for a privileged AD account allows complete authentication bypass, enabling unauthorized access, data breaches, ransomware, or major disruptions.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Lack of native MFA: </strong><span>The direct vsphere.local-to-AD integration offers no built-in enforcement of strong authentication like phishing resistant FIDO2 . While compatibility exists for external systems (Smart Cards, RSA SecurID), these require separate, dedicated infrastructure and are not inherent features, leaving a significant authentication assurance gap if unimplemented.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Facilitation of lateral movement and privilege escalation: </strong><span>Compromised AD credentials, even non-administrative ones with minimal vSphere rights, allow threat actors initial vCenter access. vCenter can then be exploited as a pivot point for further network infiltration, privilege escalation within the virtual environment, or attacks on guest systems via console/API access, all stemming from the initial single-factor credential compromise.</span></p>
</li>
</ul>
<p><span>Integrating vSphere vCenter directly with AD for identity management, while common, inherently introduces significant security vulnerabilities stemming from coupled dependencies, reliance on single-factor authentication, a lack of native strong MFA, and facilitated attack pathways. These not only critically expose the virtual infrastructure but also provide avenues to exploit the VCSA appliance's attack surface, such as its underlying Linux shell and the lack of comprehensive endpoint detection and response (EDR) capabilities.</span></p>
<h2><span>Securing vSphere: The Tier 0 Challenge</span></h2>
<p><span>The widespread practice of running Tier 0 services—most critically, AD domain controllers (often used for direct Identity integration)—directly on vSphere hypervisors introduces a significant and often overlooked security risk. By placing Active Directory Domain Controllers on vSphere, any successful attack against the hypervisor effectively hands threat actors the keys to the entire AD environment, enabling complete domain takeover. Mandiant observes that a general lack of awareness and proactive mitigation persists.</span></p>
<p><span>The danger is significant and present, for example, even for vSphere permissions that appear low-risk or are operationally common. For example, the privilege to snapshot an AD virtual machine can be weaponized for complete AD takeover. This specific vSphere capability, often assigned for backup routines, enables offline NTDS.dit (AD database) exfiltration. This vSphere-level action renders many in-guest Windows Server security controls ineffective, bypassing not only traditional measures like strong passwords and MFA, but also advanced protections such as LSASS credential guard and EDR, which primarily monitor activity </span><span>within</span><span> the operating system. This effectively paves a direct route to full domain compromise for a threat actor possessing this specific permission. </span></p>
<p><span>Mandiant observed these tactics, techniques, and procedures (TTPs) attributed to various ransomware groups across multiple incidents. The absence of VM encryption and logging makes this a relatively simple task to obtain the AD database while being undetected.</span></p>
<p><span>The following table contains a list of sample threats matched to related permissions:</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Threat </strong></p>
</td>
<td>
<p><strong>Risk</strong></p>
</td>
<td>
<p><strong>Minimum vSphere Permission Required</strong></p>
</td>
</tr>
<tr>
<td>
<p><strong>Unencrypted vMotion</strong></p>
</td>
<td>
<p><span>Memory-in-transit (e.g., LSASS, krbtgt hashes) can be captured during migration.</span></p>
</td>
<td>
<p><strong>Role:</strong><span> Virtual Machine Power User or higher </span><strong>Permission</strong><span>: Host &gt; Inventory &gt; Migrate powered on virtual machine</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Unencrypted VM Disks</strong></p>
</td>
<td>
<p><span>AD database (NTDS.dit), registry hives, and password hashes can be stolen from VMDKs.</span></p>
</td>
<td>
<p><strong>Role</strong><span>: Datastore Consumer, VM Admin or higher. </span><strong>Permission </strong><span>Datastore &gt; Browse, Datastore &gt; Low level file operations</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Snapshot Creation</strong></p>
</td>
<td>
<p><span>Snapshots preserve memory and disk state; can be used to extract in-memory credentials.</span></p>
</td>
<td>
<p><strong>Role</strong><span>: Virtual Machine Power User or higher. </span><strong>Permission</strong><span>: Virtual Machine &gt; State &gt; Create Snapshot</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Mounting VMDK to another VM</strong></p>
</td>
<td>
<p><span>Enables offline extraction of AD secrets (e.g., NTDS.dit, registry, SYSVOL).</span></p>
</td>
<td>
<p><strong>Role</strong><span>: VM Admin or custom with disk-level access. </span><strong>Permission </strong><span>Virtual Machine &gt; Configuration &gt; Add existing disk, Datastore &gt; Browse</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Exporting / Cloning VM</strong></p>
</td>
<td>
<p><span>Enables offline AD analysis, allowing credential extraction or rollback attacks.</span></p>
</td>
<td>
<p><strong>Role</strong><span>: Virtual Machine Administrator or higher. </span><strong>Permission: </strong><span>Virtual Machine &gt; Provisioning &gt; Clone, Export OVF Template</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Console Access (VMRC / Web Console)</strong></p>
</td>
<td>
<p><span>Full keyboard/video access enables manual attacks or credential harvesting.</span></p>
</td>
<td>
<p><strong>Role</strong><span>: Virtual Machine User or higher. </span><strong>Permission:</strong><span> Virtual Machine &gt; Interaction &gt; Console interaction</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>vNIC on Improper VLAN</strong></p>
</td>
<td>
<p><span>VM exposed to lateral movement or direct attack from compromised systems.</span></p>
</td>
<td>
<p><strong>Role:</strong><span> Virtual Machine Admin or custom. </span><strong>Permission</strong><span>: Virtual Machine &gt; Configuration &gt; Modify device settings</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Copy/Paste via vSphere Tools</strong></p>
</td>
<td>
<p><span>Silent exfiltration of credentials/scripts via clipboard or drag/drop.</span></p>
</td>
<td>
<p><span>No specific vCenter privilege — host config or tools policy used</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>BIOS/Boot Order Abuse</strong></p>
</td>
<td>
<p><span>ISO boot enables password resets, security bypass, or persistence.</span></p>
</td>
<td>
<p><strong>Role:</strong><span> Virtual Machine Admin or custom. </span><strong>Permission:</strong><span> Virtual Machine &gt; Configuration &gt; Modify device settings</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p><span>Delegation of trust from vSphere vCenter to AD grants implicit administrator privileges on the trusted systems to any AD domain administrator. This elevates the risk profile of AD compromise, impacting the entire infrastructure. To mitigate this, implement a two-pronged strategy: first, create a separate, dedicated vSphere environment specifically for the most critical Tier 0 assets, including AD. This isolated environment should be physically or logically separated from other systems and highly secured with robust network segmentation. Second, implement a zero-trust security model for the control plane of this environment, verifying every access request regardless of source. Within this isolated environment, deploy a dedicated "infrastructure-only" IdP (on-premises or cloud). Implementing the principle of least privilege is paramount. </span></p>
<p><span>A dedicated, isolated vSphere environment for Tier 0 assets (e.g., Active Directory) should have strictly limited administrative access (via a PAW), granting permissions only to those directly managing the infrastructure. This significantly reduces the impact of a breach by preventing lateral movement and minimizing damage. Unnecessary integrations should be avoided to maintain the environment's security and adhere to the least-privilege model.</span></p>
<p><span>To effectively safeguard critical Tier 0 assets operating within the vSphere environment–specifically systems like Privileged Access Management (PAM), Security Information and Event Management (SIEM) virtual appliances, and any associated AD tools deployed as virtual appliances–a multilayered security approach is essential. These assets must be treated as independent, self-sufficient environments. This means not only isolating their network traffic and operational dependencies but also, critically, implementing a dedicated and entirely separate identity provider (IdP) for their authentication and authorization processes. For the highest level of assurance, these Tier 0 virtual machines should be hosted directly on dedicated physical servers. This practice of physical and logical segregation provides a far greater degree of separation than shared virtualized environments. </span></p>
<p><span>The core objective here is to break the authorization dependency chain, ensuring that credentials or permissions compromised elsewhere in the network cannot be leveraged to gain access to these Tier 0 systems. This design creates defense in depth security barriers, fundamentally reducing the likelihood and impact of a complete system compromise.</span></p>
<h2><span>Conclusion</span></h2>
<p><span>Mandiant has observed that threat actors are increasingly targeting vSphere, not just for ransomware deployment, but also as a key avenue for data exploitation and exfiltration. This shift is demonstrated by recent threat actor activity observed by GTIG, where adversaries have leveraged compromised vSphere environments to exfiltrate sensitive data such as AD databases before or alongside ransomware execution.</span></p>
<p><span>As this document has detailed, the widespread reliance on vSphere, coupled with often underestimated risks inherent in its integration with AD and the persistence of insecure default configurations, creates a dangerously vulnerable landscape. Threat actors are not only aware of these weaknesses but are actively exploiting them with sophisticated attacks increasingly targeting ESXi and vCenter to achieve maximum impact.</span></p>
<p><span>The usability and stability that make vSphere a foundational standard for on-premise and private clouds can be misleading; they do not equate to inherent security. The evolution of the threat landscape, particularly the direct targeting of the hypervisor layer which bypasses traditional endpoint defenses, necessitates a fundamental shift in how vSphere security is approached. Relying on outdated practices, backups, perimeter defenses alone, or assuming EDR on guest VMs provides sufficient protection for the underlying infrastructure creates significant security gaps and exposes an organization to severe risks.</span></p>
<p><span>Identity integration vulnerabilities will be exploited, therefore, organizations are strongly urged to immediately assess their vSphere environment's AD integration status and decisively prioritize the implementation of the mitigation strategies outlined in this document. This proactive stance is crucial to effectively counter modern threats and includes:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><strong>Decoupling critical dependencies:</strong><span> Severing direct ESXi host integration with AD is paramount to shrinking the AD attack surface.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing authentication:</strong><span> Implementing robust, phishing-resistant MFA for vCenter, preferably via identity federation with modern IdPs, is no longer optional but essential.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Systematic hardening:</strong><span> Proactively addressing the insecure defaults for ESXi and vCenter, enabling features like execInstalledOnly, Secure Boot, TPM, Lockdown Mode, and configuring stringent firewall rules.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enhanced visibility:</strong><span> Implementing comprehensive remote logging for both ESXi and vCenter, feeding into a SIEM with use cases specifically designed to detect hypervisor-level attacks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Protecting Tier 0 assets:</strong><span> Strategically isolating critical workloads like Active Directory Domain Controllers in dedicated, highly secured vSphere environments with strict, minimized access controls and encrypted VMs and vMotion.</span></p>
</li>
</ol>
<p><span>The upcoming </span><a href="https://blogs.vmware.com/cloud-foundation/2025/03/31/reminder-vsphere-7-to-reach-end-of-service-october-2-2025/" rel="noopener" target="_blank"><span>end-of-life for vSphere 7 in October 2025</span></a><span> means that vast numbers of organizations will not be able to receive product support, security patches and updates for a product that underpins Infrastructure. This presents a critical juncture for organizations and a perfect storm for threat actors. The transition away from vSphere 7 should be viewed as a key opportunity to re-architect for security, not merely a routine upgrade to implement new features and obtain support. Failure to proactively address these interconnected risks by implementing these recommended mitigations will leave organizations exposed to targeted attacks that can swiftly cripple their entire virtualized infrastructure, leading to operational disruption and financial loss. The time to adopt a resilient, defense-in-depth security posture to protect these critical vSphere environments is unequivocally now.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chromium]]></title>
<description><![CDATA[After reading this
post
at “Linux Today” I decided to install the so expected Linux version of
Chrome, the Google’s browser.
As I use Arch Linux, I haven’t expected to have a compiled version
linked directly by the chromium’s website. Instead, I was hoping Arch’s
developers already packaged it. A...]]></description>
<link>https://tsecurity.de/de/3501265/downloads/chromium/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501265/downloads/chromium/</guid>
<pubDate>Fri, 08 May 2026 23:07:43 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>After reading <a href="http://www.linuxtoday.com/developer/2009060502035RVDTNT" title="Chrome on Linux: Rough, fast &amp; promising">this
post</a>
at “Linux Today” I decided to install the so expected Linux version of
Chrome, the Google’s browser.</p>
<p>As I use Arch Linux, I haven’t expected to have a compiled version
linked directly by the chromium’s website. Instead, I was hoping Arch’s
developers already packaged it. And, with no big surprises, they did.
Just to clarify a thing before continuing:
<a href="http://chromium.org/" title="Chromium">Chromium</a> is the open source projected
behind Chrome (which is not opensource).</p>
<p>I’m not writing this post to repeat what’s already written there. So
read it too. As opposed to his …</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser war continues…]]></title>
<description><![CDATA[One month ago I wrote a post talking about the new Chrome for linux, or
better yet, that the Chromium (this one is opensource) is finally
working well under Linux, and so fast.
Well, while the Chromium guys are working hard to get a decent browser,
the firefox guys didn’t stop working and last we...]]></description>
<link>https://tsecurity.de/de/3501261/downloads/the-browser-warcontinues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501261/downloads/the-browser-warcontinues/</guid>
<pubDate>Fri, 08 May 2026 23:07:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One month ago I wrote a post talking about the new Chrome for linux, or
better yet, that the Chromium (this one is opensource) is finally
working well under Linux, and so fast.</p>
<p>Well, while the Chromium guys are working hard to get a decent browser,
the firefox guys didn’t stop working and last week Mozilla released the
so waited Firefox 3.5.</p>
<!--more-->

<p>My 2 biggest complaints about the prior version were that (i) the
awesome bar gets slow as time pass and you visit a lot of sites and (ii)
the start up time. The first one I …</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Por uma web melhor e mais segura]]></title>
<description><![CDATA[Hoje adicionei no site um script para alertar usuários que usam versões
antigas (e inseguras) de browsers. O projeto é o “Salve a Web, por
favor”. Ele é opensource e pode ser visto no repositório do
github.
Basta carregar o script com a seguinte entrada na sua página:



Acho que pela própria nat...]]></description>
<link>https://tsecurity.de/de/3501221/downloads/por-uma-web-melhor-e-maissegura/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501221/downloads/por-uma-web-melhor-e-maissegura/</guid>
<pubDate>Fri, 08 May 2026 23:06:59 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hoje adicionei no site um script para alertar usuários que usam versões
antigas (e inseguras) de browsers. O projeto é o “Salve a Web, por
favor”. Ele é opensource e pode ser visto no repositório do
<a href="https://github.com/globocom/sawpf" title="Salve a web, por favor">github</a>.
Basta carregar o script com a seguinte entrada na sua página:</p>
<div class="highlight"><pre><span></span><code><span class="p">&lt;</span><span class="nt">script</span> <span class="na">type</span><span class="o">=</span><span class="s">"text/javascript"</span> <span class="na">src</span><span class="o">=</span><span class="s">"http://sawpf.com/1.0.js"</span><span class="p">&gt;&lt;/</span><span class="nt">script</span><span class="p">&gt;</span>
</code></pre></div>

<p>Acho que pela própria natureza dos posts no meu blog, a divisão dos
browsers não é parecida com aquela global, em que o Internet Explorer
ainda é o browser mais usado. Porém acho importante alerr os usuários.
Quem sabe poderemos …</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ANNOUNCE: codespell 1.4]]></title>
<description><![CDATA[codespell 1.4 is out! Nothing really new, just a maintenance release: 1
bug fix and some new entries to the dictionary. See the entire
announcement on its mailing
list.
As per patches I’m receiving it seems that codespell is
being successfully used by opensource projects. I’m glad codespell can
h...]]></description>
<link>https://tsecurity.de/de/3501203/downloads/announce-codespell14/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501203/downloads/announce-codespell14/</guid>
<pubDate>Fri, 08 May 2026 23:06:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>codespell 1.4 is out! Nothing really new, just a maintenance release: 1
bug fix and some new entries to the dictionary. See the entire
announcement on its <a href="http://groups.google.com/group/codespell/browse_thread/thread/35f5572eb201f9ce">mailing
list</a>.</p>
<p>As per patches I’m receiving it seems that codespell is
being successfully used by opensource projects. I’m glad codespell can
help those projects, particularly people who don’t have English as their
mother tongue as I don’t. It’s also an opportunity to people starting on
a project, <a href="https://politreco.com/2011/11/linuxcon-brazil/">as I said in last LinuxCon
Brazil</a>.</p>
<p>I’m not submitting patches anymore to Linux kernel myself using
codespell …</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPL violations close to home]]></title>
<description><![CDATA[Many times I hear about GPL violations in vendors software, especially it seems in embedded routers. There are two cases which hit me in my home.The first is our FIOS router which is an Actionec MI424-WR which runs Linux inside. You can even get to a telnet prompt. The problem is that it has a cr...]]></description>
<link>https://tsecurity.de/de/3500987/unix-server/gpl-violations-close-to-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500987/unix-server/gpl-violations-close-to-home/</guid>
<pubDate>Fri, 08 May 2026 23:01:15 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Many times I hear about GPL violations in vendors software, especially it seems in embedded routers. There are two cases which hit me in my home.<br><br>The first is our <a href="http://verizon.com/fios">FIOS</a> router which is an <a href="http://www.fibercrap.com/article/actiontec-mi424wr-router-fios-weapon-of-choice-1150-1.html">Actionec MI424-WR</a> which runs Linux inside. You can even get to a telnet prompt. The problem is that it has a crappy DHCP server and always seems to assign different IP addresses even to the same MAC address. This breaks ssh and other services which do strong man-in-the-middle prevention.  It seem the vendor hasn't fixed the problem, but as a <a href="http://www.softwarefreedom.org/news/2007/dec/07/busybox/">result of a GPL violations sui</a>t the <a href="http://opensource.actiontec.com/">some source is available</a> but the DHCP code is not included probably because it is BSD licensed so they don't have to. Given this I'll just punt and do the lazy solution and just turn it into an dumb Ethernet bridge and use something better like <a href="http://www.vyatta.com/products/hardware_appliances.php">Vyatta V514</a> test box or<a href="http://en.wikipedia.org/wiki/Linksys_WRT54G_series"> Linksys WR54TG</a>, both of which are repairable.<br><br>The second is the <a href="http://www.asus.com/products.aspx?l1=3&amp;l2=179&amp;l3=815&amp;l4=0&amp;model=2593&amp;modelmenu=1">Asus P6T motherboard</a> which has a <a href="http://hardware.slashdot.org/article.pl?no_d2=1&amp;sid=08/05/14/173220">SplashVM</a> feature. This allows booting to a lightweight desktop in less than a minute (the BIOS is still slow to get its hardware setup).  The desktop is based on Linux with standard kernel and browser. It is kind of a toy, but good for checking gmail etc. Since SplashVM is using GPL, if the vendor was following the GPL license I should be able to find the source on their website. It is possible to <a href="http://www.splashtop.com/open_source.php">find some pieces on the Splashtop vendor website</a>, but it is the responsibility of the system vendor not the subcontractor to make available the source for the <span>actual</span> firmware they are shipping. In this case, it matters to me for a couple of reasons. I wrote the driver for the  Marvell Yukon-2 EC Ultra NIC's on this motherboard and would like to know if 1) the vendor fixed some bugs 2) the vendor still has some bugs that other users will pester me about. As copyright holder for this driver, I may have to go nasty to find out; stay tuned.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mailing List hosting for FOSS Projects]]></title>
<description><![CDATA[Recently I've encountered several occasions in which a FOSS project would
have been interested in some reliable, independent mailing list hosting for
their project communication.
I was surprised how difficult it was to find anyone running such a service.
From the user / FOSS project point of view...]]></description>
<link>https://tsecurity.de/de/3500685/unix-server/mailing-list-hosting-for-foss-projects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500685/unix-server/mailing-list-hosting-for-foss-projects/</guid>
<pubDate>Fri, 08 May 2026 22:52:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Recently I've encountered several occasions in which a FOSS project would
have been interested in some reliable, independent mailing list hosting for
their project communication.</p>
<p>I was surprised how difficult it was to find anyone running such a service.</p>
<p>From the user / FOSS project point of view, the criteria that I would have are:</p>
<ul class="simple">
<li><p>operated by some respected entity that is unlikely to turn hostile,
discontinue the service or go out of business altogether</p></li>
<li><p>free of any type of advertisements (we all know how annoying those are)</p></li>
<li><p>cares about privacy, i.e. doesn't sell the subscriber lists or
non-public archives</p></li>
<li><p>use FOSS to run the service itself, such as GNU mailman, listserv,
ezmlm, ...</p></li>
<li><p>an easy path to migrate away to another service (or self-hosting) as
they grow or their requirements change.  A simple mail forward to that
new address for the related addresses is typically sufficient for that</p></li>
</ul>
<p>If you think mailing lists serve no purpose these days anyways, and
everyone is on github:  Please have a look at the many thousands of FOSS
project mailing lists out there still in use.  Not everyone wants to
introduce a dependency to the whim of a proprietary
software-as-a-service provider.</p>
<p>I never had this problem as I always hosted my own mailman instance on
lists.gnumonks.org anyway, and all the entities that I've been involved
in (whether non-profit or businesses) had their own mailing list hosts.
From franken.de in the 1990ies to netfilter.org, openmoko.org and now
osmocom.org, we all pride oursevles in self-hosting.</p>
<p>But then there are plenty of smaller projects that neither have the
skills nor the funding available.  So they go to yahoo groups or some
other service that will then hold them hostage without a way to switch
their list archives from private to public, without downloadable
archives or forwarding in the case they want to move away :(</p>
<p>Of course the larger FOSS projects also have their own list servers,
starting from vger.kernel.org to Linux distributions like Debian
GNU/Linux.  But what if your FOSS project is not specifically <em>Linux</em>
related?</p>
<p>The sort-of obvious candidates that I found all don't really fit:</p>
<ul class="simple">
<li><p><a class="reference external" href="https://lists.gnu.org/">https://lists.gnu.org/</a> is for official GNU projects</p></li>
<li><p><a class="reference external" href="https://lists.nongnu.org/">https://lists.nongnu.org/</a> is for projects on <a class="reference external" href="http://savannah.nongnu.org/">Savannah</a> (which is much more than just a
mailing list service, many projects don't need or want a "Forge")</p></li>
<li><p><a class="reference external" href="https://vger.kernel.org/">https://vger.kernel.org/</a> is specifically for Linux kernel development</p></li>
<li><p><a class="reference external" href="https://lists.freedesktop.org/">https://lists.freedesktop.org/</a> is specifically for desktop/UI related projects</p></li>
<li><p><a class="reference external" href="https://mail.kde.org/mailman/listinfo/">https://mail.kde.org/mailman/listinfo/</a> is hosting lists for KDE related projects</p></li>
<li><p><a class="reference external" href="https://mail.gnome.org/mailman/listinfo/">https://mail.gnome.org/mailman/listinfo/</a> likewise for Gnome projects</p></li>
<li><p><a class="reference external" href="http://lists.fsfe.org/">http://lists.fsfe.org/</a> appears to be for FSFE specific/internal lists only, and not a public service</p></li>
<li><p><a class="reference external" href="http://lists.spi-inc.org/">http://lists.spi-inc.org/</a> likewise is for SPI's own lists only</p></li>
<li><p><a class="reference external" href="https://opensource.org/lists">https://opensource.org/lists</a> also only runs lists for themselves</p></li>
<li><p><a class="reference external" href="http://lists.digitalfreedomfoundation.org/lists/listinfo">http://lists.digitalfreedomfoundation.org/lists/listinfo</a> has no public lists</p></li>
<li><p><a class="reference external" href="http://lists.jpberlin.de/">http://lists.jpberlin.de/</a> hosts tons of mailing lists for any kind of
topic, but is a paid service</p></li>
<li><p><a class="reference external" href="https://wiki.list.org/COM/Mailman%20hosting%20services">https://wiki.list.org/COM/Mailman%20hosting%20services</a> lists various
other paid services</p></li>
</ul>
<p>Now don't get me wrong, I'm of course not <em>expecting</em> that there are
commercial entities operating free-of charge list hosting services where
you neither pay with money, nor your data, nor by becoming a spam
receiver.</p>
<p>But still, in the wider context of the Free Software community, I'm
seriously surprised that none of the various non-for-profit /
non-commercial foundations or associations are offering a public mailing
list hosting service for FOSS projects.</p>
<p>One can of course always ask any from the above list and ask for a
mailing list even though it's strictly speaking off-topic to them.  But
who will do that, if he has to ask uninvited for a favor?</p>
<p>I think there's something missing.  I don't have the time to set up a
related service, but I would certainly want to contribute in terms of
funding in case any existing FOSS related legal entity wanted to
expand.  If you already have a legal entity, abuse contacts, a team of
sysadmins, then it's only half the required effort.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2013-1759 | Opensource Technologies Responsive Logo Slideshow cross site scripting (Bug 120379 / XFDB-82165)]]></title>
<description><![CDATA[A vulnerability has been found in Opensource Technologies Responsive Logo Slideshow and classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2013-1759. It is possible to initiate the attack remotely. There is...]]></description>
<link>https://tsecurity.de/de/3497827/sicherheitsluecken/cve-2013-1759-opensource-technologies-responsive-logo-slideshow-cross-site-scripting-bug-120379-xfdb-82165/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497827/sicherheitsluecken/cve-2013-1759-opensource-technologies-responsive-logo-slideshow-cross-site-scripting-bug-120379-xfdb-82165/</guid>
<pubDate>Fri, 08 May 2026 04:54:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/opensource_technologies:responsive_logo_slideshow">Opensource Technologies Responsive Logo Slideshow</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2013-1759">CVE-2013-1759</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Geodata für Ulm - ein Ansatz für das Crowdsourcing von Geodaten auch für nicht OSM'ler (fossgis2014)]]></title>
<description><![CDATA[Das Schlagwort OpenData geistert seit einiger zeit durch Deutschlands Verwaltungen. Und zu Recht, denn immer mehr Menschen interessieren sich heutzutage für öffentlich zugängliche Daten, insbesondere auch für Geodaten - zahlreiche Beispiele für kostenfreie Services und Anwendungen, die die Geodat...]]></description>
<link>https://tsecurity.de/de/3497054/it-security-video/open-geodata-fuer-ulm-ein-ansatz-fuer-das-crowdsourcing-von-geodaten-auch-fuer-nicht-osmler-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497054/it-security-video/open-geodata-fuer-ulm-ein-ansatz-fuer-das-crowdsourcing-von-geodaten-auch-fuer-nicht-osmler-fossgis2014/</guid>
<pubDate>Thu, 07 May 2026 20:19:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Schlagwort OpenData geistert seit einiger zeit durch Deutschlands Verwaltungen. Und zu Recht, denn immer mehr Menschen interessieren sich heutzutage für öffentlich zugängliche Daten, insbesondere auch für Geodaten - zahlreiche Beispiele für kostenfreie Services und Anwendungen, die die Geodaten als OpenData für den Nutzer frei zur Verfügung stellen, finden sich im Internet. Es geht hierbei außerdem häufig nicht nur um reines „Gucken“, sondern zunehmend auch um das Mitmachen und Mitgestalten von Geodaten durch den Nutzer selbst. OpenStreetMap ist ein leuchtendes Beispiel dafür.

Aus diesen Überlegungen heraus wurde 2012 in einer Vorstudie geprüft, wie sich die Stadt Ulm am OpenData-Gedanken beteiligen kann. Im Frühjahr 2013 wurde dann das Projekt „map-it.ulm.de“ als eine Anwendung zum Sammeln von freien Daten über die Bürger einer Stadt im Rahmen der Gesamtumsetzung des öffentlichen Geoportals der Stadt Ulm verwirklicht.

Das Projekt hat mit der 1. Aktion „Zeig mir deinen Lieblingsplatz!“ Ende Juni 2013 begonnen. Das Ziel war, die meist geliebten Orte in Ulm und Umgebung, aufgeteilt in 5 Kategorien, über Eintragung in der Karte durch Ditigalizieren zu sammeln und diese zu bewerten. Zu diesem Zweck wurde eine auf der OpenSource JavaScript Bibliotheken Ext JS 4.1.1, OpenLayers 2.12 und GeoExt 2 GIS-Applikation entwickelt. Durch die benutzerfreundliche Bedienung und zahlreiche Texthinweise konnte die Eintragung von Lieblingsplätzen sehr intuitiv gestaltet werden. In knapp 2 Wochen wurden auf diese Art und Weise über 450 POIs gesammelt, mehr als 900 Menschen haben am Projekt teilgenommen. Der gesammelte Datensatz wurde anschließend im Geoportal der Stadt Ulm veröffentlicht, mit den OSM POI-Daten abgeglichen und ist jederzeit zum Anschauen und Download als Open Data abrufbar.

Dieser Vortrag soll einen Ausblick über verwendete Techniken und Ideen zur Projektrealisierung geben und diskutieren, ob und wie dies ein Weg sein kann, einfache POI-Daten, auch für OpenStreetMap zu sammeln.
about this event: https://fossgis-konferenz.de/2014/programm/events/729.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Hochgenaue Zeit- und Positionsbestimmung (fossgis2014)]]></title>
<description><![CDATA[Eine Einführung in die Funktionsweise von Satellitenpositionsbestimmung mit interessanten und spannenden Details, die auch die Relevanz hochgenauer Positionsbestimmung für OpenStreetMap nicht vermissen lässt.

Die Grundlagen der Satellitenpositionsbestimmung sind den meisten wohl
bekannt. Dennoch...]]></description>
<link>https://tsecurity.de/de/3496966/it-security-video/hochgenaue-zeit-und-positionsbestimmung-fossgis2014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496966/it-security-video/hochgenaue-zeit-und-positionsbestimmung-fossgis2014/</guid>
<pubDate>Thu, 07 May 2026 19:49:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine Einführung in die Funktionsweise von Satellitenpositionsbestimmung mit interessanten und spannenden Details, die auch die Relevanz hochgenauer Positionsbestimmung für OpenStreetMap nicht vermissen lässt.

Die Grundlagen der Satellitenpositionsbestimmung sind den meisten wohl
bekannt. Dennoch bieten die Funktionsweise und Betriebsbedingungen von
GPS und Co. viele interessante und spannende Details. Z.B. wurde der
künstliche Fehler von GPS abgeschaltet, damit das US-Militär erhöhte
Positionsgenauigkeit im Golfkrieg erhielt.

Dieser Vortrag führt in die Funktionsweise von GPS ein, und zeigt
viele Erweiterungen zur Erhöhung der Genauigkeit, die von den
Systemarchitekten nie vorgesehen waren. Dies führt bis zu modernen
Verfahren für RTKs, die in Echtzeit Positionsbestimmungen im
Millimeterbereich ermöglichen.

Neben dieser Funktionsbeschreibung soll der Vortrag vor allem aber
auch einen Überblick bieten, wie diese Hochgenauigkeit mit kleinen
Tricks auch mit handelsüblicher Hardware und OpenSource-Software
möglich ist und wieviel davon auch im Handy erreicht werden kann. Dass
diese exakte Positionsbestimmung auch in Zeiten hochauflösender
Satellitenbilder nicht nur dem Selbstzweck dient wird abschließend
anhand möglicher Anwendungen aufgezeigt und vorgestellt.
about this event: https://fossgis-konferenz.de/2014/programm/events/685.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo Demand Is So High Apple Needs More A18 Pro Chips]]></title>
<description><![CDATA[Apple’s $599 MacBook Neo has turned into the kind of hit Apple usually wants, but its success now creates a pricing problem. Demand has pushed Apple to raise production plans, while higher chip and DRAM costs threaten the low price that made the laptop so attractive in the first place.



The Neo...]]></description>
<link>https://tsecurity.de/de/3496877/ios-mac-os/macbook-neo-demand-is-so-high-apple-needs-more-a18-pro-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496877/ios-mac-os/macbook-neo-demand-is-so-high-apple-needs-more-a18-pro-chips/</guid>
<pubDate>Thu, 07 May 2026 19:12:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s $599 MacBook Neo has turned into the kind of hit Apple usually wants, but its success now creates a pricing problem. Demand has pushed Apple to raise production plans, while higher chip and DRAM costs threaten the low price that made the laptop so attractive in the first place.



The Neo’s appeal is easy to understand. It gives students, families, and Chromebook buyers a real Mac at a price that does not feel out of reach. That matters because the $599 model opened macOS to buyers who would normally pick a low-end Windows laptop or a ChromeOS machine instead.



Apple underestimated demand



Apple has already admitted that the MacBook Neo is supply-constrained, and CEO Tim Cook addressed the issue during the company’s April 30 investor call.




“Right now we’re supply-constrained on the MacBook Neo. We were very bullish on the product before announcing it, but we under-called the level of enthusiasm that would be with it.”




Tim Culpan reports that Apple now wants suppliers to prepare for around 10 million MacBook Neo units, nearly double the original estimate of 5 million to 6 million. That decision keeps the product in customers’ hands, but it also changes the economics behind the laptop.



The cheap chips are running out



The first MacBook Neo batch reportedly used downbinned A18 Pro chips originally meant for the iPhone 16 Pro. These chips had one GPU core disabled, which matched the Neo’s advertised five-core GPU setup and helped Apple control costs.



That trick does not work forever. Apple now needs TSMC to produce a new batch of A18 Pro chips for extra Neo units. Many of those chips will likely be fully functional, which means Apple still ships them with one GPU core turned off, but pays more than it did for the earlier downbinned stock.



At the same time, DRAM prices have climbed, which puts more pressure on the Neo’s bill of materials.



The $599 model now looks vulnerable



Culpan suggests Apple could remove the base 256GB MacBook Neo and keep the $699 512GB model as the new entry point. Apple recently used a similar move with the Mac mini, where the cheaper 256GB version disappeared and the higher-storage model remained.



That would protect margins, but it would also weaken the strongest part of the Neo story. The $599 price made the laptop feel different from every other MacBook. A $699 starting price still looks competitive, but it no longer carries the same shock value.



Apple could also keep the current lineup and accept lower margins for now, especially if the Neo brings more users into the macOS ecosystem. Either way, the next few months will show whether Apple treats the $599 Neo as a permanent entry Mac or a launch-window advantage that became too expensive to keep.]]></content:encoded>
</item>
<item>
<title><![CDATA[Effizientes Mappen von Hausnummern (fossgis2013)]]></title>
<description><![CDATA[Von den 30 Millionen Adressen in Deutschland sind derzeit in OSM nur ca. 10% erfasst. In anderen Ländern ist der Anteil meist noch geringer.
Adress-Suchmaschinen wie NOMINATIM, aber auch Navigationssysteme, LBS-Anwendungen u.v.m. sind auf hinreichend genaue Adressangaben angewiesen.
Steve Coast, ...]]></description>
<link>https://tsecurity.de/de/3495341/it-security-video/effizientes-mappen-von-hausnummern-fossgis2013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495341/it-security-video/effizientes-mappen-von-hausnummern-fossgis2013/</guid>
<pubDate>Thu, 07 May 2026 11:19:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Von den 30 Millionen Adressen in Deutschland sind derzeit in OSM nur ca. 10% erfasst. In anderen Ländern ist der Anteil meist noch geringer.
Adress-Suchmaschinen wie NOMINATIM, aber auch Navigationssysteme, LBS-Anwendungen u.v.m. sind auf hinreichend genaue Adressangaben angewiesen.
Steve Coast, der Gründer von OSM, hat erst kürzlich darauf hingewiesen, daß die noch am Anfang befindliche Erfassung von Adressen in OSM der letzte ernstzunehmende Grund ist, proprietären Karten gegenüber OSM in manchen Mainstream-Anwendungen den Vorrang zu geben.
Eine Unterstützung von Mappern beim effizienten Erfassen von Hausnummern und Adressen ist daher wünschenswert.

Keypad-Mapper 3 ist eine Android-Software, die hocheffizientes Mappen von Hausnummern und Adressen ermöglicht.

Die neue Version 3 wartet mit produktivitätssteigernden Features auf, die qualitativ hochwertige Datenerfassung mit hohem Durchsatz verbinden.
Die App ist auch von OSM-Einsteigern leicht zu bedienen und daher massentauglich, z.B. für Anfängerkurse in Schulen, VHS etc.

Im Vortrag soll aufgezeigt werden, wie Keypad-Mapper 3 das Mappen von Hausnummern und Adressen unterstützt.


Referent:
Dipl.-Ing. Markus Semm
Gründer und Geschäftsführer der ENAiKOON GmbH, Berlin (Anbieter von Telematiklösungen für gewerbliche Kunden)
Herr Semm ist einer der Top 1100 Mapper weltweit.
ENAiKOON setzt bei seinen Lösungen ausschließlich auf OpenStreetMap und unterstützt die Community inhaltlich wie auch finanziell

Warum Hausnummern / Adressen mappen?
Welche Datenmodelle gibt es für Hausnummern und Adressen in OSM?
Historie der Software
Features der Software
Backend-Unterstützung des Hausnummern-Mappers durch ENAiKOON OSM-Dienste
Seiteneffekt: Beitrag zum OpenSource Projekt opencellid.org
about this event: https://fossgis-konferenz.de/2013/programm/events/496.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[OSGeo-Live rocks! (fossgis2013)]]></title>
<description><![CDATA[Das Projekt OSGeo-Live gewährt einen umfassenden Überblick über freie und offene GIS-Software und GeoDaten

OSGeo-Live ist ein OpenSource-Projekt, das mehr als 50 Softwareprojekte aus dem Bereich FOSS+GIS bündelt. Sie finden Projekte aus den Bereichen Web Mapping Clients und Server, DesktopGIS, D...]]></description>
<link>https://tsecurity.de/de/3495257/it-security-video/osgeo-live-rocks-fossgis2013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495257/it-security-video/osgeo-live-rocks-fossgis2013/</guid>
<pubDate>Thu, 07 May 2026 10:49:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Projekt OSGeo-Live gewährt einen umfassenden Überblick über freie und offene GIS-Software und GeoDaten

OSGeo-Live ist ein OpenSource-Projekt, das mehr als 50 Softwareprojekte aus dem Bereich FOSS+GIS bündelt. Sie finden Projekte aus den Bereichen Web Mapping Clients und Server, DesktopGIS, Datenbanken, Krisenmanagement, Navigation und Karten sowie räumliche Tools. 

Die OSGeo-Live ist somit ein sehr gutes Beispiel für ein erfolgreiches OpenSource-Projekt. Dabei handelt es sich nicht um ein klassisches Software-Projekt, sondern um eine Zusammenstellung verschiedenster Anwendungen und Informationen, die dem interessierten Publikum als gut sortierte Werkzeugkiste angeboten wird.

Projektübergreifend wurden viele Freiwillige gefunden, die regelmäßig die Inhalte aktualisieren. Damit ist ein Produkt entstanden, was als globale Visitenkarte nicht nur der OSGeo-Projekte dient. OSGe-Live kann in Workshops und eigenen Veranstaltungen verwendet werden. Alle FOSS- und GIS-relevante Software wird mehrsprachig und mit Dokumentation zur Verfügung gestellt. So ligen beispielsweise Übersetzungen ins Deutsche, Italienische, Polnische, Griechische, Japanische, Französiche, Catalanische, Chinesiche, Koreanische vor.

Dieser Vortrag liefert Einblicke in die Entstehung und den Aufbau dieses Projektes. Die ehrgeizigen Ziele wie mehrsprachige Dokumentation, Benutzung von Beispieldatensätzen und Support in der Community stellen ganz unterschiedliche Anforderungen. Es gilt nicht nur technische Probleme zu lösen. Hinzu kommen terminliche Absprachen, damit zu bestimmten Anlässen wie wichtigen Konferenzen und Workshops aktuelle Versionen bereit stehen.

=FOSSGIS=
Auch auf der **FOSSGIS Konferenz 2013** kommt die OSGeo-Live in den Workshops zum Einsatz und wird als DVD an die Teilnehmer der Konferenz verteilt.


about this event: https://fossgis-konferenz.de/2013/programm/events/576.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim Cook Says Apple “Undercalled” Demand for Its $599 MacBook Neo]]></title>
<description><![CDATA[Apple expected the MacBook Neo to expand the Mac lineup, but even the company did not predict just how strong demand would become after launch.



During Apple’s Q2 2026 earnings call, CEO Tim Cook said customer response to the new budget-friendly laptop has been “off the charts,” with demand sig...]]></description>
<link>https://tsecurity.de/de/3481040/ios-mac-os/tim-cook-says-apple-undercalled-demand-for-its-599-macbook-neo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481040/ios-mac-os/tim-cook-says-apple-undercalled-demand-for-its-599-macbook-neo/</guid>
<pubDate>Fri, 01 May 2026 20:52:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple expected the MacBook Neo to expand the Mac lineup, but even the company did not predict just how strong demand would become after launch.



During Apple’s Q2 2026 earnings call, CEO Tim Cook said customer response to the new budget-friendly laptop has been “off the charts,” with demand significantly outperforming Apple’s own forecasts. Since launching in March at $599, the MacBook Neo has quickly become one of Apple’s most important growth drivers, especially among first-time Mac buyers and long-time users finally replacing older machines.



Apple underestimated MacBook Neo demand



Cook made it clear that Apple entered the launch with confidence, but the company still underestimated how aggressively consumers, schools, and emerging markets would respond to its lowest-priced MacBook ever.




“Yeah, right now we’re supply constrained on the MacBook Neo. We were very bullish on the product before announcing it, but we undercalled the level of enthusiasm that would be with it, and it’s very much focus on getting the Mac to even more people than we were reaching before. We’ve very focused on customers new to the Mac and customers that have been holding on to their Mac a very long period of time. We’re doing well with both of those.”— Apple CEO Tim Cook




That surge in demand has already created supply constraints, with Apple’s online store showing delivery windows stretching to several weeks for certain configurations.



MacBook Neo is hitting so hard







MacBook Neo’s aggressive pricing strategy appears to be doing exactly what Apple intended, which is opening the Mac ecosystem to entirely new customer groups.



At $599 for standard buyers and $499 for education customers, the device directly targets:




Students



Budget laptop shoppers



Chromebook and Windows switchers



Emerging market buyers



Long-delayed Mac upgraders




Cook specifically highlighted growing adoption in education, including school systems moving away from Windows PCs and Chromebooks.



Because the laptop uses the A18 Pro chip, Apple also benefits from leveraging its mobile silicon strategy while keeping costs low enough to push broader adoption.



Supply issues show Apple has a real hit



Strong demand often creates marketing headlines, but Apple’s current supply limitations suggest MacBook Neo is delivering meaningful volume.



Cook also noted that MacBook Neo helped Apple achieve a record March quarter for new Mac customers, showing this is more than just existing Apple users buying a cheaper device.



For Apple, MacBook Neo appears to be doing something rare by creating an entirely new entry point into the Mac ecosystem while also driving major sales growth. If supply improves, this affordable MacBook could become one of Apple’s most important long-term expansion products.]]></content:encoded>
</item>
<item>
<title><![CDATA[Was gibt es Neues in Fedora Workstation? Fedora 44 Rezension und Bewertung]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 20x - Views:295 In diesem Video zeigt Jean Fedora Workstation in der neuen Version Fedora 44. Was gibt es für Neuerungen und für wen würde ich diese Linux-Distribution empfehlen?
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreib...]]></description>
<link>https://tsecurity.de/de/3480464/linux-tipps/was-gibt-es-neues-in-fedora-workstation-fedora-44-rezension-und-bewertung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480464/linux-tipps/was-gibt-es-neues-in-fedora-workstation-fedora-44-rezension-und-bewertung/</guid>
<pubDate>Fri, 01 May 2026 15:38:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 20x - Views:295 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/30Yk0rzU6ZQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean Fedora Workstation in der neuen Version Fedora 44. Was gibt es für Neuerungen und für wen würde ich diese Linux-Distribution empfehlen?<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Intro<br />
00:31 Fedora allgemein<br />
05:33 GNOME 50<br />
07:41 Software<br />
13:59 Nix für Fedora<br />
15:56 Installer<br />
20:04 Weitere Features und Funktionen<br />
29:58 Mein Fazit<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linux #opensource #fedora #rhel #redhead<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Managing OT risk at scale: Why OT cyber decisions are leadership decisions]]></title>
<description><![CDATA[The first time I approached an OT environment, I assumed that the strategies effective in IT cybersecurity would be equally applicable. I was wrong. The experience revealed a fundamental difference, highlighting the need for a distinct approach to OT cyber risk management.



The mistake was not ...]]></description>
<link>https://tsecurity.de/de/3479972/it-security-nachrichten/managing-ot-risk-at-scale-why-ot-cyber-decisions-are-leadership-decisions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479972/it-security-nachrichten/managing-ot-risk-at-scale-why-ot-cyber-decisions-are-leadership-decisions/</guid>
<pubDate>Fri, 01 May 2026 11:22:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The first time I approached an OT environment, I assumed that the strategies effective in IT cybersecurity would be equally applicable. I was wrong. The experience revealed a fundamental difference, highlighting the need for a distinct approach to OT cyber risk management.</p>



<p>The mistake was not technical. It was conceptual. I was treating OT as another security domain that needed stronger controls, better tooling and greater discipline. But OT lives under different conditions. Systems stay in service for years, sometimes decades. Patching is limited. Change windows are negotiated. Vendor dependencies are part of daily operations. Asset visibility is often incomplete and the highly distributed environments depend heavily on third-party access.</p>



<p>In summary, OT cyber risk fundamentally constitutes a challenge of leadership and governance. The primary concern at scale is not isolated technical controls at individual sites, but rather the enterprise’s ability to ensure consistent decision-making across all sites through clearly defined roles and shared accountability.</p>



<h2 class="wp-block-heading">OT changes the nature of cyber risk</h2>



<p>Boards have improved their cyber oversight of IT, but OT requires a different perspective. Here, cyber risk goes beyond data and compliance into operational processes, industrial assets and critical services.</p>



<p>OT architecture begins in the physical world, moves through control systems and operations networks, and increasingly connects to enterprise systems and cloud services. This creates a consequence profile distinct from IT, in which cyber risk directly affects physical operations.</p>



<p>OT operating constraints include long asset lifecycles, incomplete asset visibility, embedded third-party access, fragmented ownership across engineering, operations, site leadership, vendors and security. IT cyber assumptions often fail in OT because risk and responsibility structures diverge fundamentally.</p>



<p>The governance baseline for OT remains thin, as reflected in recent <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/in-full/3-the-trends-reshaping-cybersecurity/">World Economic Forum research</a> that highlights broader issues of leadership and oversight. Only 16 percent of organizations with industrial environments report OT security issues to their boards and just 20 percent maintain dedicated OT security teams. Furthermore, in only 36 percent of cases is the CISO directly responsible for OT security. These low levels of reporting and responsibility indicate not only a maturity gap in organizational processes but, more critically, a substantial accountability gap that directly reinforces the thesis: OT cyber risk management at scale is fundamentally a challenge of leadership and governance, rather than solely a technical concern.</p>



<p>At scale, a local weakness becomes an enterprise coordination issue. Differences in maturity, ownership, vendor dependencies and business priorities create uneven exposure. The board question is not whether OT controls exist, but whether the enterprise can make consistent, defensible decisions about OT cyber risk before and during disruption.</p>



<h2 class="wp-block-heading">At scale, incident outcomes become leadership outcomes</h2>



<p>Effective OT oversight shifts from control-by-control discussions to scenario and consequence analysis.</p>



<p>Common OT exposure paths include remote access abuse, shared accounts, weak segmentation, infected maintenance media, compromised workstations and poorly governed vendor connectivity. In OT, these exposures have direct operational consequences. A SCADA compromise can reduce visibility across power operations. Poor remote access governance can degrade rail operations. Infected media can trigger plant downtime. Unauthorized parameter changes can force emergency shutdowns and manual safety validation.</p>



<p>OT risk appetite cannot be reduced to the enterprise itself. OT impact may extend to the economy, environmental, critical services and, sometimes, human safety. As the consequences broaden, oversight standards must rise. A technical control gap is one risk. A governance structure that cannot support safe, coherent decisions under pressure is a different order of magnitude in terms of exposure.</p>



<p>In OT, incident outcomes are determined by leadership choices made before disruption begins.</p>



<ul class="wp-block-list">
<li>Should the organization isolate quickly to stop propagation, or continue operating in a constrained way to protect essential output?</li>



<li>Should authority be centralized to improve consistency, or federated to improve speed and local judgment?</li>



<li>Should the organization restore quickly, or verify process integrity first and accept a longer recovery path?</li>



<li>Should vendor and remote support remain broadly enabled for operational convenience, or be reduced because it has become part of the real perimeter?</li>
</ul>



<p>No single option is always correct. The key is whether leaders understand trade-offs before action is required. Executive decisions such as isolate versus operate, centralize versus federate and restore versus verify change outcomes. These are governance choices, not technical defaults.</p>



<p>I have seen both sides of this in practice. In one environment, centralization accelerated capability building. It improved consistency, but it also introduced the risk of slower decisions in a crisis because authority sat too far from the operational edge. In another, responsibility was distributed across business units, which improved local ownership but increased coordination risk under stress. The lesson was never ideological. It was operational. The operating model had to match the risk reality.</p>



<p>This is also why the strongest board-level conversations in OT are rarely about tools first. They are about decision rights, escalation logic, crisis thresholds and assurance. The <a href="https://www.nist.gov/cyberframework">NIST Cybersecurity Framework 2.0</a> is useful here not because it provides boards with a script, but because it explicitly frames cybersecurity as part of how organizations understand and manage cyber risk.</p>



<h2 class="wp-block-heading">What boards should ask now</h2>



<p>Boards do not need to become technical experts in OT. They do need to demand decision-grade oversight.</p>



<p><strong>First</strong>, clarify the operating model. Who owns OT cyber risk across the enterprise? Where does business unit accountability sit? Which decisions are centralized and which are delegated? Who has authority in a crisis when continuity and containment are in tension? If these answers are unclear, residual risk is likely underestimated.</p>



<p>To help make this concrete, consider two common operating models. In a centralized model, OT cyber risk governance, tooling decisions and incident response authority reside primarily at the enterprise or group level, typically under the leadership of a central security or risk function. Local sites implement enterprise direction but have limited autonomy to define controls or crisis actions. In contrast, a federated model grants more decision rights to individual business units or operating sites. Here, local leaders often own OT cyber controls, incident triage and vendor management, while the central organization coordinates standards and provides guidance. Each model brings different trade-offs in consistency, speed and local adaptation. Directors should ask management to clarify which approach is in place today and why it fits the organization’s risk profile.</p>



<p><strong>Second</strong>, identify the two or three OT cyber scenarios that would most impact continuity, key operations and external defensibility. Scenarios should be concrete enough to guide priorities, budget and crisis preparation. Generic statements about protecting critical infrastructure are not enough.</p>



<p><strong>Third</strong>, require assurance. Boards should ask whether a baseline exists and whether it has been independently tested for effectiveness. Governance and assurance should sit above the technical baseline and operating model. In OT, site assessments, adversarial simulations, tabletop exercises and validation of remote access controls provide more insight than maturity scoring.</p>



<p><strong>Fourth</strong>, address innovation. AI and cloud are changing operational environments, even when adoption begins at the physical layer. The leadership agenda is moving toward governance, resilience and control of increasingly complex digital dependencies. For OT, boards should treat these shifts as operating model and assurance questions, not just technology questions.</p>



<p>This is where the board agenda becomes practical. Directors should ask management to clarify decision rights, define the top OT cyber scenarios, establish an enterprise minimum baseline for priority environments and run independent assurance on the sites or operations that matter most. These are not technical housekeeping tasks. They are the foundations of defensible oversight.</p>



<p>This article builds on a recent <a href="https://www.rsaconference.com/usa/programs/cyber-leaders-forum">RSAC session on managing OT risk at scale</a>, but the lesson is broader. OT cyber risk at scale is not simply a controls problem. It is a leadership problem because real outcomes depend on governance, accountability and pre-agreed trade-offs. The organizations that navigate OT disruption better are usually not the ones with the most ambitious slide decks. They are the ones who decided in advance how they will govern, escalate, verify and recover.</p>



<p>That is what the shift boards should insist on. In OT, resilience is built by decisions made before the incident alarm sounds.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>



<p><a href="https://www.cio.com/it-strategy/"></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The DSPM promise vs the enterprise reality]]></title>
<description><![CDATA[The data sprawl problem is worse than anyone admits



Before a DSPM tool can protect data, it must find it. That sounds straightforward. In practice, it is the first place most programs quietly begin to unravel.



Enterprises have been operating in hybrid and multi-cloud environments for a long...]]></description>
<link>https://tsecurity.de/de/3477294/it-security-nachrichten/the-dspm-promise-vs-the-enterprise-reality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477294/it-security-nachrichten/the-dspm-promise-vs-the-enterprise-reality/</guid>
<pubDate>Thu, 30 Apr 2026 13:05:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The data sprawl problem is worse than anyone admits</h2>



<p>Before a DSPM tool can protect data, it must find it. That sounds straightforward. In practice, it is the first place most programs quietly begin to unravel.</p>



<p>Enterprises have been operating in hybrid and multi-cloud environments for a long time. Data has followed every workflow — into Salesforce, into SharePoint, into dozens of S3 buckets that were created by developers who have since moved on, and into collaboration tools adopted during the pandemic without any formal data classification policy attached. Nobody tracked it systematically. <a href="https://www.cyera.com/reports/dspm-adoption-report" rel="nofollow">Research from Cyera’s 2024 DSPM Adoption Report</a> found that 90% of the world’s data was created in just the last two years, and total data volume by 2025 reached 181 zettabytes. Security teams are being asked to govern a landscape that is growing faster than any tool or team was designed to handle.</p>



<p>When DSPM scanners go to work on a large enterprise environment, the volume of findings almost always exceeds initial expectations — sometimes by an order of magnitude. One organization I worked with discovered sensitive customer PII in seventeen cloud storage locations that they had no formal record of. Another found regulated financial data sitting in a collaboration workspace that had been shared with an external contractor two years prior and never revoked.</p>



<p>The visibility is genuinely valuable. But, as <a href="https://www.wiz.io/academy/data-security/data-security-posture-management-dspm" rel="nofollow">Wiz notes in their DSPM framework</a>, visibility without remediation capacity is just a longer list of things that can go wrong. And that is exactly where the first real friction begins.</p>



<h2 class="wp-block-heading"><a></a>Ownership is a political problem, not a technical one</h2>



<p>DSPM tools are exceptionally good at identifying data risk. They are not designed to resolve the organizational question of who is responsible for fixing it. That question, in most enterprises, does not have a clean answer.</p>



<p>Security teams surface the finding. The data sits in a business unit’s environment. The IT team may own the cloud account, but the data owner is in Finance, HR, or a product team operating on a separate roadmap and budget cycle. When the DSPM platform generates a remediation ticket, the question of who closes it — and who gets measured on closing it — is rarely answered in advance.</p>



<p>This creates what I call the remediation gap. Findings accumulate. Risk scores rise. But nothing gets fixed, because no single team has both the authority and the incentive to fix it. Security points at the business. The business points at IT. IT points at the data owner. The data owner has a product launch in six weeks and no security budget. <a href="https://www.forcepoint.com/blog/insights/data-security-posture-management-dspm-guide">Forcepoint’s DSPM implementation research</a> confirms this pattern: Even capable platforms underdeliver when rollout turns into a scanning project with unclear ownership and remediation that lives in a permanently deferred backlog.</p>



<p>I have watched this dynamic play out in organizations across industries. It is not a technology failure. It is a governance failure — and no DSPM platform in the market today ships with a solution to it. That solution must be built by leadership, before deployment, with teeth. That means defined data ownership models, escalation paths and accountability metrics that connect to performance conversations, not just security dashboards.<strong></strong></p>



<h2 class="wp-block-heading">Classification debt is real, and it goes well with compounding</h2>



<p>Every DSPM implementation depends on one foundational input: A coherent data classification framework. Most enterprises do not have one that is current, enforced, or agreed upon across business units.</p>



<p>Organizations are equipped with policy documents written five years ago, and what was defined there, nobody uses consistently. What adds more is a growing volume of unstructured content that was never classified at all. <a href="https://securiti.ai/dspm-trends/">According to a 2024 industry survey cited by Securiti</a>, 83% of IT and cybersecurity leaders assert that lack of visibility into data contributes significantly to their weak security posture — a figure that points directly at the classification gap sitting underneath most programs.</p>



<p>DSPM tools apply machine learning to infer sensitivity from data patterns — and they are increasingly good at it. But inference is not a substitute for intentional classification. False positives create noise. False negatives create blind spots. Both erode trust in the platform over time. And once analysts stop trusting the findings, the program stalls regardless of how sophisticated the tooling is.</p>



<p>The harder truth is that many organizations use the DSPM project as a forcing function to finally build the classification framework they should have built years ago. That is not inherently wrong. But it dramatically expands the scope and timeline, and it requires business stakeholder engagement that security teams are rarely resourced to drive on their own. Executives who budget for a DSPM tool without budgeting for the classification work alongside it are setting their programs up for a slow, expensive drift toward shelfware.</p>



<h2 class="wp-block-heading"><a></a>Integration complexity is systematically underestimated</h2>



<p>DSPM vendors will show you a connector library that spans AWS, Azure, GCP, Microsoft 365, Salesforce, Snowflake and a long list of other platforms. What the demo does not show you is what happens when your specific version of a legacy ERP system does not match the connector’s assumptions or when your on-premises database sits behind a network segment the cloud-native scanner cannot reach without significant architectural change.</p>



<p>Enterprise environments are heterogeneous by nature. <a href="https://www.paloaltonetworks.com/cyberpedia/dspm-market" rel="nofollow">Palo Alto Networks’ market analysis</a> puts the DSPM market on a trajectory toward $2 billion by 2025, growing at rates between 25% and 37% annually — a reflection of just how aggressively organizations are investing in this space. But investment velocity and implementation maturity are not the same thing. The average large organization runs hundreds of distinct data stores across multiple cloud providers, legacy systems and third-party SaaS applications. Getting DSPM coverage across all of them is not a deployment — it is an ongoing engineering program.</p>



<p>Connectors break when APIs change. New data sources appear with every acquisition and product build. Maintaining coverage requires dedicated resources that are rarely factored into the initial business case. Executives should push their vendors on exactly which environments will have full coverage at go-live versus which ones are on a roadmap with no committed timeline. The distinction matters enormously because a DSPM deployment with significant coverage gaps gives a false sense of security that can be more dangerous than no deployment at all.</p>



<p>This is a point worth reinforcing with your procurement team: <a href="https://www.forcepoint.com/blog/insights/gartner-dspm-market-guide-5-top-takeaways" rel="nofollow">Gartner’s Market Guide for DSPM</a> explicitly flags that organizations can no longer separate data visibility from data control — and that coverage depth, not just breadth, is the critical variable when evaluating platforms.<strong></strong></p>



<h2 class="wp-block-heading">Alert fatigue arrives faster than expected</h2>



<p>A fully operational DSPM deployment in a large enterprise will generate findings at a volume that most security operations teams are not built to absorb. The irony is that the better the tool works, the faster alert fatigue sets in.</p>



<p>Risk prioritization is the answer in theory. In practice, prioritization logic requires ongoing tuning that takes months of calibration with your specific data environment. <a href="https://www.varonis.com/blog/dspm-for-cisos">Varonis, in their DSPM guidance for CISOs</a>, makes the point directly: The goal should not be to generate a list of findings but to surface meaningful, actionable alerts that can be remediated — ideally with automation doing the heavy lifting. Most implementations fall well short of that standard in the early months.</p>



<p>In the meantime, analysts are triaging hundreds of findings per week, many of which turn out to be acceptable risks or known exceptions. Teams burn out. Findings get acknowledged and deprioritized. The board dashboard shows a healthy posture score that no longer reflects ground reality. <a href="https://www.zscaler.com/blogs/product-insights/3-key-predictions-dspm-2025-future-cloud-data-security" rel="nofollow">Zscaler’s analysis of cloud data security challenges</a> identifies this precisely: Security teams need AI and ML-powered prioritization not just to reduce noise but to help analysts focus effort on the data exposures that could realistically lead to a breach.</p>



<p>This is not an argument for turning off the tool. It is an argument for honest capacity planning. If your security operations team is already stretched, a DSPM deployment without additional analyst headcount or a meaningful automation investment is not going to improve your security posture. It is going to add a new category of noise to an already overloaded function.</p>



<h2 class="wp-block-heading"><a></a>What good looks like</h2>



<p>None of the friction described here is insurmountable. Organizations that get DSPM right tend to share a few common attributes that have nothing to do with which vendor they chose.</p>



<p>They treat DSPM as an organizational change program, not a technology deployment. They invest in governance structures before they deploy scanners. They define data ownership at the business unit level with clear accountability, and they build that accountability into how people are measured and managed. They budget for the classification work alongside the tooling. They phase their integration roadmap honestly, scope the first phase to environments where coverage will be complete, and build confidence before expanding.</p>



<p>They also pay attention to what <a href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/beyond-visibility-the-new-microsoft-purview-data-security-posture-management-dsp/4470984" rel="nofollow">Microsoft’s research on enterprise data security posture</a> flags as the underlying imperative: Organizations must stop seeing data security as a collection of individual tools and start treating it as a holistic program anchored in measurable business outcomes. That shift in framing changes everything — from how the board conversation is structured to how remediation accountability is assigned across the business.</p>



<p>Most importantly, they have executive sponsorship that goes beyond signing the purchase order. The CISOs who successfully land DSPM programs are the ones who have a CFO, COO, or CEO who understands that data security risk is a business risk — and who is willing to hold business unit leaders accountable for their piece of it.</p>



<p>DSPM, at its best, gives your enterprise the situational awareness it needs to make informed decisions about data risk. The organizations that leverage awareness as a genuine security improvement are the ones that walk in with eyes open — prepared for the friction, staffed for the remediation work and governed for the accountability.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deconstructing the data center: A massive (and massively liberating) project]]></title>
<description><![CDATA[A few years back, Bhaskar Ramachandran read the tea leaves and what he saw was clear: With all the enhancements hyperscalers continuous make, there was no value in having on-premises data centers any longer.



“There is just no way for a private company to match that,” says Ramachandran, global ...]]></description>
<link>https://tsecurity.de/de/3476923/it-security-nachrichten/deconstructing-the-data-center-a-massive-and-massively-liberating-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476923/it-security-nachrichten/deconstructing-the-data-center-a-massive-and-massively-liberating-project/</guid>
<pubDate>Thu, 30 Apr 2026 11:06:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A few years back, <a href="https://www.linkedin.com/in/bhasram/">Bhaskar Ramachandran</a> read the tea leaves and what he saw was clear: With all the enhancements hyperscalers continuous make, there was no value in having on-premises data centers any longer.</p>



<p>“There is just no way for a private company to match that,” says Ramachandran, <a href="https://www.linkedin.com/in/bhasram/"></a>global vice president and CIO of paints and coatings manufacturer PPG. “This is their business, and they’re really good at it, and it was clear that the size of the hyperscalers is just going to win over the infrastructure game. So it didn’t make sense for us to keep up with the infrastructure.”</p>



<p>PPG began dismantling its eight global data centers about four years ago, with the final one completed in November 2025. For a 143-year-old company that has gone through 60-some acquisitions, that was no small feat.</p>



<p>Applications and infrastructure became a lot to manage, combined with trying to maintain a strong cybersecurity posture and compliance. “You can’t consistently manage this sort of a footprint, and it becomes really unwieldy very quickly,” Ramachandran says.</p>



<p>Decommissioning a data center is like defusing a complex bomb. Every wire, sequence, and step must be handled with care, because one wrong move can be a blow to your organization in downtime risks, data breaches, or a hit to its bottom line. </p>



<p>“The decommissioning of data centers is underestimated in terms of complexity, financial risks, reputation loss, and data exposure,” according to Gartner. The firm estimates that by 2030, twice as many enterprise data centers will have been decommissioned compared to those built. Reasons include consolidations, obsolescence, and shifting workloads to cloud and colocation services.</p>



<h2 class="wp-block-heading">The inadvertent data center</h2>



<p>In some instances, data centers have cropped up without much forethought. “Most organizations I work with didn’t build a data center intentionally — they grew into one,” says <a href="https://www.linkedin.com/in/aaron-walker/">Aaron Walker</a>, CEO of IT consultancy Overbyte, and a former associate partner at IBM Consulting. “A rack in a closet became a row in a repurposed room, and suddenly, you have a facility that was never designed for the job holding years of infrastructure decisions.”</p>



<p>Deconstructing that environment is work that often gets overlooked, says Walker.</p>



<p>He recently consulted with a large, fully remote online school in the throes of this process. The deconstruction work began with a full audit of what systems existed. From there every workload was categorized to determine what gets migrated, what gets moved to cloud-native infrastructure, and what gets retired entirely, he says.</p>



<p>Then came the physical side: decommissioning hardware and deciding what equipment had residual value and what to recycle. </p>



<p>“The timeline pressures are real,” Walker says. “You can’t just power things down. Dependencies surface that nobody documented.”</p>



<p>The IT organizational side had its own challenges. “People have years of institutional knowledge tied to physical systems, and there’s genuine anxiety about dismantling something they built and maintained,” he says. </p>



<p>Walker’s team also ran into issues trying to upgrade systems during the migration, which is generally a mistake, he says. “A data center deconstruction is already a significant change event, and layering additional upgrades on top of it introduces unnecessary risk. In most cases, it is better to separate modernization from migration.”</p>



<p>From start to finish, the deconstruction ran about a year, but timing will vary from project to project, he says.</p>



<h2 class="wp-block-heading">Less hassle, more flexibility</h2>



<p>When the time came for digital marketing agency Helium SEO to consider what to do with its data center, CTO <a href="https://www.linkedin.com/in/paul-demott/">Paul DeMott</a> says the math was simple. “We were paying $12,000 a month toward the colocation fees, hardware support, and the maintenance cost for the physical servers sitting in racks. Cloud infrastructure promised better reliability, automatic scaling, and way less hassle once we were done moving everything.”</p>



<p>The most compelling reason to rid itself of a physical footprint, though, was flexibility. Physical servers equated to capacity planning six months ahead, DeMott says, and if they needed more resources, IT had to wait weeks for hardware to come and get installed.</p>



<p>“Cloud allows resources to be spun up in minutes and shut down at the same speed,” he says. “We went from buying expensive hardware that depreciated to purchasing what we are actually using.”</p>



<p>IT began by creating a list of all the apps running on physical servers and classifying them according to how difficult it would be to move them. “Simple web apps moved first as they barely needed changes,” DeMott says. “Databases and anything which stores data — that’s a little bit later because we’d have had to plan the migration well.”</p>



<p>Some older apps had to be changed to work on the cloud, he adds. The actual move took place over six months, and IT decommissioned the data center while deploying apps to the cloud in tandem, moving the services step by step with backup plans for each one.</p>



<p>Still, the process wasn’t seamless. “Translating 15TB of data to the cloud takes 72 hours on our internet connection, and that was the biggest problem,” DeMott notes. IT ended up using AWS Snowball, a physical hard drive, because it took staff weeks to upload everything, “and [it] ruined the performance in our network.”</p>



<p>Another issue was figuring out the cloud costs, which DeMott characterizes as “brutal. Different types of servers, storage, data transfer costs made it almost impossible to budget,” he says. “Our first month bill accrued at 40% more than we estimated because we forgot about charges for moving data out of the cloud.”</p>



<p>It took IT three months of “fumbling” to get costs below what the company paid for the data center before things stabilized.</p>



<h2 class="wp-block-heading">The power of ‘cloud only’</h2>



<p>Once PPG made the decision to dismantle its data centers and move everything to the cloud, it was time to spread the word internally. “When you say, ‘cloud only,’ it makes it much easier for you to have conversations,” Ramachandran says. “It just sets the entire organization up on a single mission … just those two words make it very, very clear to everybody in the company what that means. There is no room for interpretation.”</p>



<p>The news was revealed at a global town hall, and initially, Ramachandran says, the sentiment was, “this too, shall pass. Then people decided to get on board.”</p>



<p>There were the typical <a href="https://www.cio.com/article/272222/change-management-change-management-definition-and-solutions.html">organizational change management</a> issues to deal with. Building momentum takes time, he says, but once the first data center was shut down, people came to the realization that “Okay, we are actually doing this,” Ramachandran says. “Then there was no resistance … everybody got on board, and things started to accelerate.”</p>



<p>Officials ensured that all the training IT needed was made available to them and the company paid for everything, certifications included. “We recognized it in town halls; anybody that went through this training and got the certification. We celebrated people. We promoted people that did the things we wanted them to do,” he says. All of this helped reinforce the mission.</p>



<p>“For the most part, business users didn’t care; their apps were available and they didn’t care where they were,” although there were a couple of exceptions among more technically savvy employees who were concerned about workflow and the security implications of cloud. There was a perception among some that a data center was more secure, Ramachandran says.</p>



<p>That led to looking at publicly available information on all the cybersecurity incidents in the recent past. The research indicated a clear pattern, he says.</p>



<p>“And the pattern is: The more significant cybersecurity events were actually happening to companies” that were largely on-prem environments, Ramachandran observes. “So you came to this point where the cloud actually became lot more secure than on-prem infrastructure.”</p>



<p>There are several reasons why, he maintains, including that, relatively speaking, it is a lot easier to implement security policies consistently in the cloud because “you have a single pane of glass enforcement of policies that you don’t have in an on-prem environment.”</p>



<p>This makes managing your attack surface area more straightforward, Ramachandran says. “So you put all of this together, you package it up on the presentation, and talk to those people one on one, and then say, ‘This is why.’”</p>



<h2 class="wp-block-heading">The dismantling process</h2>



<p>PPG works with a single hyperscaler for its business in China and three others. Deciding what apps went where was largely a function of the technology and which hyperscaler “lends itself to that brand of technology versus the other.” In some instances, where a decision of which to use wasn’t clear, IT made the call.</p>



<p>Step one was deciding on an approach, and PPG opted to modernize its apps at the same time as the deconstruction work. “When you pull together the business case to modernize applications, we came to a conclusion that if we do modernization on the application layer and the infrastructure layer at the same time, I would probably be retired by the time we migrated the data center,” Ramachandran says.</p>



<p>That made it easy to decide when to do a lift and shift and when to not bother migrating certain applications, he says. Then IT could focus on other business priorities to modernize the workforce.</p>



<p>“We just adjusted our roadmap to say the new [app] would go straight into the cloud” while not bothering to move older workloads, Ramachandran says.</p>



<h2 class="wp-block-heading">The human element</h2>



<p>The next step was “finding the people that are hungry to do something new and probably have a bit of experience and … they are waiting for someone to say, ‘Hey, let’s do this,’” Ramachandran says of the data center deconstruction. “They are forward thinkers. Every organization in our scale has [them]. It’s identifying those people and then … empowering them. They became the leaders in the new infrastructure.”</p>



<p>Once the migration started, it was important to celebrate the wins. That gets more people interested in being a part of the new organization PPG was forming called the Cloud COE (center of excellence).</p>



<p>The biggest mistake companies make is treating deconstruction as a single project instead of a phased operational shift, says <a href="https://www.linkedin.com/in/rolandparker/">Roland Parker</a>, founder and CEO of Impress Computers, a managed IT services and cybersecurity firm in Houston.</p>



<p>“We walked one 200-person manufacturer through moving workloads in priority tiers — production-critical systems last, not first — which kept their floor running while we systematically eliminated physical infrastructure over 14 months,” he says.</p>



<p>However, it’s “the human side [that] kills more timelines than the tech does,” Parker observes. “Field supervisors and plant managers have work-arounds built around how legacy systems behave.” So, before touching a single rack, Parker’s team audits those informal processes, “because if you don’t, you migrate the infrastructure and orphan the people who actually use it.”</p>



<p>Overbyte’s Walker agrees, saying that almost all the snafus his team ran into during the online school deconstruction project were not technical, but came down to visibility. “At some point, you have to confront unknown systems; things with incomplete or outdated documentation,” he says. “We had moments where, after beginning to deprovision systems, stakeholders surfaced saying, ‘Wait, that’s still in use.’”</p>



<h2 class="wp-block-heading">Dismantling systems is not the end</h2>



<p>PPG experienced no disruptions during the dismantling process, Ramachandran says, other than some tactical delays and contracts that needed updating.</p>



<p>“There were some learnings on the network side because networking can get complex,” he says. “Sometimes, we extended the outage windows” to up to five hours, for example. Those were the hiccups.”</p>



<p>From start to finish, the decommissioning process of all eight data centers took about three years. “The end is not migrating all the workloads. The end is actually shutting down the data center,” Ramachandran stresses. This requires deconstructing the power, the cooling, fire systems, and multiple generators used for backup, which had to be removed by helicopter.</p>



<p>“You have to take the diesel fuel out and dispose it off and sell it. We have to get recertification of the building for safety, because this is a building where you had kilowatts of power coming in, which basically [also] went through a deconstruction process,” he says. “So you have to get a safety certification … all of this takes time because we have to give the building back to the building management the way they gave it to us.”</p>



<h2 class="wp-block-heading">What data center deconstruction buys you</h2>



<p>The painstaking data center deconstruction process has given Ramachandran valuable insight. “Make sure your best people spend time creating value for the business, as opposed to babysitting infrastructure,” he says, because infrastructure no longer adds value.</p>



<p>“You also do a lot of inherent risk management by getting rid of data centers and moving to a cloud environment you don’t have to worry about,” he adds. Noting the current state of the economy, Ramachandran says coping with sudden price increases for memory and chips is no longer stressful since they aren’t buying infrastructure.</p>



<p>“You’re basically giving back working capital to the company, because you’re moving the organization from a fixed capital environment to your variable cost model completely,” he says, “and you don’t have to refresh your hardware every four or five years.”</p>



<p>Cost was never the objective for the data center deconstruction, Ramachandran notes. “Nonetheless, when we did the business case, we said it’s not going to cost us any more or any less, but will buy us better security, better flexibility, better agility for the organization,” as well as better focus and technology. “And we achieved all of those.”</p>



<p>The value is in all those other areas. “We are not data center operators. The team is now focused on delivering applications that are meaningful to the business,” Ramachandran says. “The team is much closer than ever to the business because we are not talking infrastructure but how to make the business better.”</p>



<p>Walker says companies should measure twice, cut once. “Most teams want to jump straight into migration,” he says, “but the real work is building a complete inventory and mapping dependencies upfront.”</p>



<p>While it made sense for PPG to modernize some apps at the same time as the data center deconstruction work, Walker advises IT leaders to resist the urge to do everything at once. “Focus on moving what you understand first, and isolate the unknowns early,” he says.<br>“The success of these projects is usually determined by how well you handle the edge cases, not the easy wins.”</p>



<p>Any new technological development IT can make without interrupting operations dramatically reduces time to market, Ramachandran says.</p>



<p>Working on the latest technologies makes IT happy, and that helps with talent retention, he adds, “because we can say we’re cloud only, so this 143-year-old company looks modern. That is meaningful in so many ways.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinas neues KI-Modell läuft ohne Nvidia — und der Westen schweigt]]></title>
<description><![CDATA[Author: QuantenStrategie - Bewertung: 3x - Views:63 Diese Woche hat China ein KI-Modell ausgeliefert, das weitgehend 
unabhängig von amerikanischer Hardware ist. DeepSeek V4 — optimiert 
für Huawei-Chips, Open Source, und nur knapp hinter Googles 
Spitzenmodell auf der Erde.

Das US-Chip-Embargo ...]]></description>
<link>https://tsecurity.de/de/3473786/it-security-nachrichten/chinas-neues-ki-modell-laeuft-ohne-nvidia-und-der-westen-schweigt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473786/it-security-nachrichten/chinas-neues-ki-modell-laeuft-ohne-nvidia-und-der-westen-schweigt/</guid>
<pubDate>Wed, 29 Apr 2026 10:52:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: QuantenStrategie - Bewertung: 3x - Views:63 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/_oXT9VfnnPo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Diese Woche hat China ein KI-Modell ausgeliefert, das weitgehend <br />
unabhängig von amerikanischer Hardware ist. DeepSeek V4 — optimiert <br />
für Huawei-Chips, Open Source, und nur knapp hinter Googles <br />
Spitzenmodell auf der Erde.<br />
<br />
Das US-Chip-Embargo sollte genau das verhindern. Stattdessen hat <br />
es China gezwungen, einen eigenen KI-Stack zu bauen. Mit Huaweis <br />
Ascend 950 als Hardware. Mit Supernode als Antwort auf Nvidias <br />
NVLink. Und mit einem Open-Source-Modell, das jeder Entwickler <br />
auf der Welt herunterladen kann.<br />
<br />
In diesem Video analysieren wir:<br />
<br />
▸ Was DeepSeek V4 wirklich kann — und wo es noch hinter OpenAI <br />
und Google liegt<br />
▸ Wie Huaweis Supernode-Architektur Nvidias NVLink ersetzt<br />
▸ Die drei technischen Tricks: Mixture-of-Experts, Token-Effizienz, <br />
und chinesische Interconnect-Technologie<br />
▸ Warum das Chip-Embargo Reagans Fehler von 1983 wiederholt<br />
▸ Was das für Europa, Aleph Alpha, Mistral und den EU AI Act bedeutet<br />
▸ Die offene Frage: Wurde V4 wirklich auf Huawei trainiert — <br />
oder auf geschmuggelten Nvidia-Chips?<br />
<br />
Während die westliche Berichterstattung diese Geschichte kaum <br />
einordnet, hat Peking gerade einen Stack ausgeliefert, der ohne <br />
Genehmigung aus Washington funktioniert.<br />
<br />
📌 KAPITEL<br />
00:00 Die Woche, die Washington nicht erwartet hat<br />
01:30 Reagans Lektion von 1983<br />
03:00 Was DeepSeek V4 wirklich kann<br />
05:00 Die drei Engineering-Tricks<br />
07:30 Die eigentliche Waffe: Open Source<br />
09:00 Was das für Europa bedeutet<br />
10:30 Schmuggel-Vorwurf vs. Realität<br />
12:00 Die Drei-Jahres-Bilanz<br />
<br />
<br />
🔔 ABONNIEREN für mehr Analysen zum Chip-Krieg, zur KI-Hardware <br />
und zur globalen Technologie-Macht.<br />
<br />
#DeepSeek #DeepSeekV4 #Huawei #Nvidia #KI #ChipKrieg #ChinaKI <br />
#OpenSource #KünstlicheIntelligenz #TechNews #ChipEmbargo <br />
#AscendChip #AICompute #KIDeutsch<br />
<br />
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━<br />
<br />
📚 QUELLEN<br />
<br />
▸ DeepSeek V4 Modellkarte und technisches Whitepaper (Hugging Face)<br />
▸ Reuters: "DeepSeek's V4 may have been trained on Nvidia Blackwell <br />
chips" (April 2026)<br />
▸ Counterpoint Research, Wei Sun — Analyse zur KI-Souveränität Chinas<br />
▸ Stanford AI Index 2026 — Jahresreport zur globalen KI-Landschaft<br />
▸ The Information — Nvidia-Stellungnahme zu Schmuggel-Vorwürfen<br />
▸ South China Morning Post — Berichterstattung zu Huaweis <br />
Ascend 950 und Supernode-Architektur<br />
<br />
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━<br />
<br />
⚠️ TRANSPARENZ-HINWEIS<br />
<br />
Stand der Berichterstattung: 28. April 2026. Die Frage, ob <br />
DeepSeek V4 auf Huawei-Hardware oder auf möglicherweise <br />
geschmuggelten Nvidia-Chips trainiert wurde, ist zum <br />
Veröffentlichungszeitpunkt nicht abschließend geklärt. Dieses <br />
Video gibt den aktuellen Stand widersprüchlicher Quellen wieder.<br />
<br />
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━<br />
DeepSeek, DeepSeek V4, DeepSeek vs ChatGPT, Huawei, Huawei Ascend, Huawei Ascend 950, Nvidia, Nvidia Blackwell, KI, Künstliche Intelligenz, KI Modell, China KI, Chinesische KI, Open Source KI, Open Source AI, Chip-Krieg, Chipkrieg, Chip Embargo, US Chip Embargo, Halbleiter, Halbleiter China, Halbleiterkrieg, KI China USA, China gegen USA, Tech-Krieg, Technologiekrieg, GPT-5, GPT-5.5, OpenAI, Gemini, Gemini 3.1 Pro, Google KI, AI sovereignty, KI Souveränität, NVLink, Supernode, Mixture of Experts, MoE, KI Hardware, AI Chip, KI Chip, Frontier Model, Hugging Face, China Tech, Peking, Washington, Reagan, Sowjetunion, Skunk Works, SR-71, Aleph Alpha, Mistral AI, EU AI Act, Europa KI, Digitale Souveränität, Tech News Deutsch, KI News, KI Aktuell, Chip News, Halbleiter News, künstliche intelligenz erklärt, deepseek erklärt, chip krieg erklärt, china ki dominanz, ascend 950, blackwell GPU, AI inference, AI training, KI Inferenz, KI Training, deutsche tech kanal, dokumentation KI<br />
<br />
<br />
<br />
#DeepSeek #Huawei #Nvidia #KI #ChipKrieg<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft gibt MS-DOS 1.00 frei – den Code, der alles veränderte]]></title>
<description><![CDATA[Microsoft hat den Quellcode von MS-DOS 1.00 als Open Source hier auf Github bereitgestellt. Zum 45. Geburtstag von MS-DOS 1.00, wie Microsoft erklärt.



Microsoft schreibt zur Begründung: Bei diesen Veröffentlichungen geht es darum, historisch bedeutsame Systemsoftware für Studienzwecke, zur Erh...]]></description>
<link>https://tsecurity.de/de/3473531/it-nachrichten/microsoft-gibt-ms-dos-100-frei-den-code-der-alles-veraenderte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473531/it-nachrichten/microsoft-gibt-ms-dos-100-frei-den-code-der-alles-veraenderte/</guid>
<pubDate>Wed, 29 Apr 2026 09:16:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat den Quellcode von MS-DOS 1.00 als Open Source <a href="https://github.com/DOS-History/Paterson-Listings">hier auf Github </a>bereitgestellt. Zum 45. Geburtstag von MS-DOS 1.00, wie Microsoft erklärt.</p>



<p>Microsoft <a href="https://opensource.microsoft.com/blog/2026/04/28/continuing-the-story-of-early-dos-development/">schreibt</a> zur Begründung: Bei diesen Veröffentlichungen geht es darum, historisch bedeutsame Systemsoftware für Studienzwecke, zur Erhaltung und einfach aus Neugierde zugänglich zu machen. Den Plural “diesen” verwendet Microsoft, weil es in der Vergangenheit bereits <a href="https://www.pcwelt.de/article/1173172/ms-dos-1-25-und-2-0-quellcode-auf-github-verfuegbar.html" target="_blank" rel="noreferrer noopener">MS-DOS 1.25, 2.11 </a>und 4.0 (<a href="https://www.pcwelt.de/article/2315745/ms-dos-4-0-quellcode-open-source.html" target="_blank" rel="noreferrer noopener">MS-DOS 4.0: Quellcode ab sofort als Open Source verfügbar – mit Multitasking!)</a> als Open Source für jeden Interessierten veröffentlicht hat. Microsoft fährt fast schon euphorisch fort:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Doch diese Arbeit endet nicht mit einem GitHub-Repo. Die Geschichte der Software lebt zwar im Code, aber auch in gescannten Programmauszügen, internen Dokumenten, Assembler-Ausdrucken und den manchmal wunderbar analogen Artefakten, die zeigen, wie Betriebssysteme in den späten 1970er- und frühen 1980er-Jahren entstanden sind. Wenn Sie die <a href="https://devblogs.microsoft.com/commandline/re-open-sourcing-ms-dos-1-25-and-2-0/">ursprüngliche Ankündigung </a>zur Wiederveröffentlichung von MS-DOS 1.25 und 2.0 als Open Source im Windows Command Line-Blog lesen, werden Sie erkennen, wie wichtig der Kontext ist, wenn man verstehen will, woher die heutigen Plattformen stammen.</p>
</blockquote>



<p>Für IT-Historiker dürfte die jetzt veröffentlichte Sammlung ein wahrer Schatz sein, wie Microsoft erläutert: <em>“Wir freuen uns sehr, heute einige neu verfügbare Quellcode-Materialien vorstellen zu können, die einen noch früheren Einblick in die Entwicklung von PC-DOS 1.00, der ersten Version von DOS für den IBM PC, bieten. Ein engagiertes Team aus Historikern und Archivaren unter der Leitung von Yufeng Gao und Rich Cini hat daran gearbeitet, den Stapel an Quellcode-Ausdrucken aus der DOS-Ära von Tim Paterson, dem Entwickler von DOS, aufzuspüren, einzuscannen und zu transkribieren”</em>. </p>



<p>Und weiter: <em>“Die Listings umfassen den Quellcode des 86-DOS 1.00-Kernels, mehrere Entwicklungs-Snapshots des PC-DOS 1.00-Kernels sowie einige bekannte Dienstprogramme wie CHKDSK. Dabei handelte es sich nicht nur um Assembler-Listings, sondern auch um Listings des Assemblers selbst! Dieses Werk bietet einen seltenen Einblick in die Entstehungsgeschichte von MS-DOS/PC-DOS und in die damalige Praxis der Betriebssystementwicklung – und zwar nicht so, wie sie später rekonstruiert wurde”.</em></p>



<p>Was Microsoft in seinem obigen Posting nicht erwähnt: Bill Gates hat MS-DOS 1.00 nicht etwa komplett selbst entwickelt. Sondern Gates, der 1980 schnell ein funktionierendes Betriebssystem für den IBM-PC benötigte, kaufte das damals verfügbare 86-DOS alias QDOS, wie Zdnet <a href="https://www.zdnet.com/article/microsoft-open-sources-dos-1-0-much-more-than-the-code/">schreibt</a>. Von Seattle Computer Products dessen Gründer Tim Patterson. <a href="https://www.xda-developers.com/microsoft-open-sources-ms-dos-1-0-offering-rare-look-pc-history/">Kaufpreis</a>: rund 75.000 US-Dollar (nach anderen Angaben 50.000 Dollar). Gates passte 86-DOS noch etwas an und fertig war PC-DOS 1.0 im August 1981. </p>



<p>Microsoft behielt aber die Rechte an diesem DOS und vertrieb es als MS-DOS für andere IBM-kompatible Rechner weiter (<a href="https://www.pcwelt.de/article/2656671/50-jahre-microsoft-erfolge-fehlschlaege-ueberraschungen.html" target="_blank" rel="noreferrer noopener">50 Jahre Microsoft: Die größten Erfolge, Pleiten und Überraschungen</a>). Damit war der Grundstein für den sagenhaften Aufstieg von Microsoft gelegt (das erste Produkt von Microsoft war übrigens nicht MS-DOS, sondern Basic). Mehr dazu lesen Sie in <a href="https://www.pcwelt.de/article/1156681/heute-vor-40-jahren-brachte-microsoft-windows-in-den-handel.html" target="_blank" rel="noreferrer noopener">unserer Geschichte von Windows</a>.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">Mehr lesen:</h2>



<p><a href="https://www.pcwelt.de/article/2937881/dosbox-alte-software-spiele-am-neuen-pc-nutzen.html" target="_blank" rel="noreferrer noopener">Alte Spiele, neuer PC: So bringen Sie DOS-Klassiker unter Windows 11 zum Laufen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the meeting room has become the true test of hybrid work]]></title>
<description><![CDATA[The way organizations support collaboration today still varies widely from space to space. Small huddle rooms, project spaces, and large boardrooms often come with different setups, different workflows, and different expectations. 



For employees, that inconsistency creates friction. For IT tea...]]></description>
<link>https://tsecurity.de/de/3471094/it-nachrichten/why-the-meeting-room-has-become-the-true-test-of-hybrid-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471094/it-nachrichten/why-the-meeting-room-has-become-the-true-test-of-hybrid-work/</guid>
<pubDate>Tue, 28 Apr 2026 14:02:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The way organizations support collaboration today still varies widely from space to space. Small huddle rooms, project spaces, and large boardrooms often come with different setups, different workflows, and different expectations. </p>



<p>For employees, that inconsistency creates friction. For IT teams, it creates complexity. And for organizations, it quietly undermines the promise of hybrid work. </p>



<p>What’s becoming clear is that the meeting room is no longer just a physical space. It is where hybrid work either flows or fails. </p>



<p><strong>Meetings remain the backbone of collaboration</strong> </p>



<p>Despite new ways of working, meetings remain central to how teams align, make decisions, and move projects forward. People come to the office not to sit behind individual screens, but to connect, co‑create, and build momentum together.  </p>



<p>In a hybrid reality, those moments increasingly involve a mix of in‑room and remote participants. </p>



<p>That places a new kind of pressure on meeting spaces. They must support different group sizes, different collaboration styles, and different platforms, without forcing users to think about the technology behind it.  </p>



<p>When meetings start late because cables are missing, audio behaves differently per room, or content sharing feels unpredictable; attention shifts away from the conversation before it even begins. Hybrid collaboration only works when technology disappears into the background. </p>



<p><strong>Consistency drives adoption</strong> </p>



<p>One of the most underestimated factors in hybrid collaboration is consistency in user experience. Employees move between meeting spaces throughout the day. Every change in setup introduces uncertainty and hesitation. Over time, that leads to avoidance, workarounds, or reliance on personal devices instead of shared spaces. </p>



<p>Organizations that succeed approach meeting rooms as a connected ecosystem rather than a collection of individual rooms. A consistent experience across huddle spaces and boardrooms lowers the learning curve, increases confidence, and drives adoption naturally. People know what to expect, how to start, and how to share, regardless of where they are. </p>



<p>For IT teams, that same consistency reduces support overhead and simplifies management. Standardized setups, predictable workflows, and centralized visibility replace the constant firefighting that fragmented environments create. </p>



<p><strong>Technology should support people, not distract them</strong> </p>



<p>As collaboration technology evolves, expectations rise. Users no longer accept tools that require explanation or preparation. They expect meetings to start smoothly, participants to be seen and heard clearly, and content to be shared without effort. </p>



<p>This is where the balance between usability, <a href="https://www.barco.com/en/products/clickshare-conferencing-collaboration/security?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL" target="_blank" rel="noreferrer noopener">security</a>, and intelligence becomes critical. Ease of use drives adoption, but it cannot come at the expense of governance or trust. At the same time, intelligence must enhance the experience without adding complexity. Features like automatic audio calibration, speaker framing, or real‑time transcription only deliver value when they feel intuitive and reliable. The goal is not to showcase technology, but to create conditions where collaboration feels natural, inclusive, and uninterrupted. </p>



<p><strong>From technology choice to workplace experience</strong> </p>



<p>Ultimately, the quality of hybrid collaboration is determined less by individual features than by the experience. Employees judge meeting technology by how it makes them feel: confident or hesitant, included or sidelined, focused or distracted. </p>



<p>From huddle room to boardroom, the most effective collaboration environments share the same principles. They are simple to use, consistent across spaces, secure by design, and flexible enough to evolve. They respect people’s time and attention, allowing teams to focus on ideas rather than interfaces. </p>



<p>As organizations continue to refine their hybrid strategies, <a href="https://www.barco.com/en/products/clickshare-conferencing-collaboration?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL" target="_blank" rel="noreferrer noopener">meeting room solutions</a> remain a revealing indicator. When collaboration flows effortlessly, hybrid work has a real chance to succeed. When it doesn’t, even the best policies and tools elsewhere struggle to compensate. </p>



<p>In the end, the future of hybrid work is not decided in strategy documents. It is decided, meeting by meeting, in the rooms where people come together to work. </p>


<div class="text text--no-top-margin"><h2></h2><p></p><p><a class="button button--primary" data-amp-height="40" target="" href="https://www.barco.com/en/products/clickshare-conferencing-collaboration?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL"> Discover hybrid collaboration with ClickShare</a></p></div>


<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the meeting room has become the true test of hybrid work]]></title>
<description><![CDATA[The way organizations support collaboration today still varies widely from space to space. Small huddle rooms, project spaces, and large boardrooms often come with different setups, different workflows, and different expectations. 



For employees, that inconsistency creates friction. For IT tea...]]></description>
<link>https://tsecurity.de/de/3470910/it-security-nachrichten/why-the-meeting-room-has-become-the-true-test-of-hybrid-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470910/it-security-nachrichten/why-the-meeting-room-has-become-the-true-test-of-hybrid-work/</guid>
<pubDate>Tue, 28 Apr 2026 13:05:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The way organizations support collaboration today still varies widely from space to space. Small huddle rooms, project spaces, and large boardrooms often come with different setups, different workflows, and different expectations. </p>



<p>For employees, that inconsistency creates friction. For IT teams, it creates complexity. And for organizations, it quietly undermines the promise of hybrid work. </p>



<p>What’s becoming clear is that the meeting room is no longer just a physical space. It is where hybrid work either flows or fails. </p>



<p><strong>Meetings remain the backbone of collaboration</strong> </p>



<p>Despite new ways of working, meetings remain central to how teams align, make decisions, and move projects forward. People come to the office not to sit behind individual screens, but to connect, co‑create, and build momentum together.  </p>



<p>In a hybrid reality, those moments increasingly involve a mix of in‑room and remote participants. </p>



<p>That places a new kind of pressure on meeting spaces. They must support different group sizes, different collaboration styles, and different platforms, without forcing users to think about the technology behind it.  </p>



<p>When meetings start late because cables are missing, audio behaves differently per room, or content sharing feels unpredictable; attention shifts away from the conversation before it even begins. Hybrid collaboration only works when technology disappears into the background. </p>



<p><strong>Consistency drives adoption</strong> </p>



<p>One of the most underestimated factors in hybrid collaboration is consistency in user experience. Employees move between meeting spaces throughout the day. Every change in setup introduces uncertainty and hesitation. Over time, that leads to avoidance, workarounds, or reliance on personal devices instead of shared spaces. </p>



<p>Organizations that succeed approach meeting rooms as a connected ecosystem rather than a collection of individual rooms. A consistent experience across huddle spaces and boardrooms lowers the learning curve, increases confidence, and drives adoption naturally. People know what to expect, how to start, and how to share, regardless of where they are. </p>



<p>For IT teams, that same consistency reduces support overhead and simplifies management. Standardized setups, predictable workflows, and centralized visibility replace the constant firefighting that fragmented environments create. </p>



<p><strong>Technology should support people, not distract them</strong> </p>



<p>As collaboration technology evolves, expectations rise. Users no longer accept tools that require explanation or preparation. They expect meetings to start smoothly, participants to be seen and heard clearly, and content to be shared without effort. </p>



<p>This is where the balance between usability, <a href="https://www.barco.com/en/products/clickshare-conferencing-collaboration/security?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL" target="_blank" rel="sponsored">security</a>, and intelligence becomes critical. Ease of use drives adoption, but it cannot come at the expense of governance or trust. At the same time, intelligence must enhance the experience without adding complexity. Features like automatic audio calibration, speaker framing, or real‑time transcription only deliver value when they feel intuitive and reliable. The goal is not to showcase technology, but to create conditions where collaboration feels natural, inclusive, and uninterrupted. </p>



<p><strong>From technology choice to workplace experience</strong> </p>



<p>Ultimately, the quality of hybrid collaboration is determined less by individual features than by the experience. Employees judge meeting technology by how it makes them feel: confident or hesitant, included or sidelined, focused or distracted. </p>



<p>From huddle room to boardroom, the most effective collaboration environments share the same principles. They are simple to use, consistent across spaces, secure by design, and flexible enough to evolve. They respect people’s time and attention, allowing teams to focus on ideas rather than interfaces. </p>



<p>As organizations continue to refine their hybrid strategies, <a href="https://www.barco.com/en/products/clickshare-conferencing-collaboration?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL" target="_blank" rel="sponsored">meeting room solutions</a> remain a revealing indicator. When collaboration flows effortlessly, hybrid work has a real chance to succeed. When it doesn’t, even the best policies and tools elsewhere struggle to compensate. </p>



<p>In the end, the future of hybrid work is not decided in strategy documents. It is decided, meeting by meeting, in the rooms where people come together to work. </p>


<div class="text text--no-top-margin"><h2></h2><p></p><p><a class="button button--primary" data-amp-height="40" target="" href="https://www.barco.com/en/products/clickshare-conferencing-collaboration?ccmpgn=T-00017331&amp;utm_source=the-foundry&amp;utm_medium=sponsored-article&amp;utm_campaign=190001_ENP_GBL_pr_global_computerworld_fy26q2_PEDEL" rel="sponsored">Discover hybrid collaboration with ClickShare</a></p></div></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deconstructing the data center: A massive (and massively liberating) project]]></title>
<description><![CDATA[A few years back, Bhaskar Ramachandran read the tea leaves and what he saw was clear: With all the enhancements hyperscalers continuous make, there was no value in having on-premises data centers any longer.



“There is just no way for a private company to match that,” says Ramachandran, global ...]]></description>
<link>https://tsecurity.de/de/3470758/it-security-nachrichten/deconstructing-the-data-center-a-massive-and-massively-liberating-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470758/it-security-nachrichten/deconstructing-the-data-center-a-massive-and-massively-liberating-project/</guid>
<pubDate>Tue, 28 Apr 2026 12:19:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A few years back, <a href="https://www.linkedin.com/in/bhasram/" rel="nofollow">Bhaskar Ramachandran</a> read the tea leaves and what he saw was clear: With all the enhancements hyperscalers continuous make, there was no value in having on-premises data centers any longer.</p>



<p>“There is just no way for a private company to match that,” says Ramachandran, <a href="https://www.linkedin.com/in/bhasram/" rel="nofollow"></a>global vice president and CIO of paints and coatings manufacturer PPG. “This is their business, and they’re really good at it, and it was clear that the size of the hyperscalers is just going to win over the infrastructure game. So it didn’t make sense for us to keep up with the infrastructure.”</p>



<p>PPG began dismantling its eight global data centers about four years ago, with the final one completed in November 2025. For a 143-year-old company that has gone through 60-some acquisitions, that was no small feat.</p>



<p>Applications and infrastructure became a lot to manage, combined with trying to maintain a strong cybersecurity posture and compliance. “You can’t consistently manage this sort of a footprint, and it becomes really unwieldy very quickly,” Ramachandran says.</p>



<p>Decommissioning a data center is like defusing a complex bomb. Every wire, sequence, and step must be handled with care, because one wrong move can be a blow to your organization in downtime risks, data breaches, or a hit to its bottom line. </p>



<p>“The decommissioning of data centers is underestimated in terms of complexity, financial risks, reputation loss, and data exposure,” according to Gartner. The firm estimates that by 2030, twice as many enterprise data centers will have been decommissioned compared to those built. Reasons include consolidations, obsolescence, and shifting workloads to cloud and colocation services.</p>



<h2 class="wp-block-heading">The inadvertent data center</h2>



<p>In some instances, data centers have cropped up without much forethought. “Most organizations I work with didn’t build a data center intentionally — they grew into one,” says <a href="https://www.linkedin.com/in/aaron-walker/" rel="nofollow">Aaron Walker</a>, CEO of IT consultancy Overbyte, and a former associate partner at IBM Consulting. “A rack in a closet became a row in a repurposed room, and suddenly, you have a facility that was never designed for the job holding years of infrastructure decisions.”</p>



<p>Deconstructing that environment is work that often gets overlooked, says Walker.</p>



<p>He recently consulted with a large, fully remote online school in the throes of this process. The deconstruction work began with a full audit of what systems existed. From there every workload was categorized to determine what gets migrated, what gets moved to cloud-native infrastructure, and what gets retired entirely, he says.</p>



<p>Then came the physical side: decommissioning hardware and deciding what equipment had residual value and what to recycle. </p>



<p>“The timeline pressures are real,” Walker says. “You can’t just power things down. Dependencies surface that nobody documented.”</p>



<p>The IT organizational side had its own challenges. “People have years of institutional knowledge tied to physical systems, and there’s genuine anxiety about dismantling something they built and maintained,” he says. </p>



<p>Walker’s team also ran into issues trying to upgrade systems during the migration, which is generally a mistake, he says. “A data center deconstruction is already a significant change event, and layering additional upgrades on top of it introduces unnecessary risk. In most cases, it is better to separate modernization from migration.”</p>



<p>From start to finish, the deconstruction ran about a year, but timing will vary from project to project, he says.</p>



<h2 class="wp-block-heading">Less hassle, more flexibility</h2>



<p>When the time came for digital marketing agency Helium SEO to consider what to do with its data center, CTO <a href="https://www.linkedin.com/in/paul-demott/" rel="nofollow">Paul DeMott</a> says the math was simple. “We were paying $12,000 a month toward the colocation fees, hardware support, and the maintenance cost for the physical servers sitting in racks. Cloud infrastructure promised better reliability, automatic scaling, and way less hassle once we were done moving everything.”</p>



<p>The most compelling reason to rid itself of a physical footprint, though, was flexibility. Physical servers equated to capacity planning six months ahead, DeMott says, and if they needed more resources, IT had to wait weeks for hardware to come and get installed.</p>



<p>“Cloud allows resources to be spun up in minutes and shut down at the same speed,” he says. “We went from buying expensive hardware that depreciated to purchasing what we are actually using.”</p>



<p>IT began by creating a list of all the apps running on physical servers and classifying them according to how difficult it would be to move them. “Simple web apps moved first as they barely needed changes,” DeMott says. “Databases and anything which stores data — that’s a little bit later because we’d have had to plan the migration well.”</p>



<p>Some older apps had to be changed to work on the cloud, he adds. The actual move took place over six months, and IT decommissioned the data center while deploying apps to the cloud in tandem, moving the services step by step with backup plans for each one.</p>



<p>Still, the process wasn’t seamless. “Translating 15TB of data to the cloud takes 72 hours on our internet connection, and that was the biggest problem,” DeMott notes. IT ended up using AWS Snowball, a physical hard drive, because it took staff weeks to upload everything, “and [it] ruined the performance in our network.”</p>



<p>Another issue was figuring out the cloud costs, which DeMott characterizes as “brutal. Different types of servers, storage, data transfer costs made it almost impossible to budget,” he says. “Our first month bill accrued at 40% more than we estimated because we forgot about charges for moving data out of the cloud.”</p>



<p>It took IT three months of “fumbling” to get costs below what the company paid for the data center before things stabilized.</p>



<h2 class="wp-block-heading">The power of ‘cloud only’</h2>



<p>Once PPG made the decision to dismantle its data centers and move everything to the cloud, it was time to spread the word internally. “When you say, ‘cloud only,’ it makes it much easier for you to have conversations,” Ramachandran says. “It just sets the entire organization up on a single mission … just those two words make it very, very clear to everybody in the company what that means. There is no room for interpretation.”</p>



<p>The news was revealed at a global town hall, and initially, Ramachandran says, the sentiment was, “this too, shall pass. Then people decided to get on board.”</p>



<p>There were the typical <a href="https://www.cio.com/article/272222/change-management-change-management-definition-and-solutions.html">organizational change management</a> issues to deal with. Building momentum takes time, he says, but once the first data center was shut down, people came to the realization that “Okay, we are actually doing this,” Ramachandran says. “Then there was no resistance … everybody got on board, and things started to accelerate.”</p>



<p>Officials ensured that all the training IT needed was made available to them and the company paid for everything, certifications included. “We recognized it in town halls; anybody that went through this training and got the certification. We celebrated people. We promoted people that did the things we wanted them to do,” he says. All of this helped reinforce the mission.</p>



<p>“For the most part, business users didn’t care; their apps were available and they didn’t care where they were,” although there were a couple of exceptions among more technically savvy employees who were concerned about workflow and the security implications of cloud. There was a perception among some that a data center was more secure, Ramachandran says.</p>



<p>That led to looking at publicly available information on all the cybersecurity incidents in the recent past. The research indicated a clear pattern, he says.</p>



<p>“And the pattern is: The more significant cybersecurity events were actually happening to companies” that were largely on-prem environments, Ramachandran observes. “So you came to this point where the cloud actually became lot more secure than on-prem infrastructure.”</p>



<p>There are several reasons why, he maintains, including that, relatively speaking, it is a lot easier to implement security policies consistently in the cloud because “you have a single pane of glass enforcement of policies that you don’t have in an on-prem environment.”</p>



<p>This makes managing your attack surface area more straightforward, Ramachandran says. “So you put all of this together, you package it up on the presentation, and talk to those people one on one, and then say, ‘This is why.’”</p>



<h2 class="wp-block-heading">The dismantling process</h2>



<p>PPG works with a single hyperscaler for its business in China and three others. Deciding what apps went where was largely a function of the technology and which hyperscaler “lends itself to that brand of technology versus the other.” In some instances, where a decision of which to use wasn’t clear, IT made the call.</p>



<p>Step one was deciding on an approach, and PPG opted to modernize its apps at the same time as the deconstruction work. “When you pull together the business case to modernize applications, we came to a conclusion that if we do modernization on the application layer and the infrastructure layer at the same time, I would probably be retired by the time we migrated the data center,” Ramachandran says.</p>



<p>That made it easy to decide when to do a lift and shift and when to not bother migrating certain applications, he says. Then IT could focus on other business priorities to modernize the workforce.</p>



<p>“We just adjusted our roadmap to say the new [app] would go straight into the cloud” while not bothering to move older workloads, Ramachandran says.</p>



<h2 class="wp-block-heading">The human element</h2>



<p>The next step was “finding the people that are hungry to do something new and probably have a bit of experience and … they are waiting for someone to say, ‘Hey, let’s do this,’” Ramachandran says of the data center deconstruction. “They are forward thinkers. Every organization in our scale has [them]. It’s identifying those people and then … empowering them. They became the leaders in the new infrastructure.”</p>



<p>Once the migration started, it was important to celebrate the wins. That gets more people interested in being a part of the new organization PPG was forming called the Cloud COE (center of excellence).</p>



<p>The biggest mistake companies make is treating deconstruction as a single project instead of a phased operational shift, says <a href="https://www.linkedin.com/in/rolandparker/" rel="nofollow">Roland Parker</a>, founder and CEO of Impress Computers, a managed IT services and cybersecurity firm in Houston.</p>



<p>“We walked one 200-person manufacturer through moving workloads in priority tiers — production-critical systems last, not first — which kept their floor running while we systematically eliminated physical infrastructure over 14 months,” he says.</p>



<p>However, it’s “the human side [that] kills more timelines than the tech does,” Parker observes. “Field supervisors and plant managers have work-arounds built around how legacy systems behave.” So, before touching a single rack, Parker’s team audits those informal processes, “because if you don’t, you migrate the infrastructure and orphan the people who actually use it.”</p>



<p>Overbyte’s Walker agrees, saying that almost all the snafus his team ran into during the online school deconstruction project were not technical, but came down to visibility. “At some point, you have to confront unknown systems; things with incomplete or outdated documentation,” he says. “We had moments where, after beginning to deprovision systems, stakeholders surfaced saying, ‘Wait, that’s still in use.’”</p>



<h2 class="wp-block-heading">Dismantling systems is not the end</h2>



<p>PPG experienced no disruptions during the dismantling process, Ramachandran says, other than some tactical delays and contracts that needed updating.</p>



<p>“There were some learnings on the network side because networking can get complex,” he says. “Sometimes, we extended the outage windows” to up to five hours, for example. Those were the hiccups.”</p>



<p>From start to finish, the decommissioning process of all eight data centers took about three years. “The end is not migrating all the workloads. The end is actually shutting down the data center,” Ramachandran stresses. This requires deconstructing the power, the cooling, fire systems, and multiple generators used for backup, which had to be removed by helicopter.</p>



<p>“You have to take the diesel fuel out and dispose it off and sell it. We have to get recertification of the building for safety, because this is a building where you had kilowatts of power coming in, which basically [also] went through a deconstruction process,” he says. “So you have to get a safety certification … all of this takes time because we have to give the building back to the building management the way they gave it to us.”</p>



<h2 class="wp-block-heading">What data center deconstruction buys you</h2>



<p>The painstaking data center deconstruction process has given Ramachandran valuable insight. “Make sure your best people spend time creating value for the business, as opposed to babysitting infrastructure,” he says, because infrastructure no longer adds value.</p>



<p>“You also do a lot of inherent risk management by getting rid of data centers and moving to a cloud environment you don’t have to worry about,” he adds. Noting the current state of the economy, Ramachandran says coping with sudden price increases for memory and chips is no longer stressful since they aren’t buying infrastructure.</p>



<p>“You’re basically giving back working capital to the company, because you’re moving the organization from a fixed capital environment to your variable cost model completely,” he says, “and you don’t have to refresh your hardware every four or five years.”</p>



<p>Cost was never the objective for the data center deconstruction, Ramachandran notes. “Nonetheless, when we did the business case, we said it’s not going to cost us any more or any less, but will buy us better security, better flexibility, better agility for the organization,” as well as better focus and technology. “And we achieved all of those.”</p>



<p>The value is in all those other areas. “We are not data center operators. The team is now focused on delivering applications that are meaningful to the business,” Ramachandran says. “The team is much closer than ever to the business because we are not talking infrastructure but how to make the business better.”</p>



<p>Walker says companies should measure twice, cut once. “Most teams want to jump straight into migration,” he says, “but the real work is building a complete inventory and mapping dependencies upfront.”</p>



<p>While it made sense for PPG to modernize some apps at the same time as the data center deconstruction work, Walker advises IT leaders to resist the urge to do everything at once. “Focus on moving what you understand first, and isolate the unknowns early,” he says.<br>“The success of these projects is usually determined by how well you handle the edge cases, not the easy wins.”</p>



<p>Any new technological development IT can make without interrupting operations dramatically reduces time to market, Ramachandran says.</p>



<p>Working on the latest technologies makes IT happy, and that helps with talent retention, he adds, “because we can say we’re cloud only, so this 143-year-old company looks modern. That is meaningful in so many ways.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Konzeption eines Spatial Business Intelligence Systems zur Analyse und Steuerung von Re-Produktionsketten (fossgis2012)]]></title>
<description><![CDATA[Re-Produktionsketten sind Kombinationen technischer Prozesse des Wasser- und Energiesektors im ländlichen Raum, die in stofflicher, energetischer oder wirtschaftlicher Hinsicht miteinander in Beziehung gesetzt sind und als Ziel die lokale Wertschöpfung und Ressourceneinsparung verfolgen. In diese...]]></description>
<link>https://tsecurity.de/de/3469020/it-security-video/konzeption-eines-spatial-business-intelligence-systems-zur-analyse-und-steuerung-von-re-produktionsketten-fossgis2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469020/it-security-video/konzeption-eines-spatial-business-intelligence-systems-zur-analyse-und-steuerung-von-re-produktionsketten-fossgis2012/</guid>
<pubDate>Mon, 27 Apr 2026 19:32:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Re-Produktionsketten sind Kombinationen technischer Prozesse des Wasser- und Energiesektors im ländlichen Raum, die in stofflicher, energetischer oder wirtschaftlicher Hinsicht miteinander in Beziehung gesetzt sind und als Ziel die lokale Wertschöpfung und Ressourceneinsparung verfolgen. In diesem interdisziplinären Arbeitsfeld setzt sich das Forschungsprojekt mit der Identifizierung, dem Aufbau und der Steuerung derartiger regionaler Stoffkreisläufe auseinander. Angesichts steigender Preise für Energie und Rohstoffe interessieren sich Kommunen und Unternehmen sehr für den Aufbau solcher regionaler Wertschöpfungsketten. Für die räumlich-analytische Untersuchung der starken räumlichen Beziehungen zwischen den Akteuren, den technischen und natürlichen Elementen der Re-Produktionsketten soll ein räumliches Entscheidungsunterstützungssystem (Spatial Business Intelligence System) auf Grundlage von OpenSource Komponenten aufgebaut werden, welches auf kommunaler Ebene zum Einsatz kommen soll. Die tragende Herausforderung ist dabei die kombinierte räumliche Betrachtung von GIS-Analysen und Business Intelligence in einer Web-basierten Anwendung. Ein solches System besteht aus verschiedensten Technologien um den umfangreichen Prozess aus Datenrecherche, -beschaffung, -bereitstellung, -integration und -modellierung zu verarbeiten und zu steuern.


about this event: https://fossgis-konferenz.de/2012/programm/events/452.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[QGIS und gvSIG - Desktop-GIS Lösungsansätze (fossgis2012)]]></title>
<description><![CDATA[Zunehmend rücken Open Source Desktop-GIS in den Fokus der öffentlichen Verwaltung und anderer GIS-Anwender. Dies liegt vor allem daran, dass auch im OpenSource Umfeld nun absolute Highend-Lösungen für Desktop-GIS verfügbar sind. Wussten Sie, dass Sie in QGIS Google-Karten anzeigen oder dass Sie i...]]></description>
<link>https://tsecurity.de/de/3469018/it-security-video/qgis-und-gvsig-desktop-gis-loesungsansaetze-fossgis2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469018/it-security-video/qgis-und-gvsig-desktop-gis-loesungsansaetze-fossgis2012/</guid>
<pubDate>Mon, 27 Apr 2026 19:32:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zunehmend rücken Open Source Desktop-GIS in den Fokus der öffentlichen Verwaltung und anderer GIS-Anwender. Dies liegt vor allem daran, dass auch im OpenSource Umfeld nun absolute Highend-Lösungen für Desktop-GIS verfügbar sind. Wussten Sie, dass Sie in QGIS Google-Karten anzeigen oder dass Sie in gvSIG einfach 3D-Darstellungen erstellen können?

Der Vortrag versucht einen Vergleich zwischen den beiden prominentesten Vertretern der Open Source Desktop GIS. Dabei geht es nicht darum, Funktionslisten gegenüberzustellen und abzuarbeiten, sondern neben Funktionsgruppen auch die Philosophie der beiden Systeme zu vergleichen. An einigen Beispielen wird praktisch aufgezeigt, wie klassische GIS-Fragestellungen mit beiden Systemen gelöst werden können. Dabei wird jeweils eine Lösung derselben Aufgabe in beiden Systemen vorgestellt.


about this event: https://fossgis-konferenz.de/2012/programm/events/427.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Forschungsdatenmanagement mit Open-Source-Software (fossgis2012)]]></title>
<description><![CDATA[In diesem Beitrag wird die Entwicklung und Implementation des Datenmanagement des interdisziplinären Sonderforschungsbereich 806 (SFB806) vorgestellt. 
Der SFB806 ist ein, von der deutschen Forschungsgemeinschaft (DFG) gefördertes, interdisziplinäres Forschungsprojekt an den Universitäten Köln, B...]]></description>
<link>https://tsecurity.de/de/3469016/it-security-video/forschungsdatenmanagement-mit-open-source-software-fossgis2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469016/it-security-video/forschungsdatenmanagement-mit-open-source-software-fossgis2012/</guid>
<pubDate>Mon, 27 Apr 2026 19:32:26 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In diesem Beitrag wird die Entwicklung und Implementation des Datenmanagement des interdisziplinären Sonderforschungsbereich 806 (SFB806) vorgestellt. 
Der SFB806 ist ein, von der deutschen Forschungsgemeinschaft (DFG) gefördertes, interdisziplinäres Forschungsprojekt an den Universitäten Köln, Bonn und Aachen, dass sich mit der Ausbreitung des modernen Menschen (Homo Sapiens) von Afrika nach Mitteleuropa befasst. Insgesamt sind über 100 Forscher am Projekt beteiligt, die a.) Daten produzieren, die sicher archiviert und der Forschungscommunity zugänglich gemacht werden müssen. Und b.) Daten für ihre Forschungen benötigen.
Die SFB806-Datenbank implementiert also zwei Aspekte, a. ein Archiv der Forschungsergebnisse des SFB806 und b. eine integrierte Datenbasis und (Geodaten-)Infrastruktur als Grundlage für Forschungen im SFB806. 
Fokus des Beitrags ist die OpenSource-Software basierte Umsetzung der beiden Aspekte, unter Verwendung von Technologien wie OGC Standards und Semantic Web (RDF) Methoden für das Backend, und webbasierten Interfaces (Webportal/WebGIS,SPARQL Endpoint) für das System.


about this event: https://fossgis-konferenz.de/2012/programm/events/364.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Es ist nicht CCleaner: Dieses Opensource Tuning-Tool laden CHIP-Leser bevorzugt]]></title>
<description><![CDATA[Wenn ein Windows-PC über Jahre zumüllt, sollte ordentlich ausgemistet werden. Viele Jahre griff man dann automatisch zu CCleaner. Doch in den CHIP Download-Charts liegt ein anderes Tool vorne.]]></description>
<link>https://tsecurity.de/de/3468396/downloads/es-ist-nicht-ccleaner-dieses-opensource-tuning-tool-laden-chip-leser-bevorzugt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468396/downloads/es-ist-nicht-ccleaner-dieses-opensource-tuning-tool-laden-chip-leser-bevorzugt/</guid>
<pubDate>Mon, 27 Apr 2026 16:16:08 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://im.chip.de/ii/8/4/1/4/6/1/5/3/aufmacher_v4-1732e4ea68a40cb8.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;hash=c0397c389743875381a6e244b4585c2c9b96f03eab27ab3ebeb177355a8ece0f"> Wenn ein Windows-PC über Jahre zumüllt, sollte ordentlich ausgemistet werden. Viele Jahre griff man dann automatisch zu CCleaner. Doch in den CHIP Download-Charts liegt ein anderes Tool vorne.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2006-5513 | GeoNetwork opensource 2.0.2 sql injection (XFDB-29771 / BID-20671)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in GeoNetwork opensource 2.0.2. Impacted is an unknown function. Executing a manipulation can lead to sql injection.

This vulnerability is registered as CVE-2006-5513. It is possible to launch the attack remotely. No exploit is availabl...]]></description>
<link>https://tsecurity.de/de/3463824/sicherheitsluecken/cve-2006-5513-geonetwork-opensource-202-sql-injection-xfdb-29771-bid-20671/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463824/sicherheitsluecken/cve-2006-5513-geonetwork-opensource-202-sql-injection-xfdb-29771-bid-20671/</guid>
<pubDate>Sat, 25 Apr 2026 12:22:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/geonetwork:opensource">GeoNetwork opensource 2.0.2</a>. Impacted is an unknown function. Executing a manipulation can lead to sql injection.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2006-5513">CVE-2006-5513</a>. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI data centre emissions vastly underestimated, UK admits]]></title>
<description><![CDATA[New projections raise forecasts of climate impact by up to 136 times]]></description>
<link>https://tsecurity.de/de/3462510/ai-nachrichten/ai-data-centre-emissions-vastly-underestimated-uk-admits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462510/ai-nachrichten/ai-data-centre-emissions-vastly-underestimated-uk-admits/</guid>
<pubDate>Fri, 24 Apr 2026 21:02:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New projections raise forecasts of climate impact by up to 136 times]]></content:encoded>
</item>
<item>
<title><![CDATA[Officials hugely underestimated impact of AI datacentres on UK carbon emissions]]></title>
<description><![CDATA[Revised figures increase fears about how the energy-intensive sites could worsen the climate emergency The UK government vastly underestimated the climate impact of artificial intelligence, it has emerged, after officials raised their estimate of carbon emissions from the technology by a factor o...]]></description>
<link>https://tsecurity.de/de/3462180/ai-nachrichten/officials-hugely-underestimated-impact-of-ai-datacentres-on-uk-carbon-emissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462180/ai-nachrichten/officials-hugely-underestimated-impact-of-ai-datacentres-on-uk-carbon-emissions/</guid>
<pubDate>Fri, 24 Apr 2026 18:32:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Revised figures increase fears about how the energy-intensive sites could worsen the climate emergency </p><p>The UK government vastly underestimated the climate impact of artificial intelligence, it has emerged, after officials raised their estimate of carbon emissions from the technology by a factor of more than 100.</p><p>According to new data quietly published this week, energy use by AI datacentres in the UK could cause the emission of up to 123m tonnes of carbon dioxide (MtCO₂) – about as much as generated by 2.7 million people – over the next 10 years.</p> <a href="https://www.theguardian.com/technology/2026/apr/24/officials-hugely-underestimated-impact-of-ai-datacentres-on-uk-carbon-emissions">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dieses Tool zeigt live, mit welchen Ländern Ihr PC kommuniziert]]></title>
<description><![CDATA[Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></description>
<link>https://tsecurity.de/de/3455340/it-nachrichten/dieses-tool-zeigt-live-mit-welchen-laendern-ihr-pc-kommuniziert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3455340/it-nachrichten/dieses-tool-zeigt-live-mit-welchen-laendern-ihr-pc-kommuniziert/</guid>
<pubDate>Wed, 22 Apr 2026 17:17:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/5bc1b21b-a45c-49aa-a7a3-34e8ece540ed.6d1adb2a-9b70-4257-a09a-e0d17d01da2e.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=245563ea5b6ade5693d41e8616a2f8176728562f05445b29367c44d1381723bc"> Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></content:encoded>
</item>
<item>
<title><![CDATA[The changing face of IT: From operator to orchestrator]]></title>
<description><![CDATA[For decades, IT organizations were measured by stability, uptime, cost efficiency and service delivery. Success meant systems ran reliably, incidents were minimized and budgets were controlled.



That model is no longer enough.



In today’s environment, defined by cost pressure, supply chain vo...]]></description>
<link>https://tsecurity.de/de/3454332/it-security-nachrichten/the-changing-face-of-it-from-operator-to-orchestrator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454332/it-security-nachrichten/the-changing-face-of-it-from-operator-to-orchestrator/</guid>
<pubDate>Wed, 22 Apr 2026 12:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For decades, IT organizations were measured by stability, uptime, cost efficiency and service delivery. Success meant systems ran reliably, incidents were minimized and budgets were controlled.</p>



<p>That model is no longer enough.</p>



<p>In today’s environment, defined by cost pressure, supply chain volatility and accelerating digital expectations, the role of IT is fundamentally transforming. The modern CIO is no longer just an operator of systems, but an orchestrator of business value.</p>



<h2 class="wp-block-heading">The new mandate: Business value over technology</h2>



<p>Digital transformation was once synonymous with technology modernization. But leading organizations have learned a hard truth: Technology does not create value, outcomes do.</p>



<p>Today, CIOs are accountable for:</p>



<ul class="wp-block-list">
<li>Margin improvement and cost reduction</li>



<li>Faster product development cycles</li>



<li>Supply chain resilience</li>



<li>Operational efficiency and quality</li>
</ul>



<p>This requires a fundamental shift in mindset: “Don’t sell technology. Enable business value and let technology follow.”</p>



<p>Every digital investment must tie directly to measurable impact EBIT uplift, working capital improvement, productivity gains, not just system upgrades.</p>



<h2 class="wp-block-heading">Run and transform: The dual engine of modern IT</h2>



<p>The transition from operator to orchestrator is anchored in a dual mandate:<br><br></p>



<p><em>Run the business + Transform the business</em></p>



<p><strong>Run the business</strong> ensures:</p>



<ul class="wp-block-list">
<li>Secure, resilient IT and OT environments</li>



<li>Stable ERP and plant operations</li>



<li>Compliance and cybersecurity</li>



<li>Predictable service delivery</li>
</ul>



<p><strong>Transform the business</strong> drives:</p>



<ul class="wp-block-list">
<li>Data, AI and automation at scale</li>



<li>Digital capabilities across engineering, manufacturing and supply chain</li>



<li>Agile, product-centric ways of working</li>
</ul>



<p>The differentiator is not managing these separately but orchestrating them seamlessly together.</p>



<p>This orchestration is what elevates IT from a support function to a strategic partner.</p>



<h2 class="wp-block-heading">From projects to products: Rewiring the operating model</h2>



<p>Traditional IT is structured around projects and technology silos. High-performing organizations are shifting to product and platform operating models aligned to business value streams.</p>



<p>This means:</p>



<ul class="wp-block-list">
<li>Product teams own outcomes, not just delivery</li>



<li>Platform teams enable reuse, scalability and speed</li>



<li>Business and IT operate as one integrated team</li>
</ul>



<p>The impact is significant:</p>



<ul class="wp-block-list">
<li>Faster decision-making</li>



<li>Clear accountability for outcomes</li>



<li>Reduced duplication and total cost</li>
</ul>



<p>The guiding principle becomes simple: Standardize first. Digitize second. Scale through platforms.</p>



<h2 class="wp-block-heading">Digital thread: Unlocking end-to-end value</h2>



<p>One of the biggest unlocks in industrial enterprises is the digital thread connecting engineering, manufacturing, supply chain and commercial systems into a unified ecosystem.</p>



<p>When connected, organizations gain:</p>



<ul class="wp-block-list">
<li>Real-time visibility across the value chain</li>



<li>Faster product development cycles</li>



<li>Cost transparency from design to delivery</li>



<li>Predictive, data-driven decision-making</li>
</ul>



<p>Without this integration, enterprises operate in silos — resulting in inefficiencies, delays and margin erosion.</p>



<p>The digital thread is not just a technology concept it is a business capability multiplier.</p>



<h2 class="wp-block-heading">AI as a force multiplier, not a side initiative</h2>



<p>Artificial intelligence is rapidly becoming embedded across every business function — but its true value lies not in isolated use cases, but in scaling intelligence across the enterprise.</p>



<p>Leading organizations are moving beyond experimentation to:</p>



<ul class="wp-block-list">
<li>Embed AI into core workflows (engineering, quality, supply chain)</li>



<li>Automate decision-making at scale</li>



<li>Enable predictive and prescriptive insights</li>
</ul>



<p>Examples include:</p>



<ul class="wp-block-list">
<li>Predictive quality models reducing defects before they occur</li>



<li>AI-driven quoting improving margins and win rates</li>



<li>Intelligent supply chain analytics optimizing inventory and logistics</li>
</ul>



<p>The shift is clear:<br><br></p>



<p><em>From dashboards → to decisions → to autonomous execution</em></p>



<p>However, AI’s success depends on two critical enablers: Trusted data and organizational adoption.</p>



<h2 class="wp-block-heading">Citizen development: Scaling innovation beyond IT</h2>



<p>One of the most powerful — and often underestimated — levers of transformation is citizen development.</p>



<p>In a world where demand for digital solutions far exceeds IT capacity, empowering business users to build solutions is no longer optional, it is essential.</p>



<p>Citizen development enables:</p>



<ul class="wp-block-list">
<li>Faster identification and execution of use cases at the plant and function level</li>



<li>Reduced dependency on centralized IT teams</li>



<li>Increased ownership and adoption of digital solutions</li>
</ul>



<p>But this is not about uncontrolled proliferation. Successful organizations balance empowerment with governance through:</p>



<ul class="wp-block-list">
<li>Standardized platforms (low-code/no-code, data, automation)</li>



<li>Clear guardrails for security, data and architecture</li>



<li>Digital champions embedded within business functions</li>
</ul>



<p>The role of IT shifts from builder to platform provider, coach and orchestrator of innovation.</p>



<p>When done right, citizen development creates a multiplier effect, turning every function into a contributor to digital transformation.</p>



<h2 class="wp-block-heading">Observability &amp; AIOps: Managing complexity at scale</h2>



<p>As digital ecosystems grow, so does complexity. Traditional monitoring approaches, reactive and fragmented, are no longer sufficient.</p>



<p>The next frontier is AI-driven observability and AIOps, where:</p>



<ul class="wp-block-list">
<li>Logs, metrics and events are continuously analyzed</li>



<li>Anomalies are detected proactively</li>



<li>Automated remediation reduces downtime</li>
</ul>



<p>This shift enables organizations to:</p>



<ul class="wp-block-list">
<li>Improve reliability and resilience</li>



<li>Reduce operational cost</li>



<li>Build internal intelligence rather than relying on external vendors</li>
</ul>



<p>Observability becomes a core orchestration capability, enabling IT to manage increasingly complex digital environments with confidence.</p>



<h2 class="wp-block-heading">Talent, culture and leadership: The real differentiators</h2>



<p>Technology alone does not transform organizations, people, culture and leadership do.</p>



<p>Key shifts include:</p>



<ul class="wp-block-list">
<li>Skills</li>



<li>Building capabilities in data, AI and automation across the organization</li>



<li>Culture</li>



<li>Driving speed, experimentation and continuous learning</li>



<li>Leadership</li>



<li>Ensuring strong sponsorship and business-led digital adoption</li>
</ul>



<p>The most successful organizations empower business teams to identify opportunities, while IT provides the platforms and governance to scale them.</p>



<h2 class="wp-block-heading">Governance: From control to value realization</h2>



<p>Modern governance is no longer about approvals — it is about outcomes.</p>



<p>Effective models focus on:</p>



<ul class="wp-block-list">
<li>Alignment to business priorities</li>



<li>Transparent portfolio management</li>



<li>Continuous tracking of value (EBIT, cost, productivity)</li>
</ul>



<p>The key question shifts from <em>“Is this project on track?”</em> to <em>“Is this delivering measurable business value?”</em></p>



<h2 class="wp-block-heading">Conclusion: The CIO as orchestrator-in-chief</h2>



<p>The CIO role has fundamentally evolved — from operator to orchestrator.</p>



<p>Today’s CIO must:</p>



<ul class="wp-block-list">
<li>Align technology to business outcomes</li>



<li>Integrate data, platforms and processes</li>



<li>Enable innovation at scale across the enterprise</li>
</ul>



<p>The organizations that will lead are not those that adopt the most technology, but those that orchestrate technology, data, AI and people into measurable outcomes.</p>



<p>In a world of constrained budgets and rising expectations, the mandate is clear: Run with discipline. Orchestrate with intent. Transform with measurable impact.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[We Found Vulnerabilities in Open Source Libraries — And That's Okay]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:0 We found vulnerabilities in open-source libraries. That doesn't mean open source is bad. It means we actually check what we use.  #OpenSource #SecureDevelopment #Kaspersky]]></description>
<link>https://tsecurity.de/de/3454042/malware-trojaner-viren/we-found-vulnerabilities-in-open-source-libraries-and-thats-okay/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454042/malware-trojaner-viren/we-found-vulnerabilities-in-open-source-libraries-and-thats-okay/</guid>
<pubDate>Wed, 22 Apr 2026 10:47:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/snrgjTvOjps?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>We found vulnerabilities in open-source libraries. That doesn't mean open source is bad. It means we actually check what we use.  #OpenSource #SecureDevelopment #Kaspersky<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-40865 | horilla-opensource horilla 1.5.0 HR File access control (EUVD-2026-24231)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in horilla-opensource horilla 1.5.0. Affected is an unknown function of the component HR File Handler. This manipulation causes improper access controls.

This vulnerability is registered as CVE-2026-40865. Remote exploitation of t...]]></description>
<link>https://tsecurity.de/de/3452959/sicherheitsluecken/cve-2026-40865-horilla-opensource-horilla-150-hr-file-access-control-euvd-2026-24231/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452959/sicherheitsluecken/cve-2026-40865-horilla-opensource-horilla-150-hr-file-access-control-euvd-2026-24231/</guid>
<pubDate>Tue, 21 Apr 2026 23:22:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/horilla-opensource:horilla">horilla-opensource horilla 1.5.0</a>. Affected is an unknown function of the component <em>HR File Handler</em>. This manipulation causes improper access controls.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-40865">CVE-2026-40865</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain]]></title>
<description><![CDATA[One employee at Vercel adopted an AI tool. One employee at that AI vendor got hit with an infostealer. That combination created a walk-in path to Vercel’s production environments through an OAuth grant that nobody had reviewed.Vercel, the cloud platform behind Next.js and its millions of weekly n...]]></description>
<link>https://tsecurity.de/de/3452947/it-nachrichten/vercel-breach-exposes-the-oauth-gap-most-security-teams-cannot-detect-scope-or-contain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452947/it-nachrichten/vercel-breach-exposes-the-oauth-gap-most-security-teams-cannot-detect-scope-or-contain/</guid>
<pubDate>Tue, 21 Apr 2026 23:17:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One employee at Vercel adopted an AI tool. One employee at that AI vendor got hit with an infostealer. That combination created a walk-in path to Vercel’s production environments through an OAuth grant that nobody had reviewed.</p><p>Vercel, the cloud platform behind Next.js and its millions of weekly npm downloads, <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">confirmed on Sunday</a> that attackers gained unauthorized access to internal systems. Mandiant was brought in. Law enforcement was notified. Investigations remain active. An update on Monday confirmed that Vercel collaborated with GitHub, Microsoft, npm, and Socket to verify that no Vercel npm packages were compromised. Vercel also announced it is now defaulting environment variable creation to “sensitive.” Next.js, Turbopack, AI SDK, and all Vercel-published npm packages remain uncompromised after a coordinated audit with GitHub, Microsoft, npm, and Socket.</p><p>Context.ai was the entry point. <a href="https://www.ox.security/blog/vercel-context-ai-supply-chain-attack-breachforums/">OX Security’s analysis</a> found that a Vercel employee installed the Context.ai browser extension and signed into it using a corporate Google Workspace account, granting broad OAuth permissions. When Context.ai was breached, the attacker inherited that employee’s Workspace access, pivoted into Vercel environments, and escalated privileges by sifting through environment variables not marked as “sensitive.” Vercel’s bulletin states that variables marked sensitive are stored in a manner that prevents them from being read. Variables without that designation were accessible in plaintext through the dashboard and API, and the attacker used them as the escalation path.</p><p>CEO <a href="https://x.com/rauchg/status/2045995362499076169">Guillermo Rauch described</a> the attacker as “highly sophisticated and, I strongly suspect, significantly accelerated by AI.” Jaime Blasco, CTO of Nudge Security, <a href="https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html">independently surfaced</a> a second OAuth grant tied to Context.ai’s Chrome extension, matching the client ID from Vercel’s published IOC to Context.ai’s Google account before Rauch’s public statement. The Hacker News reported that Google removed Context.ai’s Chrome extension from the Chrome Web Store on March 27. Per The Hacker News and Nudge Security, that extension embedded a second OAuth grant enabling read access to users’ Google Drive files.</p><h2>Patient zero. A Roblox cheat and a Lumma Stealer infection</h2><p><a href="https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/">Hudson Rock published forensic evidence</a> on Monday, reporting that the breach origin traces to a February 2026 Lumma Stealer infection on a Context.ai employee’s machine. According to Hudson Rock, browser history showed the employee downloading Roblox auto-farm scripts and game exploit executors. Harvested credentials included Google Workspace logins, Supabase keys, Datadog tokens, Authkit credentials, and the support@context.ai account. Hudson Rock identified the infected user as a core member of “context-inc,” Context.ai’s tenant on the Vercel platform, with administrative access to production environment variable dashboards.</p><p>Context.ai <a href="https://context.ai/security-update">published its own bulletin</a> on Sunday (updated Monday), disclosing that the breach affects its deprecated AI Office Suite consumer product, not its enterprise Bedrock offering (Context.ai’s agent infrastructure product, unrelated to AWS Bedrock). Context.ai says it detected unauthorized access to its AWS environment in March, hired CrowdStrike to investigate, and shut down the environment. Its updated bulletin then disclosed that the scope was broader than initially understood: the attacker also compromised OAuth tokens for consumer users, and one of those tokens opened the door to Vercel’s Google Workspace.</p><p>Dwell time is the detail that should concern security directors. Nearly a month separated Context.ai’s March detection from the Vercel disclosure on Sunday. A separate Trend Micro analysis references an intrusion beginning as <a href="https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html">early as June 2024</a> — a finding that, if confirmed, would extend the dwell time to roughly 22 months. VentureBeat could not independently reconcile that timeline with Hudson Rock's February 2026 dating; Trend Micro did not respond to a request for comment before publication.</p><h2>Where detection goes blind</h2><p>Security directors can use this table to benchmark their own detection stack against the four-hop kill chain this breach exploited.</p><table><tbody><tr><td><p><b>Kill Chain Hop</b></p></td><td><p><b>What Happened</b></p></td><td><p><b>Who Should Detect</b></p></td><td><p><b>Typical Coverage</b></p></td><td><p><b>Gap</b></p></td></tr><tr><td><p><b>1. Infostealer on employee device</b></p></td><td><p>Context.ai employee downloaded Roblox cheat scripts; Lumma Stealer harvested Workspace creds, Supabase/Datadog/Authkit keys.</p></td><td><p>EDR on endpoint; credential exposure monitoring.</p></td><td><p>Low. Device likely under-monitored. No stealer log monitoring at most orgs.</p></td><td><p>Most enterprises do not subscribe to infostealer intelligence feeds or correlate stealer logs against employee email domains.</p></td></tr><tr><td><p><b>2. AWS compromise at Context.ai</b></p></td><td><p>Attacker used harvested credentials to access Context.ai’s AWS. Detected in March.</p></td><td><p>Context.ai cloud security; AWS CloudTrail.</p></td><td><p>Partially detected. Context.ai stopped AWS access but missed OAuth token exfiltration.</p></td><td><p>Initial investigation did not identify OAuth token exfiltration. Scope was underestimated until Vercel disclosure.</p></td></tr><tr><td><p><b>3. OAuth token theft into Vercel Workspace</b></p></td><td><p>Compromised OAuth token used to access a Vercel employee’s Google Workspace. Employee had granted “Allow All” permissions via Chrome extension.</p></td><td><p>Google Workspace audit logs; OAuth app monitoring; CASB.</p></td><td><p>Very low. Most orgs do not monitor third-party OAuth token usage patterns.</p></td><td><p>No approval workflow intercepted the grant. No anomaly detection on OAuth token use from a compromised third party. This is the hop no one saw.</p></td></tr><tr><td><p><b>4. Lateral movement into Vercel production</b></p></td><td><p>Attacker enumerated non-sensitive env vars (accessible via dashboard/API), harvested customer credentials.</p></td><td><p>Vercel platform audit logs; behavioral analytics.</p></td><td><p>Moderate. Vercel detected the intrusion after the attacker accessed customer credentials.</p></td><td><p>Detection occurred after exfiltration, not before. Env var access by a compromised Workspace account did not trigger real-time alerting.</p></td></tr></tbody></table><h2>What’s confirmed vs. what’s claimed</h2><p>Vercel’s bulletin confirms unauthorized access to internal systems, a limited subset of affected customers, and two IOCs tied to Context.ai’s Google Workspace OAuth apps. Rauch confirmed that Next.js, Turbopack, and Vercel’s open-source projects are unaffected.</p><p>Separately, a threat actor using the ShinyHunters name <a href="https://www.bleepingcomputer.com/news/security/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/">posted on BreachForums</a> claiming to hold Vercel’s internal database, employee accounts, and GitHub and NPM tokens, with a $2M asking price. Austin Larsen, principal threat analyst at Google Threat Intelligence, <a href="https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/">assessed the claimant</a> as “likely an imposter.” Actors previously linked to ShinyHunters have denied involvement. None of these claims has been independently verified.</p><h2>Six governance failures the Vercel breach exposed</h2><p><b>1. AI tool OAuth scopes go unaudited. </b>Context.ai’s own bulletin states that a Vercel employee granted “Allow All” permissions using a corporate account. Most security teams have no inventory of which AI tools their employees have granted OAuth access to.</p><p>CrowdStrike CTO Elia Zaitsev put it bluntly at RSAC 2026: “Don’t give an agent access to everything just because you’re lazy. Give it access to only what it needs to get the job done.” Jeff Pollard, VP and principal analyst at Forrester, told Cybersecurity Dive that the attack is a reminder about <a href="https://www.cybersecuritydive.com/news/vercel-customers-targeted-after-third-party-tool-compromised/817949/">third-party risk management concerns and AI tool permissions</a>.</p><p><b>2. Environment variable classification is doing real security work. </b>Vercel distinguishes between variables marked “sensitive” (stored in a manner that prevents reading) and those without that designation (accessible in plaintext through the dashboard and API). Attackers used the accessible variables as the escalation path. A developer convenience toggle determined the blast radius. Vercel has since changed its default: new environment variables now default to sensitive.</p><p>“Modern controls get deployed, but if legacy tokens or keys aren’t retired, the system quietly favors them,” Merritt Baer, CSO at Enkrypt AI and former Deputy CISO at AWS, told VentureBeat. </p><p><b>3. Infostealer-to-SaaS-to-supply-chain escalation chains lack detection coverage. </b>Hudson Rock’s reporting reveals a kill chain that crossed four organizational boundaries. No single detection layer covers that chain. Context.ai’s updated bulletin acknowledged that the scope extended beyond what was initially identified during its CrowdStrike-led investigation.</p><p><b>4. Dwell time between vendor detection and customer notification exceeds attacker timelines.</b> Context.ai detected the AWS compromise in March. Vercel disclosed on Sunday. Every CISO should ask their vendors: what is your contractual notification window after detecting unauthorized access that could affect downstream customers?</p><p><b>5. Third-party AI tools are the new shadow IT. </b>Vercel’s bulletin describes Context.ai as “a small, third-party AI tool.” <a href="https://www.securityweek.com/the-shadow-ai-problem-how-saas-apps-are-quietly-enabling-massive-breaches/">Grip Security’s March 2026 analysis</a> of 23,000 SaaS environments found a 490% year-over-year increase in AI-related attacks. Vercel is the latest enterprise to learn this the hard way.</p><p><b>6. AI-accelerated attackers compress response timelines. </b>Rauch’s assessment of AI acceleration comes from what his IR team observed. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike’s 2026 Global Threat Report</a> puts the baseline at a 29-minute average eCrime breakout time, 65% faster than 2024.</p><h2>Security director action plan</h2><table><tbody><tr><td><p><b>Attack Surface</b></p></td><td><p><b>What Failed</b></p></td><td><p><b>Recommended Action</b></p></td><td><p><b>Owner</b></p></td></tr><tr><td><p><b>OAuth governance</b></p></td><td><p>Context.ai held broad “Allow All” Workspace permissions. No approval workflow intercepted.</p></td><td><p>Inventory every AI tool OAuth grant org-wide. Revoke scopes exceeding least privilege. Check both Vercel IOCs now.</p></td><td><p>Identity / IAM</p></td></tr><tr><td><p><b>Env var classification</b></p></td><td><p>Variables not marked “sensitive” remained accessible. Accessibility became the escalation path.</p></td><td><p>Default to non-readable. Require a security sign-off to downgrade any variable to accessible.</p></td><td><p>Platform eng + security</p></td></tr><tr><td><p><b>Infostealer-to-supply-chain</b></p></td><td><p>Kill chain spanned Lumma Stealer, Context.ai AWS, OAuth tokens, Vercel Workspace, and production environments.</p></td><td><p>Correlate Infostealer intel feeds against employee domains. Automate credential rotation when creds surface in stealer logs.</p></td><td><p>Threat intel + SOC</p></td></tr><tr><td><p><b>Vendor notification lag</b></p></td><td><p>Nearly a month between Context.ai detection and Vercel disclosure.</p></td><td><p>Require 72-hour notification clauses in all contracts involving OAuth or identity integration.</p></td><td><p>Third-party risk / legal</p></td></tr><tr><td><p><b>Shadow AI adoption</b></p></td><td><p>One employee’s unapproved AI tool became the breach vector for hundreds of orgs.</p></td><td><p>Extend shadow IT discovery to AI agent platforms. Treat unapproved adoption as a security event.</p></td><td><p>Security ops + procurement</p></td></tr><tr><td><p><b>Lateral movement speed</b></p></td><td><p>Rauch suspects AI acceleration. Attacker compressed the access-to-escalation window.</p></td><td><p>Cut detection-to-containment SLAs below 29-minute eCrime average.</p></td><td><p>SOC + IR team</p></td></tr></tbody></table><h2>Run both IoC checks today</h2><p>Search your Google Workspace admin console (Security &gt; API Controls &gt; Manage Third-Party App Access) for two OAuth App IDs.</p><p>The first is 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com, tied to Context.ai’s Office Suite.</p><p>The second is 110671459871-f3cq3okebd3jcg1lllmroqejdbka8cqq.apps.googleusercontent.com, tied to Context.ai’s Chrome extension and granting Google Drive read access.</p><p>If either touched your environment, you are in the blast radius regardless of what Vercel discloses next.</p><h2>What this means for security directors</h2><p>Forget the Vercel brand name for a moment. What happened here is the first major proof case that AI agent OAuth integrations create a breach class that most enterprise security programs cannot detect, scope, or contain. A Roblox cheat download in February led to production infrastructure access in April. Four organizational boundaries, two cloud providers, and one identity perimeter. No zero-day required.</p><p>For most enterprises, employees have connected AI tools to corporate Google Workspace, Microsoft 365 or Slack instances with broad OAuth scopes — without security teams knowing. The Vercel breach is the case study for what that exposure looks like when an attacker finds it first.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises are rethinking Kubernetes]]></title>
<description><![CDATA[For years, Kubernetes held an almost mythic place in enterprise IT. It was positioned as the control plane for the future, the standard abstraction for cloud-native systems, and the platform that would finally free enterprises from infrastructure lock-in. To be fair, some of that was true. Kubern...]]></description>
<link>https://tsecurity.de/de/3451005/ai-nachrichten/enterprises-are-rethinking-kubernetes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451005/ai-nachrichten/enterprises-are-rethinking-kubernetes/</guid>
<pubDate>Tue, 21 Apr 2026 11:48:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a> held an almost mythic place in enterprise IT. It was positioned as the control plane for the future, the standard abstraction for <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" data-type="link" data-id="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> systems, and the platform that would finally free enterprises from infrastructure lock-in. To be fair, some of that was true. Kubernetes brought discipline to container orchestration, enabled portable deployment models, and provided architects with a powerful framework for managing distributed applications at scale.</p>



<p>However, the market is changing, and so are enterprise expectations. The question is no longer whether Kubernetes is technically impressive. It clearly is. The question is whether it still represents the best fit for a growing number of mainstream enterprise use cases. In many cases, the answer is increasingly no. What we are seeing is not the death of Kubernetes but the end of its unquestioned dominance as the default strategic choice. Here’s why. </p>



<h2 class="wp-block-heading">Too operationally expensive</h2>



<p>As Kubernetes adoption grew, many organizations hesitated to admit that it introduced operational complexity and needed specialized skills, constant tuning, and strong governance. Running Kubernetes well requires mature engineering, observability, security, networking, and life-cycle management—much more than a side project. Many underestimated this burden.</p>



<p>What looked elegant in architectural diagrams became a real-world tax on operations teams. Clusters multiplied. Toolchains sprawled. Upgrades became risky. Policy enforcement became an engineering discipline in its own right. Enterprises realized they were not just adopting an orchestration platform. They were building and maintaining an internal product that required sustained investment and scarce expertise.</p>



<p>That might be acceptable for digital-native businesses whose scale and complexity justify the effort. It is a much harder sell for enterprises that want reliable deployments, resilient applications, and reasonable cloud costs. In those cases, Kubernetes can feel like overengineering disguised as strategic modernization. When a company spends more time managing the platform than delivering business value on top of it, the novelty wears off quickly.</p>



<h2 class="wp-block-heading">Portability becomes less important</h2>



<p>Kubernetes was marketed as a hedge against lock-in, enabling applications to run across on-premises, cloud, and <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge</a>. However, most enterprises faced ecosystem dependencies—storage, networking, security, identity, observability, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, managed services, and cloud-native databases—creating practical lock-in that Kubernetes didn’t eliminate.</p>



<p>What enterprises gained in workload portability, they often lost in ecosystem complexity. They standardized on Kubernetes while still depending heavily on a particular cloud provider’s managed services and operational conventions. The result was a strange middle ground: all the complexity of a highly abstracted platform without the full simplicity of using opinionated native services end-to-end.</p>



<p>This matters more now because boards and executive teams are less interested in theoretical architectural optionality and more focused on measurable business outcomes. They want speed, resilience, cost control, and lower risk. If a managed application platform, <a href="https://www.infoworld.com/article/2261831/what-is-serverless-serverless-computing-explained.html">serverless </a>environment, or provider-specific <a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">platform-as-a-service</a> offering gets them there faster, many are willing to accept some level of dependency. Enterprises are becoming more candid about the trade-offs. They are realizing that strategic flexibility is valuable, but not at any cost.</p>



<p>This is where Kubernetes starts losing favor. Portability has value, but for many enterprises, it hasn’t justified the operational and organizational burden it entails. The promise exceeded the actual return.</p>



<h2 class="wp-block-heading">Better abstractions are catching up</h2>



<p>Perhaps the most important shift is that enterprises are moving away from buying raw technical primitives and toward consuming higher-level platforms that better align with developer productivity and business outcomes. Platform engineering teams increasingly hide Kubernetes behind internal developer platforms. Public cloud providers continue to improve managed container services, serverless offerings, and integrated application environments that reduce hands-on infrastructure management. Developers, meanwhile, do not want to become part-time cluster operators. They want fast paths to build, deploy, secure, and monitor applications without stitching together a dozen components.</p>



<p>In other words, Kubernetes may still be present under the hood, but it is becoming less visible and less central to strategic buying decisions. That is usually a sign of maturity. Technologies shift from being the headline to being plumbing. Enterprises are not asking, “How do we adopt Kubernetes?” as often as they are asking, “What is the fastest, safest, most cost-effective way to deliver modern applications?” That is a much healthier question.</p>



<p>The answer increasingly points to curated platforms, opinionated developer environments, and managed services that abstract away Kubernetes rather than exposing it. This is not a rejection of cloud-native principles. It is a rejection of unnecessary cognitive load. Enterprises are deciding they do not need to own every layer of complexity to realize the benefits of modern architecture.</p>



<h2 class="wp-block-heading">Surrendering the spotlight</h2>



<p>None of this means Kubernetes is disappearing. It remains important for large-scale, heterogeneous, and highly customized environments. It is still an excellent fit for organizations with strong platform maturity, regulatory constraints, or sophisticated multicloud operational needs. But that is a narrower slice of the market than the hype cycle once suggested.</p>



<p>What is losing popularity is not Kubernetes as a technology, but Kubernetes as the unquestioned standard for enterprises. This difference is important. Companies are becoming more selective about where to accept complexity and where to avoid it. They are less inclined to idealize infrastructure and more eager to choose simplicity when it exists.</p>



<p>That is probably a good thing. The job of enterprise architecture is not to admire elegant technology for its own sake. It is to align technology choices with operational realities, economic constraints, and business outcomes. By that standard, Kubernetes still has a place, but it no longer gets a free pass.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing between MySQL, MariaDB and PostgreSQL - Educating on the differences]]></title>
<description><![CDATA[Author: MariaDB Foundation - Bewertung: 1x - Views:7 Part 2 of a 3-part series: Database Trends — What is changing in the database world

In this segment, Kaj Arnö continues the conversation with Kellyn Gorman (Redgate), focusing on how organisations choose between MySQL, MariaDB, and PostgreSQL....]]></description>
<link>https://tsecurity.de/de/3448425/videos/choosing-between-mysql-mariadb-and-postgresql-educating-on-the-differences/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448425/videos/choosing-between-mysql-mariadb-and-postgresql-educating-on-the-differences/</guid>
<pubDate>Mon, 20 Apr 2026 15:34:34 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: MariaDB Foundation - Bewertung: 1x - Views:7 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/wfMsXhCK48c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Part 2 of a 3-part series: Database Trends — What is changing in the database world<br />
<br />
In this segment, Kaj Arnö continues the conversation with Kellyn Gorman (Redgate), focusing on how organisations choose between MySQL, MariaDB, and PostgreSQL.<br />
<br />
Rather than comparing features alone, the discussion highlights what truly drives decisions in practice: migration complexity, compatibility, and operational risk.<br />
<br />
Key topics:<br />
• Why database migrations are often underestimated<br />
• How compatibility can significantly reduce migration effort<br />
• Practical considerations when choosing between MySQL, MariaDB, and PostgreSQL<br />
<br />
“Most processes are not going to require refactoring… that’s going to decrease your migration time.”<br />
<br />
This part offers a grounded, experience-based perspective on database decision-making in real-world environments.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dieses Tool zeigt, wo Ihr Datenverkehr auf der Welt entlang geht]]></title>
<description><![CDATA[Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></description>
<link>https://tsecurity.de/de/3441117/it-nachrichten/dieses-tool-zeigt-wo-ihr-datenverkehr-auf-der-welt-entlang-geht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441117/it-nachrichten/dieses-tool-zeigt-wo-ihr-datenverkehr-auf-der-welt-entlang-geht/</guid>
<pubDate>Fri, 17 Apr 2026 09:32:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/5bc1b21b-a45c-49aa-a7a3-34e8ece540ed.6d1adb2a-9b70-4257-a09a-e0d17d01da2e.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=245563ea5b6ade5693d41e8616a2f8176728562f05445b29367c44d1381723bc"> Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></content:encoded>
</item>
<item>
<title><![CDATA[Freie App zeigt es in Echtzeit: So weit verzweigt sich Ihr Internet-Verkehr]]></title>
<description><![CDATA[Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></description>
<link>https://tsecurity.de/de/3438463/it-nachrichten/freie-app-zeigt-es-in-echtzeit-so-weit-verzweigt-sich-ihr-internet-verkehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438463/it-nachrichten/freie-app-zeigt-es-in-echtzeit-so-weit-verzweigt-sich-ihr-internet-verkehr/</guid>
<pubDate>Thu, 16 Apr 2026 13:17:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/9d405ba0-c941-48d4-970b-fe034ae6e79f.d2fd3021-e109-4438-85e2-06c4e0e1db03.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=c68ca4321c912e20b53a401d7af7c95610335865d05f1db67d73f49543161125"> Auf welchen Servern sind Sie unterwegs, wenn Sie im Internet surfen? Eine Opensource-App schlüsselt Ihren Traffic in Echtzeit nach besuchten Ländern auf.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ease into Azure Kubernetes Application Network]]></title>
<description><![CDATA[If you’re using Kubernetes, especially a managed version like Azure Kubernetes Service (AKS), you don’t need to think about the underlying hardware. All you need to do is build your application and it should run, its containers managed by the service’s orchestrator.



At least that’s the theory....]]></description>
<link>https://tsecurity.de/de/3438009/ai-nachrichten/ease-into-azure-kubernetes-application-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438009/ai-nachrichten/ease-into-azure-kubernetes-application-network/</guid>
<pubDate>Thu, 16 Apr 2026 11:04:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If you’re using <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, especially a managed version like <a href="https://www.infoworld.com/article/4058764/smoother-kubernetes-sailing-with-aks-automatic.html">Azure Kubernetes Service</a> (AKS), you don’t need to think about the underlying hardware. All you need to do is build your application and it should run, its containers managed by the service’s orchestrator.</p>



<p>At least that’s the theory. However, implementing a platform that abstracts your code from the servers and network that support it brings its own problems, and a whole new discipline. <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">Platform engineers</a> fill the gap between software and hardware, supporting security and networking, as well as managing storage and other key services.</p>



<p>Kubernetes is part of an ecosystem of <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native services</a> that provide the supporting framework for running and managing scalable distributed systems, including the tools needed to package and deploy applications, as well as components that extend the functionality of Kubernetes’ own nodes and pods.</p>



<p>Key components of this growing ecosystem are the various <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">service meshes</a>. These offer a way to manage connectivity between nodes and between your applications and the outside network, with tools for handling basic network security. Often implemented as “sidecar” containers, running alongside Kubernetes pods, these network proxies can consume added resources as your applications scale. That means more configuration and management, ensuring that configurations are kept up-to-date and that secrets are secure.</p>



<h2 class="wp-block-heading">Istio goes ambient</h2>



<p>One of the key service mesh implementations, <a href="https://www.infoworld.com/article/2258313/what-is-istio-the-kubernetes-service-mesh-explained.html">Istio</a>, has developed an alternate way of operating, <a href="https://istio.io/latest/docs/ambient/">what the project calls “ambient mode”</a>. Here, instead of having individual sidecars for each pod, your service mesh is implemented as per-node proxies or as a single proxy that supports an entire Kubernetes namespace. It’s an approach that allows you to start implementing a service mesh without increasing the complexity of your platform, making it easy to go from a basic development Kubernetes implementation to a production environment without having to change your application pods.</p>



<p>It’s called ambient mode because there’s no need to add new service mesh elements as your application scales. Instead, the service mesh is always there, and your pods simply join it and take advantage of the existing configuration. The resulting implementation is both easier to use and easier to understand.</p>



<p><a href="https://www.infoworld.com/article/2260999/introducing-the-service-mesh-interface.html?utm=hybrid_search">Microsoft has used Istio as part of Azure Kubernetes Service for many years</a>. Istio is one of a suite of open-source tools that provide the backbone of Azure’s cloud-native computing platform.</p>



<h2 class="wp-block-heading">Introducing Azure Kubernetes Application Network</h2>



<p>So, it’s not surprising to <a href="https://opensource.microsoft.com/blog/2026/03/24/whats-new-with-microsoft-in-open-source-and-kubernetes-at-kubecon-cloudnativecon-europe-2026/">l</a>earn that Microsoft is <a href="https://opensource.microsoft.com/blog/2026/03/24/whats-new-with-microsoft-in-open-source-and-kubernetes-at-kubecon-cloudnativecon-europe-2026/">using Istio’s ambient mesh as the basis of Azure Kubernetes Application Network</a>. The new service (<a href="https://learn.microsoft.com/en-us/azure/application-network/">available in preview</a>) allows application developers to add managed network services to their applications without needing the support of a platform engineering team to implement a service mesh. It will even help you migrate away from the now-deprecated ingress-nginx by providing access to the recommended Kubernetes Gateway API without needing more sidecars and letting you use your existing ingress-nginx configurations while you complete your migration. </p>



<p><a href="https://learn.microsoft.com/en-us/azure/application-network/overview">Microsoft describes the preview of Azure Kubernetes Application Network</a> as “a fully managed, ambient-based service network solution for Azure Kubernetes Service (AKS).” The underlying data and control planes are managed by AKS, so all you need to do is connect your AKS clusters to an Application Network and AKS will then manage the service mesh for you, without any changes to your applications.</p>



<p>Like other implementations of Istio’s ambient mesh, there are two levels to Application Network: a core set of node-level application proxies that handle connectivity and security for application services, and an optional set of lower-level proxies that support routing and apply network policies, acting as a software-defined network inside your Kubernetes environment.</p>



<p>This approach lets you build and test a Kubernetes application on your local development hardware without using Application Network features, then deploy it to AKS along with the required network configuration — simplifying both development and deployment. It also reduces development overheads, both in compute and developer resources.</p>



<h2 class="wp-block-heading">Using Azure Kubernetes Application Network</h2>



<p>Once deployed Application Network connects the services in your application securely, managing encrypted connections automatically and managing the required certificates. It can support unencrypted connections, for when you aren’t sending confidential data and don’t need the associated overhead. As the service is managed by AKS, new pods are automatically provisioned as they are deployed, with the ambient mesh supporting both scale-up and scale-down operations.</p>



<p><a href="https://learn.microsoft.com/en-us/azure/application-network/architecture">The architecture of Application Network is much like that of an Istio ambient mesh</a>. The main difference is that the service’s management and control planes are managed by Azure, with application owners limited to working with the service’s data plane, configuring operations and setting policies for their application workloads. Azure’s control of the management plane automates certificate management, ensuring that connections stay secure and there is little risk of certificate expiration, using the tools built into Azure Key Vault.</p>



<p>The Application Network data plane holds proxies and gateways used by the service mesh, and these are deployed when the service is launched, along with the required Kubernetes configurations. The key to operation is <a href="https://github.com/istio/ztunnel">ztunnel</a>, a proxy that intercepts inter-service requests, secures the connection, and routes requests to another ztunnel running with the destination service. A gateway oversees connections between ztunnels running in remote clusters, allowing your service mesh to scale out with demand.</p>



<h2 class="wp-block-heading">Building your first ambient service mesh in AKS</h2>



<p><a href="https://learn.microsoft.com/en-us/azure/application-network/get-started">Getting started with Azure Kubernetes Application Network</a> requires the Azure CLI. If you’re working with an existing AKS cluster, then you will need to enable integration with Microsoft Entra and enable OpenID Connect.</p>



<p>As the Application Network service is in preview, start by registering it in your account. This can take some time, but once it’s registered you can install the AppNet CLI extension that’s used to manage and control Application Network for your AKS clusters. You can now start to set up the ambient service mesh, either creating new clusters to use it, or adding the service mesh to existing AKS deployments.</p>



<p>Starting from scratch is the easiest way, as it ensures that you’re running in the same tenant. AKS clusters and Application Network can be in the same resource group if you want, but it’s not necessary. You’re free to use separate resource groups for management.</p>



<p>The <code>appnet</code> command makes it easy to create an Application Network from the command line; all you need is a name for the network, a resource group, a location, and an identity type. Once you’ve run the command to create your ambient mesh, wait for the mesh to be provisioned before joining a cluster to your network. This again simply needs a resource group, a name for the member cluster, and its resource group and cluster name. At the same time, you define how the network will be managed, i.e. whether you manage upgrades yourself or leave Azure to manage them for you. Additional clusters can be added to the network the same way.</p>



<p>With an Application Network and member clusters in place, the next step is to use Kubernetes’ own tooling to add support for the ambient mesh to your applications. <a href="https://learn.microsoft.com/en-us/azure/application-network/traffic-management-use-cases">Microsoft provides a useful example</a> that shows how to use Application Network with the Kubernetes Gateway API to manage ingress. You need to use <code>kubectl</code> and <code>istioctl</code> commands to enable gateways and verify their operation, adding services and ensuring that they are visible to each other through their respective ztunnels.</p>



<h2 class="wp-block-heading">Securing applications with policies</h2>



<p>Policies can be used to control access from the application ingress to specific services as well as between services, reducing the risk of breaches and ensuring that you control how traffic is routed in your application. These policies can be locked down to ensure only specific methods can be used, so only allowing HTTP GET operations on a read-only service, and POST where data needs to be delivered. Other options can be used to enforce OpenID Connect authorization at a mesh level.</p>



<p>Not all Azure Kubernetes clusters are supported in the preview, which is only available in Azure’s largest regions. For now, Application Network won’t work with private clusters or with Windows node pools. Once running you can’t switch upgrade modes, and as it’s based on Istio, you can’t enable Istio service meshes in your cluster. These requirements aren’t showstoppers, and you should be able to get started experimenting with the service as it’s still in preview.</p>



<p>AKS Application Network is a powerful tool that helps simplify and secure the process of building and running inter-cluster networks in an AKS application. As it is an ambient service, it’s possible to scale as necessary, and can help provide secure bridges between clusters. By working at a Kubernetes level, it’s possible to use Application Network to provide policy driven production network rules, allowing developers to build and test code in unrestricted environments before moving to test and production clusters.</p>



<p>As Application Network uses familiar Kubernetes and Istio constructions, it’s possible to build configurations into Helm charts and other deployment tools, ensuring configurations are part of your build artifacts and that network configurations and policies are delivered with your code every time you push a new build – without needing platform engineering support.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I made a Linux distro guessing game.]]></title>
<description><![CDATA[It's in https://distro.fedesito.me , It's a Pokedle inspired game, in which you try to choose the Linux distro based on it's characteristics/features. If you want to add features/distros feel free to do a pull request, the project is opensource at my ShitHub (link in website). EDIT: fixed some bu...]]></description>
<link>https://tsecurity.de/de/3437211/linux-tipps/i-made-a-linux-distro-guessing-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437211/linux-tipps/i-made-a-linux-distro-guessing-game/</guid>
<pubDate>Thu, 16 Apr 2026 03:53:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>It's in <a href="https://distro.fedesito.me/">https://distro.fedesito.me</a> , It's a Pokedle inspired game, in which you try to choose the Linux distro based on it's characteristics/features.</p> <p>If you want to add features/distros feel free to do a pull request, the project is opensource at my ShitHub (link in website).</p> <p>EDIT: fixed some bugs and added instructions</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xz3phyr"> /u/xz3phyr </a> <br> <span><a href="https://i.redd.it/bnxbcawttbvg1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sm1jhz/i_made_a_linux_distro_guessing_game/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qwen 3.5 Auch auf kleiner Hardware? 👾 #insideai #qwen3 #ki]]></title>
<description><![CDATA[Author: Fraunhofer IEM - Bewertung: 0x - Views:0 Tommy erklärt, dass Locale OpenSource Modelle der beste Weg ist.

🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/

📢 Mehr erfahren & vernetzen:
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem
📸 Instagram: https...]]></description>
<link>https://tsecurity.de/de/3427822/videos/qwen-35-auch-auf-kleiner-hardware-insideai-qwen3-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427822/videos/qwen-35-auch-auf-kleiner-hardware-insideai-qwen3-ki/</guid>
<pubDate>Mon, 13 Apr 2026 08:02:18 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Fraunhofer IEM - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tCXlpx8PNQA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Tommy erklärt, dass Locale OpenSource Modelle der beste Weg ist.<br />
<br />
🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/<br />
<br />
📢 Mehr erfahren & vernetzen:<br />
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem<br />
📸 Instagram: https://www.instagram.com/fraunhofer.iem<br />
📩 Newsletter: https://www.iem.fraunhofer.de/newsletter<br />
<br />
📺 Abonniere unseren YouTube-Kanal: @FraunhoferIEM<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Absolute Kontrolle KI auf lokaler Hardware! 💻 #insideai #local #ki]]></title>
<description><![CDATA[Author: Fraunhofer IEM - Bewertung: 9x - Views:247 Tommy erklärt, dass Locale OpenSource Modelle der beste Weg ist.

🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/

📢 Mehr erfahren & vernetzen:
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem
📸 Instagram: htt...]]></description>
<link>https://tsecurity.de/de/3426959/videos/absolute-kontrolle-ki-auf-lokaler-hardware-insideai-local-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3426959/videos/absolute-kontrolle-ki-auf-lokaler-hardware-insideai-local-ki/</guid>
<pubDate>Sun, 12 Apr 2026 20:47:02 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Fraunhofer IEM - Bewertung: 9x - Views:247 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AFQ6cZKi-6A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Tommy erklärt, dass Locale OpenSource Modelle der beste Weg ist.<br />
<br />
🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/<br />
<br />
📢 Mehr erfahren & vernetzen:<br />
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem<br />
📸 Instagram: https://www.instagram.com/fraunhofer.iem<br />
📩 Newsletter: https://www.iem.fraunhofer.de/newsletter<br />
<br />
📺 Abonniere unseren YouTube-Kanal: @FraunhoferIEM<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Rust to the Pixel Baseband]]></title>
<description><![CDATA[Posted by Jiacheng Lu, Software Engineer, Google Pixel Team

Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped wit...]]></description>
<link>https://tsecurity.de/de/3424550/it-security-nachrichten/bringing-rust-to-the-pixel-baseband/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424550/it-security-nachrichten/bringing-rust-to-the-pixel-baseband/</guid>
<pubDate>Fri, 10 Apr 2026 20:37:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="byline-author">Posted by Jiacheng Lu, Software Engineer, Google Pixel Team</span>

<p>Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. <a href="https://security.googleblog.com/2023/12/hardening-cellular-basebands-in-android.html">Recognizing the risks</a> associated within the complex modem firmware, Pixel 9 shipped with <a href="https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html">mitigations</a> against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html">"Deploying Rust in Existing Firmware Codebases"</a>, this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying the foundation for broader adoption of memory-safe code in other areas.</p>

<p>Here we share our experience of working on it, and hope it can inspire the use of more memory safe languages in low-level environments.</p>

<h3>Why Modem Memory Safety Can’t Wait</h3>
<p>In recent years, we have seen increasing interest in the cellular modem from attackers and security researchers. For example, Google's Project Zero <a href="https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html">gained remote code execution</a> on Pixel modems over the Internet. Pixel modem has tens of Megabytes of executable code. Given the complexity and remote attack surface of the modem, other critical memory safety vulnerabilities may remain in the predominantly memory-unsafe firmware code.</p>

<h3>Why DNS?</h3>
<p>The DNS protocol is most commonly known in the context of browsers finding websites. With the evolution of cellular technology, modern cellular communications have migrated to digital data networks; consequently, even basic operations such as call forwarding rely on DNS services.</p>

<p>DNS is a complex protocol and requires parsing of untrusted data, which can lead to vulnerabilities, particularly when implemented in a memory-unsafe language (example: <a href="https://nvd.nist.gov/vuln/detail/cve-2024-27227">CVE-2024-27227</a>). Implementing the DNS parser in Rust offers value by decreasing the attack surfaces associated with memory unsafety.</p>

<h3>Picking a DNS library</h3>
<p>DNS already has a level of support in the open-source Rust community. We evaluated multiple open source crates that implement DNS. Based on <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html#:~:text=Existing%20Crate">criteria shared in earlier posts</a>, we identified <a href="https://crates.io/crates/hickory-proto">hickory-proto</a> as the best candidate. It has excellent maintenance, over 75% test coverage, and widespread adoption in the Rust community. Its pervasiveness shows its potential as the de-facto DNS choice and long term support. Although hickory-proto initially lacked <code>no_std</code> support, which is needed for Bare-metal environments (see our <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html#:~:text=Bare-metal%20Environments">previous post</a> on this topic), we were able to add support to it and its dependencies.</p>

<h2>Adding <code>no_std</code> support</h2>
<p>The work to enable <code>no_std</code> for hickory-proto is mostly mechanical. We shared the process <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html#:~:text=Porting%20a%20std%20Library%20to%20no_std">in a previous post</a>. We undertook modifications to hickory_proto and its dependencies to enable <code>no_std</code> support. The upstream <code>no_std</code> work also results in a <code>no_std</code> URL parser, beneficial to other projects.</p>

<ul>
  <li><a href="https://github.com/hickory-dns/hickory-dns/pull/2104">https://github.com/hickory-dns/hickory-dns/pull/2104</a></li>
  <li><a href="https://github.com/servo/rust-url/pull/831">https://github.com/servo/rust-url/pull/831</a></li>
  <li><a href="https://github.com/krisprice/ipnet/pull/58">https://github.com/krisprice/ipnet/pull/58</a></li>
</ul>

<p>The above PRs are great examples of how to extend <code>no_std</code> support to existing std-only crates.</p>

<h2>Code size study</h2>
<p>Code size is the one of the factors that we evaluated when picking the DNS library to use.</p>

<table border="1" cellpadding="8" cellspacing="0">
  <tbody>
    <tr>
      <td rowspan="3">Code size<br>by category</td>
      <td>Rust implemented Shim that calls Hickory-proto on receiving a DNS response</td>
      <td>4KB</td>
    </tr>
    <tr>
      <td>core, alloc, compiler_builtins<br>(reusable, one-time cost)</td>
      <td>17KB</td>
    </tr>
    <tr>
      <td>Hickory-proto library and dependencies</td>
      <td>350KB</td>
    </tr>
  </tbody>
</table>

<br>
<hr>
<br>

<table border="1" cellpadding="8" cellspacing="0">
  <tbody>
    <tr>
      <td>Sum</td>
      <td></td>
      <td>371KB</td>
    </tr>
  </tbody>
</table>


<p>We built prototypes and measured size with <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html#:~:text=Build%20Optimizations">size-optimized settings</a>. Expectedly, <code>hickory_proto</code> is not designed with embedded use in mind, and is not optimized for size. As the Pixel modem is not tightly memory constrained, we prioritized community support and code quality, leaving code size optimizations as future work.</p>

<p>However, the additional code size may be a blocker for other embedded systems. This could be addressed in the future by adding additional feature flags to conditionally compile only required functionality. Implementing this modularity would be a valuable future work.</p>

<h3>Hook-up Rust to modem firmware</h3>
<p>Before building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and <a href="https://doc.rust-lang.org/nomicon/ffi.html"><code>FFI</code></a> to verify the integration of Rust with the existing modem firmware code base.</p>

<h2>Compile Rust code to staticlib</h2>
<p>While using <code>cargo</code> is the default choice for compilation in the Rust ecosystem, it <a href="https://security.googleblog.com/2021/05/integrating-rust-into-android-open.html#:~:text=No%20nested%20build%20systems">presents challenges</a> when integrating it into existing build systems. We evaluated two options:</p>

<ol>
  <li>Using <code>cargo</code> to build a <a href="https://doc.rust-lang.org/beta/rustc/command-line-arguments.html#--crate-type-a-list-of-types-of-crates-for-the-compiler-to-emit"><code>staticlib</code></a> before the modem builds. Then add the produced staticlib into the linking step.</li>
  <li>Directly work with <code>rustc</code> and integrate the Rust compilation steps into the existing modem build system.</li>
</ol>

<p>Option #1 does not scale if we are going to add more Rust components in the future, as linking multiple staticlibs may cause <a href="https://github.com/rust-lang/rust/issues/44322">duplicated symbol errors</a>. We chose option #2 as it scales more easily and allows tighter integration into our existing build system. Our existing C/C++ codebase uses <a href="https://pigweed.dev/">Pigweed</a> to drive the primary build system. Pigweed supports Rust targets (<a href="https://cs.opensource.google/pigweed/pigweed/+/main:pw_build/rust_library.gni;drc=87f7abc323e345dd2729d5039a7ee0ee49c2fd56">example</a>) with direct calls to <a href="https://cs.opensource.google/pigweed/pigweed/+/main:pw_toolchain/generate_toolchain.gni;l=415;drc=e194c83f1d063833745f49da8f85b583be9774bb"><code>rustc</code></a> through <a href="https://gn.googlesource.com/gn/+/main/docs/reference.md#buildfile-functions-tool_specify-arguments-to-a-toolchain-tool_back-to-top-usage"><code>rust tools</code> defined in <code>GN</code></a>.</p>

<p>We compiled all the Rust crates, including hickory-proto, its dependencies, and core, compiler_builtin, alloc, to <a href="https://doc.rust-lang.org/reference/linkage.html#r-link.rlib"><code>rlib</code></a>. Then, we created a <code>staticlib</code> target with a single lib.rs file which references all the <a href="https://doc.rust-lang.org/reference/linkage.html#r-link.rlib"><code>rlib</code></a> crates using <a href="https://doc.rust-lang.org/std/keyword.crate.html"><code>extern crate</code></a> keywords.</p>

<h2>Build core, alloc, and compiler_builtins</h2>
<p><a href="https://android.googlesource.com/toolchain/android_rust/+/mirror-goog-main-rust-toolchain-source">Android’s Rust Toolchain</a> distributes source code of <code>core</code>, <code>alloc</code>, and <code>compiler_builtins</code>, and we leveraged this for the modem. They can be included to the build graph by adding a <code>GN</code> target with <a href="https://gn.googlesource.com/gn/+/main/docs/reference.md#var_crate_root"><code>crate_root</code></a> pointing to the root <code>lib.rs</code> of each crate.</p>

<p>Pixel modem firmware already has a well-tested and specialized global memory allocation system to support some dynamic memory allocations. <code>alloc</code> support was added by implementing the <a href="https://doc.rust-lang.org/alloc/alloc/trait.GlobalAlloc.html">GlobalAlloc</a> with <a href="https://doc.rust-lang.org/nomicon/ffi.html">FFI</a> calls to the allocators C APIs:</p>

<pre><code class="language-rust">use core::alloc::{GlobalAlloc, Layout};

extern "C" {
    fn mem_malloc(size: usize, alignment: usize) -&gt; *mut u8;
    fn mem_free(ptr: *mut u8, alignment: usize);
}

struct MemAllocator;

unsafe impl GlobalAlloc for MemAllocator {
    unsafe fn alloc(&amp;self, layout: Layout) -&gt; *mut u8 {
        mem_malloc(layout.size(), layout.align())
    }

    unsafe fn dealloc(&amp;self, ptr: *mut u8, layout: Layout) {
        mem_free(ptr, layout.align());
    }
}

#[global_allocator]
static ALLOCATOR: MemAllocator = MemAllocator;
</code></pre>

<p>Pixel modem firmware already implements a backend for the Pigweed <a href="https://pigweed.dev/pw_assert/#backend-api">crash facade</a> as the global crash handler. Exposing it into Rust <code>panic_handler</code> through FFI unifies the crash handling for both Rust and C/C++ code.</p>

<pre><code class="language-rust">#![no_std]
use core::panic::PanicInfo;

extern "C" {
    pub fn PwCrashBackend(sigature: *const i8, file_name: *const i8, line: u32);
}

#[panic_handler]
fn panic(panic_info: &amp;PanicInfo) -&gt; ! {
    let mut filename = "";
    let mut line_number: u32 = 0;

    if let Some(location) = panic_info.location() {
        filename = location.file();
        line_number = location.line();
    }

    let mut cstr_buffer = [0u8; 128];
    // Never writes to the last byte to make sure `cstr_buffer` is always zero
    // terminated.
    let (_, writer) = cstr_buffer.split_last_mut().unwrap();
    for (place, ch) in writer.iter_mut().zip(filename.bytes()) {
        *place = ch;
    }

    unsafe {
        PwCrashBackend(
            "Rust panic\0".as_ptr() as *const i8,
            cstr_buffer.as_ptr() as *const i8,
            line_number,
        );
    }

    loop {}
}
</code></pre>

<h2>Link Rust staticlib</h2>
<p>The Pixel modem firmware linking has a step that calls the linker to link all the objects generated from C/C++ code. By using <code>llvm-ar -x</code> to extract object files from the Rust combined staticlib and supplying them to the linker, the Rust code appears in the final modem image.</p>

<p>There was a performance issue we experienced due to weak symbols during linking. The inclusion of Rust <code>core</code> and <code>compiler-builtin</code> caused unexpected power and performance regressions on various tests. Upon analysis, we realized that modem optimized implementations of <code>memset</code> and <code>memcpy</code> provided by the modem firmware are accidentally replaced by those defined in <code>compiler_builtin</code>. It seems to happen because both <code>compiler_builtin</code> crate and the existing codebase defines symbols as weak, linker has no way to figure out which one is weaker. We fixed the regression by stripping the <code>compiler_builtin</code> crate before linking using a one line shell script.</p>

<pre><code class="language-bash">llvm-ar -t &lt;rust staticlib&gt; | grep compiler_builtins | xargs llvm-ar -d &lt;rust staticlib&gt;
</code></pre>

<h3>Integrating hickory-proto</h3>

<h2>Expose Rust API and calling back to C++</h2>
<p>For the DNS parser, we declared the DNS response parsing API in C and then implemented <a href="https://security.googleblog.com/2024/09/deploying-rust-in-existing-firmware.html#:~:text=Exposing%20the%20Same%20API">the same API</a> in Rust.</p>

<pre><code class="language-c">int32_t process_dns_response(uint8_t*, int32_t);
</code></pre>

<p>The Rust function returns an integer standing for the error code. The received DNS answers in the DNS response are required to be updated to in-memory data structures that are coupled with the original C implementation, therefore, we use existing C functions to do it. The existing C functions are dispatched from the Rust implementation.</p>

<pre><code class="language-rust">pub unsafe extern "C" fn process_dns_response(
    dns_response: *const u8,
    response_len: i32,
) -&gt; i32 {
    //... validate inputs `dns_response` and `response_len`.


    // SAFETY:
    // It is safe because `dns_response` is null checked above. `response_len`
    // is passed in, safe as long as it is set correctly by vendor code.
    match process_response(unsafe {
        slice::from_raw_parts(dns_response, response_len)
    }) {
         Ok(()) =&gt; 0,
         Err(err) =&gt; err.into(),
    }
}

fn process_response(response: &amp;[u8]) -&gt; Result&lt;()&gt; {
    let response = hickory_proto::op::Message::from_bytes(response)?;
    let response = hickory_proto::xfer::DnsResponse::from_message(response)?;

   
    for answer in response.answers() {  
        match answer.record_type() {
            hickory_proto::RecordType:... =&gt; {
                // SAFETY:
                // It is safe because the callback function does not store
                // reference of the inputs or their members.
                unsafe {
                    callback_to_c_function(...)?;
                }
            }
            
            // ... more match arms omitted.
        }    
    }

    Ok(())
}
</code></pre>

<p>In our case, the DNS responding parsing function API is simple enough for us to hand write, while the callbacks back to C functions for handling the response have complex data type conversions. Therefore, we leveraged bindgen to generate FFI code for the callbacks.</p>

<h2>Build third-party crates</h2>
<p>Even with all features disabled, hickory-proto introduces more than 30 dependent crates. Manually written build rules are difficult to ensure correctness and scale poorly when upgrading dependencies into new versions.</p>

<p>Fuchsia has developed <a href="https://fuchsia.googlesource.com/fuchsia/+/master/tools/cargo-gnaw/"><code>cargo-gnaw</code></a> to support building their third party Rust crates. <code>Cargo-gnaw</code> works by invoking <code>cargo metadata</code> to resolve dependencies, then parse and generate GN build rules. This ensures correctness and ease of maintenance.</p>

<h3>Conclusion</h3>
<p>The Pixel 10 series of phones marks a pivotal moment, being the first Pixel device to integrate a memory-safe language into its modem.</p>

<p>While replacing one piece of risky attack surface is itself valuable, this project lays the foundation for future integration of memory-safe parsers and code into the cellular baseband, ensuring the baseband’s security posture will <a href="https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html#:~:text=Final%20thoughts">continue to improve</a> as development continues.</p>


<i>Special thanks to Armando Montanez, Bjorn Mellem, Boky Chen, Cheng-Yu Tsai, Dominik Maier, Erik Gilling, Ever Rosales, Hungyen Weng, Ivan Lozano, James Farrell, Jeffrey Vander Stoep, Jiacheng Lu, Jingjing Bu, Min Xu, Murphy Stein, Ray Weng, Shawn Yang, Sherk Chung, Stephan Chen, Stephen Hines.</i>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSCache - I created a new lightweight software for file caching on our home servers]]></title>
<description><![CDATA[Hey everyone! tl;dr fscache - Lightweight Linux FUSE caching software that caches any existing FS. You might have seen me from my Plex post here. Since then, a few people have reached out to me to ask if I could make this library generic. After spending a few days working on refactoring the codeb...]]></description>
<link>https://tsecurity.de/de/3418961/linux-tipps/fscache-i-created-a-new-lightweight-software-for-file-caching-on-our-home-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3418961/linux-tipps/fscache-i-created-a-new-lightweight-software-for-file-caching-on-our-home-servers/</guid>
<pubDate>Thu, 09 Apr 2026 03:53:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone!</p> <p>tl;dr <a href="https://github.com/DudeCmonMan/fscache">fscache</a> - Lightweight Linux FUSE caching software that caches any existing FS.</p> <p>You might have seen me from my <a href="https://www.reddit.com/r/PleX/comments/1scmhy2/comment/oeteodi/">Plex post here</a>. Since then, a few people have reached out to me to ask if I could make this library generic. After spending a few days working on refactoring the codebase and testing non-stop, I've finally gotten to a point I can present it as a new binary <strong>FSCache</strong>. One of the core principles I had when developing this was that "it just works" with minimum effort. Would love to get some feedback and bug reports. My dream is to eventually see this on any ole apt command. Now that it's generic, it makes sense to post in <a href="https://www.reddit.com/r/Linux">r/Linux</a>.</p> <p>In my homelab journey, I wanted to have a simple file caching software that 1) Mounted on an existing filesystem, 2) Was filesystem agnostic, and 3) Had some rules I could tune. Unfortunately, existing solutions had too much "churn" for me to truly do what I want. B-Cache only works on new filesystems, MergerFS requires tiering and custom scripts, LVMCache is not really compatible with SnapRaid, etc. There was no perfect solution.</p> <p>That's why I created FSCache. 3 lines of config edits and execute. The benefit of FSCache is that it works using FUSE overmounting, it sits on top of ANY number of existing filesystems and allows you to cache files to another drive (SSD cache) based on a set of rules. At the moment it has two modes, prefetch mode, which is basically just a generic cacher and plex-episode-prediction mode (which handles Plex specific setups). When a file is moved into Cache, the cached file it delivered to the requestor instead of the backing file. The requesting software has zero awareness of what's happening.</p> <p>There are run commands for FSCache. There is fscache start --config &lt;config&gt; and there is fscache watch. Start simply starts the caching daemon, this can be setup as a service. fscache watch opens up a gui and attaches to the daemon - this of it as top or nvidia-smi if you've used that before.</p> <p><a href="https://preview.redd.it/6n4is4mha2ug1.png?width=758&amp;format=png&amp;auto=webp&amp;s=0448f3f3ff6f50a80c7f2d7f207d36f43d630e68">https://preview.redd.it/6n4is4mha2ug1.png?width=758&amp;format=png&amp;auto=webp&amp;s=0448f3f3ff6f50a80c7f2d7f207d36f43d630e68</a></p> <p>The generic cacher works with any rule you setup, Ex. If you have a game drive that people access quite often, you can set it up to cache the hit file + neighboring files, you can set it up to cache hits only, and you can even ask it to cache the entire parent folder + all subdirs. </p> <p>The Plex Cacher intercepts I/O and has special integrations that cache plex specific file I/O. The specific logic is to ignore scans and only focus on real sessions. There may be some misses, but would love to see bug reports for these. It's very hard to chase these issues down.</p> <p>This tool is still in development, so please report any bugs you might see. I have done testing myself and have extensive system level tests in the codebase, but the amount of testing can do alone is only so much.</p> <p><strong>Big thanks</strong> to <a href="https://www.reddit.com/u/trapexit">u/trapexit</a>, author of MergerFS. He gave me some comments about my original code and inspired me to use FUSE via MergerFS. I look forward to more conversations!</p> <p><strong>As always, be careful. This tool was build to be non-destructive, heavily tested (incl. E2E tests), and read-only (outside of cache), but as with all FS Operations, please be careful of software in development.</strong></p> <p><a href="https://github.com/DudeCmonMan/fscache">https://github.com/DudeCmonMan/fscache</a></p> <p><strong>A bit of background on myself</strong></p> <p>I'm a homelab enthusiast, I am lucky enough to enjoy the monotony of working on a server that provides to people. I'm a Software Engineer with a background in hardware and embedded systems, so this kind of stuff is fun for me. The work I do for my career and my hobbies are directly aligned, I am blessed that I find comfort in messing with servers.</p> <p>I generally write in Python, but I've recently moved to Rust and will probably be using Rust completely going forward. It's good to back to compiled binaries. I've come full circle from C++ as my "native language" to C#, to Python, even VBA, now back to a compiled language Rust. Being language agnostic is great, especially in the age of AI.</p> <p>I've worked on a ton of codebases, but this is my first opensource one that I want to share with the world.</p> <p><strong>For the more technical</strong></p> <p>FSCache uses these main layers:<br> FUSE -&gt; Action Engine (event emitter) -&gt; Preset Integration + SQLite Cache Database</p> <ul> <li>FUSE is the fundamental underlying magic here, it allows us to integrate filesystem handles from userspace. It IS magic.</li> <li>Action Event injects events based on the handles we have on FUSE, so that higher level libraries have a common abstraction that they can event handle.</li> <li>Preset Integration is where we apply all of our custom logic, prefetcher, plex-episode-predictor, etc.</li> <li>All of our caching logic and storage is handled in the sqlite cache database</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Meisgoot312"> /u/Meisgoot312 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1sgb5ut/fscache_i_created_a_new_lightweight_software_for/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sgb5ut/fscache_i_created_a_new_lightweight_software_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lightning Talks IV (sotm2025)]]></title>
<description><![CDATA[## Spatial Innovation in Carigara: Applying Opensource Mapping Tools for Community Development
_by Ariel Donic_

## Enhancing Passenger Ride Experience Using GrabMaps
_by Vic Puno_

## From OSM Data to Transport Models
_by Yannick Roth_

## What is a stop? Mapping Public Transport Routes
_by Wilh...]]></description>
<link>https://tsecurity.de/de/3418356/it-security-video/lightning-talks-iv-sotm2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3418356/it-security-video/lightning-talks-iv-sotm2025/</guid>
<pubDate>Wed, 08 Apr 2026 20:31:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[## Spatial Innovation in Carigara: Applying Opensource Mapping Tools for Community Development
_by Ariel Donic_

## Enhancing Passenger Ride Experience Using GrabMaps
_by Vic Puno_

## From OSM Data to Transport Models
_by Yannick Roth_

## What is a stop? Mapping Public Transport Routes
_by Wilhansen Li_

Creative Commons Attribution 3.0 Unported https://creativecommons.org/licenses/by/3.0/
about this event: https://2025.stateofthemap.org/sessions/YDSFTB/]]></content:encoded>
</item>
<item>
<title><![CDATA[Gefahr durch Open Source KI Modelle? 🚨 #insideai #opensource #ki]]></title>
<description><![CDATA[Author: Fraunhofer IEM - Bewertung: 0x - Views:25 Tommy erklärt, dass Open Source trotz des potenziellen Missbrauchs wichtig ist.

🎞️ Komplette Folge: https://youtu.be/xYZmGck9Pyk
🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/

📢 Mehr erfahren & vernetzen:
🔗 LinkedIn: h...]]></description>
<link>https://tsecurity.de/de/3417431/videos/gefahr-durch-open-source-ki-modelle-insideai-opensource-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417431/videos/gefahr-durch-open-source-ki-modelle-insideai-opensource-ki/</guid>
<pubDate>Wed, 08 Apr 2026 15:17:57 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Fraunhofer IEM - Bewertung: 0x - Views:25 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/CQ4G1iPCtgo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Tommy erklärt, dass Open Source trotz des potenziellen Missbrauchs wichtig ist.<br />
<br />
🎞️ Komplette Folge: https://youtu.be/xYZmGck9Pyk<br />
🎙 Mit dabei: Tommy Falkowski https://www.linkedin.com/in/tommy-falkowski/<br />
<br />
📢 Mehr erfahren & vernetzen:<br />
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem<br />
📸 Instagram: https://www.instagram.com/fraunhofer.iem<br />
📩 Newsletter: https://www.iem.fraunhofer.de/newsletter<br />
<br />
📺 Abonniere unseren YouTube-Kanal: https://www.youtube.com/@UCcYK2VMK5ts0MDSy0kaxdSw<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents]]></title>
<description><![CDATA[Microsoft has quietly introduced the Agent Governance Toolkit, an open-source project designed to monitor and control AI agents during execution as enterprises try to move them into production workflows.



The toolkit, which is a response to the Open Worldwide Application Security Project’s (OWA...]]></description>
<link>https://tsecurity.de/de/3416770/it-security-nachrichten/microsofts-new-agent-governance-toolkit-targets-top-owasp-risks-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416770/it-security-nachrichten/microsofts-new-agent-governance-toolkit-targets-top-owasp-risks-for-ai-agents/</guid>
<pubDate>Wed, 08 Apr 2026 11:51:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has quietly introduced the Agent Governance Toolkit, an open-source project designed to monitor and control AI agents during execution as enterprises try to move them into production workflows.</p>



<p>The toolkit, which is a response to the Open Worldwide Application Security Project’s (OWASP) emerging focus on AI and LLM security risks, adds a runtime security layer that enforces policies to mitigate issues such as prompt injection, and improves visibility into agent behavior across complex, multi-step workflows, <a href="http://linkedin.com/in/imransiddique1986" target="_blank" rel="noreferrer noopener">Imran Siddique</a>, principal group engineering manager at Microsoft wrote in a <a href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/" target="_blank" rel="noreferrer noopener">blog post.</a></p>



<p>More specifically, the toolkit maps to OWASP’s <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/" target="_blank" rel="noreferrer noopener">top 10 risks for agentic systems</a>, including goal hijacking, tool misuse, identity abuse, supply chain risks, code execution, memory poisoning, insecure communications, cascading failures, human-agent trust exploitation, and rogue agents.</p>



<p>The rationale behind the toolkit, Siddique wrote, stems from how AI systems increasingly resemble loosely governed distributed environments, where multiple untrusted components share resources, make decisions, and interact externally with minimal oversight.</p>



<p>That prompted Microsoft to apply proven design patterns from operating systems, service meshes, and site reliability engineering to bring structure, isolation, and control to these environments, Siddique added.</p>



<p>The result was the Redmond-headquartered giant packaging these principles into the toolkit comprising seven components available in Python, TypeScript, Rust, Go, and .NET.</p>



<p>The cross-language approach, Siddique explained, is aimed at meeting developers where they are and enabling integration across heterogeneous enterprise stacks.</p>



<p>As for the components, the toolkit includes modules such as a policy enforcement layer named Agent OS, a secure communication and identity framework named Agent Mesh, an execution control environment named Agent Runtime, and additional components, such as Agent SRE, Agent Compliance, and Agent Lightning, covering reliability, compliance, marketplace governance, and reinforcement learning oversight.</p>



<p>Beyond its modular design, Siddique further wrote that the toolkit is built to work with existing development ecosystems: “We designed the toolkit to be framework-agnostic from day one. Each integration hooks into a framework’s native extension points, <a href="https://www.infoworld.com/article/2334784/what-is-langchain-easier-development-of-llm-applications.html">LangChain</a>’s callback handlers, CrewAI’s task decorators, <a href="https://www.infoworld.com/article/4014981/get-started-with-google-agent-development-kit.html">Google ADK’s plugin system</a>, <a href="https://www.infoworld.com/article/4069808/unpacking-the-microsoft-agent-framework.html">Microsoft Agent Framework</a>’s middleware pipeline, so adding governance doesn’t require rewriting agent code.”</p>



<p>This approach, the senior executive explained, would reduce integration overhead and risk, allowing developers to introduce governance controls into production systems without disrupting existing workflows or incurring the cost and complexity of rearchitecting applications.</p>



<p>Siddique even went on to give examples of several framework integrations that are already deployed in production workloads, including LlamaIndex’s TrustedAgentWorker integration.</p>



<p>For those wishing to explore the toolkit, which is currently in public preview, it is available under an MIT license and <a href="https://github.com/microsoft/agent-governance-toolkit">structured as a monorepo</a> with independently installable components.</p>



<p>Microsoft, in the future, plans to transition the project to a foundation-led model and is already engaging with the OWASP agentic AI community to support broader governance and stewardship, Siddique wrote.</p>



<p><em>The article originally appeared in <a href="https://www.infoworld.com/article/4155591/microsofts-new-agent-governance-toolkit-targets-top-owasp-risks-for-ai-agents.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents]]></title>
<description><![CDATA[Microsoft has quietly introduced the Agent Governance Toolkit, an open source project designed to monitor and control AI agents during execution as enterprises try, and move them into production workflows.



The toolkit, which is a response to the Open Worldwide Application Security Project’s (O...]]></description>
<link>https://tsecurity.de/de/3416768/ai-nachrichten/microsofts-new-agent-governance-toolkit-targets-top-owasp-risks-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416768/ai-nachrichten/microsofts-new-agent-governance-toolkit-targets-top-owasp-risks-for-ai-agents/</guid>
<pubDate>Wed, 08 Apr 2026 11:47:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has quietly introduced the Agent Governance Toolkit, an open source project designed to monitor and control AI agents during execution as enterprises try, and move them into production workflows.</p>



<p>The toolkit, which is a response to the Open Worldwide Application Security Project’s (OWASP) emerging focus on AI and LLM security risks, adds a runtime security layer that enforces policies to mitigate issues such as prompt injection, and improves visibility into agent behavior across complex, multi-step workflows, <a href="http://linkedin.com/in/imransiddique1986" target="_blank" rel="noreferrer noopener">Imran Siddique</a>, principal group engineering manager at Microsoft wrote in a <a href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/" target="_blank" rel="noreferrer noopener">blog post.</a></p>



<p>More specifically, the toolkit maps to OWASP’s <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/" target="_blank" rel="noreferrer noopener">top 10 risks for agentic systems</a>, including goal hijacking, tool misuse, identity abuse, supply chain risks, code execution, memory poisoning, insecure communications, cascading failures, human-agent trust exploitation, and rogue agents.</p>



<p>The rationale behind the toolkit, Siddique wrote, stems from how AI systems increasingly resemble loosely governed distributed environments, where multiple untrusted components share resources, make decisions, and interact externally with minimal oversight.</p>



<p>That prompted Microsoft to apply proven design patterns from operating systems, service meshes, and site reliability engineering to bring structure, isolation, and control to these environments, Siddique added.</p>



<p>The result was the Redmond-headquartered giant packaging these principles into the toolkit comprising seven components available in Python, TypeScript, Rust, Go, and .NET.</p>



<p>The cross language approach, Siddique explained, is aimed at meeting developers where they are and enabling integration across heterogeneous enterprise stacks.</p>



<p>As for the components, the toolkit includes modules such as a policy enforcement layer named Agent OS, a secure communication and identity framework named Agent Mesh, an execution control environment named Agent Runtime, and additional components, such as Agent SRE, Agent Compliance, and Agent Lightning, covering reliability, compliance, marketplace governance, and reinforcement learning oversight.</p>



<p>Beyond its modular design, Siddique further wrote that the toolkit is built to work with existing development ecosystems: “We designed the toolkit to be framework-agnostic from day one. Each integration hooks into a framework’s native extension points, <a href="https://www.infoworld.com/article/2334784/what-is-langchain-easier-development-of-llm-applications.html">LangChain</a>’s callback handlers, CrewAI’s task decorators, <a href="https://www.infoworld.com/article/4014981/get-started-with-google-agent-development-kit.html">Google ADK’s plugin system</a>, <a href="https://www.infoworld.com/article/4069808/unpacking-the-microsoft-agent-framework.html">Microsoft Agent Framework</a>’s middleware pipeline, so adding governance doesn’t require rewriting agent code.”</p>



<p>This approach, the senior executive explained, would reduce integration overhead and risk, allowing developers to introduce governance controls into production systems without disrupting existing workflows or incurring the cost and complexity of rearchitecting applications.</p>



<p>Siddique even went on to give examples of several framework integrations that are already deployed in production workloads, including LlamaIndex’s TrustedAgentWorker integration.</p>



<p>For those wishing to explore the toolkit, which is currently in public preview, it is available under an MIT license and <a href="https://github.com/microsoft/agent-governance-toolkit">structured as a monorepo</a> with independently installable components.</p>



<p>Microsoft, in the future, plans to transition the project to a foundation-led model and is already engaging with the OWASP agentic AI community to support broader governance and stewardship, Siddique wrote.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Vendors Skip Linux Support]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Hardware and software vendors often choose not to support Linux, despite its widespread use.

While Linux fragmentation (distros, kernels, libraries) makes support harder, the decision not to support it shifts risk onto users. Thi...]]></description>
<link>https://tsecurity.de/de/3405609/it-security-video/when-vendors-skip-linux-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405609/it-security-video/when-vendors-skip-linux-support/</guid>
<pubDate>Fri, 03 Apr 2026 16:02:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8mMmPWn39Ps?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hardware and software vendors often choose not to support Linux, despite its widespread use.<br />
<br />
While Linux fragmentation (distros, kernels, libraries) makes support harder, the decision not to support it shifts risk onto users. This can lead to insecure workarounds, unsupported devices, and reduced visibility in enterprise environments. The burden of compatibility becomes a security issue—not just a usability one.<br />
<br />
Should vendors be expected to support open platforms, or is fragmentation a valid reason to opt out?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#linux #opensource #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rescuezilla: System auf neue Festplatte umziehen]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 44x - Views:220 In diesem Video zeigt Jean, wie man mit Rescuezilla ein Backup von einer kompletten Partition machen kann, um sein ganzes System auf eine neue Festplatte oder einen neuen Rechner umzuziehen.
Wenn Du das Video unterstützen willst, dann gib bitte ei...]]></description>
<link>https://tsecurity.de/de/3405535/linux-tipps/rescuezilla-system-auf-neue-festplatte-umziehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405535/linux-tipps/rescuezilla-system-auf-neue-festplatte-umziehen/</guid>
<pubDate>Fri, 03 Apr 2026 15:27:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 44x - Views:220 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/w8HsNI1I1cQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean, wie man mit Rescuezilla ein Backup von einer kompletten Partition machen kann, um sein ganzes System auf eine neue Festplatte oder einen neuen Rechner umzuziehen.<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Rescuezilla: https://rescuezilla.com/<br />
- Zum Stream von Hauke und Jean: https://youtube.com/live/LsV_juJ5KKs<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Intro<br />
00:38 Voraussetzungen<br />
01:29 USB-Stick vorbereiten<br />
02:54 System sichern<br />
09:24 System wiederherstellen<br />
15:31 Outro<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linux #rescuezilla #opensource #backup<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-Source ist unsicher? #opensource]]></title>
<description><![CDATA[Author: heise & c't - Bewertung: 20x - Views:143]]></description>
<link>https://tsecurity.de/de/3399459/videos/open-source-ist-unsicher-opensource/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3399459/videos/open-source-ist-unsicher-opensource/</guid>
<pubDate>Wed, 01 Apr 2026 15:18:08 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: heise &amp; c't - Bewertung: 20x - Views:143 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/uctHwgAn2Co?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Technical Deep Dive into CVE-2024-23380: Exploiting GPU Memory Corruption to Android Root]]></title>
<description><![CDATA[In our last blog, we talked about Binder exploit and fuzzing,  and how they can be used to achieve Local Privilege Escalation (LPE) from a zero-permission application to root. In this blog, we will continue the journey of LPE, focusing on the KGSL GPU driver on the Qualcomm platform.
At BlackHat ...]]></description>
<link>https://tsecurity.de/de/3397674/hacking/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397674/hacking/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/</guid>
<pubDate>Wed, 01 Apr 2026 01:06:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In our last blog, we talked about Binder <a href="https://androidoffsec.withgoogle.com/posts/attacking-android-binder-analysis-and-exploitation-of-cve-2023-20938/">exploit</a> and <a href="https://androidoffsec.withgoogle.com/posts/binder-fuzzing/">fuzzing</a>,  and how they can be used to achieve Local Privilege Escalation (LPE) from a zero-permission application to root. In this blog, we will continue the journey of LPE, focusing on the KGSL GPU driver on the Qualcomm platform.</p>
<p>At BlackHat USA 2024, we published our <a href="https://i.blackhat.com/BH-US-24/Presentations/REVISED02-US24-Gong-The-Way-to-Android-Root-Wednesday.pdf">research</a> on the Qualcomm KGSL GPU. Over the past year, we have seen several great analyses of this issue by others <a href="https://dawnslab.jd.com/android_gpu_attack_defence_introduction/">[4]</a> <a href="https://mdr.skyeye.qianxin.com/forum/share/3936">[5]</a> <a href="https://www.bilibili.com/video/BV1jweJzpEZ5/?vd_source=2096b94efd1dbcf748f72adcb090be4a">[6]</a>. Since then, we have received many questions from security researchers, regarding the specific issues they encountered while trying to reproduce the exploit. In this blog, we will outline in detail the process for exploiting, and answer some frequently asked questions from the security researcher community.</p>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#background-introduction" class="nostyle">
        Background Introduction
    </a>
</div>
</h1>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#android-privilege-attack-surfaces" class="nostyle">
        Android Privilege Attack Surfaces
    </a>
</div>
</h2>
<p>In Android, to <a href="https://source.android.com/docs/security/overview">protect the user data and the system</a>, a user-installed application is usually constrained in a Sandbox, granting them very limited permissions (known as unprivileged or zero-permission status).</p>
<p>To execute unauthorized actions, an attacker must escalate to a higher privilege level, such as System permissions, with the ultimate goal of achieving Kernel-level access (Root). While it is possible to escalate privileges incrementally—starting with minor privilege gains, and finally achieving Root—this multi-stage approach significantly increases exploit complexity. Consequently, the most common attack vector is targeting the interfaces exposed by the Kernel directly.</p>
<p>The Kernel exposes a very limited set of interfaces to a zero-permission application. Although some vendors have special interfaces exposed (e.g., the <a href="https://github.blog/security/vulnerability-research/fall-of-the-machines-exploiting-the-qualcomm-npu-neural-processing-unit-kernel-driver/">NPU driver</a>, or the <a href="https://projectzero.google/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html">fastrpc driver</a> on Qualcomm devices), the most widely used attack vectors for exploiting Android devices are still Binder (which we described in previous blogs) and GPU <a href="https://github.com/secmob/TiYunZong-An-Exploit-Chain-to-Remotely-Root-Modern-Android-Devices/blob/master/us-20-Gong-TiYunZong-An-Exploit-Chain-to-Remotely-Root-Modern-Android-Devices-wp.pdf">[10]</a> <a href="https://googleprojectzero.blogspot.com/2020/09/attacking-qualcomm-adreno-gpu.html">[11]</a> <a href="https://github.blog/2022-06-16-the-android-kernel-mitigations-obstacle-race/">[12]</a> <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2431&amp;q=label%3AVendor-Qualcomm&amp;can=1">[13]</a> (which we will discuss in this blog). We will focus specifically on Android devices powered by  Qualcomm SoCs.</p>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_1_android-attack-surface.png"><figcaption>
      <h4>Android attack surface to kernel root</h4>
    </figcaption>
</figure>


<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#qualcomm-gpu-architecture" class="nostyle">
        Qualcomm GPU Architecture
    </a>
</div>
</h2>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_2_qualcomm_adreno_gpu_architecture.png"><figcaption>
      <h4>Qualcomm Adreno GPU Architecture</h4>
    </figcaption>
</figure>

<p>GPU is a well-known component for its ability to render graphics. For security researchers, GPU hardware is a <a href="https://security.googleblog.com/2025/12/further-hardening-android-gpus.html#:~:text=The%20Graphics%20Processing%20Unit%20(GPU,exploits%20have%20targeted%20the%20GPU.">complex, highly privileged, and proprietary coprocessor</a>, which is separate from the Application Processor (AP) running the Android OS. To bridge the gap between userspace applications and this hardware, Qualcomm utilizes the KGSL driver. This driver exposes a device node at <code>/dev/kgsl-3d0</code>. Crucially, this node is accessible to all applications, allowing them to open the driver directly.</p>
<p>For example, the following code simply opens the device node and allocates a memory of size 0x1000 (using IOCTL_KGSL_GPUOBJ_ALLOC) which could be used by both the GPU and application.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="kt">int</span> <span class="n">fd</span> <span class="o">=</span> <span class="nf">open</span><span class="p">(</span><span class="s">"/dev/kgsl-3d0"</span><span class="p">,</span> <span class="n">O_RDWR</span> <span class="o">|</span> <span class="n">O_NONBLOCK</span> <span class="o">|</span> <span class="n">O_ASYNC</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_gpuobj_alloc</span> <span class="n">alloc_shared_mem</span> <span class="o">=</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">      <span class="p">.</span><span class="n">size</span> <span class="o">=</span> <span class="mh">0x1000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"><span class="p">};</span>
</span></span><span class="line"><span class="cl"><span class="n">rc</span> <span class="o">=</span> <span class="nf">ioctl</span><span class="p">(</span><span class="n">fd</span><span class="p">,</span> <span class="n">IOCTL_KGSL_GPUOBJ_ALLOC</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">alloc_shared_mem</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="nf">close</span><span class="p">(</span><span class="n">fd</span><span class="p">);</span>
</span></span></code></pre></div><p>The GPU driver functions available for userspace applications differ by GPU vendors. However, there are some basic functions that are common across most GPU architectures:</p>
<ul>
<li><strong>GPU process lifecycle management -</strong> The userspace can spawn one or more GPU processes in the GPU hardware for rendering content.</li>
<li><strong>GPU Memory Management</strong> - used to manage the shared memory between userspace applications and GPU hardware.</li>
<li><strong>GPU command execution and synchronization</strong>. Utilized by userspace to dispatch commands to the GPU and ensure they execute in the correct order (synchronization).</li>
</ul>
<p>We will cover more details in the next section on Memory Management.</p>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#kgsl-memory-management" class="nostyle">
        KGSL Memory Management
    </a>
</div>
</h1>
<p>One of the key functions in the memory management of the GPU driver is to share memory between userspace applications and GPU hardware. A good explanation for this can be found in <a href="https://projectzero.google/2020/09/attacking-qualcomm-adreno-gpu.html">Project Zero’s blog</a>, with the following diagram adapted from it:</p>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_3_gpu_and_userspace_application_sharing_physical_memory.png"><figcaption>
      <h4>GPU and userspace application sharing physical memory</h4>
    </figcaption>
</figure>

<p>To efficiently move data between the userspace application and GPU hardware, both should use the same physical memory directly. In the above diagram, the userspace application maps the physical memory into the userland virtual address space through the MMU, and the GPU hardware maps it to the GPU process’s virtual address space through the IOMMU, allowing them to share data through this physical memory directly.
The KGSL driver manages these shared memories. From the KGSL driver’s perspective, based on who owns the backend physical pages, how the memory space looks like, there are three types of memory objects:</p>
<ul>
<li><strong>Basic Memory Object:</strong> Physical pages owned and allocated by the KGSL driver</li>
<li><strong>Userspace Memory Object:</strong> Physical pages owned by the userspace application</li>
<li><strong>Virtual Buffer Object:</strong> A flexible object allows mapping with discontiguous physical memory as well as discontiguous virtual memory.</li>
</ul>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#memory-object-lifetime-and-reference-count" class="nostyle">
        Memory Object Lifetime and Reference Count
    </a>
</div>
</h2>
<p>For all the objects described above, the KGSL driver will create exactly the same data structure, the <code>struct kgsl_mem_entry</code>, which is as follows:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_mem_entry</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kref</span> <span class="n">refcount</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="n">memdesc</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">void</span> <span class="o">*</span><span class="n">priv_data</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">rb_node</span> <span class="n">node</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">unsigned</span> <span class="kt">int</span> <span class="n">id</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kgsl_process_private</span> <span class="o">*</span><span class="n">priv</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p>The KGSL driver distinguishes these object types from the details of <code>kgsl_mem_entry.memdesc</code>, which has the following structure:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kgsl_pagetable</span> <span class="o">*</span><span class="n">pagetable</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">void</span> <span class="o">*</span><span class="n">hostptr</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">unsigned</span> <span class="kt">int</span> <span class="n">hostptr_count</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">uint64_t</span> <span class="n">gpuaddr</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">phys_addr_t</span> <span class="n">physaddr</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">uint64_t</span> <span class="n">size</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">atomic_t</span> <span class="n">priv</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">sg_table</span> <span class="o">*</span><span class="n">sgt</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">const</span> <span class="k">struct</span> <span class="n">kgsl_memdesc_ops</span> <span class="o">*</span><span class="n">ops</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">uint64_t</span> <span class="n">flags</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">device</span> <span class="o">*</span><span class="n">dev</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">unsigned</span> <span class="kt">long</span> <span class="n">attrs</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">page</span> <span class="o">**</span><span class="n">pages</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="kt">unsigned</span> <span class="kt">int</span> <span class="n">page_count</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p>For different types of objects, <code>kgsl_mem_entry.memdesc.flags</code> and other fields (like <code>ops, priv</code>) will be different, so that the KGSL driver could distinguish them and manipulate them properly.</p>
<p>The core security mechanism to guarantee that the memory objects are correctly allocated and freed through the complicated multi-thread environment, is the <a href="https://docs.kernel.org/core-api/kref.html">reference counting system</a>, as you can see in the field <code>kgsl_mem_entry.refcount</code>.</p>
<ul>
<li>When an object is created, the refcount is initialized to 1</li>
<li>Every usage of the object should perform the following operation atomically: check that the refcount is not zero, and increase the refcount. This is usually achieved by <code>kref_get_unless_zero</code></li>
<li>Once finished using the object, use <code>kref_put</code> to decrease the refcount. When the refcount is not zero, this object should not be freed. When and only when the refcount is zero, free the object and its related resources (atomically; during this process, the object should not be accessed by anyone else).</li>
</ul>
<p>This reference counting system is efficient and robust. Not only the memory objects, most of the other KGSL objects are also secured by this mechanism and prevent lots of security issues.</p>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#basic-memory-object-bmo" class="nostyle">
        Basic Memory Object (BMO)
    </a>
</div>
</h2>
<p>We refer to this object as the “Basic Memory Object” (BMO) because it illustrates the fundamental memory management method of the GPU driver.
The following code shows how the userspace application creates a Basic Memory Object</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="kt">int</span> <span class="n">fd</span> <span class="o">=</span> <span class="nf">open</span><span class="p">(</span><span class="s">"/dev/kgsl-3d0"</span><span class="p">,</span> <span class="n">O_RDWR</span> <span class="o">|</span> <span class="n">O_NONBLOCK</span> <span class="o">|</span> <span class="n">O_ASYNC</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_gpuobj_alloc</span> <span class="n">alloc_shared_mem</span> <span class="o">=</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">      <span class="p">.</span><span class="n">size</span> <span class="o">=</span> <span class="n">size</span><span class="p">,</span>  	<span class="c1">// Request memory size (will be aligned to PAGE_SIZE)
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>      <span class="p">.</span><span class="n">flags</span> <span class="o">=</span> <span class="n">flags</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"><span class="p">};</span>
</span></span><span class="line"><span class="cl"><span class="n">rc</span> <span class="o">=</span> <span class="nf">ioctl</span><span class="p">(</span><span class="n">fd</span><span class="p">,</span> <span class="n">IOCTL_KGSL_GPUOBJ_ALLOC</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">alloc_shared_mem</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_gpuobj_info</span> <span class="n">info</span> <span class="o">=</span> <span class="p">{.</span><span class="n">id</span> <span class="o">=</span> <span class="n">alloc_shared_mem</span><span class="p">.</span><span class="n">entry_id</span><span class="p">};</span>
</span></span><span class="line"><span class="cl"><span class="n">rc</span> <span class="o">=</span> <span class="nf">ioctl</span><span class="p">(</span><span class="n">fd</span><span class="p">,</span> <span class="n">IOCTL_KGSL_GPUOBJ_INFO</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">info</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="kt">void</span> <span class="o">*</span><span class="n">buf</span> <span class="o">=</span> <span class="nf">mmap</span><span class="p">((</span><span class="kt">void</span> <span class="o">*</span><span class="p">)</span><span class="nb">NULL</span><span class="p">,</span> <span class="n">entry_size</span><span class="p">,</span> <span class="n">PROT_READ</span> <span class="o">|</span> <span class="n">PROT_WRITE</span><span class="p">,</span> <span class="n">MAP_SHARED</span><span class="p">,</span> <span class="n">fd</span><span class="p">,</span> <span class="n">info</span><span class="p">.</span><span class="n">gpuaddr</span><span class="p">);</span>
</span></span></code></pre></div><p>When IOCTL_KGSL_GPUOBJ_ALLOC is called, the underlying KGSL driver performs the following steps:</p>
<ol>
<li>Create the <code>struct kgsl_mem_entry</code> object</li>
<li>Allocate the requested memory (the parameter <code>kgsl_gpuobj_alloc.size</code> is the memory size, will be aligned to PAGE_SIZE by the KGSL driver), which we refer to as the backend physical memory</li>
<li>Allocate the GPU IOMMU virtual address for this physical memory in GPU hardware</li>
<li>Setup the IOMMU physical-virtual mapping for the GPU hardware. So that after the mapping is created, the GPU hardware can access this physical memory through the GPU virtual address.</li>
<li>(Optional) When the <code>mmap</code> is called, then the kernel driver sets up the MMU mapping for the corresponding physical memory and virtual address for the userspace application, so that the userspace application can access the physical memory through the virtual address.</li>
</ol>
<p>So we can see from the above process, with the Basic Memory Object, the backend memory is allocated by KGSL driver and shared to both GPU and userspace.</p>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#userspace-memory-object-umo" class="nostyle">
        Userspace Memory Object (UMO)
    </a>
</div>
</h2>
<p>Userspace Memory Object is quite similar to Basic Memory Object. The difference is that, with the Userspace Memory Object, the userspace MMU mapping is already created (physical memory is already mapped to the virtual address of the userspace application), and then imported into KGSL driver and shared to GPU.
Assuming the userspace application already has memory allocated at <code>virtual address ptr</code>, then the Userspace Memory Object can be created by IOCTL_KGSL_GPUOBJ_IMPORT or IOCTL_KGSL_MAP_USER_MEM, and the underlying KGSL driver will then</p>
<ol>
<li>Create the <code>struct kgsl_mem_entry</code> object</li>
<li>Retrieve the physical memory of <code>virtual address ptr</code></li>
<li>Allocate the GPU IOMMU virtual address for this physical memory in GPU hardware</li>
<li>Setup the IOMMU physical-virtual mapping for the GPU hardware.</li>
</ol>
<p>So now both the GPU hardware and userspace applications can access this physical memory.</p>
<p>After the Basic Memory Object and the Userspace Memory Object are created, the memory layout of the object is as follows:</p>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_4_memory_layout_for_BMO_and_UMO.png"><figcaption>
      <h4>Memory layout for BMO and UMO</h4>
    </figcaption>
</figure>

<p>In these two cases, the KGSL driver will take care of the GPU physical-virtual memory mapping and unmapping according to the memory status. The physical-virtual mapping is always a fixed contiguous mapping, which is relatively simple usage.</p>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#virtual-buffer-object-vbo" class="nostyle">
        Virtual Buffer Object (VBO)
    </a>
</div>
</h2>
<p>The basic idea of VBO is to add more flexibility to the memory management, by switching the fixed contiguous mapping to one that supports both physically and virtually non-contiguous memory.</p>
<p>To use the VBO, we can do the following</p>
<ol>
<li>Call <code>IOCTL_KGSL_GPUOBJ_ALLOC</code> with the flag <code>KGSL_MEMFLAGS_VBO</code>, then an empty <code>kgsl_mem_entry</code> with type VBO will be created. The VBO will have a GPU hardware virtual memory. As an initial state, the virtual address has no physical memory, or has a physical memory of zero-page (a page with all zero content and writing to it has no effect). Nothing will happen if we read or write this virtual memory in the GPU hardware.</li>
<li>To make use of the VBO, we have to call <code>IOCTL_KGSL_GPUMEM_BIND_RANGES</code>, to bind one (or more) existing <code>kgsl_mem_entry</code> (Basic Memory Object or Userspace Memory Object) to the virtual address range of VBO. The binding process is as follows:
<ol>
<li>For the requested virtual address and length, KGSL driver will check whether there is already a binding in this address range of VBO. If one exists, it unbinds first to release the physical-virtual mapping in GPU hardware</li>
<li>KGSL driver retrieves the physical memory of the existing <code>kgsl_mem_entry</code>, and sets up the physical-virtual mapping to the requested virtual address. So that the GPU hardware can access the physical address through the virtual address in the VBO.</li>
</ol>
</li>
<li>By repeating step 2 several times, we can create a memory layout similar to the following graph. In the graph, you can see there are two existing <code>kgsl_mem_entry</code> (<code>kgsl_mem_entry_A</code> and <code>kgsl_mem_entry_B</code>). The VBO <code>ksgl_mem_entry_VBO</code> is using the physical memory from both <code>kgsl_mem_entry_A</code> and <code>kgsl_mem_entry_B</code>.</li>
</ol>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_5_Memory_layout_of_VBO.png"><figcaption>
      <h4>Memory layout of VBO</h4>
    </figcaption>
</figure>

<ol start="4">
<li>Since there might be multiple objects bound to a VBO at the same time, the <code>kgsl_memdesc</code> of VBO <code>kgsl_mem_entry</code> has a special member called <code>ranges</code> to track the binding objects and addresses. This member is a Red-Black Tree (<a href="https://www.kernel.org/doc/html/v5.9/core-api/rbtree.html">rbtree</a>). When an object is bound to a VBO, both the object and the address range are inserted into the tree. When unbinding, the object is removed from the tree. To avoid concurrency issues when multiple threads manipulate the <code>ranges</code> at the same time, it’s critical to use the <code>ranges_lock</code> properly.</li>
</ol>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_mem_entry</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kref</span> <span class="n">refcount</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="n">memdesc</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">	<span class="cm">/** @ranges: rbtree base for the interval list of vbo ranges */</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">rb_root_cached</span> <span class="n">ranges</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="cm">/** @ranges_lock: Mutex to protect the range database */</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">mutex</span> <span class="n">ranges_lock</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p>So the memory of the VBO could be spliced, merged, split, removed… It’s really flexible, but also brings more challenges to memory management. We can see there are a series of issues occurring in VBO, <a href="https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/graphics-kernel/-/commit/919306871384731b35cbfafb208bbd13bff08605">CVE-2024-23380</a>, CVE-2024-23384, CVE-2024-23381, CVE-2024-23372, CVE-2024-33034, which shows the complexity of this new memory management mechanism. CVE-2024-23380 is one of these issues we are going to discuss here.</p>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#cve-2024-23380---use-after-free-caused-by-a-race-condition-when-managing-vbos" class="nostyle">
        CVE-2024-23380 - Use-After-Free caused by a race condition when managing VBOs
    </a>
</div>
</h1>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#issue-description" class="nostyle">
        Issue Description
    </a>
</div>
</h2>
<p>As we know from the previous section, we can bind Basic Memory Object (BMO) to a VBO, so that the VBO could have one (or more) backend physical memory. During the binding, the backend memory will be mapped to the virtual memory of the GPU. So that GPU process could access this physical memory through the virtual memory mapping.</p>
<p>After all jobs accessing this memory are finished, the BMO could unbind from the VBO, which is then unmapping the virtual memory from physical memory.</p>
<p>While the VBO is maintaining a physical-virtual mapping, the BMO should not be released, since it holds the backend physical memory used by the VBO. This is protected by the reference counting system we mentioned previously. Every time when a BMO is binding to a VBO, the reference count of the BMO should increase.</p>
<p>The vulnerability here is, when two threads bind and unbind the same VBO at the same time, there is a race condition which could corrupt the reference count of the BMO, allowing it to be released while the physical memory is still binding to the VBO. So that in this case, after the backend memory of the BMO has been released, the VBO can still access the physical memory, leading to a physical page use-after-free.</p>
<p>The race condition of triggering this issue is described as follows:</p>
<ul>
<li>In the above process, we can see that when binding (Step 2 in Thread A) the BMO to the VBO, the BMO is placed into the rbtree <code>ranges</code>, and its reference count is increased simultaneously.</li>
<li>When Thread A releases the <code>ranges</code> mutex, since the BMO is already in the rbtree <code>ranges</code>, other threads can access this rbtree <code>ranges</code> and unbind the BMO from the VBO, decreasing the reference count at the same time. After Thread B unbinds the BMO from the VBO (Step 2 in Thread B), the VBO no longer holds the reference to the BMO. As a result, the BMO could be freed by userspace at any time.</li>
<li>However, in Thread A, the binding process is not finished yet. Thread A will continue mapping the physical memory of the BMO to the VBO address range (Step 4 in Thread A) — even if the BMO is no longer bound to the VBO.</li>
<li>Now userspace can free the BMO (since nobody else is using the BMO from the driver’s perspective), as well as the physical memory of the BMO — although the physical memory is still used by the VBO. That’s the vulnerability.</li>
</ul>
<p>After successfully triggering the issue, we can get the following wrong memory status, as illustrated below.</p>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_6_wrong_memory_status_after_issue_trigger.png"><figcaption>
      <h4>Wrong memory status after issue triggered</h4>
    </figcaption>
</figure>

<p>We can see, the “Freed pages” previously owned by the Basic Memory Object have already been freed, but it’s still mapping to the GPU virtual memory address space.</p>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#exploitation" class="nostyle">
        Exploitation
    </a>
</div>
</h2>
<p>From the above vulnerability description, we know that by triggering the issue, we can control physical pages that have already been freed. If the physical pages are later used for important kernel data—for example, the <a href="https://cloudfuzz.github.io/android-kernel-exploitation/chapters/linux-privilege-escalation.html#process-credentials"><code>struct cred</code></a> which contains critical process credentials (e.g., user IDs, group IDs, and capabilities)—we can modify this important kernel data to gain privilege escalation (e.g., modify <code>cred.uid</code> to 0). So here is the Exploitation Sequence:</p>
<ol>
<li>Trigger the vulnerability to control enough physical memory pages</li>
<li>Fill the pages with a specific, useful objects</li>
<li>Modify these objects to achieve arbitrary read/write access.</li>
</ol>
<p>Let’s go through the exploit step-by-step.</p>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-1---trigger-the-vulnerability-control-freed-physical-page" class="nostyle">
        Step 1 - Trigger The Vulnerability, Control Freed Physical Page
    </a>
</div>
</h3>
<p>As described above, we can trigger the issue by running two different threads, binding and unbinding  the same Virtual Buffer Object(VBO) at the same time, then there is a chance that we will trigger the issue. A successful trigger leaves us in control of a physical page that the kernel considers “freed”.
To confirm that we have triggered the issue, we can use the method described below in section <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#how-do-we-know-whether-the-issue-is-triggered-or-not">Some Exploit Issues In Detail</a>.
Now, we have all the information about how to trigger the issue and control lots of freed pages. Let’s repeat this step until we get enough freed pages.</p>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-2---release-freed-memory-into-kernel-memory" class="nostyle">
        Step 2 - Release Freed Memory Into Kernel Memory
    </a>
</div>
</h3>
<p>In most of the cases (depending on the configuration of <code>kgsl_pool_max_pages</code>), the freed memory will not go directly back to the kernel memory. Instead, it will be put back into a pool, so that the buffer can be reused for the next KGSL physical page allocation.</p>
<p>This pool is reserved exclusively for the GPU driver. If the freed page remains in this pool, it will simply be reused for graphics data. Since manipulating graphics data has no effect on the kernel, we must force the driver to release this page from its dedicated pool.</p>
<p>The method is to trigger a system-wide low memory condition. For example, if we allocate a large amount of memory in the userspace, this operation will consume too much memory and the system memory will be quite low. In this situation, the system will try to <a href="https://docs.kernel.org/admin-guide/mm/concepts.html#reclaim"><code>reclaim</code></a> memory that is already owned by components but freeable, so that to avoid out-of-memory issues at the best efforts of the system.</p>
<p>The KGSL memory management system will react to the system memory reclaim request, and release as much as possible memory in the pool back to the system, so that the physical page controlled by us (through the vulnerability from Step 1) could be reused by the kernel.</p>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-3---spray-kgsl_mem_entry-into-kernel-heap" class="nostyle">
        Step 3 - Spray kgsl_mem_entry into Kernel Heap
    </a>
</div>
</h3>
<p>Now, we need to fill the freed physical page with a specific object we can manipulate. We choose <code>kgsl_mem_entry</code> because it is powerful and easy to spray. The method to create the <code>kgsl_mem_entry</code> has already been described above in <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#basic-memory-object-bmo">BASIC_MEMORY_OBJECT</a>. Call <code>ioctl(fd, IOCTL_KGSL_GPUOBJ_ALLOC, …)</code> will allocate a memory entry in the KGSL driver, so that we will get a <code>kgsl_mem_entry.</code></p>
<p>It’s important to note that if we request a Basic Memory Object, then backend physical memory will also be allocated, so that we might consume too many physical pages, which is not necessary and might reduce the success rate. To avoid this extra memory consumption, we’d better choose to allocate VBO, or Userspace Memory Object.</p>
<p>By repeating this step, we can spray a huge amount of <code>kgsl_mem_entry</code> into the kernel heap.</p>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-4----scan-for-kgsl_mem_entry-in-controlled-physical-pages" class="nostyle">
        Step 4 -  Scan For kgsl_mem_entry In Controlled Physical Pages
    </a>
</div>
</h3>
<p>After the heap spray, we must identify some of the <code>kgsl_mem_entry</code> that will be luckily located in the physical pages controlled by us. Now we can scan the pages, to find out where these objects are.
In <code>struct kgsl_mem_entry</code>, there is a member named <code>metadata</code>, which is controlled by the userspace.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_mem_entry</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kref</span> <span class="n">refcount</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="n">memdesc</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">	<span class="kt">char</span> <span class="n">metadata</span><span class="p">[</span><span class="n">KGSL_GPUOBJ_ALLOC_METADATA_MAX</span> <span class="o">+</span> <span class="mi">1</span><span class="p">];</span>   <span class="o">&lt;--</span>
</span></span></code></pre></div><p>We can call <code>IOCTL_KGSL_GPUOBJ_SET_INFO</code> to modify the metadata to a special Sentinel as follows:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl">    <span class="k">struct</span> <span class="n">kgsl_gpuobj_set_info</span> <span class="n">set_info</span> <span class="o">=</span> <span class="p">{</span><span class="mi">0</span><span class="p">};</span>
</span></span><span class="line"><span class="cl">    <span class="n">set_info</span><span class="p">.</span><span class="n">flags</span> <span class="o">=</span> <span class="n">KGSL_GPUOBJ_SET_INFO_METADATA</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">    <span class="n">set_info</span><span class="p">.</span><span class="n">metadata</span> <span class="o">=</span> <span class="p">(</span><span class="kt">uint64_t</span><span class="p">)</span><span class="o">&amp;</span><span class="n">metadata</span><span class="p">[</span><span class="mi">0</span><span class="p">];</span>
</span></span><span class="line"><span class="cl">    <span class="n">set_info</span><span class="p">.</span><span class="n">metadata_len</span> <span class="o">=</span> <span class="n">KGSL_GPUOBJ_ALLOC_METADATA_MAX</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">    <span class="n">set_info</span><span class="p">.</span><span class="n">id</span> <span class="o">=</span> <span class="n">alloc_vbo</span><span class="p">.</span><span class="n">id</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">    <span class="nf">memcpy</span><span class="p">(</span><span class="o">&amp;</span><span class="n">metadata</span><span class="p">[</span><span class="mi">0</span><span class="p">],</span> <span class="o">&amp;</span><span class="n">SENTINEL</span><span class="p">,</span><span class="k">sizeof</span><span class="p">(</span><span class="n">SENTINEL</span><span class="p">));</span>
</span></span><span class="line"><span class="cl">    <span class="nf">ioctl</span><span class="p">(</span><span class="n">dev_fd_per_process</span><span class="p">,</span> <span class="n">IOCTL_KGSL_GPUOBJ_SET_INFO</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">set_info</span><span class="p">);</span>
</span></span></code></pre></div><p>So we can put a special Sentinel into this metadata, then we can find the <code>kgsl_mem_entry</code> in the controlled physical pages.</p>
<p>The method to scan the physical page is the same as what we used in Step 1 (<a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#how-to-read-content-out-from-unbound-vbo">to read content out from unbound VBO</a>), that is using the GPU command to copy content out.</p>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-5---modify-kgsl_memdesc-to-map-kernel-memory" class="nostyle">
        Step 5 - Modify kgsl_memdesc To Map Kernel Memory
    </a>
</div>
</h3>
<p>Along with <code>metadata</code>, in <code>struct kgsl_mem_entry</code>, there is another useful member <code>struct kgsl_memdesc memdesc</code>.</p>
<p>From the structure definition <code>struct kgsl_memdesc</code>, we can see there are lots of useful members.
The first one is <code>const struct kgsl_memdesc_ops *ops</code>, which usually point to <code>kgsl_page_ops</code></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">static</span> <span class="k">const</span> <span class="k">struct</span> <span class="n">kgsl_memdesc_ops</span> <span class="n">kgsl_page_ops</span> <span class="o">=</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">free</span> <span class="o">=</span> <span class="n">kgsl_free_pages</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">vmflags</span> <span class="o">=</span> <span class="n">VM_DONTDUMP</span> <span class="o">|</span> <span class="n">VM_DONTEXPAND</span> <span class="o">|</span> <span class="n">VM_DONTCOPY</span> <span class="o">|</span> <span class="n">VM_MIXEDMAP</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">vmfault</span> <span class="o">=</span> <span class="n">kgsl_paged_vmfault</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">map_kernel</span> <span class="o">=</span> <span class="n">kgsl_paged_map_kernel</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">unmap_kernel</span> <span class="o">=</span> <span class="n">kgsl_paged_unmap_kernel</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">put_gpuaddr</span> <span class="o">=</span> <span class="n">kgsl_unmap_and_put_gpuaddr</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"><span class="p">};</span>
</span></span></code></pre></div><p>This <code>kgsl_page_ops</code> is useful. The member function <code>.vmfault</code> is related to page fault handling.</p>
<p>Recall how the <a href="https://en.wikipedia.org/wiki/Page_fault">Page Fault</a> works: when accessing a virtual memory that the backend physical memory has not yet been prepared, a VM page fault event is raised and the kernel will handle it by preparing the memory. This also works when a KGSL Memory Object is mmapped to userspace. We can mmap the Basic Memory Object and map the underlying physical memory into the virtual memory of userspace applications. The MMU may not be set up until the userspace is trying to access this virtual memory - that’s what the <code>.vmfault</code> is doing, to set up the real physical-virtual memory mapping.</p>
<p>The current function <code>kgsl_page_ops.kgsl_paged_vmfault</code> is setting up the physical-virtual mapping from <code>kgsl_memdesc-&gt;pages</code></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">static</span> <span class="kt">vm_fault_t</span> <span class="nf">kgsl_paged_vmfault</span><span class="p">(</span><span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="o">*</span><span class="n">memdesc</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">				<span class="k">struct</span> <span class="n">vm_area_struct</span> <span class="o">*</span><span class="n">vma</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">				<span class="k">struct</span> <span class="n">vm_fault</span> <span class="o">*</span><span class="n">vmf</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">	<span class="k">if</span> <span class="p">(</span><span class="n">offset</span> <span class="o">&gt;=</span> <span class="n">memdesc</span><span class="o">-&gt;</span><span class="n">size</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">		<span class="k">return</span> <span class="n">VM_FAULT_SIGBUS</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">	<span class="k">if</span> <span class="p">(</span><span class="n">memdesc</span><span class="o">-&gt;</span><span class="n">pages</span><span class="p">[</span><span class="n">pgoff</span><span class="p">])</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">		<span class="n">page</span> <span class="o">=</span> <span class="n">memdesc</span><span class="o">-&gt;</span><span class="n">pages</span><span class="p">[</span><span class="n">pgoff</span><span class="p">];</span>
</span></span><span class="line"><span class="cl">		<span class="nf">get_page</span><span class="p">(</span><span class="n">page</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">	<span class="n">ret</span> <span class="o">=</span> <span class="nf">vmf_insert_page</span><span class="p">(</span><span class="n">vma</span><span class="p">,</span> <span class="n">vmf</span><span class="o">-&gt;</span><span class="n">address</span><span class="p">,</span> <span class="n">page</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p>As we have fully controlled the `kgsl_memdesc`, we can manipulate <code>kgsl_memdesc-&gt;pages</code> to map arbitrary physical memory to the userspace. This requires <code>kgsl_memdesc-&gt;pages</code> to point to our controlled data with a known virtual address, which of course is doable but is slightly (just a little bit!) more complicated than the method we are using.</p>
<p>There are also other <code>kgsl_page_ops</code> for other types of kgsl_mem_entry, for example, <code>kgsl_contiguous_ops</code>, which behave differently.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">static</span> <span class="k">const</span> <span class="k">struct</span> <span class="n">kgsl_memdesc_ops</span> <span class="n">kgsl_contiguous_ops</span> <span class="o">=</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">free</span> <span class="o">=</span> <span class="n">kgsl_contiguous_free</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">vmflags</span> <span class="o">=</span> <span class="n">VM_DONTDUMP</span> <span class="o">|</span> <span class="n">VM_PFNMAP</span> <span class="o">|</span> <span class="n">VM_DONTEXPAND</span> <span class="o">|</span> <span class="n">VM_DONTCOPY</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">vmfault</span> <span class="o">=</span> <span class="n">kgsl_contiguous_vmfault</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">	<span class="p">.</span><span class="n">put_gpuaddr</span> <span class="o">=</span> <span class="n">kgsl_unmap_and_put_gpuaddr</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"><span class="p">};</span>
</span></span></code></pre></div><p>If we replace the original <code>kgsl_page_ops</code> with <code>kgsl_contiguous_ops</code>, then we can get a <code>kgsl_mem_entry</code> with the following <code>vm_fault (kgsl_contiguous_vmfault)</code> behavior.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">static</span> <span class="kt">vm_fault_t</span> <span class="nf">kgsl_contiguous_vmfault</span><span class="p">(</span><span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="o">*</span><span class="n">memdesc</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">				<span class="k">struct</span> <span class="n">vm_area_struct</span> <span class="o">*</span><span class="n">vma</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">				<span class="k">struct</span> <span class="n">vm_fault</span> <span class="o">*</span><span class="n">vmf</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl">	<span class="kt">unsigned</span> <span class="kt">long</span> <span class="n">offset</span><span class="p">,</span> <span class="n">pfn</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">	<span class="n">offset</span> <span class="o">=</span> <span class="p">((</span><span class="kt">unsigned</span> <span class="kt">long</span><span class="p">)</span> <span class="n">vmf</span><span class="o">-&gt;</span><span class="n">address</span> <span class="o">-</span> <span class="n">vma</span><span class="o">-&gt;</span><span class="n">vm_start</span><span class="p">)</span> <span class="o">&gt;&gt;</span>
</span></span><span class="line"><span class="cl">		<span class="n">PAGE_SHIFT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">	<span class="n">pfn</span> <span class="o">=</span> <span class="p">(</span><span class="n">memdesc</span><span class="o">-&gt;</span><span class="n">physaddr</span> <span class="o">&gt;&gt;</span> <span class="n">PAGE_SHIFT</span><span class="p">)</span> <span class="o">+</span> <span class="n">offset</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">	<span class="k">return</span> <span class="nf">vmf_insert_pfn</span><span class="p">(</span><span class="n">vma</span><span class="p">,</span> <span class="n">vmf</span><span class="o">-&gt;</span><span class="n">address</span><span class="p">,</span> <span class="n">pfn</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p>For <code>kgsl_contiguous_vmfault</code>, it simply gets the physical address from <code>memdesc-&gt;physaddr</code> and then creates the physical-virtual mapping.</p>
<p>We just need to modify the <code>memdesc-&gt;physaddr</code> to the destination we are interested in, then we can map this physical address to userspace through the <code>vm_fault</code> process.</p>
<p>To summarize, here we are modifying the <code>kgsl_memdesc.physaddr</code> to physical address of the kernel, and <code>kgsl_memdesc.size</code> to kernel physical memory size, and <code>kgsl_memdesc.ops</code> to <code>kgsl_contiguous_ops</code>, so that we can map the whole kernel physical memory to userspace through the <code>vm_fault</code> process in one shot.</p>
<p>The final modified <code>kgsl_memdesc</code> is as follows:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">kgsl_memdesc</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"><span class="p">...</span>
</span></span><span class="line"><span class="cl">		<span class="kt">phys_addr_t</span> <span class="n">physaddr</span><span class="p">;</span>    <span class="c1">// = KERNEL_PHYS_ADDRESS
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>		<span class="kt">uint64_t</span> <span class="n">size</span><span class="p">;</span>           <span class="c1">// = KERNEL_PHYS_SIZE
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>		<span class="p">...</span>
</span></span><span class="line"><span class="cl">		<span class="k">const</span> <span class="k">struct</span> <span class="n">kgsl_memdesc_ops</span> <span class="o">*</span><span class="n">ops</span><span class="p">;</span> <span class="c1">// = kgsl_contiguous_ops
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="p">}</span>
</span></span></code></pre></div>
<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#step-6---arbitrary-code-execution-in-kernel" class="nostyle">
        Step 6 - Arbitrary Code Execution In Kernel
    </a>
</div>
</h3>
<p>Building on the results of Step 5, by setting <code>physaddr</code> to the kernel’s physical address (which in most of the Android devices is a known fixed address at the moment), we can map the entire kernel memory into userspace, including both the data area and the code area. We can also map the code area, which is typically read-only memory, as readable and writable to the userspace. This capability exists because we are remapping the kernel’s physical memory directly. Consequently, the standard virtual memory protection mechanisms are bypassed, allowing us to always map the physical memory as writable.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl">  <span class="c1">// From Step 5, we have modified the kgsl_memdesc as follows
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="cm">/*
</span></span></span><span class="line"><span class="cl"><span class="cm">      struct kgsl_memdesc {
</span></span></span><span class="line"><span class="cl"><span class="cm">...
</span></span></span><span class="line"><span class="cl"><span class="cm">		phys_addr_t physaddr;    // = KERNEL_PHYS_ADDRESS
</span></span></span><span class="line"><span class="cl"><span class="cm">		uint64_t size;           // = KERNEL_PHYS_SIZE
</span></span></span><span class="line"><span class="cl"><span class="cm">		...
</span></span></span><span class="line"><span class="cl"><span class="cm">		const struct kgsl_memdesc_ops *ops; // = kgsl_contiguous_ops
</span></span></span><span class="line"><span class="cl"><span class="cm">}
</span></span></span><span class="line"><span class="cl"><span class="cm">   */</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="c1">// Userspace run mmap to the kgsl_mem_entry
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="kt">char</span> <span class="o">*</span><span class="n">kernel_base</span> <span class="o">=</span>
</span></span><span class="line"><span class="cl">      <span class="nf">mmap</span><span class="p">((</span><span class="kt">void</span> <span class="o">*</span><span class="p">)</span><span class="nb">NULL</span><span class="p">,</span> <span class="n">KERNEL_PHYS_SIZE</span><span class="p">,</span> <span class="n">PROT_READ</span> <span class="o">|</span> <span class="n">PROT_WRITE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">                     <span class="n">MAP_SHARED</span><span class="p">,</span> <span class="n">fd</span><span class="p">,</span> <span class="n">gpu_addr</span><span class="p">))</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="c1">// Now the KERNEL_PHYS_ADDRESS is mapped to kernel_base
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="c1">// If we try to access to kernel_base
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="c1">// the following code in the kernel will be execute
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="c1">// to setup the physical-virtual mapping
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="cm">/*
</span></span></span><span class="line"><span class="cl"><span class="cm">static vm_fault_t kgsl_contiguous_vmfault(struct kgsl_memdesc *memdesc,
</span></span></span><span class="line"><span class="cl"><span class="cm">...
</span></span></span><span class="line"><span class="cl"><span class="cm">	return vmf_insert_pfn(vma, vmf-&gt;address, pfn);
</span></span></span><span class="line"><span class="cl"><span class="cm">}
</span></span></span><span class="line"><span class="cl"><span class="cm">  */</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="c1">// Now we can do arbitrary read/write to the kernel memory
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>
</span></span><span class="line"><span class="cl">  <span class="c1">// Replace the Linux Banner
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="kt">char</span> <span class="o">*</span><span class="n">p</span> <span class="o">=</span> <span class="s">"Exploit by Xiling Gong of Android RedTeam, Google:)</span><span class="se">\n</span><span class="s">"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">  <span class="nf">memcpy</span><span class="p">(</span><span class="n">kernel_base</span> <span class="o">+</span> <span class="n">LINUX_PROC_BANNER</span><span class="p">,</span> <span class="n">p</span><span class="p">,</span> <span class="nf">strlen</span><span class="p">(</span><span class="n">p</span><span class="p">)</span> <span class="o">+</span> <span class="mi">1</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="c1">// Modify the function sel_read_enforce
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>  <span class="nf">memcpy</span><span class="p">(</span><span class="n">kernel_base</span> <span class="o">+</span> <span class="n">SEL_READ_ENFORCE</span><span class="p">,</span> <span class="n">PATCHED_CODE</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">PATCHED_CODE</span><span class="p">));</span>
</span></span></code></pre></div><p>From the above code snippet, we can see, after we finish <code>mmap</code>, we can modify the read-only data section (e.g., Linux Banner), or the read-only code section (e.g., <code>sel_read_enforce</code>) in the kernel memory.</p>
<p>In the example code snippet, we have directly modified code of the function <code>sel_read_enforce</code>, which is called when userspace tries to read the SELinux configuration (for example <code>adb shell getenforce</code>). When userspace triggers <code>sel_read_enforce</code>, our arbitrary code will run. This means we are running arbitrary code in the kernel, which is the highest privilege, including Root privilege and the ability to disable SELinux.</p>

<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#overall-exploitation-steps" class="nostyle">
        Overall exploitation steps
    </a>
</div>
</h2>
<p>Let’s summarize the overall exploitation steps as follows:</p>
<figure><img src="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/figure_7_summary_of_the_overall_exploitation_steps.png"><figcaption>
      <h4>Summary of the overall exploitation steps for CVE-2024-23380</h4>
    </figcaption>
</figure>


<h2>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#some-exploit-issues-in-detail" class="nostyle">
        Some Exploit Issues In Detail
    </a>
</div>
</h2>
<p>In this section, we will explain in detail some of the issues we encountered during the exploitation. These issues are also frequently asked by other security researchers.</p>
<ol>
<li>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#what-happens-if-we-fail-to-trigger-the-issue-will-we-crash-the-device" class="nostyle">
        What happens if we fail to trigger the issue, will we crash the device?
    </a>
</div>
</h3>
<p>The vulnerability is a race condition issue. Some of the race condition issues are quite unstable - if the issue fails to trigger, it will have some side effects (like memory corruption). The good news is, this race condition issue is quite stable, nothing bad happens if the race fails. Actually when the race fails, that means the backend physical memory is not bound to the Virtual Buffer Object (VBO), that’s what the driver expects in normal case.</p>
</li>
<li>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#how-do-we-know-whether-the-issue-is-triggered-or-not" class="nostyle">
        How do we know whether the issue is triggered or not?
    </a>
</div>
</h3>
<p>Of course, if we don’t know the race result, we can still get the exploit to work. We can just keep racing (for example, one hour), until we think we have collected enough freed pages. However, for a more reliable and more effective exploit, it’s always better to know the race result if we could.
From the issue description, we know that if the race fails, then the VBO will be bound back to zero-page, and if the issue triggered, then the VBO will still be bound to the Freed-page. So we can write some special Sentinel into the page before we do the race, and check whether the Sentinel changed after the race. If the Sentinel remains, then that means we triggered the issue and successfully controlled the freed physical page.</p>
</li>
<li>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#how-to-read-content-out-from-unbound-vbo" class="nostyle">
        How to read content out from unbound VBO?
    </a>
</div>
</h3>
<p>The answer is to read it from the GPU process using a GPU command.
Remember the VBO has a virtual address in the GPU process, and the GPU process is fully controlled by the userspace application. Craft the special GPU command and run it on the GPU process, then we can read the content out to another buffer. Here is some sample code. For more information, please refer to <a href="https://project-zero.issues.chromium.org/issues/42451155"><strong>adrenaline</strong></a> from <a href="https://googleprojectzero.blogspot.com/2020/09/attacking-qualcomm-adreno-gpu.html">Project Zero</a>.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl">  <span class="k">for</span> <span class="p">(</span><span class="kt">int</span> <span class="n">i</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span> <span class="n">i</span> <span class="o">&lt;</span> <span class="n">TARGET_VBO_SIZE</span> <span class="o">/</span> <span class="n">PAGE_SIZE</span><span class="p">;</span> <span class="n">i</span><span class="o">++</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">    <span class="o">*</span><span class="n">write_cmds</span><span class="o">++</span> <span class="o">=</span> <span class="nf">cp_type7_packet</span><span class="p">(</span><span class="n">CP_MEM_TO_MEM</span><span class="p">,</span> <span class="mi">5</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">    <span class="o">*</span><span class="n">write_cmds</span><span class="o">++</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">    <span class="c1">// Dest
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>    <span class="n">write_cmds</span> <span class="o">+=</span> <span class="nf">cp_gpuaddr</span><span class="p">(</span><span class="n">write_cmds</span><span class="p">,</span> <span class="n">dest_gpu_va</span> <span class="o">+</span> <span class="n">i</span> <span class="o">*</span> <span class="mi">4</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">    <span class="c1">// Src
</span></span></span><span class="line"><span class="cl"><span class="c1"></span>    <span class="n">write_cmds</span> <span class="o">+=</span> <span class="nf">cp_gpuaddr</span><span class="p">(</span><span class="n">write_cmds</span><span class="p">,</span> <span class="n">source_gpu_va</span> <span class="o">+</span> <span class="n">PAGE_SIZE</span> <span class="o">*</span> <span class="n">i</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">    <span class="k">if</span> <span class="p">((</span><span class="n">write_cmds</span> <span class="o">-</span> <span class="n">write_cmd_buf</span><span class="p">)</span> <span class="o">*</span> <span class="mi">4</span> <span class="o">&gt;</span> <span class="mh">0xC0000</span><span class="p">)</span> <span class="k">break</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">  <span class="p">}</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="nf">SYSCHK</span><span class="p">(</span><span class="nf">munmap</span><span class="p">(</span><span class="n">write_cmd_buf</span><span class="p">,</span> <span class="n">write_cmd_buf_size</span><span class="p">));</span>
</span></span><span class="line"><span class="cl">  <span class="nf">kgsl_flush_memory_cache</span><span class="p">(</span><span class="n">dev_fd</span><span class="p">,</span> <span class="n">write_cmd_buf_id</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="kt">uint32_t</span> <span class="n">cmdsize</span> <span class="o">=</span> <span class="p">(</span><span class="n">write_cmds</span> <span class="o">-</span> <span class="n">write_cmd_buf</span><span class="p">)</span> <span class="o">*</span> <span class="mi">4</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">  <span class="nf">kgsl_gpu_command_payload</span><span class="p">(</span><span class="n">dev_fd</span><span class="p">,</span> <span class="n">ctx_id</span><span class="p">,</span> <span class="mi">0</span><span class="p">,</span> <span class="n">cmdsize</span><span class="p">,</span> <span class="mi">1</span><span class="p">,</span> <span class="mi">0</span><span class="p">,</span> <span class="n">write_cmd_gpuaddr</span><span class="p">,</span>
</span></span><span class="line"><span class="cl">                           <span class="n">cmdsize</span><span class="p">);</span>
</span></span></code></pre></div></li>
<li>

<h3>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#handling-the-false-positive-unbind-before-bind" class="nostyle">
        Handling the False Positive: Unbind Before Bind
    </a>
</div>
</h3>
<p>In practice, researchers often encounter a false positive: a scenario where the race condition fails to trigger the vulnerability, yet the VBO still correctly reads the Sentinel value from the physical memory.
This happens when the Unbind operation successfully executes <em>before</em> the Bind operation. The sequence is <strong>Unbind -&gt; Bind</strong> (a race failure).</p>
<ul>
<li><strong>Unbind:</strong> Executes on an unbound VBO range (no-op).</li>
<li><strong>Bind:</strong> Executes normally, successfully mapping the VBO’s virtual address to the Basic Memory Object’s physical pages.</li>
</ul>
<p>Since the final state is a successful binding, reading the VBO still returns the Sentinel value, making this outcome indistinguishable from a true UAF success based purely on the Sentinel check. This is the false positive.
The solution is to perform an <strong>additional, explicit unbind operation</strong> immediately after each race attempt. This resolves the ambiguity by differentiating the kernel’s state:</p>
<ul>
<li><strong>If the race was a False Positive (Unbind -&gt; Bind):</strong> The VBO is currently a valid, kernel-managed binding. The extra unbind executes successfully, unmapping the physical page and reverting the VBO range back to the zero-page. Subsequent reading of the VBO will show the Sentinel is gone (replaced by zeros), confirming the race failed.</li>
<li><strong>If the race was a True UAF Success (Bind -&gt; Unbind):</strong> The vulnerability has already caused the Basic Memory Object’s physical page to be freed (UAF state), while the GPU’s virtual mapping remains intact. Since the physical page is no longer under KGSL’s active management, the extra unbind attempt has no functional effect on the memory state or the IOMMU mapping. Subsequent reading of the VBO will still show the Sentinel is present, confirming successful exploitation and control over the freed page.</li>
</ul>
</li>
</ol>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#conclusion" class="nostyle">
        Conclusion
    </a>
</div>
</h1>
<p>We have described the details of how to exploit CVE-2024-23380. After we finish the first step (reproduce the issue and control physical pages), the major kernel mitigations (e.g., kCFI, W^X, DEP) will not prevent further execution, because of the powerful “Physical Pages” capability of the GPU driver.
It’s been many years since GPU caught the attention of security researchers. The vulnerability (CVE-2024-23380) described in this blog has been remediated in <a href="https://source.android.com/docs/security/bulletin/2024-07-01#Qualcomm-components">July 2024</a>, however, there are ongoing discoveries of GPU issues that are being addressed through regular security updates (e.g., the patched <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21479">CVE-2025-21479</a> in 2025, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21385">CVE-2026-21385</a> in 2026). GPU security will remain important in the foreseeable future. How to find vulnerabilities ahead of the potential exploits, how to mitigate and ease the attack from “Physical Pages” is still an important topic as always.</p>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#credits" class="nostyle">
        Credits
    </a>
</div>
</h1>
<p>We would like to thank the <strong>external security research community</strong> for their continued discussion, analysis, and contributions to GPU security.
We also wish to thank <strong>all of our teammates</strong> for their general support and assistance in the creation of this blog post. We would like to express special gratitude to <strong>Martijn Bogaard</strong>, <strong>Xingyu Jin, Zi Fan Tan</strong> for their crucial support and comprehensive review.</p>

<h1>
<div>
    <a href="https://androidoffsec.withgoogle.com/posts/a-technical-deep-dive-into-cve-2024-23380-exploiting-gpu-memory-corruption-to-android-root/#references" class="nostyle">
        References
    </a>
</div>
</h1>
<ol>
<li><a href="https://androidoffsec.withgoogle.com/posts/attacking-android-binder-analysis-and-exploitation-of-cve-2023-20938/"><strong>Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938</strong> (Binder exploit)</a></li>
<li><a href="https://androidoffsec.withgoogle.com/posts/binder-fuzzing/"><strong>Binder Fuzzing</strong> (Binder fuzzing)</a></li>
<li><a href="https://i.blackhat.com/BH-US-24/Presentations/REVISED02-US24-Gong-The-Way-to-Android-Root-Wednesday.pdf"><strong>The Way to Android Root: Exploiting Your GPU on Smartphone</strong> (BlackHat USA 2024 research)</a></li>
<li><a href="https://dawnslab.jd.com/android_gpu_attack_defence_introduction/"><strong>Introduction to Android GPU Vulnerability Attack and Defense</strong></a></li>
<li><a href="https://mdr.skyeye.qianxin.com/forum/share/3936"><strong>Analysis of Qualcomm GPU Vulnerabilities</strong></a></li>
<li><a href="https://www.bilibili.com/video/BV1jweJzpEZ5/?vd_source=2096b94efd1dbcf748f72adcb090be4a"><strong>Exploit CVE-2024-23380</strong> (Bilibili Video)</a></li>
<li><a href="https://source.android.com/docs/security/overview"><strong>Android Security Overview: Protecting the user data and the system</strong></a></li>
<li><a href="https://github.blog/security/vulnerability-research/fall-of-the-machines-exploiting-the-qualcomm-npu-neural-processing-unit-kernel-driver/"><strong>Exploiting the Qualcomm NPU (NPU driver)</strong></a></li>
<li><a href="https://projectzero.google/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html"><strong>Qualcomm DSP driver unexpected exploit</strong> (fastrpc driver)</a></li>
<li><a href="https://github.com/secmob/TiYunZong-An-Exploit-Chain-to-Remotely-Root-Modern-Android-Devices/blob/master/us-20-Gong-TiYunZong-An-Exploit-Chain-to-Remotely-Root-Modern-Android-Devices-wp.pdf"><strong>TiYunZong Exploit Chain to Remotely Root Modern Android Devices</strong></a></li>
<li><a href="https://googleprojectzero.blogspot.com/2020/09/attacking-qualcomm-adreno-gpu.html"><strong>Attacking the Qualcomm Adreno GPU</strong></a></li>
<li><a href="https://github.blog/2022-06-16-the-android-kernel-mitigations-obstacle-race/"><strong>The Android kernel mitigations obstacle race</strong></a></li>
<li><a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2431&amp;q=label%3AVendor-Qualcomm&amp;can=1"><strong>Project Zero Issue 2431: code in user-writable mapping is executed in non-protected mode</strong></a></li>
<li><a href="https://security.googleblog.com/2025/12/further-hardening-android-gpus.html#:~:text=The%20Graphics%20Processing%20Unit%20%5C(GPU,exploits%20have%20targeted%20the%20GPU"><strong>Further hardening Android GPUs</strong></a></li>
<li><a href="https://docs.kernel.org/core-api/kref.html"><strong>Linux Kernel Documentation: kref</strong> (reference counting system)</a></li>
<li><a href="https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/graphics-kernel/-/commit/919306871384731b35cbfafb208bbd13bff08605"><strong>Qualcomm Graphics Kernel Git Commit</strong> (Patch for CVE-2024-23380)</a></li>
<li><a href="https://cloudfuzz.github.io/android-kernel-exploitation/chapters/linux-privilege-escalation.html#process-credentials"><strong>Android Kernel Exploitation: Process Credentials</strong> (struct cred)</a></li>
<li><a href="https://docs.kernel.org/admin-guide/mm/concepts.html#reclaim"><strong>Linux Kernel Documentation: Memory Reclaim</strong></a></li>
<li><a href="https://en.wikipedia.org/wiki/Page_fault"><strong>Wikipedia: Page Fault</strong></a></li>
<li><a href="https://project-zero.issues.chromium.org/issues/42451155"><strong>Project Zero Issue 42451155: Adrenaline</strong> (GPU command to read content)</a></li>
<li><a href="https://source.android.com/docs/security/bulletin/2024-07-01#Qualcomm-components"><strong>Android Security Bulletin—July 2024</strong> (Qualcomm components remediation)</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21479"><strong>NVD Detail: CVE-2025-21479</strong></a></li>
<li><a href="https://github.blog/security/vulnerability-research/corrupting-memory-without-memory-corruption/#memory-management-in-the-mali-kernel-driver"><strong>Memory Management In The Mali Kernel Driver</strong> (Corrupting memory without memory corruption)</a></li>
<li><a href="https://www.kernel.org/doc/html/v5.9/core-api/rbtree.html"><strong>Rbtree in Linux</strong></a></li>
</ol>]]></content:encoded>
</item>
<item>
<title><![CDATA[Streit um neues „Euro-Office”]]></title>
<description><![CDATA[Das kürzlich angekündigte „Euro-Office"-Projekt von Nextcloud und IONOS sorgt für Ärger. OnlyOffice, Entwickler der gleichnamigen Online-Bürosuite, erhebt schwere Vorwürfe

Tags: #Lizenz | #OpenSource]]></description>
<link>https://tsecurity.de/de/3396124/it-security-nachrichten/streit-um-neues-euro-office/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396124/it-security-nachrichten/streit-um-neues-euro-office/</guid>
<pubDate>Tue, 31 Mar 2026 14:52:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920.jpg" class="attachment-full size-full wp-post-image" alt="Euro Office" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/03/Euro-Office-Quelle-Gitlub-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title='Streit um neues „Euro-Office" 1'></p>
    Das kürzlich angekündigte „Euro-Office"-Projekt von Nextcloud und IONOS sorgt für Ärger. OnlyOffice, Entwickler der gleichnamigen Online-Bürosuite, erhebt schwere Vorwürfe

<p>Tags: <a href="https://www.it-daily.net/thema/lizenz">#Lizenz</a> | <a href="https://www.it-daily.net/thema/opensource">#OpenSource</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 key takeaways from RSA Conference 2026]]></title>
<description><![CDATA[Writing a conference preview is an act of professional speculation. You read the agenda, map the schedule session density, and make your personal best call about where the intellectual energy will concentrate.



From my perspective going in, RSA Conference 2026 outlined a defining tension for CI...]]></description>
<link>https://tsecurity.de/de/3395374/it-security-nachrichten/6-key-takeaways-from-rsa-conference-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395374/it-security-nachrichten/6-key-takeaways-from-rsa-conference-2026/</guid>
<pubDate>Tue, 31 Mar 2026 10:37:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Writing a conference preview is an act of professional speculation. You read the agenda, map the schedule session density, and make your personal best call about where the intellectual energy will concentrate.</p>



<p>From my perspective going in, RSA Conference 2026 <a href="https://www.csoonline.com/article/4146664/5-key-priorities-for-your-rsac-2026-agenda.html">outlined a defining tension for CISOs today</a>: how to enable AI adoption fast enough to stay competitive while securing the enterprise against a threat landscape AI itself is reshaping.</p>



<p>Now that RSAC 2026 has run its course, it’s worth holding pre-event predictions, such as my five key priorities for CISOs and their teams, against what actually emerged from the sessions, VC panels, and hallway conversations that tend to be more candid than anything on stage.</p>



<p>The verdict: the frame held. In fact, there was very little conversation without AI being front and center. At the Moscone Center in San Francisco I kept hearing, ‘We live in unprecedented times’ — a cliché that I do believe is true.</p>



<p>My own surprises were mostly matters of AI emphasis and velocity with stronger and perhaps sharper commercial edges than I expected.</p>



<h2 class="wp-block-heading">The AI saturation hypothesis was confirmed</h2>



<p>My RSAC 2026 preview argued that AI was no longer a track but had become the event itself, with approximately 40% of the agenda AI-weighted across every cyber domain.</p>



<p>That certainly bore out on stage. Every panel, whether focused on investment, products, identity, or offensive capability, returned to AI. Yoav Leitersdorf of YL Ventures put this bluntly: “Everyone only wants to talk about AI, and if you aren’t doing AI, investors don’t want to talk to you.”</p>



<p>Kevin Mandia from Ballistic Ventures at the RSA Annual Executive Dinner noted that we have to take humans out of the loop, so that AI versus AI is the new paradigm. He explained that AI agents have been introduced into red teaming exercises and are capable of operating at scale and with speed. So, while AI compresses the attack cycle, AI can also “automate” existing teams to improve their response from 5 days to 5 minutes.</p>



<p>What my preview couldn’t fully anticipate was the degree to which the AI narrative forked into two distinct commercial pressures running simultaneously.</p>



<p>Dave DeWalt of NightDragon captured both sides: AI as a tool for defense and offense, but also AI as a structural force flattening the competitive landscape between established vendors and startups. His observation that Series A funding is now looking to be $100 million — and that he’d never seen capital deploy this fast — landed with impact.</p>



<p>RSAC 2026 felt less like a learning event and more like a deal-making environment with educational sessions attached.</p>



<h2 class="wp-block-heading">Securing the AI stack: Yes, but the threat surface has grown</h2>



<p>The first technical priority I offered for CISOs in my conference preview was securing the AI stack — RAG workflows, LLM data pipelines, vector databases, and model APIs — on the basis that prompt injection, training data poisoning, and model inversion attacks were no longer theoretical.</p>



<p>The floor validated this but added dimensions my preview had underweighted. Mike Leland of Island framed the enterprise AI risk surface comprehensively: data leakage, shadow AI, prompt injection, copyright and IP infringement, hallucinations, and data residency. These aren’t sequential concerns — they arrive simultaneously the moment an organization allows AI tools into the environment.</p>



<p>The AI red teaming conversation surfaced with more commercial urgency than anticipated. Frontier Labs’ Brian Singer described environments where AI attackers operate at 1,000 times the speed of human adversaries, pushing the securing-the-stack conversation from defensive posture into something more active. While my preview was right about the topic, it underestimated the operational tempo.</p>



<p>On the conference floor I caught up with Singulr CEO Shiv Agarwaland Richard Bird, Singulr’s CSO and chief strategyofficer,whose platform is attempting to solve this visibility problem at scale. Their starting point was blunt: “AI usage is going out of control at the enterprise. The CIO, the CSO, they need some level of control, but without stopping or slowing down innovation.”</p>



<p>What Singulr’s discovery work is revealing is more of an issue than most boards appreciate. Bird told me that across enterprise assessments, they consistently surface between 350 and 430 AI services and features in active use, the overwhelming majority of which were never formally sanctioned. The shadow AI problem isn’t theoretical. It’s already deployed.</p>



<p>He offered a more nuanced risk framing than most vendors I encountered: context matters as much as the tool itself. “ChatGPT is a very well-contracted and approved AI service,” he said. “But if someone is using it with a personal account and model training has not been turned off, it brings the same risk as a service put up by two people in a garage.” Unfortunately sanction alone doesn’t confer safety.</p>



<h2 class="wp-block-heading">Non-human identity: The standout theme of the conference</h2>



<p>My preview identified non-human identity (NHI) governance as rapidly becoming one of the most consequential operational gaps in enterprise security. This proved to be my most prescient call. It wasn’t just a track; it became a through-line across multiple panels. Ross Haleliuk noted bluntly that machine identities already outnumber human ones.</p>



<p>Mark McClain, founder of SailPoint, reframed the entire identity management problem around agent intent and context: Humans we assumed were at an office or working remotely, but do we understand the intention of an AI agent, and do we have guardrail policies capable of reasoning about that?</p>



<p>McClain’s framing felt the most intellectually honest moment of the conference on this topic. He acknowledged that new technology was coming that would put his own platform under pressure, while simultaneously arguing that anyone who believes you can master the agentic world in isolation without human oversight is being misled.</p>



<p>The infrastructure question was taken further in my conversation with Noam Issachar and Jake Turetsky of Jazz, whose platform is building what they describe as a control plane for the agentic layer. Their framing was architecturally provocative: “AI is the new infrastructure. An AI agent can conduct and take action for something that looks like data transformation and never go into the lower tiers of the technology stack.” In their view, the agent layer is becoming the new HTTP — a data transport and transformation tier that sits above traditional infrastructure but below application logic.</p>



<p>What they found most troubling was the governance vacuum that currently exists in that space: “If AI is truly transformational, then why is there no transformation of processes, policies, and governance to reflect the fact that traffic management is already happening there?” It’s a fair challenge. The architecture has moved faster than the frameworks built to govern it.</p>



<h2 class="wp-block-heading">AI governance: Present, but absorbed into broader conversations</h2>



<p>The compliance priority in my preview centered on the EU AI Act and the need for CISOs to develop defensible licence-to-operate frameworks for AI deployment.</p>



<p>This theme was present at RSAC but was somewhat absorbed into broader discussions about regulatory alignment rather than treated as a standalone priority. VP of Google Threat Intelligence Sandra Joyce’s exchange with Richard Horne of the NCSC touched on the tension between defenders and attackers both benefiting from AI — the NCSC providing framework standards that regulators then align to, a model of governance by reference rather than prescription.</p>



<p>Jay Bavasi, CEO of EC Council, offered the most direct governance framing I encountered across the entire week: “Our attitude as a community has been shoot first, ask questions later. But what we should be doing is ask questions first, shoot later.”</p>



<p>The data behind that charge is harder to dismiss than the rhetoric. Bavasi cited that 84% of Fortune 500 companies reference AI implementation in their 10-K filings. He noted that the proportion that claims to have actual AI governance in place is just 18%. With 72 countries having already launched AI regulations or frameworks, the gap between disclosure and accountability is widening, not closing.</p>



<p>Singulr’s Bird reinforced this concern from an operational standpoint, noting that the governance conversation is still largely performative inside most enterprises — boards are discussing AI risk without the institutional mechanisms to actually manage it.</p>



<p>In-Q-Tel’s Katie Gray offered the sharpest counterweight to the governance narrative: There has never been a better time to sell to the US government, and the DoD spends $5 billion on cyber annually. In that environment, governance conversations are less about compliance architecture and more about positioning to capture procurement.</p>



<h2 class="wp-block-heading">Shadow AI: Validated and commercially urgent</h2>



<p>My preview’s risk priority around shadow AI and vibe coding — unsanctioned AI tool usage largely invisible to security teams — was confirmed across multiple sessions. Leland’s readiness framework put it plainly: Do you have visibility of shadow AI tool usage across the enterprise? Can you identify and prevent inappropriate data usage with gen AI tools?</p>



<p>Singulr’s Agarwal added a dimension that most vendors are reluctant to name. The most commonly discovered unsanctioned AI application in enterprise assessments is Grammarly — not a rogue model or an exotic data exfiltration tool, a writing assistant that most employees assume is benign and most IT teams have never thought to classify as AI risk.</p>



<p>His broader point about risk posture deserves to sit with board directors: “Your monthly board report is kind of useless in a way because your risk position today versus this morning is different.” A static governance snapshot of a dynamic and real-time threat surface is a category error, not a reporting format.</p>



<p>Team8’s Amir Zilberstein flagged investment in a reimagined DLP category on exactly this basis, the old category was hated, but AI-driven classification changes what’s possible.</p>



<h2 class="wp-block-heading">What my preview missed</h2>



<p>Two things the pre-event article didn’t fully anticipate:</p>



<p>First, the capital concentration dynamic. Amir Zilberstein’s observation that more funding is going to fewer companies, combined with David DeWalt’s seed and Series A figures, describes a market consolidating at the top even as it fragments at the bottom. The 9,900 cyber companies DeWalt cited aren’t all going to survive contact with AI titans crossing over from the SaaS world.</p>



<p>Second, the workforce conversation. This was the thread I found most unresolved across every conversation I had on stage and off.</p>



<p>Many speakers quoted Jensen Huang’s 1:2,000 agent-to-human ratio framing. Then I’d note Yoav Leitersdorf counsel to keep R&amp;D flat and grow through AI, and Mark McClain’s observation that AI agents operate at a speed humans physically cannot match — these signals point to a structural workforce shift that cybersecurity leadership hasn’t fully internalized yet.</p>



<p>EC Council’s Bavasi was the most direct voice on this. He pushed back on the premise that CISOs should own AI wholesale: “CISOs are already suffering. A thousand things are already going on. It is one of the most short-lived jobs in the world. And you’re about to throw a behemoth to them.”</p>



<p>He cited 4 million cybersecurity jobs unfilled today, with that figure likely to double as the agentic layer matures — not because demand shrinks, but because the skill profile required is fundamentally different.</p>



<p>Bavasi also landed what I’d call the most confronting statistic of the week — not about threat actors, but about the industry’s own readiness: “We are living in an era where AI agents already have a social media community of their own. We live in an era where humans are being threatened and blackmailed and we still haven’t figured out how we’re going to implement responsible AI governance and ethics,” he said.</p>



<h2 class="wp-block-heading">Closing observation</h2>



<p>While my preview was focused on what CISOs needed to learn at RSAC, what the floor revealed was that some of that may require them to rethink how their teams are built, how their governance is structured, and how they report to boards, which are asking AI governance questions but receiving answers designed for a different era.</p>



<p>The intelligence is accumulating. The institutional response is lagging. That gap was the real story of RSAC 2026.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ÖPNV bei OpenStreetMap (fossgis2011)]]></title>
<description><![CDATA[Der Verkehrsverbund Rhein-Sieg (VRS) und der Aachener Verkehrsverbund (AVV) sehen den Öffentlichen Personenverkehr (ÖPNV) als zentrales Element bei OSM, von dessen stetiger inhaltlicher Verbesserung und Weiterentwicklung beide Seiten – OSM und die Verkehrsverbünde – positiv partizipieren.

Der Ei...]]></description>
<link>https://tsecurity.de/de/3391624/it-security-video/oepnv-bei-openstreetmap-fossgis2011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3391624/it-security-video/oepnv-bei-openstreetmap-fossgis2011/</guid>
<pubDate>Mon, 30 Mar 2026 02:01:42 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Verkehrsverbund Rhein-Sieg (VRS) und der Aachener Verkehrsverbund (AVV) sehen den Öffentlichen Personenverkehr (ÖPNV) als zentrales Element bei OSM, von dessen stetiger inhaltlicher Verbesserung und Weiterentwicklung beide Seiten – OSM und die Verkehrsverbünde – positiv partizipieren.

Der Einsatz von OpenStreetMap (OSM) bietet auch für die Verkehrsverbünde in Deutschland mannigfaltige Möglichkeiten. Schon frühzeitig haben dies sowohl der VRS als auch der AVV erkannt und bringen sich seit 2008 intensiv bei OSM ein.
Dies beinhaltet eine breite Palette: Vom Austausch mit den örtlichen Communities; als konkreter ÖPNV-Ansprechpartner, wie und was bei den Verkehrsverbünden funktioniert bzw. umsetzbar ist; einem Bericht im OSMBlog (http://blog.openstreetmap.de/2010/09/openstreetmap-und-offentlicher-nahverkehr-vrs-avv/); einem erstem Workshop-Angebot zur Konkretisierung des ÖPNV-Tagging (http://wiki.openstreetmap.org/wiki/VRS_Workshop) bis hin zu ersten Umsetzungen (http://www.avv.de/ressorts/meine-verbindung/verbindung-suchen/online/) auf den Internetseiten der Verbünde. So stellt z.B. die (Bundes-)länderübergreifende Verfügbarkeit von OSM-Karten für AVV und VRS eine wesentliche interne administrative Verbesserung bei hoher Qualität dar.
Vergangenheit und Zukunft
Im VRS wurde Mitte 2009 die Datenfreigabe für OSM beschlossen, so dass seitdem der Zugriff auf Haltestellen und Linienverlaufsinformationen besteht. Zukünftig ist auch der Zugriff auf die Fahrplandaten geplant. Ferner wurde ein eigener OSM-WMS-Server wurde für die zukünftigen Aufgaben erstellt.
Gemeinsam planen AVV und VRS auch die Erarbeitung und Finanzierung eines ÖPNV-Plugin für den Editor JOSM.
OpenSource als Leitbild
AVV und VRS setzen auf OpenSource. Server und Contentmanagementsystem beim AVV und VRS basieren schon seit längerem auf OpenSource-Komponenten. Die Umstellung der Benutzerschnittstelle der Internet-Fahrplanauskunft beim AVV auf OpenSource-Komponenten ist aber eine echte Innovation in diesem Bereich. Entwicklungsaufwand und -zeit konnten durch den Einsatz fertiger OpenSource-Komponenten erheblich reduziert werden. Der VRS wird ab 2011 nachziehen. Mit der Kombination von OpenSource-Komponenten und der OpenStreetMap-Karte kommen AVV und VRS ihrer Verantwortung nach, besonders sparsam mit den öffentlichen Mitteln zu haushalten. Ein weiterer Vorteil von OpenSource für den AVV und VRS ist, dass sie nicht langfristig an einen einzelnen Softwareanbieter gebunden sind und so einen hohen Freiheitsgrad bei der Vergabe künftiger Aufträge im Zusammenhang mit der Fahrplanauskunft haben.
about this event: https://fossgis-konferenz.de/2011/programm/events/191.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Schluss mit Microsoft: Europäische Firmen bauen eigene Office-Suite]]></title>
<description><![CDATA[Ein Bündnis europäischer Technologieunternehmen arbeitet an einer eigenen Office-Suite als Alternative zu US-Diensten. Eine erste Vorschau von "Euro-Office" steht bereits zur Verfügung und soll die digitale Unabhängigkeit von Europa stärken.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3388918/it-security-nachrichten/schluss-mit-microsoft-europaeische-firmen-bauen-eigene-office-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388918/it-security-nachrichten/schluss-mit-microsoft-europaeische-firmen-bauen-eigene-office-suite/</guid>
<pubDate>Sat, 28 Mar 2026 12:53:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,157801.html"><img hspace="5" border="0" align="left" alt="Open Source, Sourcecode, Opensource, Source Code, Open Source Software, Quelloffen, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56862.jpg"></a>
			Ein Bündnis europäischer Technologieunternehmen arbeitet an einer eigenen Office-Suite als Alternative zu US-Diensten. Eine erste Vorschau von "Euro-Office" steht bereits zur Verfügung und soll die digitale Unabhängigkeit von Europa stärken.			(<a href="https://winfuture.de/news,157801.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32300 | opensource-workshop connect-cms up to 1.41.0/2.41.0 My Page improper authorization (GHSA-qr6x-wvxr-8hm9)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0. Affected is an unknown function of the component My Page. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2026-32300. It is possible t...]]></description>
<link>https://tsecurity.de/de/3388703/sicherheitsluecken/cve-2026-32300-opensource-workshop-connect-cms-up-to-14102410-my-page-improper-authorization-ghsa-qr6x-wvxr-8hm9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388703/sicherheitsluecken/cve-2026-32300-opensource-workshop-connect-cms-up-to-14102410-my-page-improper-authorization-ghsa-qr6x-wvxr-8hm9/</guid>
<pubDate>Sat, 28 Mar 2026 11:18:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. Affected is an unknown function of the component <em>My Page</em>. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as <a href="https://vuldb.com/source_cve/352660">CVE-2026-32300</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32278 | opensource-workshop connect-cms up to 1.41.0/2.41.0 Form Plugin File unrestricted upload (GHSA-mv3p-7p89-wq9p)]]></title>
<description><![CDATA[A vulnerability has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 and classified as critical. This affects an unknown function of the component Form Plugin. Performing a manipulation of the argument File results in unrestricted upload.

This vulnerability is known as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3388702/sicherheitsluecken/cve-2026-32278-opensource-workshop-connect-cms-up-to-14102410-form-plugin-file-unrestricted-upload-ghsa-mv3p-7p89-wq9p/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388702/sicherheitsluecken/cve-2026-32278-opensource-workshop-connect-cms-up-to-14102410-form-plugin-file-unrestricted-upload-ghsa-mv3p-7p89-wq9p/</guid>
<pubDate>Sat, 28 Mar 2026 11:18:35 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This affects an unknown function of the component <em>Form Plugin</em>. Performing a manipulation of the argument <em>File</em> results in unrestricted upload.

This vulnerability is known as <a href="https://vuldb.com/source_cve/352636">CVE-2026-32278</a>. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32276 | opensource-workshop connect-cms up to 1.41.0/2.41.0 code injection (GHSA-hxqw-6qv7-cqfv)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0. The affected element is an unknown function. This manipulation causes code injection.

This vulnerability appears as CVE-2026-32276. The attack may be initiated remotely. Ther...]]></description>
<link>https://tsecurity.de/de/3388686/sicherheitsluecken/cve-2026-32276-opensource-workshop-connect-cms-up-to-14102410-code-injection-ghsa-hxqw-6qv7-cqfv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388686/sicherheitsluecken/cve-2026-32276-opensource-workshop-connect-cms-up-to-14102410-code-injection-ghsa-hxqw-6qv7-cqfv/</guid>
<pubDate>Sat, 28 Mar 2026 11:16:00 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. The affected element is an unknown function. This manipulation causes code injection.

This vulnerability appears as <a href="https://vuldb.com/source_cve/352634">CVE-2026-32276</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32277 | opensource-workshop connect-cms up to 1.41.0/2.41.0 cross site scripting (GHSA-cmfh-mpmf-fmq4)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in opensource-workshop connect-cms up to 1.41.0/2.41.0. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-32277. The attack may be launched remotel...]]></description>
<link>https://tsecurity.de/de/3388685/sicherheitsluecken/cve-2026-32277-opensource-workshop-connect-cms-up-to-14102410-cross-site-scripting-ghsa-cmfh-mpmf-fmq4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388685/sicherheitsluecken/cve-2026-32277-opensource-workshop-connect-cms-up-to-14102410-cross-site-scripting-ghsa-cmfh-mpmf-fmq4/</guid>
<pubDate>Sat, 28 Mar 2026 11:15:53 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/source_cve/352635">CVE-2026-32277</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32299 | opensource-workshop connect-cms up to 1.41.0/2.41.0 access control (GHSA-62ch-j6x7-722j)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in opensource-workshop connect-cms up to 1.41.0/2.41.0. This impacts an unknown function. Such manipulation leads to improper access controls.

This vulnerability is listed as CVE-2026-32299. The attack may be performed from remote. There ...]]></description>
<link>https://tsecurity.de/de/3388680/sicherheitsluecken/cve-2026-32299-opensource-workshop-connect-cms-up-to-14102410-access-control-ghsa-62ch-j6x7-722j/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388680/sicherheitsluecken/cve-2026-32299-opensource-workshop-connect-cms-up-to-14102410-access-control-ghsa-62ch-j6x7-722j/</guid>
<pubDate>Sat, 28 Mar 2026 11:13:35 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. This impacts an unknown function. Such manipulation leads to improper access controls.

This vulnerability is listed as <a href="https://vuldb.com/source_cve/352659">CVE-2026-32299</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32279 | opensource-workshop connect-cms up to 1.41.0/2.41.0 server-side request forgery (GHSA-jh46-85jr-6ph9)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in opensource-workshop connect-cms up to 1.41.0/2.41.0. This affects an unknown function. This manipulation causes server-side request forgery.

This vulnerability is tracked as CVE-2026-32279. The attack is possible to be carried out remotely....]]></description>
<link>https://tsecurity.de/de/3388664/sicherheitsluecken/cve-2026-32279-opensource-workshop-connect-cms-up-to-14102410-server-side-request-forgery-ghsa-jh46-85jr-6ph9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388664/sicherheitsluecken/cve-2026-32279-opensource-workshop-connect-cms-up-to-14102410-server-side-request-forgery-ghsa-jh46-85jr-6ph9/</guid>
<pubDate>Sat, 28 Mar 2026 11:10:12 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">critical</a> has been reported in <a href="https://vuldb.com/product/opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. This affects an unknown function. This manipulation causes server-side request forgery.

This vulnerability is tracked as <a href="https://vuldb.com/source_cve/352658">CVE-2026-32279</a>. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32276 | opensource-workshop connect-cms up to 1.41.0/2.41.0 code injection (GHSA-hxqw-6qv7-cqfv)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0. The affected element is an unknown function. This manipulation causes code injection.

This vulnerability appears as CVE-2026-32276. The attack may be initiated remotely. Ther...]]></description>
<link>https://tsecurity.de/de/3388243/sicherheitsluecken/cve-2026-32276-opensource-workshop-connect-cms-up-to-14102410-code-injection-ghsa-hxqw-6qv7-cqfv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388243/sicherheitsluecken/cve-2026-32276-opensource-workshop-connect-cms-up-to-14102410-code-injection-ghsa-hxqw-6qv7-cqfv/</guid>
<pubDate>Sat, 28 Mar 2026 07:00:01 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. The affected element is an unknown function. This manipulation causes code injection.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.352634">CVE-2026-32276</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32299 | opensource-workshop connect-cms up to 1.41.0/2.41.0 access control (GHSA-62ch-j6x7-722j)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in opensource-workshop connect-cms up to 1.41.0/2.41.0. This impacts an unknown function. Such manipulation leads to improper access controls.

This vulnerability is listed as CVE-2026-32299. The attack may be performed from remote. There ...]]></description>
<link>https://tsecurity.de/de/3388242/sicherheitsluecken/cve-2026-32299-opensource-workshop-connect-cms-up-to-14102410-access-control-ghsa-62ch-j6x7-722j/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388242/sicherheitsluecken/cve-2026-32299-opensource-workshop-connect-cms-up-to-14102410-access-control-ghsa-62ch-j6x7-722j/</guid>
<pubDate>Sat, 28 Mar 2026 06:58:35 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. This impacts an unknown function. Such manipulation leads to improper access controls.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.352659">CVE-2026-32299</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32278 | opensource-workshop connect-cms up to 1.41.0/2.41.0 Form Plugin File unrestricted upload (GHSA-mv3p-7p89-wq9p)]]></title>
<description><![CDATA[A vulnerability has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 and classified as critical. This affects an unknown function of the component Form Plugin. Performing a manipulation of the argument File results in unrestricted upload.

This vulnerability is known as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3388241/sicherheitsluecken/cve-2026-32278-opensource-workshop-connect-cms-up-to-14102410-form-plugin-file-unrestricted-upload-ghsa-mv3p-7p89-wq9p/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388241/sicherheitsluecken/cve-2026-32278-opensource-workshop-connect-cms-up-to-14102410-form-plugin-file-unrestricted-upload-ghsa-mv3p-7p89-wq9p/</guid>
<pubDate>Sat, 28 Mar 2026 06:58:28 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This affects an unknown function of the component <em>Form Plugin</em>. Performing a manipulation of the argument <em>File</em> results in unrestricted upload.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.352636">CVE-2026-32278</a>. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32277 | opensource-workshop connect-cms up to 1.41.0/2.41.0 cross site scripting (GHSA-cmfh-mpmf-fmq4)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in opensource-workshop connect-cms up to 1.41.0/2.41.0. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-32277. The attack may be launched remotel...]]></description>
<link>https://tsecurity.de/de/3388234/sicherheitsluecken/cve-2026-32277-opensource-workshop-connect-cms-up-to-14102410-cross-site-scripting-ghsa-cmfh-mpmf-fmq4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388234/sicherheitsluecken/cve-2026-32277-opensource-workshop-connect-cms-up-to-14102410-cross-site-scripting-ghsa-cmfh-mpmf-fmq4/</guid>
<pubDate>Sat, 28 Mar 2026 06:55:25 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.352635">CVE-2026-32277</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32279 | opensource-workshop connect-cms up to 1.41.0/2.41.0 server-side request forgery (GHSA-jh46-85jr-6ph9)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in opensource-workshop connect-cms up to 1.41.0/2.41.0. This affects an unknown function. This manipulation causes server-side request forgery.

This vulnerability is tracked as CVE-2026-32279. The attack is possible to be carried out remotely....]]></description>
<link>https://tsecurity.de/de/3388226/sicherheitsluecken/cve-2026-32279-opensource-workshop-connect-cms-up-to-14102410-server-side-request-forgery-ghsa-jh46-85jr-6ph9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388226/sicherheitsluecken/cve-2026-32279-opensource-workshop-connect-cms-up-to-14102410-server-side-request-forgery-ghsa-jh46-85jr-6ph9/</guid>
<pubDate>Sat, 28 Mar 2026 06:53:01 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">critical</a> has been reported in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. This affects an unknown function. This manipulation causes server-side request forgery.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.352658">CVE-2026-32279</a>. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32300 | opensource-workshop connect-cms up to 1.41.0/2.41.0 My Page improper authorization (GHSA-qr6x-wvxr-8hm9)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0. Affected is an unknown function of the component My Page. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2026-32300. It is possible t...]]></description>
<link>https://tsecurity.de/de/3388223/sicherheitsluecken/cve-2026-32300-opensource-workshop-connect-cms-up-to-14102410-my-page-improper-authorization-ghsa-qr6x-wvxr-8hm9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3388223/sicherheitsluecken/cve-2026-32300-opensource-workshop-connect-cms-up-to-14102410-my-page-improper-authorization-ghsa-qr6x-wvxr-8hm9/</guid>
<pubDate>Sat, 28 Mar 2026 06:52:51 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.opensource-workshop:connect-cms">opensource-workshop connect-cms up to 1.41.0/2.41.0</a>. Affected is an unknown function of the component <em>My Page</em>. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.352660">CVE-2026-32300</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Erzeugung von Raster-Tiles aus Vektor-Tiles in einer PMTiles-Datei (fossgis2026)]]></title>
<description><![CDATA[PMTiles ist derzeit der _de facto_ Standard für die _cloud native_ Bereitstellung von Vector Tiles. Auch für die MOBIDROM Routing Services stellen wir Vektor-Tiles im Shortbread-Schema aus einer PMTiles-Datei bereit. Für die Bereitstellung von Raster-Tiles aus den PMTiles-Dateien haben wir zwei n...]]></description>
<link>https://tsecurity.de/de/3386827/it-security-video/erzeugung-von-raster-tiles-aus-vektor-tiles-in-einer-pmtiles-datei-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386827/it-security-video/erzeugung-von-raster-tiles-aus-vektor-tiles-in-einer-pmtiles-datei-fossgis2026/</guid>
<pubDate>Fri, 27 Mar 2026 15:48:16 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PMTiles ist derzeit der _de facto_ Standard für die _cloud native_ Bereitstellung von Vector Tiles. Auch für die MOBIDROM Routing Services stellen wir Vektor-Tiles im Shortbread-Schema aus einer PMTiles-Datei bereit. Für die Bereitstellung von Raster-Tiles aus den PMTiles-Dateien haben wir zwei neue Möglichkeiten entwickelt, die im Rahmen dieses Lightning-Talks kurz vorgestellt werden.

Die Kern-Infrastruktur bei MOBIDROM - der Landesagentur für Mobilitätsdaten in NRW - ist _cloud native_, d.h. die meisten unserer Dienste werden in einer managed Kubernetes-Umgebung betrieben.  Aus diesem Grund war es für uns selbstverständlich, auch bei der Modernisierung unserer Tileserver-Infrastruktur auch auf moderne _cloud native_ Ansätze zu setzen. Für die Bereitstellung von Raster-Tiles war hier das von Protomaps entwickelte PMTiles-Format die erste Wahl. 

Ein weiteres Ziel der Modernisierung war eine offene (OpenSource) und stringente Architektur. Es sollte unbedingt vermieden werden, unterschiedliche Style-Definitionen für Vektor- und Raster-Tiles pflegen zu müssen. Zu diesem Zweck haben wir Lösungen entwickelt, die auf Basis von in PMTiles gespeicherten Vektor-Tiles im Shortbread-Schema und MapLibre Style Definitionen im JSON-Format entsprechende Raster-Tiles erzeugen können.

Die beiden vorgestellten Lösungen mit von uns entwickelter PMTiles Unterstützung sind:
- die [PMTiles DataStore Extension](https://docs.geoserver.org/main/en/user/community/pmtiles-store/index.html) für den GeoServer / GeoServer Cloud
  Mit diesem Community-Modul ist es möglich, Vektor-Tiles aus einer PMTiles-Datei als DataStore im GeoServer zu verwenden, mit Hilfe der MBStyle-Erweiterung zu rendern und als WMS, WMTS,... bereitzustellen. Vorteil ist, dass hier die gesamte Geoserver(-Cloud)-Infrastruktur für Rendering und Caching genutzt werden kann. Nachteil ist die unvollständige Unterstützung der Style Spec im MBStyles-Addon des Geoservers.
- eine Erweiterung des [_'vt-raster-konverters'_](https://github.com/Smart-Mapping/vt-raster-converter) der AG SmartMapping der Arbeitsgemeinschaft der Vermessungsverwaltungen der Länder der Bundesrepublik Deutschland (AdV)
Dieses ursprünglich für MBTiles entwickelte Tool nutzt [Maplibre GL Native](https://github.com/maplibre/maplibre-native), um Raster-Tiles aus Vektor-Tiles zu erzeugen. Wir haben dieses Tool für die Nutzung von PMTiles-Dateien oder direkten Abruf von Vektor-Teils von einem Tileserver erweitert. Vorteil ist hier vor allem die vollständige Unterstützung der Maplibre Style Spec, so dass die Tiles exakt so gerendert werden, wie bei direkter Nutzung der Vektor Tiles im Browser. Nachteil ist der Fokus auf reines Rendering. Caching, Transformation, ... müssen nachgelagert z.B. von Mapproxy oder GeoWebCache übernommen werden.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/ZXMWGF/]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers exploit critical Langflow RCE within hours as CISA sounds alarm]]></title>
<description><![CDATA[Attackers have exploited a critical Langflow RCE within hours of disclosure, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to formally flag it for urgent remediation.



The flaw, which allows running arbitrary code on vulnerable Langflow instances without >credentials,...]]></description>
<link>https://tsecurity.de/de/3386318/it-security-nachrichten/attackers-exploit-critical-langflow-rce-within-hours-as-cisa-sounds-alarm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386318/it-security-nachrichten/attackers-exploit-critical-langflow-rce-within-hours-as-cisa-sounds-alarm/</guid>
<pubDate>Fri, 27 Mar 2026 13:07:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Attackers have exploited a critical Langflow RCE within hours of disclosure, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to formally flag it for urgent remediation.</p>



<p>The flaw, which allows running arbitrary code on vulnerable Langflow instances without &gt;credentials, was weaponized within 20 hours of the open-source AI-pipeline tool <a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx" target="_blank">disclosing</a> it.</p>



<p>According to a Sysdig <a href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours" target="_blank" rel="noreferrer noopener">report</a>, crooks started hitting a fleet of honeypot nodes with vulnerable instances across multiple cloud providers and regions right after they went live. Sysdig observed four such attempts within hours of deployment, with one attacker progressing to environment variable exfiltration.</p>



<p>“This is notable because no public POC repository existed on GitHub at the time of the first attack,” Sysdig researchers said. “The advisory itself contained enough detail (the vulnerable endpoint path and the mechanism for code injection via flow node definitions) for attackers to construct a working exploit without additional research.”</p>



<p>CISA has <a href="https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">added</a> the flaw to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch their systems by April 8, 2026.</p>



<h2 class="wp-block-heading"><a></a>A default setting allows code injection</h2>



<p>The vulnerability, tracked as CVE-2026-33017, stems from an exposed API endpoint in Langflow, the open-source visual framework for building AI agents and Retrieval-Augmented Generation (<a href="https://www.csoonline.com/article/4132860/why-2025s-agentic-ai-boom-is-a-cisos-worst-nightmare.html">RAG</a>) pipelines.</p>



<p>The exposure allows attackers to submit malicious workflow data containing embedded Python code. Instead of using trusted data, the application executes this attacker-supplied code without any sandboxing, leading to unauthenticated remote code execution on affected systems, according to an NVD <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33017" target="_blank" rel="noreferrer noopener">description</a>.</p>



<p>“The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code,” the description added. “This is distinct from <a href="https://www.csoonline.com/article/3978918/critical-flaw-in-ai-agent-dev-tool-langflow-under-active-exploitation.html">CVE-2025-3248</a>, which fixed /api/v1/validate/code by adding authentication.”</p>



<p>The Code Injection flaw affects Langflow versions up to (excluding) 1.8.2, and has been fixed in v1.9.0. It received a critical CVSS rating of 9.3 out of 10, owing to its “unauthenticated” and simple exploitability, massive AI attack surface, and high impact.</p>



<h2 class="wp-block-heading">Pace of exploit raises concerns</h2>



<p>Exploitation activity was observed less than a day after the vulnerability became public, which, Sysdig noted, demonstrates threat actors quickly operationalizing new vulnerabilities (probably through automation).</p>



<p>Attackers could build a working exploit just from the advisory description and quickly start scanning for flawed instances. “Exfiltrated information included keys and credentials, which provided access to connected databases and potential software supply chain compromise,” Sysdig researchers said.</p>



<p>With patch windows collapsing significantly, <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">runtime detection</a> remains a primary and the only option, Sysdig noted. “Every attacker in this campaign followed the same post-exploitation playbook: execute a shell command via Python’s os.popen(), then exfiltrate the output over HTTP,” it said, adding that runtime rules can detect these attempts.</p>



<p>The way runtime detection can help is by working on “day zero,” the researchers explained. “These rules do not require a signature for CVE-2026-33017 specifically because they detect the exploitation behavior, not the vulnerability. The same rules would fire regardless of whether the initial access came through CVE-2026-33017, CVE-2025-3248, or any other RCE in an application.”</p>



<p>Sysdig also shared a list of indicators of compromise (IOCs), including attacker source IPs, C2 and staging infrastructure detected, Dropper URLs, and <a href="https://docs.projectdiscovery.io/opensource/interactsh/overview" target="_blank" rel="noreferrer noopener">interactsh</a> callback domains. It recommends immediately upgrading to patched versions, restricting exposure, and monitoring for anomalous activity, emphasizing that exposed instances should be treated as potentially compromised.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The unplanned work behind every AI use case]]></title>
<description><![CDATA[For most enterprises, the question of whether to invest in AI is no longer up for debate. AI is already part of the roadmap, the budget, and the board conversation. The harder question now is how to make AI deliver value at scale, not once, but repeatedly, across teams, functions, and geographies...]]></description>
<link>https://tsecurity.de/de/3386267/it-nachrichten/the-unplanned-work-behind-every-ai-use-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386267/it-nachrichten/the-unplanned-work-behind-every-ai-use-case/</guid>
<pubDate>Fri, 27 Mar 2026 12:46:59 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For most enterprises, the question of whether to invest in AI is no longer up for debate. AI is already part of the roadmap, the budget, and the board conversation. The harder question now is how to make AI deliver value at scale, not once, but repeatedly, across teams, functions, and geographies.</p>



<p>That is where many organizations are struggling.</p>



<p>AI pilots often succeed. Teams demonstrate working models, agents, or assistants that show clear promise. The difficulty begins when those pilots are expected to move into production and then expand across the enterprise. Progress slows. Complexity increases. Confidence fades. What looked straightforward in a controlled environment becomes fragile in the real world.</p>



<p>In most cases, this has little to do with the quality of the model. It has everything to do with the system required to run AI reliably inside an enterprise.</p>



<p><strong>The gap between building AI and running it</strong></p>



<p>AI is still commonly discussed as if it were a discrete capability. A model is trained. A use case is defined. An application is deployed. In practice, the model is only one part of a much larger picture.</p>



<p>The moment AI moves toward production, a broader set of requirements comes into play. Infrastructure must be provisioned and operated. Data pipelines need to be maintained. Models must be deployed, monitored, updated, and governed over time. Security controls must be enforced. Audit and compliance expectations must be met. Costs must be tracked, explained, and justified as usage grows.</p>



<p>None of this work is optional. It determines whether AI can be trusted, scaled, and sustained. Yet it is often underestimated at the outset. Many AI initiatives begin with a narrow focus on the use case itself, assuming the surrounding work can be addressed incrementally.</p>



<p>That assumption is where most programs begin to stall.</p>



<p><strong>The hidden platform work no one plans for</strong></p>



<p>Every AI initiative introduces platform work, whether organizations intend it or not. Teams select tools, build environments, and define processes to solve immediate needs. Over time, these decisions accumulate. Different teams take different paths. Knowledge fragments. Operational complexity grows.</p>



<p>What emerges is not a deliberate platform strategy, but an accidental one. AI adoption slows not because ambition has faded, but because each additional use case becomes harder to support. Deployments take longer. Costs become less predictable. Risk becomes harder to explain to regulators and leadership.</p>



<p>This is not a failure of technology. It is a mismatch between ambition and operating model.</p>



<p><strong>Why AI does not scale like traditional software</strong></p>



<p>Enterprises have decades of experience scaling applications. They know how to manage infrastructure, security, and operations for conventional systems. AI behaves differently.</p>



<p>Models are influenced by data as much as code. Their behavior can change over time. They introduce requirements around explainability, bias, and accountability that traditional applications never had to address. Treating AI as just another workload often leads to friction across development, deployment, and governance.</p>



<p>To compensate, organizations rely on manual effort and individual expertise. Custom solutions are built. Reviews are handled case by case. Progress depends on people rather than systems. This approach can work for a handful of initiatives. It does not work when AI is expected to scale across the enterprise.</p>



<p><strong>Build versus buy is not the starting question</strong></p>



<p>Build versus buy is often the first question leaders ask once AI initiatives begin to scale. Should these capabilities be built internally, or sourced from a platform or partner? It is a reasonable question, but it is frequently asked too early.</p>



<p>In practice, build versus buy is not a starting point. It is the outcome of a more fundamental decision about how the organization intends to operate AI at scale. As AI adoption expands, operational complexity rises quickly. Internally built tools become harder to maintain as models, techniques, and regulatory expectations evolve. Switching costs increase as workflows become more agent-driven. Procurement grows more complex, with concerns around pricing models, flexibility, and long-term dependency moving into the CIO’s line of sight.</p>



<p>In this context, the more important leadership question is whether the organization can move reliably from experimentation to production, and then repeat that process across teams, use cases, and regulatory environments. That is an operating model question, not a tooling one.</p>



<p>Building makes sense when an organization has a clear and sustained advantage that depends on owning the platform layer itself. This is often true in highly specialized environments, unique deployment constraints, or when AI capabilities are intended to be productized. Buying or partnering is usually the more practical path when speed, repeatability, and predictability matter most. In these cases, the goal is not to become an AI platform company, but an AI-powered business. The most effective approach is to buy the foundation that enables scale, and build the capabilities that differentiate.</p>



<p><strong>From AI initiatives to AI production systems</strong></p>



<p>Organizations that succeed with AI make an important shift. They stop treating AI as a series of initiatives and start managing it as a production capability.</p>



<p>A production capability emphasizes consistency over novelty. It prioritizes repeatability, visibility, and control. It allows teams to innovate within a shared framework that reduces friction and risk.</p>



<p>This does not require centralizing innovation or slowing teams down. It requires providing a common foundation that makes it easier to operate AI responsibly by default. Most enterprises have navigated similar transitions before with cloud platforms, data infrastructure, and DevOps practices. AI follows the same pattern, but with higher stakes.</p>



<p><strong>Designing for the long run</strong></p>



<p>The next phase of enterprise AI will not be defined by who experiments the fastest. It will be defined by who can operationalize intelligence in a way that is repeatable, governable, and sustainable.</p>



<p>That requires acknowledging a simple reality. AI is never just the AI. It is the system around it that determines success. Leaders who design for that reality early will scale with fewer surprises, lower risk, and far greater impact.</p>



<p>To learn more about Tata Communications <a href="https://www.tatacommunications.com/cloud/cloud-ai" rel="sponsored">AI Cloud</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stadtnavi - Eine einheitliche Lösung für verschiedene Angebote (fossgis2026)]]></title>
<description><![CDATA[Immer mehr deutsche Städte setzen auf ein Stadtnavi, eine modulare OpenSource-Lösung für Information und Navigation in der Stadt.

Vorreiter ist die Stadt Herrenberg in Baden-Württemberg. Mit den Stadtnavi [1] sollen unterschiedlichste Dienstleistungen der Stadt den Menschen nahe gebracht werden....]]></description>
<link>https://tsecurity.de/de/3386158/it-security-video/stadtnavi-eine-einheitliche-loesung-fuer-verschiedene-angebote-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386158/it-security-video/stadtnavi-eine-einheitliche-loesung-fuer-verschiedene-angebote-fossgis2026/</guid>
<pubDate>Fri, 27 Mar 2026 12:07:03 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Immer mehr deutsche Städte setzen auf ein Stadtnavi, eine modulare OpenSource-Lösung für Information und Navigation in der Stadt.

Vorreiter ist die Stadt Herrenberg in Baden-Württemberg. Mit den Stadtnavi [1] sollen unterschiedlichste Dienstleistungen der Stadt den Menschen nahe gebracht werden. Einer der Kernpunkte ist eine Routing-Lösung auf der Basis von OpenStreetMap, die auch das Umsteigen in unterschiedliche Verkehrsmittel berücksichtigen kann und für den öffentlichen Nahverkehr abhängig von Uhrzeit und Fahrplan die Routen anpasst.

Neben Herrenberg setzen auch die Städte Ludwigsburg, Kaiserslautern und Aachen und der Verkehrsverbund Pforzheim Enzkreis das Stadtnavi ein. [2]

Die Stadt Kiel bereitet aktuell in Zusammenarbeit mit den umliegenden Landkreisen Rendsburg-Eckernförde und Plön den Einsatz von Stadtnavi vor. Dafür wurde bereits ein Workshop für die Öffentlichkeit veranstaltet, um möglichst weitere Menschen für die Datenerfassung in OpenStreetMap zu gewinnen.

[1] https://stadtnavi.de/
[2] https://www.herrenberg.de/Mobilitaet/stadtnavi

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/ZS9ZJB/]]></content:encoded>
</item>
<item>
<title><![CDATA[8 steps CISOs can take to empower their teams]]></title>
<description><![CDATA[Many leaders know empowered teams deliver better results, but not all leaders understand how to get there. It all starts with knowing what empowerment truly means.



Put simply: Empowerment is the absence of micromanagement. Empowerment provides the foundation for people to develop autonomy; to ...]]></description>
<link>https://tsecurity.de/de/3385966/it-security-nachrichten/8-steps-cisos-can-take-to-empower-their-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385966/it-security-nachrichten/8-steps-cisos-can-take-to-empower-their-teams/</guid>
<pubDate>Fri, 27 Mar 2026 11:06:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many leaders know empowered teams deliver better results, but not all leaders understand how to get there. It all starts with knowing what empowerment truly means.</p>



<p>Put simply: Empowerment is the absence of micromanagement. Empowerment provides the foundation for people to develop autonomy; to take action, responsibility, and accountability; and to have the room necessary to grow to become better at execution.</p>



<p>More to the point, however, empowerment requires leaders who are mature, capable, self-secure, and willing to elevate the organization to the next level. It involves delegating decision-making power, providing training and tools, and creating a supportive environment where staff can innovate, solve problems, and contribute meaningfully without constant oversight.</p>



<p>Empowerment leads not only to higher engagement, higher productivity, and faster and better outcomes, but also higher job satisfaction, ensuring employees stay longer, adding even more value to the long-term success of a company.</p>



<p>As a leader, you can’t empower your teams without the right preparation. You need to first instill confidence in your team to make decisions and contribute meaningfully.</p>



<p>You’ll want to start with your direct reports, and empower them to break things down similarly in their respective teams and sub-teams. This won’t be achieved in a week or even in months, especially in old-fashioned companies that are run in pyramidal structures.</p>



<p>Here’s a practical list of steps leaders should take to implement empowerment throughout their organizations effectively.</p>



<h2 class="wp-block-heading">Build a foundation of trust</h2>



<p>Start by demonstrating trust in your employees’ abilities by avoiding micromanaging and allowing them to handle tasks independently. This creates a safe environment where they feel valued and responsible.</p>



<p>In weekly meetings, lead by example by asking questions — not to control, but to make employees part of the path to a solution. And then ask them to execute it.</p>



<p>In subsequent meetings, focus on where you can help. When things go well, give positive feedback and more freedom. Let things fail early, but don’t place blame; focus instead on lessons learned. <a></a></p>



<p>Once when we were rolling out a well-known EDR tool, I knew the settings weren’t tight enough, nor were the received updates applied fast enough. So I asked two people to own this, come up with suggestions for tightening the screws, and guarantee a successful rollout on multiple OSes in parallel. The phased approach took serious time, but it got us there, and without breakdowns or other hiccups. This instilled tremendous trust into the team as they could see I had empowered and entrusted them, and they responded with improved, mature actions that significantly contributed to the successful rollout and optimization.</p>



<h2 class="wp-block-heading">Set clear goals and expectations</h2>



<p>When empowering, it’s vital to define specific, measurable objectives aligned with company vision and goals. I recommend the SMART goals methodology — specific, measurable, achievable, relevant, and time-bound — to ensure everyone understands their role and how it contributes to the bigger picture, reducing ambiguity.</p>



<p>It’s important to involve your people in this exercise. Make them help formulate the objectives and metrics, ask for their input on timing, and what support may be required. Don’t set non-achievable goals and don’t underestimate the relevancy factor. People want to be part of something that makes a difference.</p>



<h2 class="wp-block-heading">Provide ongoing training and development</h2>



<p>Leaders should also invest in skill-building programs, workshops, or online courses. In addition to equipping them with the knowledge and tools to excel, leaders must also ensure their people can leverage these learned skills on the job, by applying them.</p>



<p>This will not only solidify the training they have completed but also lead to broader, more business-relevant learnings and experiences. For example, a project leader fresh off their <a href="https://www.cio.com/article/228204/pmp-project-management-certification-guide.html">PMP certification</a> empowered to execute a huge project with hundreds of dependencies will be better set up for long-term career success, and your company will benefit from it.</p>



<h2 class="wp-block-heading">Delegate authority meaningfully</h2>



<p>Assign decision-making power to employees at appropriate levels. If your latest technology solution can be implemented without your involvement, assign a direct report complete responsibility and accountability to roll out the solution with a phased approach, and monitor their progress via status reports, while also measuring outcomes.</p>



<p>Ultimate accountability rests with you of course, but by delegating authority you can better scale your team’s efforts, contributing additional overall results for your organization. If things don’t work out, keep delegated leaders accountable to solve the problems that arise. If the project involves other functions, ensure via your functional leader counterpart that delegated authorities will work cross-functionally.</p>



<h2 class="wp-block-heading">Foster open communication</h2>



<p>Encourage two-way dialogue through regular meetings, feedback sessions, and anonymous channels. Keep in mind that different cultures require different styles, and you need to adapt the channel and facilitation to that, especially in international businesses. Employees must understand, however, that these are opportunities for open dialogue not finger-pointing.</p>



<h2 class="wp-block-heading">Encourage innovation and risk taking</h2>



<p>Create a culture where calculated risks are rewarded, even if they lead to failures sometimes. One way to do that is to implement “innovation time” by setting aside time (say, 5-10% of work hours) for experimentation or improving daily work. Once you continuously require your people to think about and act on improvements, you can see the results quite literally.</p>



<p>For risk taking, ensure people understand this doesn’t mean taking just any security risk, but instead encourage them to calculate security risk versus benefits (impact) and likelihoods, and to present — or when fully empowered, to act on — their findings. For example, At risk: $100,000; potential win of $500,000. Likelihood to win 0.5? Then take the risk. Contrary example: At risk: $500,000. Potential win: $100,000. Likelihood to win &gt; 0.5? Choose not to take this security risk without additional controls and preparations.</p>



<h2 class="wp-block-heading">Supply necessary resources</h2>



<p>Ensure team members have access to the right tools, technology, and support systems. This could mean providing better software, more budget, or cross-departmental collaboration to remove barriers to success. I have teamed in the past with IT, OT, engineering, T&amp;D, legal, HR, compliance, and even sales and marketing to get things over the “budget hump” — shared wins and shared successes will enable strong corporate culture and strong trust relationships.</p>



<h2 class="wp-block-heading">Solicit and act on feedback</h2>



<p>Regularly gather input via surveys or one-on-ones, then implement changes based on it. This shows employees their opinions matter, closing the loop on empowerment and driving continuous improvement. This last one is not to be underestimated in both value, guidance, honesty, integrity, visibility, and, last but not least, empowerment. You can proudly share meaningful work, growth, autonomy, and engagement scores on your resume. That is a true accomplishment.</p>



<p>Implementing these steps requires consistent leadership commitment. Start small, measure progress through employee satisfaction surveys, and adjust as needed for your organization’s context.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[European Parliament delays implementation of parts of the EU AI Act]]></title>
<description><![CDATA[The European Parliament’s Thursday vote to delay parts of the EU AI Act adds more uncertainty to the already chaotic AI compliance universe. But analysts say that CIOs must proceed as though the compliance rules are in effect. 



In a statement, Parliament said that its members decided to “delay...]]></description>
<link>https://tsecurity.de/de/3385134/it-nachrichten/european-parliament-delays-implementation-of-parts-of-the-eu-ai-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385134/it-nachrichten/european-parliament-delays-implementation-of-parts-of-the-eu-ai-act/</guid>
<pubDate>Fri, 27 Mar 2026 03:01:31 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Parliament’s Thursday vote to delay parts of <a href="https://www.cio.com/article/4093400/european-commission-opts-for-simple-with-new-set-of-digital-rules.html" target="_blank">the EU AI Act</a> adds more uncertainty to the already chaotic AI compliance universe. But analysts say that CIOs must proceed as though the compliance rules are in effect. </p>



<p>In <a href="https://www.europarl.europa.eu/news/en/press-room/20260323IPR38829/artificial-intelligence-act-delayed-application-ban-on-nudifier-apps" target="_blank" rel="nofollow">a statement</a>, Parliament said that its members decided to “delay the application of certain rules on high-risk artificial intelligence (AI) systems, to ensure that guidance and standards to help companies with implementation are ready.”</p>



<p>There is a calendar problem with this, in that they voted to delay part of the AI rules in such a way that the deadlines will push right up against the date on which the EU has committed to making a final decision. </p>



<h2 class="wp-block-heading">Delay is not a reprieve</h2>



<p>Analysts and consultants were virtually unanimous in their recommendations that enterprise CIOs must not wait and must instead operate as though the rules are already in effect.</p>



<p>“It’s good that they have clarified the extension [because] previously it was a moving target,” said <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="nofollow">Nader Henein</a>, a Gartner VP analyst. “It’s <em>not</em> great that the final decision will happen so close to the old deadline that organizations have no choice but to proceed as originally planned. Since the first draft of the EU’s Digital Omnibus proposal back in November, our guidance to clients has been to treat any potential extension as an opportunity to better test-out and improve the process for cataloging and managing AI systems.”</p>



<p>Henein added: “The major gating factor for the current timeline was that regulators would not have been ready to enforce. This is still the case. Spain is one of a handful of countries who stood up a regulator, and even the EU AI board is behind on the kind of guidance needed by organizations to properly understand their obligations when it comes to high risk AI systems. Those obligations that, as it stands, come into effect on August 2.”</p>



<p>Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="nofollow">Brian Levine</a>, executive director of FormerGov, said that the move to delay major AI Act restrictions until 2027 “leaves CIOs in a regulatory limbo, but it doesn’t change the underlying reality: enterprises still own the risk their AI systems create.”</p>



<p>“Whether Brussels enforces the rules next year or two years from now, the operational, legal, and reputational exposure from poorly governed AI is already here. CIOs shouldn’t treat the delay as a reprieve,” Levine said. “The organizations that wait for perfect regulatory clarity are the ones most likely to discover that their models have been quietly generating compliance, privacy, or safety liabilities long before any enforcement clock started ticking.”</p>



<p>Parliament proposed that “for high-risk AI systems specifically listed in the regulation–including those involving biometrics, and those used in critical infrastructure, education, employment, essential services, law enforcement, justice and border management,” the regulation would be applied on Dec. 2, 2027. For AI systems “that are “covered by EU sectoral legislation on safety and market surveillance,” it set a date of Aug. 2, 2028. The statement also noted that members are “in favor of giving providers until November 2, 2026 to comply with rules on watermarking AI-created audio, image, video or text content to indicate its origin.” </p>



<h2 class="wp-block-heading">Use time to prepare</h2>



<p><a href="https://www.infotech.com/profiles/jason-hookey" target="_blank" rel="nofollow">Jason Hookey</a>, executive counselor at the Info-Tech Research Group, said that he agreed with some of Parliament’s decision.</p>



<p>“The EU’s choice to delay high-risk AI obligations makes sense. Most people agree with the purpose of these rules, but there are concerns that organizations won’t be able to meet them without sufficient guidance, technical standards, or appropriate support. It’s important to note that the delay only changes the timeline, not the main goals around high-risk AI,” Hookey said. “Organizations that use this time well will be better prepared for compliance, control, and building market trust. Those who wait may only put off problems and miss out on the benefits of well-managed AI.”</p>



<p>Others pointed out that the European Union’s decisions are only recommendations to its many member states, who have the authority to make any changes they want for their countries. </p>



<h2 class="wp-block-heading">Procedural risk</h2>



<p>EU resolutions operate at two levels, noted <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="nofollow">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. </p>



<p>“There is a policy decision at the EU level and there is an implementation definition at the member states level. For this reason, even after the policy is set and published, they usually leave years-long implementation times for the member states to comply and release their own legislation that will define the implementation requirements for that member state,” Villanustre said. “I don’t think this particular case will be any different, so the actual deadline may be further in the future than what the draft legislation indicates.”</p>



<p>In addition, <a href="https://www.schellman.com/about-us/leadership/doug-barbin" target="_blank" rel="nofollow">Doug Barbin</a>, president of compliance firm Schellman, warned CIOs, “there’s also a real procedural risk here: if Council and Parliament negotiations drag past August 2026, the original deadlines stay on the books. CIOs who’ve been sitting on their hands are the most exposed to that scenario. The organizations investing in governance infrastructure now won’t be the ones in crisis mode later. This is extra time — use it.”</p>



<p>Barbin said the market is slowly shifting to broader strategies. “This is where compliance is going: less around specific actions and more about governance and risk,” he said.</p>



<h2 class="wp-block-heading">High cost of waiting</h2>



<p><a href="https://www.fusioncollective.net/meet-the-team/co-founder-managing-partner/" target="_blank" rel="nofollow">Yvette Schmitter</a>, CEO of the Fusion Collective consulting firm, said she is concerned that CIOs will take the wrong message away from what the European Parliament did. </p>



<p>“I think it is bad in the sense that it gives people a false sense of security in that they have more time. [It is] trying to give them more time, but companies will never be ready,” Schmitter said. “Courts don’t care about your regulatory compliance timeline. When your AI system produces detrimental or discriminatory outcomes at scale, ‘we were waiting for final guidance’ won’t survive depositions.”</p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, argued that these decisions amount to mixed messages, which serve to deepen the AI regulatory confusion.</p>



<p>“The shift in timelines has removed a clear enforcement anchor, but it has not reduced the expectation of accountability. If anything, it has made decision-making harder. Enterprises are now operating in a mixed state where some obligations are already in force, others are expected later, and internal teams are interpreting risk in different ways. That combination creates confusion long before any regulator steps in,” he said, noting that many companies will want to slow down and wait for the final regulation.</p>



<p>“That instinct is misplaced,” he said. “Waiting assumes clarity will arrive early enough to act on it. In practice, clarity tends to arrive late, unevenly, and often after internal decisions have already been made. CIOs who choose to pause are not reducing exposure. They are simply postponing the moment when that exposure becomes visible.”</p>



<p>Gogia also suggested that there are hardcore financial costs associated with waiting.</p>



<p>“There is a belief that delays reduce spend. In reality, the opposite often happens. Work that is paused has to be restarted. Teams lose context. Designs are revisited. Governance added late is more expensive than governance built in from the start,” he said. “Vendor contracts entered into without clarity become difficult to unwind. None of this shows up immediately, which is why it is often underestimated. But over time, the cost of waiting tends to exceed the cost of acting with intent.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[European Parliament delays implementation of parts of the EU AI Act]]></title>
<description><![CDATA[The European Parliament’s Thursday vote to delay parts of the EU AI Act adds more uncertainty to the already chaotic AI compliance universe. But analysts say that CIOs must proceed as though the compliance rules are in effect. 



In a statement, Parliament said that its members decided to “delay...]]></description>
<link>https://tsecurity.de/de/3385133/it-nachrichten/european-parliament-delays-implementation-of-parts-of-the-eu-ai-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385133/it-nachrichten/european-parliament-delays-implementation-of-parts-of-the-eu-ai-act/</guid>
<pubDate>Fri, 27 Mar 2026 03:01:30 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Parliament’s Thursday vote to delay parts of <a href="https://www.cio.com/article/4093400/european-commission-opts-for-simple-with-new-set-of-digital-rules.html" target="_blank">the EU AI Act</a> adds more uncertainty to the already chaotic AI compliance universe. But analysts say that CIOs must proceed as though the compliance rules are in effect. </p>



<p>In <a href="https://www.europarl.europa.eu/news/en/press-room/20260323IPR38829/artificial-intelligence-act-delayed-application-ban-on-nudifier-apps" target="_blank" rel="noreferrer noopener">a statement</a>, Parliament said that its members decided to “delay the application of certain rules on high-risk artificial intelligence (AI) systems, to ensure that guidance and standards to help companies with implementation are ready.”</p>



<p>There is a calendar problem with this, in that they voted to delay part of the AI rules in such a way that the deadlines will push right up against the date on which the EU has committed to making a final decision. </p>



<h2 class="wp-block-heading">Delay is not a reprieve</h2>



<p>Analysts and consultants were virtually unanimous in their recommendations that enterprise CIOs must not wait and must instead operate as though the rules are already in effect.</p>



<p>“It’s good that they have clarified the extension [because] previously it was a moving target,” said <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>, a Gartner VP analyst. “It’s <em>not</em> great that the final decision will happen so close to the old deadline that organizations have no choice but to proceed as originally planned. Since the first draft of the EU’s Digital Omnibus proposal back in November, our guidance to clients has been to treat any potential extension as an opportunity to better test-out and improve the process for cataloging and managing AI systems.”</p>



<p>Henein added: “The major gating factor for the current timeline was that regulators would not have been ready to enforce. This is still the case. Spain is one of a handful of countries who stood up a regulator, and even the EU AI board is behind on the kind of guidance needed by organizations to properly understand their obligations when it comes to high risk AI systems. Those obligations that, as it stands, come into effect on August 2.”</p>



<p>Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, said that the move to delay major AI Act restrictions until 2027 “leaves CIOs in a regulatory limbo, but it doesn’t change the underlying reality: enterprises still own the risk their AI systems create.”</p>



<p>“Whether Brussels enforces the rules next year or two years from now, the operational, legal, and reputational exposure from poorly governed AI is already here. CIOs shouldn’t treat the delay as a reprieve,” Levine said. “The organizations that wait for perfect regulatory clarity are the ones most likely to discover that their models have been quietly generating compliance, privacy, or safety liabilities long before any enforcement clock started ticking.”</p>



<p>Parliament proposed that “for high-risk AI systems specifically listed in the regulation–including those involving biometrics, and those used in critical infrastructure, education, employment, essential services, law enforcement, justice and border management,” the regulation would be applied on Dec. 2, 2027. For AI systems “that are “covered by EU sectoral legislation on safety and market surveillance,” it set a date of Aug. 2, 2028. The statement also noted that members are “in favor of giving providers until November 2, 2026 to comply with rules on watermarking AI-created audio, image, video or text content to indicate its origin.” </p>



<h2 class="wp-block-heading">Use time to prepare</h2>



<p><a href="https://www.infotech.com/profiles/jason-hookey" target="_blank" rel="noreferrer noopener">Jason Hookey</a>, executive counselor at the Info-Tech Research Group, said that he agreed with some of Parliament’s decision.</p>



<p>“The EU’s choice to delay high-risk AI obligations makes sense. Most people agree with the purpose of these rules, but there are concerns that organizations won’t be able to meet them without sufficient guidance, technical standards, or appropriate support. It’s important to note that the delay only changes the timeline, not the main goals around high-risk AI,” Hookey said. “Organizations that use this time well will be better prepared for compliance, control, and building market trust. Those who wait may only put off problems and miss out on the benefits of well-managed AI.”</p>



<p>Others pointed out that the European Union’s decisions are only recommendations to its many member states, who have the authority to make any changes they want for their countries. </p>



<h2 class="wp-block-heading">Procedural risk</h2>



<p>EU resolutions operate at two levels, noted <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. </p>



<p>“There is a policy decision at the EU level and there is an implementation definition at the member states level. For this reason, even after the policy is set and published, they usually leave years-long implementation times for the member states to comply and release their own legislation that will define the implementation requirements for that member state,” Villanustre said. “I don’t think this particular case will be any different, so the actual deadline may be further in the future than what the draft legislation indicates.”</p>



<p>In addition, <a href="https://www.schellman.com/about-us/leadership/doug-barbin" target="_blank" rel="noreferrer noopener">Doug Barbin</a>, president of compliance firm Schellman, warned CIOs, “there’s also a real procedural risk here: if Council and Parliament negotiations drag past August 2026, the original deadlines stay on the books. CIOs who’ve been sitting on their hands are the most exposed to that scenario. The organizations investing in governance infrastructure now won’t be the ones in crisis mode later. This is extra time — use it.”</p>



<p>Barbin said the market is slowly shifting to broader strategies. “This is where compliance is going: less around specific actions and more about governance and risk,” he said.</p>



<h2 class="wp-block-heading">High cost of waiting</h2>



<p><a href="https://www.fusioncollective.net/meet-the-team/co-founder-managing-partner/" target="_blank" rel="noreferrer noopener">Yvette Schmitter</a>, CEO of the Fusion Collective consulting firm, said she is concerned that CIOs will take the wrong message away from what the European Parliament did. </p>



<p>“I think it is bad in the sense that it gives people a false sense of security in that they have more time. [It is] trying to give them more time, but companies will never be ready,” Schmitter said. “Courts don’t care about your regulatory compliance timeline. When your AI system produces detrimental or discriminatory outcomes at scale, ‘we were waiting for final guidance’ won’t survive depositions.”</p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, argued that these decisions amount to mixed messages, which serve to deepen the AI regulatory confusion.</p>



<p>“The shift in timelines has removed a clear enforcement anchor, but it has not reduced the expectation of accountability. If anything, it has made decision-making harder. Enterprises are now operating in a mixed state where some obligations are already in force, others are expected later, and internal teams are interpreting risk in different ways. That combination creates confusion long before any regulator steps in,” he said, noting that many companies will want to slow down and wait for the final regulation.</p>



<p>“That instinct is misplaced,” he said. “Waiting assumes clarity will arrive early enough to act on it. In practice, clarity tends to arrive late, unevenly, and often after internal decisions have already been made. CIOs who choose to pause are not reducing exposure. They are simply postponing the moment when that exposure becomes visible.”</p>



<p>Gogia also suggested that there are hardcore financial costs associated with waiting.</p>



<p>“There is a belief that delays reduce spend. In reality, the opposite often happens. Work that is paused has to be restarted. Teams lose context. Designs are revisited. Governance added late is more expensive than governance built in from the start,” he said. “Vendor contracts entered into without clarity become difficult to unwind. None of this shows up immediately, which is why it is often underestimated. But over time, the cost of waiting tends to exceed the cost of acting with intent.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4150989/european-parliament-delays-implementation-of-parts-of-the-eu-ai-act.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Von oben sieht man mehr: Willkommen bei GeoGirafe (fossgis2026)]]></title>
<description><![CDATA[Jeder nutzt sie, kaum einer kennt sie: Web Components

Web Components sind eine Technologie, die in allen Browsern unterstützt und durch viele große Player eingesetzt wird.

Nun endlich gibt es auch ein OpenSource WebGIS, dass diese modulare Technik nutzt: **GeoGirafe**

GeoGirafe ist von Beginn ...]]></description>
<link>https://tsecurity.de/de/3383265/it-security-video/von-oben-sieht-man-mehr-willkommen-bei-geogirafe-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3383265/it-security-video/von-oben-sieht-man-mehr-willkommen-bei-geogirafe-fossgis2026/</guid>
<pubDate>Thu, 26 Mar 2026 13:47:53 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jeder nutzt sie, kaum einer kennt sie: Web Components

Web Components sind eine Technologie, die in allen Browsern unterstützt und durch viele große Player eingesetzt wird.

Nun endlich gibt es auch ein OpenSource WebGIS, dass diese modulare Technik nutzt: **GeoGirafe**

GeoGirafe ist von Beginn an modular und verfolgt eine &quot;no-framework&quot; Strategie.

Dieser Vortrag zeigt dir, welche Möglichkeiten es aktuell gibt und wie vielfältige Gesichter GeoGirafe annehmen kann:
- 2D/3D Karten
- Komplexe Ebenenbäume
- Themes
- Suchfunktionen
- Zeichen/Messwerkzeuge
- Profilfunktionen
- Eigene Layer hinzufügen
- Anbindung an openid connect
- WebAPI
- uvm.

Wir werden uns 3 Anwendungsfälle näher anschauen:
- Komplexes WebGIS
- Einbindung von WebKarten mittels API
- Fachapplikation

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/LPJNVA/]]></content:encoded>
</item>
<item>
<title><![CDATA[Nova Scotia Power Data Breach Compromises Data of Over 900,000 Users]]></title>
<description><![CDATA[The Nova Scotia Power data breach has forced the utility provider to commit to stronger cybersecurity and privacy safeguards after a cyberattack exposed sensitive data of more than 900,000 current and former customers. The scale of the Nova Scotia Power data breach and the nature of the compromis...]]></description>
<link>https://tsecurity.de/de/3383029/it-security-nachrichten/nova-scotia-power-data-breach-compromises-data-of-over-900000-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3383029/it-security-nachrichten/nova-scotia-power-data-breach-compromises-data-of-over-900000-users/</guid>
<pubDate>Thu, 26 Mar 2026 12:36:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1408" height="768" src="https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Nova Scotia Power Data Breach" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1.webp 1408w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-1140x622.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1.webp 1408w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/Nova-Scotia-Power-Data-Breach-1-1140x622.webp 1140w" sizes="(max-width: 1408px) 100vw, 1408px" title="Nova Scotia Power Data Breach Compromises Data of Over 900,000 Users 1"></p>The Nova Scotia Power data breach has forced the utility provider to commit to stronger cybersecurity and privacy safeguards after a cyberattack exposed sensitive data of more than 900,000 current and former customers. The scale of the Nova Scotia Power data breach and the nature of the compromised information have raised serious questions about how organizations manage and protect customer data.

The breach, discovered on April 25, 2025, was not the result of a single failure. Instead, it unfolded over weeks—highlighting how attackers can quietly move through systems before being detected.
<h3><strong>Nova Scotia Power Data Breach Linked to Malware Infection</strong></h3>
<a href="https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/2026-ns-power-ca/" target="_blank" rel="nofollow noopener">According to details</a> shared in a compliance letter, the Nova Scotia Power data breach began on or around March 19, 2025. An employee accessed a compromised website infected with “SocGholish” <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27292">malware</a> and clicked on a malicious pop-up link. This allowed the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27303">malware</a> to install and create a foothold within the network.

From there, attackers escalated their access. Between April 8 and April 22, they moved laterally across systems using domain administrator privileges, conducted internal reconnaissance, and harvested credentials. This phase is critical, and often underestimated in <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="27299">cyber</a> incidents.

By the time the Nova Scotia Power <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="27295">data breach</a> was detected, the attackers had already spent days exploring the network.
<h3>Data Exfiltration and Ransomware Deployment</h3>
The final stage of the Nova Scotia Power data breach occurred between April 23 and April 25, when the threat actor <a href="https://thecyberexpress.com/ministry-of-finance-cyberattack/" target="_blank" rel="noopener">exfiltrated data</a> from both on-premises systems and cloud storage. Shortly after, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27293">ransomware</a> was deployed, backups were destroyed, and multiple applications stopped functioning.

The attack was only discovered when employees reported system disruptions—an indication that the breach had already reached its most damaging phase.

The attackers later contacted the company via a Tor-based <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-the-dark-web/" title="dark web" data-wpil-keyword-link="linked" data-wpil-monitor-id="27296">dark web</a> page, providing proof that sensitive customer data had been accessed. However, there is no confirmed evidence so far that the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="27302">data</a> has been publicly released or sold.

Nova Scotia Power chose not to pay the ransom, aligning with law enforcement guidance.
<h3>Scope of the Nova Scotia Power Data Breach</h3>
The Nova Scotia Power data breach impacted approximately 375,000 current customers and 540,000 former customers. The compromised data includes:
<ul>
 	<li>Names, phone numbers, and email addresses</li>
 	<li>Mailing addresses and dates of birth</li>
 	<li>Account and billing history, including bank details</li>
 	<li>Driver’s license numbers and Social Insurance Numbers (SINs)</li>
</ul>
This level of exposure significantly increases the risk of identity theft and financial <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="27300">fraud</a>, making the Nova Scotia Power data breach particularly serious.
<h3>Delayed Notifications and Customer Concerns</h3>
The handling of the Nova Scotia Power data breach has also drawn scrutiny. The <a href="https://thecyberexpress.com/data-privacy-week-2026-canada-urges-privacy/" target="_blank" rel="noopener">Office of the Privacy Commissioner of Canada</a> received multiple complaints, particularly around delayed notifications and the use of mailed letters, which slowed communication with affected individuals.

Some concerns were also raised about the collection and storage of SINs, which were part of the compromised dataset.

While Nova Scotia Power informed the public on April 28 and notified regulators by May 1, direct notifications to customers began weeks later, with additional affected individuals identified months after the initial disclosure.

This staggered communication reflects the complexity of breach investigations—but also highlights the importance of timely transparency.
<h3>Response and Security Commitments</h3>
Following the Nova Scotia Power data breach, the company took steps to contain the incident. This included isolating affected systems, resetting compromised credentials, and working with third-party <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="27298">cybersecurity</a> experts to investigate and remediate the breach.

Customers were offered credit monitoring and identity protection services, initially for 24 months and later extended to five years for all customers.

More importantly, Nova Scotia Power has now committed to strengthening its <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27297">security</a> measures under a compliance agreement. The Office of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="Privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="27294">Privacy</a> Commissioner will continue to monitor progress until all commitments are fulfilled.

Privacy Commissioner Philippe Dufresne <a href="https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260325/" target="_blank" rel="nofollow noopener">stated</a>, “I welcome this commitment by Nova Scotia Power to ensure stronger protections for the personal information of its customers. This privacy breach highlights the significant <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="27301">risks</a> of cyberattacks to individuals and companies. Strong, proactive data protection, including robust safeguards, must be prioritized by all organizations in this evolving landscape.”]]></content:encoded>
</item>
<item>
<title><![CDATA[Von Sensor bis Karte: Erste Schritte mit QGIS und SensorThings API (fossgis2026)]]></title>
<description><![CDATA[Der Vortrag zeigt, wie Sensordaten über die OGC SensorThings API mit QGIS erschlossen und visualisiert werden. Von den Grundlagen des Standards über das gezielte Erkunden und Filtern der Sensordaten bis zur kartografischen Darstellung aktueller und statistischer Messwerte wird eine praxisnahe Vor...]]></description>
<link>https://tsecurity.de/de/3382928/it-security-video/von-sensor-bis-karte-erste-schritte-mit-qgis-und-sensorthings-api-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382928/it-security-video/von-sensor-bis-karte-erste-schritte-mit-qgis-und-sensorthings-api-fossgis2026/</guid>
<pubDate>Thu, 26 Mar 2026 12:02:52 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Vortrag zeigt, wie Sensordaten über die OGC SensorThings API mit QGIS erschlossen und visualisiert werden. Von den Grundlagen des Standards über das gezielte Erkunden und Filtern der Sensordaten bis zur kartografischen Darstellung aktueller und statistischer Messwerte wird eine praxisnahe Vorgehensweise mit vielen Beispielen vorgestellt.

Schlüsselwörter: SensorThings API, QGIS, Frost-Server, IoT, OGC-Standard

1	Überblick

Das Internet of Things (IoT) erzeugt unaufhörlich Daten: Pegelstände, Verkehrszählungen, Wetterwerte, Umweltmessungen und vieles mehr. Damit diese heterogenen Sensordaten nicht in proprietären Silos verschwinden, braucht es offene Standards – und genau hier setzt die SensorThings API (STA) an.
Die SensorThings API ist ein vom OGC standardisiertes Datenmodell und Schnittstelle, die Sensordaten einheitlich beschreibt und zugänglich macht. Eine der bekanntesten und weit verbreiteten Open-Source-Referenzimplementierungen dieses Standards ist der FROST-Server (FRaunhofer Opensource SensorThings).
Auch auf der Client-Seite wird Offenheit großgeschrieben: QGIS bietet eine native Schnittstelle, mit der sich jeder SensorThings-API-konforme Server direkt anbinden lässt – ohne Plugins und ohne proprietäre Erweiterungen.
Dieser Vortrag zeigt anhand eines strukturierten Workflows, wie sich Sensordaten mit QGIS von der SensorThings API bis zur Karte erschließen lassen. Die Vorgehensweise lässt sich mit dem Akronym STEFiS merken
STEFiS
*SensorThings API
*T heorie
*E rkunden
*Fi ltern
*S tylen

2	Theorie – ein ungewöhnliches Modell mit großen Vorteilen

Die theoretische Konstruktion der SensorThings API wirkt auf den ersten Blick ungewohnt. Im praktischen Einsatz zeigt sich jedoch schnell ihr großer Mehrwert:
* Jeder STA-Server sieht gleich aus: Unabhängig vom Anbieter oder Thema ist die Struktur identisch – der Inhalt hingegen bleibt eine „Wundertüte“.
* Stabile Attribute und Datentypen: Attributnamen und Wertetypen sind standardisiert und konsistent. Das vereinfacht Auswertungen, Automatisierung und Wiederverwendung erheblich.
* Die Einbindung erfolgt immer über die Datenquellenverwaltung von QGIS
* Ein klarer Weg vom Sensor zum Messwert: Der klassische Zugriff folgt immer derselben Kette: Location → Thing → Datastream → Observation (in der deutschen QGIS-Version 3.44: Ort (Punkt) → Thing → Datenstrom → Beobachtung)

3	Erkunden – vom Sensorpool zur relevanten Teilmenge

Im nächsten Schritt geht es darum, sich im Datenangebot eines STA-Servers zurecht zu finden. Typische Fragestellungen sind z.B.: „Welche Sensoren sind vorhanden?“ und „Welche davon sind für meine Fragestellung relevant?“
Die Identifikation der gewünschten Teilmenge erfolgt meist über Attribute von Location oder Thing – etwa alle Verkehrszählstellen oder alle Pegelmessungen.
Anschließend werden die Datenströme betrachtet: Eine Wetterstation besitzt beispielsweise getrennte Datenströme für Temperatur, Luftfeuchtigkeit und Luftdruck.
Der letzte Schritt der Erkundung ist die Definition der benötigten Sensorwerte. Die einfachste – und häufigste – Anfrage lautet dabei: „Gib mir den aktuellsten Messwert.“

4	Filtern – gezielt laden statt alles holen

Das Ergebnis der Erkundung wird anschließend konkret über Filterdefinitionen in der Datenquellenverwaltung von QGIS umgesetzt
Der Default-Wert einer Datenquellen-Definition sieht so aus:
•	type=PointZ
•	entity='Location' 
•	expandTo='Thing:limit=100;
•	Datastream:limit=10;
•	Observation:orderby=phenomenonTime,desc:limit=100
•	featureLimit='10000' 
•	url='https://geoportal.kreis-herford.de/iot/v1.1'
 Jeder der 4 Teile Location – Thing – Datastream – Observation kann mit verschiedenen Methoden gefiltert werden. Im Vortrag werden diese Methoden mit Beispiel-Filtern gezeigt.

5	Stylen – von Rohdaten zur aussagekräftigen Karte

Nach dem Filtern liegen die gewünschten Sensordaten in QGIS vor. Dabei gilt: Jeder Messwert erzeugt einen Punkt. Bei zehn Messwerten entstehen also zehn identische Geometrien – jeweils mit rund 30 Attributen.
Nun beginnt – je nach Anspruch - die hier typische kartografische Feinarbeit für Darstellung und Beschriftung:
•	Redundante Punkte werden visuell reduziert
•	Zeitstempel werden von UTC in Ortszeit umgerechnet
•	Über mehrere Messwerte hinweg werden statistische Kennwerte berechnet
Auch hier werden im Vortrag die wichtigsten Ausdrücke gezeigt.

6	Vortrag verpasst ?
Alles rund um das Thema wird ab dem 01.04.26 über den OpenData-Bereich des Kreis Viersen bereitgestellt: https://opendata-kreis-viersen.de/QGIS/STA/ 


Kontakt zum Autor:
Michael Stein
Kreis Viersen - Amt für Kataster und Geoinformation -
Rathausmarkt 3
41747 Viersen
02162-39-1141
michael.stein@kreis-viersen.de

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/VXTQPF/]]></content:encoded>
</item>
<item>
<title><![CDATA[Metadateneditor Berlin – Effizient erfassen, prüfen und veröffentlichen (fossgis2026)]]></title>
<description><![CDATA[Geodatensätze ohne Metadaten sind ein wenig wie Karten ohne Legende – ohne sie wird es schwierig, sich zurechtzufinden. Die Arbeit mit ihnen kann aber zur Herausforderung werden, weshalb terrestris für die Senatsverwaltung Berlin einen Metadateneditor entwickelt hat, der die Erstellung und Veröff...]]></description>
<link>https://tsecurity.de/de/3380726/it-security-video/metadateneditor-berlin-effizient-erfassen-pruefen-und-veroeffentlichen-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380726/it-security-video/metadateneditor-berlin-effizient-erfassen-pruefen-und-veroeffentlichen-fossgis2026/</guid>
<pubDate>Wed, 25 Mar 2026 16:33:12 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Geodatensätze ohne Metadaten sind ein wenig wie Karten ohne Legende – ohne sie wird es schwierig, sich zurechtzufinden. Die Arbeit mit ihnen kann aber zur Herausforderung werden, weshalb terrestris für die Senatsverwaltung Berlin einen Metadateneditor entwickelt hat, der die Erstellung und Veröffentlichung von Metadaten vereinfacht und zugleich die Anforderungen gängiger Standards erfüllt. Die Lösung fördert den Umgang mit Metadaten und ist für alle zugänglich – auch ohne spezifisches Know-how.

Metadaten sind essentieller Bestandteil von Geodateninfrastrukturen. Wer Geodatensätze oder -dienste effizient finden und verwenden will, benötigt sie. Und wer Geodatensätze bereitstellt, ist sogar dazu verpflichtet Metadaten mitzuliefern. Sie sorgen für Transparenz, Nachvollziehbarkeit und Wiederverwendbarkeit – und doch leiden sie häufig unter einem eher verstaubten Ruf. Um die Arbeit mit ihnen zu vereinfachen, hat terrestris für die Senatsverwaltung Berlin ein benutzerfreundliches, Open Source-basiertes Metadatenerfassungssystem entwickelt.
Ziel des Projekts war die Entwicklung eines Metadateneditors, der Daten effizient und strukturiert erfasst und für die Veröffentlichung in GeoNetwork opensource vorbereitet. Die Lösung basiert auf bewährten Open Source-Komponenten und konzentriert sich auf das Wesentliche: eine klare, intuitive Oberfläche, mit der Nutzende neue Datensätze anlegen, bestehende bearbeiten sowie nach festgelegten Rollen- und Rechtekonzepten prüfen und freigeben können. Automatisierte Validierungsprozesse stellen sicher, dass alle Einträge den Standards – etwa ISO 19115, ISO 19119 und INSPIRE – entsprechen. Nach erfolgreicher Prüfung können die Metadaten direkt für die Veröffentlichung bereitgestellt werden.
Im Vortrag werden die konzeptionellen und technischen Grundlagen des Projekts vorgestellt, ergänzt durch Erfahrungen aus Entwicklung und Einführung der Anwendung. Gezeigt wird, wie Metadaten mit der Lösung einfach, sicher und nachvollziehbar erfasst, geprüft und veröffentlicht werden können.
Im Mittelpunkt steht die Benutzerfreundlichkeit: vordefinierte, rollenspezifisch konfigurierte Eingabeformulare, Statusanzeigen zur Visualisierung des Bearbeitungsfortschritts sowie die Möglichkeit, bestehende Metadatensätze als Vorlagen zu nutzen oder auf integrierte Schlagwortkataloge zuzugreifen.
Der Vortrag zeigt, welchen Mehrwert die Anwendung für öffentliche Verwaltungen und alle bietet, die regelmäßig mit Metadaten arbeiten: Sie macht die Erfassung nicht nur effizienter, sondern auch übersichtlicher, nachvollziehbarer und qualitativ besser. Mit den richtigen Werkzeugen fürs Metadatenmanagement verlieren Metadaten schnell ihr verstaubtes Image – und werden zu einem echten Arbeitserleichterer für alle die Geodatensätze und -dienste einsetzen.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/NHU8SV/]]></content:encoded>
</item>
<item>
<title><![CDATA[Idea: We need an Open Source Donation Day]]></title>
<description><![CDATA[submitted by    /u/flipcoder   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3380674/linux-tipps/idea-we-need-an-open-source-donation-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380674/linux-tipps/idea-we-need-an-open-source-donation-day/</guid>
<pubDate>Wed, 25 Mar 2026 16:23:38 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/flipcoder"> /u/flipcoder </a> <br> <span><a href="https://www.reddit.com/r/opensource/comments/1s33cp5/idea_we_need_an_open_source_donation_day/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s3bagq/idea_we_need_an_open_source_donation_day/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Optimize Your iPhone Settings for Smoother Gaming Performance]]></title>
<description><![CDATA[Compared to the graphics and gameplay elements of console games, mobile games are increasingly able to match them, online features included. However, given the fact that even the most powerful iPhones have only marginal power to run highly resource-heavy games, if your device settings are not per...]]></description>
<link>https://tsecurity.de/de/3375351/ios-mac-os/how-to-optimize-your-iphone-settings-for-smoother-gaming-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375351/ios-mac-os/how-to-optimize-your-iphone-settings-for-smoother-gaming-performance/</guid>
<pubDate>Tue, 24 Mar 2026 06:37:36 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Compared to the graphics and gameplay elements of console games, mobile games are increasingly able to match them, online features included. However, given the fact that even the most powerful iPhones have only marginal power to run highly resource-heavy games, if your device settings are not perfectly optimized, your game performance may still suffer. 



The major manifestations of background activities or wrongly configured system settings are lag spikes, excessive heating of the device, frame rate drops and slow loading times. On top of that, a few changes to settings can turn your gaming experience around completely. Here is a thorough tutorial that details the major iPhone settings for smoother gameplay:



1. Turn On Game Mode (If It Is Available)







Some of the latest iOS versions contain the Game Mode feature, which is a dedicated setting to improve gaming performance. By activating this mode, the system gives prime importance to supplying CPU and GPU power to the game you are playing rather than to other background apps.



How to check: 




Go to Settings 



Look for Game Mode (it's available on certain iOS versions) 



Turn on the toggle for Game Mode 




Why This Matters: Game Mode is a temporary solution to reduce these processes and make sure that the game has the majority of the processing power of your device. As a result, you could experience less stuttering, more responsive gameplay, and constant frame rates even during quick action sequences. More so, if you are a player who regularly plays competitive games or visually intense ones, enabling Game Mode might lead to significantly consistent performance.



2. Set the Refresh Rate to the Highest



Several of the most recent iPhone versions, especially the Pro line, have ProMotion screens with 120Hz refresh rate capacity, allowing them to change the image multiple times a second (up to 120). So basically, the higher the refresh rate is, the more times a second your display gets updated, leading to a quite smooth and comfortable viewing of motion and animation effects.



How to do it: 




Open Settings



Go to Accessibility



Tap Motion



Ensure Limit Frame Rate is turned off




Why it is significant: If you turn on the Limit Frame Rate option, your display will only show an update at 60Hz. Turning it off will enable the screen to work at its highest capability. Running at a high refresh rate allows players to witness a reduction in motion blurring, an increase in aiming accuracy, and their feeling matches the character's natural movement more closely. Fast-paced games such as FPS, racing, or battle royale games will be the ones that reap the benefits of high refresh rates the most, as players will have smoother visuals



3. Disabling Background App Refresh



Nearly all apps do background content refreshing automatically to keep themselves updated. For example, social networking apps, messenger apps, or news apps receive new data regularly even when you are not using them.



Here is how you do it:




Open Settings



Tap General &gt; Background App Refresh



Turn it off, or disable it for specific apps




Why this is important: Running activities in the background uses CPU cycles, RAM, and occasionally network bandwidth. When multiple apps refresh together, your device may very briefly slow down. Disabling background refresh for apps that you don't need enables your iPhone to concentrate more of its processing power and memory on the game that you are playing at the moment. If any lag spikes occur, it is very likely in online games, which are the kind of games that, besides a stable network, also require system resources.



4. Manage Storage to Prevent Performance Decreases 







Storage space impacts your device's performance way more unless you actually realize it. For example, if your iPhone storage is almost full, the device can have a hard time making temporary files, which are needed for caching and processing.



How to check your storage usage:




Go to Settings



Tap General



Find Storage




If you go here, you can see which apps and files are taking up your space.



Ways to free up storage:




Uninstall apps you don't use



Get rid of big video files



Delete downloaded media



Remove game installations that are no longer used 




Why you should care: Whenever you permit some free space on your device, it is similar to providing iOS with a bit of room to relax. If the storage is stuffed, the games might need more time to load textures, maps, or assets, and stuttering may happen while playing. The experts recommend that one always have 10-15% of the storage space free to run the device at peak performance.



5. Switch Off Low Power Mode When You Are Gaming Low 



Power Mode is a feature that helps to increase battery life by decreasing some background activities and also limiting the performance of the processor. 



Step to verify: 




Go to Settings 



Press Battery 



Search for Low Power Mode 




Why this matters: Having this feature enabled is very handy when you are running out of battery, but at the same time, it can have a negative effect on your gaming performance. iOS purposely slows down some system processes so as to save energy, which may result in a decrease in frame rates or a delay in response. To enjoy the best gaming experience, you should disable Low Power Mode during gameplay. On the other hand, if saving battery is really your number one reason, then you might consider recharging your device or a portable charger as better options rather than lowering your gaming performance.



6. Reduce Notifications Disruption While Gaming



Disruptions caused by notifications are often underestimated. Each notification, aside from displaying banners and playing sounds, also takes help from system resources to update app icons. 



Here are ways to reduce interruptions: 




Open Settings



Tap Focus



Choose Do Not Disturb or create a Gaming Focus profile



Allow notifications only from essential contacts or apps




Why you should care: When you are constantly getting notifications during playing sessions, they not only disrupt your concentration but also affect the game directly. Sometimes, notifications will only briefly show on the screen, or they may even make gameplay pause. If you use one particular Focus mode, it helps you to continue your game without any distractions and your device will focus on the game rather than other apps.



7. Close Unused Apps Before Launching a Game 



Many individuals unknowingly maintain a dozen or more apps running in the background at the same time. Although iOS can manage the memory quite well in an isolated manner, if you have too many apps open simultaneously then it might cause those resource-hungry games to run less smoothly.



How to close apps: 




From the bottom of the screen, swipe upwards 



This opens the App Switcher



Swipe up the apps that you aren't using. 




Reasons: Closing the background apps will make your device have more free RAM and processing power. As a result, your game should operate in a smoother way, and the chance of getting laggy moments due to background running apps will be nearly eliminated. If you plan on gaming, it is indeed an excellent move to close down any streaming, social media, or web browser apps prior to the gaming session.



8. Account and Game Setup 







Configuring device settings to perform at their best constitutes only one side of the preparation. Player progress, unlocked gears and customized settings in a user's account are other aspects that many competitive games depend on. Take Fortnite as an example, your loadout and progress essentially dictate your gameplay. That is why a lot of people not only make sure that their Fortnite accounts are ready but also set up properly before proceeding to their optimized sessions. Having a fully unlocked account with the skins, equipment and features you want can even enable you to instantly engage in the game without any further setup. 



Reasons: Your account is already set up with your usual settings and content means you don't waste time opening menus and have more time to play. If you add to this an optimal device setup, the end result is a greatly improved overall gaming experience.



9. Keep iOS Updated



Apple often releases software updates that improve the operation of devices, among other things, making sure that they support new games, too.



How to update iOS:




Launch Settings



Tap General &gt; Software Update



Download and install any available updates




Reasons: Most of the time, updates contain patches to fix glitches that might negatively affect the performance of or cause crashes in certain games.Besides that, they could also feature upgrades to graphics drivers and overall stability of the system, and since these elements have a direct impact on gaming performance, you'll be able to enjoy your games more.By regularly updating your device, you make sure that your iPhone benefits from the latest optimizations that Apple has to offer.



10. Restart Your iPhone Before Long Gaming Sessions 



Restarting is a very easy method that is neglected by many users. Here’s the steps to restart:




Hold the power button and volume button simultaneously



Slide to turn the device off.



A few seconds later, turn the device on. 




Why this matters: Restarting your device will delete temporary system files, restart background processes and update memory usage. It can fix those tiny errors or slight performance issues that may stay hidden for quite a while. The best thing is to reboot your gaming device before a long gaming session or competitive match to start afresh.



Conclusion



Purchasing new hardware is not required  to boost gaming performance on your iPhone. By changing gaming settings, keeping storage clean, and system optimization, you can greatly improve your device gaming capabilities. If you focus on system resources, cutting down the background activities, and getting your device game setup both ready, then you will get the gaming experience with the lead smooth frame rates, quicker response times, and a lot less interruptions. These small improvements can really change the play, especially for mobile gamers who are into high-demand games.]]></content:encoded>
</item>
<item>
<title><![CDATA[The insider threat rises again]]></title>
<description><![CDATA[Insider threats are coming back in a consequential way.



According to the State of Human Risk Report from Mimecast, 42% of organizations have experienced an increase in malicious insider incidents over the past year, with 42% also reporting a rise in negligent incidents for the first time.



T...]]></description>
<link>https://tsecurity.de/de/3371744/it-security-nachrichten/the-insider-threat-rises-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3371744/it-security-nachrichten/the-insider-threat-rises-again/</guid>
<pubDate>Mon, 23 Mar 2026 08:06:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Insider threats are coming back in a consequential way.</p>



<p>According to the <a href="https://www.mimecast.com/resources/ebooks/state-of-human-risk/">State of Human Risk Report</a> from Mimecast, 42% of organizations have experienced an increase in malicious insider incidents over the past year, with 42% also reporting a rise in negligent incidents for the first time.</p>



<p>The report further found that organizations experienced an average of six insider-driven incidents per month at an estimated cost of $13.1 million per incident. Additionally, 66% of the 2,500 surveyed IT security and IT decision-makers expect insider-related data loss to increase over the next 12 months.</p>



<p>“Insider risk has become one of the most consequential and underestimated threats facing organizations today, not just because of the data loss it causes, but because attackers are increasingly exploiting insiders as a deliberate entry point to bypass perimeter defenses entirely,” Mimecast CISO Leslie Nielsen said in announcing his company’s research results.</p>



<p>“The data shows both careless mistakes and deliberate actions driving incidents in equal measure,” he added. “Rather than trying to manage human behavior, organizations need adaptive controls that identify high-risk actions and adjust protections in real-time, creating friction when someone accesses data they shouldn’t, regardless of whether they have valid credentials. As AI makes it easier for insiders to exfiltrate data at scale, security must meet users at the point of risk.”</p>



<h2 class="wp-block-heading">The state of insider threats today as technologies, tactics, and motivations evolve</h2>



<p>Insider threats continue to fall into two broad camps. On one side is the malicious insider who knowingly acts with the intent to harm. On the other side is a member of the organization whose impacting actions may be accidental or negligent, or in some cases manipulated by a malicious outsider.</p>



<p>According to Forrester Research’s <a href="https://url.usb.m.mimecastprotect.com/s/H7bSCA8LmLhjXjJRSQtrSGPjFQ?domain=forrester.com">2025 Security Survey</a>, 22% of data breaches in the prior 12 months were the result of internal incidents. Some 47% were due to abuse or malicious intent, 32% were due to inadvertent misuse or an accident, and 21% involved both.</p>



<p>These categories cover a wide swath of activities, says <a href="https://www.forrester.com/analyst-bio/joseph-blankenship/BIO10765">Joseph Blankenship</a>, vice president and research director at Forrester. For example, a nonmalicious insider may accidentally email protected data to someone not authorized to have it or mistakenly allow public access to a database. A disgruntled employee may actively circumvent security controls to steal sensitive information to post to embarrass the organization.</p>



<p>Although those scenarios have been around for years, new technologies, tactics, and motivations are evolving to drive, manipulate, and enable insiders, security leaders say.</p>



<p>“My background is in the intelligence community, where we studied insider threat through a well-established lens: ego, ideology, and economics. Those motivations haven’t changed. What’s changed is the operating environment and who/what qualifies as an insider,” says <a href="https://www.sans.org/profiles/chris-cochran">Chris Cochran</a>, field CISO and vice president of AI security at the SANS Institute.</p>



<p>“It’s no longer just employees. It’s contractors, fraudulent hires who gained access through identity fraud, and now AI agents operating with persistent, privileged access,” he says. “A misconfigured agent is a superuser that never sleeps. A compromised agent is an adversary with legitimate credentials moving at machine speed. If it has trusted access and can act on data, it’s an insider, witting or unwitting.”</p>



<p>The shift to remote work, Cochran adds, also removed physical and psychological barriers to insider risks. “Downloading data to a personal device doesn’t feel like espionage, and that trivialization is the risk,” he says. “Layer on economic pressure: While companies freeze hiring and suppress raises, and you have a recipe for witting insider threat at scale.”</p>



<p><a href="https://www.linkedin.com/in/nielharper/">Niel Harper</a>, executive coach and strategic advisor at Octave Digital and a board member with governance association ISACA, points to the growth of social media as another factor spurring insider threats today.</p>



<p>Social media platforms, he says, give external threat actors information they can use to bribe, trick, or entice insiders to do their bidding. “They provide a treasure trove of information for threat actors, and a threat collective can easily conduct open-source intelligence to help them understand who is susceptible to blackmail or becoming a mercenary,” he explains.</p>



<p>In such incidents, Blankenship says malicious actors often coach insiders on how to get around security controls and evade detection.</p>



<p>Employees today are also more tech savvy and have greater access to powerful digital tools, including AI, and thus are more capable of finding ways around security controls, experts say.</p>



<p>“The average staffer can now become a really high-risk threat actor,” says Harper, who is also chief trust officer at Hugo and a former CISO, including at the international police organization Interpol.</p>



<p>Moreover, AI itself can become an insider threat, Harper adds, explaining that agents can go rogue or be programmed to do so. “So AI has changed the paradigm when it comes to insider threats,” he adds.</p>



<p>Meanwhile, the modern work environment has created new scenarios that increase the insider threat risk, Harper says.</p>



<p>For example, he says the rise in the use of contractors and outsourced providers as well as people working multiple jobs can up the opportunities for both malicious and nonmalicious incidents, as does remote work, due in part to the distributed nature of digital access for such workers.</p>



<p>Hacktivism against companies, polarization, ideological divisions, economic pressures, and fears of job loss are also driving up insider risk today, Harper adds.</p>



<p>Some of these dynamics have enabled malicious actors to land work within companies to then become insider threats, says <a href="https://app.intelligentrelations.com/api/clicks?uuid=214382e8-73fd-4555-9ce9-161f79d5aff0" target="_blank" rel="noreferrer noopener">Errol Weiss</a>, CSO at Health-ISAC. These malicious actors, <a href="https://www.csoonline.com/article/4033022/how-not-to-hire-a-north-korean-it-spy-3.html">who are often from North Korea</a>, obfuscate their identities and locations so they can be hired for legitimate roles, typically in IT. The common MO is to work for as long as possible to earn money to send back to North Korea while also <a href="https://www.csoonline.com/article/3609972/north-korean-fake-it-workers-up-the-ante-in-targeting-tech-firms.html">laying the groundwork to launch some type of attack</a> when their employers uncover their true identities. “They’re monetizing their exits by stealing data or extorting their employers on their way out,” Weiss explains.</p>



<p>Additionally, threat actors are becoming more aggressive in their attempts to get insiders to do their dirty work, says <a href="https://www.linkedin.com/in/lina-dabit-7a78a8173/?originalSubdomain=ca">Lina Dabit</a>, executive director of the CISO office at Optiv Canada. They’re paying rewards to people willing to harass targeted individuals or provide personal information, such as a personal email or family members’ names. And they’re setting up honeypots, such as romance scams, to gain leverage over insiders.</p>



<p>“We’ve always had malicious insiders, but now we have coerced insiders,” Dabit says. “I think it’s just a matter of time before a threat actor shows up at someone’s home or someone’s children’s school.”</p>



<p>At the same time, technology has made it easier to facilitate such illicit activities, she and others say. In addition to threat actors using social media and other online sources to cull data they can use to entice or coerce insiders, they’re also using the <a href="https://www.csoonline.com/article/564313/what-is-the-dark-web-how-to-access-it-and-what-youll-find.html">dark web</a> to connect with insiders willing to help. A 2026 Accenture Cyber Intelligence executive summary, titled “<a href="https://www.linkedin.com/feed/update/urn:li:activity:7430252167690866688/">Rising dark-web enabled insider risk</a>,” highlighted a 69% increase in insiders offering their access to hackers in 2025 compared to 2024 and a 127% surge in hackers recruiting insiders compared with 2022.</p>



<p>“The world is different and more dangerous than it has ever been,” warns Dabit, a former unit commander with the Cybercrime Investigative Team of the Royal Canadian Mounted Police. “Do not make assumptions that threat actor groups will fit into neat little boxes like nation-state, organized crime, hacktivism, etc. Collaboration between nation state and organized threat groups, whether intentional or simply opportunistic, [is happening and there is a] blurring between organized crime, nation-state, and hacktivism. Newer groups are not adhering to reputational norms, [and the threat environment] has become a no-holds barred approach and nothing is off the table.”</p>



<h2 class="wp-block-heading">Shifting to proactive defense</h2>



<p>Organizations must be on the lookout for insider threats, Dabit and others advise.</p>



<p>“And you need mechanisms in place to look for it,” Blankenship says, highlighting the various security technologies that can detect behaviors such as unusual or unauthorized attempts to access data and systems that could indicate an insider threat. Those, of course, are in addition to all the security and data protection controls considered standard today, he adds.</p>



<p>Dabit also advises security leaders to have a plan for how to respond if they suspect or catch an insider either inadvertently or maliciously causing harm.</p>



<p>And he advises CISOs to work with the chief legal officer and the head of HR to identify employees who could be insider threats — such as those who are about to be laid off or are disgruntled.</p>



<p>Harper recommends regular employee background checks, with more rigorous ones for executives and workers with access to sensitive information or systems.</p>



<p>Cochran says most security teams have work to do to meet the insider threats that exist today.</p>



<p>“Many of the CISOs I speak with don’t feel very confident they can detect an insider threat before serious damage occurs,” he says. “What needs to change is a shift from reactive, technically focused programs to integrated ones that fuse behavioral signals with technical telemetry, and critically, organizations need to extend insider risk frameworks to non-human/ agentic identities with the same rigor they’d apply to a human employee.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PSA: prevent Nvidia dGPU from dropping out of d3cold prematurely]]></title>
<description><![CDATA[I had a little deep-dive down the rabbit-hole today. Had more success than I anticipated, so I thought my results were worth sharing. I prefer to use the iGPU on my laptop for daily driving, and use the dGPU for LLMs and the like. If you are like that, maybe this information is of use to you. I h...]]></description>
<link>https://tsecurity.de/de/3371379/linux-tipps/psa-prevent-nvidia-dgpu-from-dropping-out-of-d3cold-prematurely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3371379/linux-tipps/psa-prevent-nvidia-dgpu-from-dropping-out-of-d3cold-prematurely/</guid>
<pubDate>Mon, 23 Mar 2026 02:35:11 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I had a little deep-dive down the rabbit-hole today. Had more success than I anticipated, so I thought my results were worth sharing.</p> <p>I prefer to use the iGPU on my laptop for daily driving, and use the dGPU for LLMs and the like. If you are like that, maybe this information is of use to you. I have no idea to what extent this applies to users still running X11. I am on Wayland.</p> <p>Some of this may also apply to more recent Nvidia hardware than my Turing GPU (RTX 20xx, GTX 1650). Feel free to chime in in the comments.</p> <p>PCIe devices have a couple of defined power modes. <code>d0</code>, <code>d3hot</code>, <code>d3cold</code> and probably a few more. <code>d3cold</code> is where you want your unused PCIe devices to be if you find your laptop to be uncomfortably hot on your lap. Or you find the fan noise to be annoying. Or, you know, make your battery last <em>a lot</em> longer.</p> <p>0</p> <p>To check what power mode your dGPU is in, do:</p> <pre><code>cat /sys/class/drm/card2/device/power_state </code></pre> <p>Note: Your dGPU may be something other than card2.</p> <p>Nvidia Turing GPUs (RTX 20xx, GTX 1650) are 'supported' in the current Nvidia drivers, but the so-called GSP firmware (which is a requirement with the opensource kernel modules in the current drivers ) lacks a couple of things for Turing. For example the ability to enter <code>d3cold</code>.</p> <p>1</p> <p>The workaround for that is to stick to the <strong>580</strong>-driver series if you have Turing graphics. 580 drivers permit to <em>not</em> load the GSP firmware, while 590 enforces it. AFAIUI.</p> <p>2</p> <p>Then, in your <code>/etc/modprobe.d/nvidia.conf</code> file or it's equivalent on your choice of Linux distro, add:</p> <pre><code>options nvidia NVreg_DynamicPowerManagement=0x02 options nvidia NVreg_EnableGpuFirmware=0 </code></pre> <p>(First line is required for Turing only). Then run <code>depmod -a</code>. (Required? Can't recall)</p> <p>With this, your laptop should be able to come up with a dGPU which is in (or enters) d3cold as soon as the PC has booted to console.</p> <p>3</p> <p><strong>But:</strong> your window manager/compositor may still wake up the dGPU. Or any other program really. And most often (but not always), the dGPU will <em>not</em> drop back to <code>d3cold</code> again even if the device isn't used for anything.</p> <p>To prevent the dGPU from entering <code>d0</code> prematurely, there are two more workarounds to apply.</p> <p>First, the following two environment variables are useful:</p> <pre><code>export GSK_RENDERER=ngl export __EGL_VENDOR_LIBRARY_FILENAMES=/usr/share/glvnd/egl_vendor.d/50_mesa.json </code></pre> <p>The first is applicable to GTK-applications. The other to Wayland. (I think. I will not pretend to understand everything here.)</p> <p>Add these to your <code>~/.bashrc</code> or <code>/etc/profile</code>.</p> <p>The <strong>second</strong> workaround is to ensure that any and all chromium-based applications (including electron-applications like signal and vscode, but also a load of various web-browsers) adds the following string to it's start-up parameters:</p> <pre><code>--render-node-override=/dev/dri/renderD128 </code></pre> <p><strong>With this, my regular applications leave the dGPU alone. And I can start llama.cpp and make use of my dGPU, and whenever I terminate llama.cpp, the dGPU drops back to</strong> <code>d3cold.</code> <strong>Brilliant</strong></p> <p>Two things are still bugging me:</p> <p>A</p> <p>I have not yet found a way to reset the dGPU in a way which makes it drop back to <code>d3cold</code> when nothing uses it and it for some reason gets stuck in <code>d0</code>.</p> <p>B</p> <p>Also, unplugging and replugging power appears to do something which disables the ability to enter <code>d3cold</code>. I can only speculate about why. Possibly related to ACPI events.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ethertype"> /u/ethertype </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s0x0m5/psa_prevent_nvidia_dgpu_from_dropping_out_of/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s0x0m5/psa_prevent_nvidia_dgpu_from_dropping_out_of/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ploutus Malware: Uptick in ATM jackpotting incidents prompts FBI warning]]></title>
<description><![CDATA[Three weeks ago, renewed activity involving Ploutus ATM malware surfaced, prompting an alert from the Federal Bureau of Investigation (FBI). At the time, we published an initial breakdown covering the threat and its implications for financial institutions — an analysis that was later recognized a...]]></description>
<link>https://tsecurity.de/de/3370022/hacking/ploutus-malware-uptick-in-atm-jackpotting-incidents-prompts-fbi-warning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3370022/hacking/ploutus-malware-uptick-in-atm-jackpotting-incidents-prompts-fbi-warning/</guid>
<pubDate>Sun, 22 Mar 2026 06:19:38 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Fzglouir4yQlVAVsrBL-dw.png"></figure><p>Three weeks ago, renewed activity involving Ploutus ATM malware surfaced, prompting an alert from the <strong>Federal Bureau of Investigation (FBI)</strong>. At the time, we published an initial breakdown covering the threat and its implications for financial institutions — an analysis that was later recognized as a <strong>Top Perspective on LinkedIn</strong>, reflecting the growing industry concern around ATM-targeted attacks.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/855/1*TTOq_Q2pimXqa-CdIyHetg.png"></figure><p><a href="https://www.linkedin.com/news/story/uptick-in-atm-jackpotting-incidents-prompts-fbi-warning-7040948/">Uptick in ATM jackpotting incidents prompts FBI warning | LinkedIn</a></p><p>The recent warning has since reignited discussions across financial security circles. But beyond the headlines, a more important question emerges:</p><blockquote><strong>Why are ATMs still vulnerable to jackpotting in 2026 — and what actually works to stop it?</strong></blockquote><p>ATM attacks are no longer about fraud. They are about <strong>direct cash extraction via system-level manipulation</strong>.</p><p>Ploutus enables attackers to bypass:</p><ul><li>Card authentication</li><li>Banking systems</li><li>Transaction validation</li></ul><p>And directly command the ATM to dispense cash.</p><p>This follow-up article goes beyond surface-level analysis — delivering a <strong>deep technical breakdown</strong> of how these attacks work, why they continue to succeed, and what actually stops them in real-world environments.</p><h3>ATM Architecture: Why Jackpotting Is Possible</h3><p>Modern ATMs are not simple machines — they are <strong>specialized endpoints</strong>.</p><p>Typical characteristics:</p><ul><li>Windows Embedded / IoT operating systems</li><li>XFS (Extensions for Financial Services) middleware</li><li>Limited CPU, memory, and storage</li><li>Often network-isolated or semi-isolated</li><li>Maintained by third-party vendors</li></ul><h3>The Critical Layer: XFS Middleware</h3><p>XFS acts as the bridge between software and hardware:</p><ul><li>Cash dispenser</li><li>Card reader</li><li>PIN pad</li><li>Receipt printer</li></ul><p>Ploutus targets this layer directly.</p><p>Instead of attacking banking systems, it <strong>speaks the ATM’s native language</strong>. Once XFS is compromised, the attacker can issue dispense commands without any transaction validation.</p><h3>Ploutus Attack Chain (End-to-End)</h3><h4>Phase 1: Initial Access</h4><p>Most real-world attacks begin with <strong>physical compromise</strong>:</p><ul><li>ATM cabinet opened</li><li>USB payload inserted</li><li>Boot process manipulated</li><li>Administrative access obtained</li></ul><p>Less frequently:</p><ul><li>Network pivot via weak segmentation</li></ul><h4>Phase 2: Malware Deployment</h4><p>The payload:</p><ul><li>Injects into ATM processes</li><li>Hooks XFS APIs</li><li>Disables protections</li><li>May establish persistence</li></ul><p>Advanced capabilities:</p><ul><li>Obfuscation</li><li>Vendor-specific targeting</li><li>Encrypted triggers</li><li>Log manipulation</li></ul><h4>Phase 3: Execution</h4><p>Attackers trigger the malware via:</p><ul><li>Keypad sequences</li><li>External input devices</li><li>Time-based triggers</li></ul><p>The ATM:</p><ul><li>Executes rapid dispense commands</li><li>Bypasses transaction flow</li><li>Operates without card interaction</li></ul><h4>Phase 4: Cash-Out</h4><ul><li>Rapid cassette emptying</li><li>$20K–$200K loss per machine</li><li>Operation completed within minutes</li></ul><h3>The Real Issue: Not Advanced — Just Uncontrolled</h3><p>Despite its reputation, Ploutus often succeeds due to <strong>basic failures</strong>:</p><ul><li>No full-disk encryption</li><li>Shared or weak credentials</li><li>USB ports left exposed</li><li>Disabled or ignored alarms</li><li>Poor physical security</li></ul><p>This aligns with industry feedback:</p><blockquote><em>“Nothing super high-tech — just basics that shouldn’t exist.”</em></blockquote><p>Attackers don’t need zero-days. They need <strong>gaps in enforcement</strong>.</p><h3>Why Traditional Anti-Malware Fails in ATMs</h3><p>ATM environments impose constraints:</p><ul><li>Network isolation limits cloud-based detection</li><li>PCI compliance restricts architecture</li><li>Low hardware resources limit EDR deployment</li><li>Patch cycles are slow</li></ul><p>From the <strong>AppGuard</strong> case study:</p><blockquote>ATMs are <strong>“network isolated &amp; low-power”</strong>, making traditional detection-heavy tools impractical .</blockquote><p>This creates a mismatch:</p><ul><li>Detection tools expect connectivity and resources</li><li>ATMs provide neither</li></ul><h3>Detection vs Prevention: The Industry Divide</h3><h4>Detection-Based Approaches</h4><ul><li>Signature AV</li><li>Machine learning AV</li><li>EDR / behavioral analytics</li></ul><p>Challenges:</p><ul><li>Alert fatigue</li><li>Requires human triage</li><li>Delayed response</li></ul><h4>Prevention-Based Approaches</h4><ul><li>Application whitelisting</li><li>Zero-trust execution control</li></ul><p>Advantages:</p><ul><li>Blocks unknown binaries</li><li>Minimal overhead</li><li>Works offline</li></ul><h3>Advanced Detection Engineering (Multi-Layer Model)</h3><p>Effective detection requires <strong>correlation across three layers</strong>:</p><h4>OS-Level Detection</h4><p><strong>Key telemetry:</strong></p><ul><li><strong>Event ID 4688 </strong>→ Process creation</li><li><strong>Event ID 7045 </strong>→ Service install</li><li><strong>Event ID 1102 </strong>→ Log clearing</li><li><strong>Sysmon Event ID 1</strong></li></ul><p><strong>Indicators:</strong></p><ul><li>Execution from USB paths</li><li>Unknown binaries</li><li>Suspicious parent-child chains</li></ul><h4>USB &amp; Physical Interaction Monitoring</h4><ul><li>Kernel-PnP logs</li><li>Device insertion anomalies</li><li>Activity outside maintenance windows</li></ul><h4>XFS Middleware Monitoring</h4><p>Monitor:</p><ul><li>DLL injection into ATM processes</li><li>Unauthorized module loading</li><li>API hooking behavior</li></ul><h4>Dispense Behavior Detection (Most Reliable)</h4><p>Normal:</p><ul><li>One dispense per transaction</li></ul><p>Malicious:</p><ul><li>Rapid repeated dispenses</li><li>No card interaction</li></ul><p><strong>Rule: IF</strong></p><ul><li>Multiple dispense events<br> AND</li><li>No card/PIN validation<br> → <strong>Trigger lock immediately</strong></li></ul><h4>Cash Dispenser Telemetry</h4><p>Correlate:</p><ul><li>High dispense volume</li><li>Null transaction IDs</li><li>After-hours activity</li></ul><blockquote>Detection must happen <strong>locally and instantly</strong>.</blockquote><h3>Sigma-Style Detection Rules</h3><h4>Suspicious USB Execution</h4><pre>Process from removable media<br>AND not signed by trusted vendor<br>→ Alert</pre><h4>Log Clearing</h4><pre>EventID = 1102<br>→ High severity alert</pre><h4>Abnormal Dispense</h4><pre>dispense_count &gt; threshold<br>AND transaction == null<br>→ Critical alert + auto lock</pre><h3>XFS Injection</h3><pre>Unknown DLL in ATM process<br>→ Block / Alert</pre><h3>MITRE ATT&amp;CK Mapping (ATM Context)</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/669/1*EOz-1mOmhkRDk_6JZj7hsA.png"></figure><p>Extension: <strong>Direct Cash Extraction (ATM-specific impact</strong>)</p><h3>Proof-of-Concept (Simulation Model)</h3><h4>Lab Setup:</h4><ul><li>Windows Embedded VM</li><li>XFS simulator</li><li>Dispenser emulator</li><li>Isolated network</li></ul><h4>Simulated Events:</h4><ul><li>USB insertion</li><li>Unauthorized execution</li><li>Multiple dispense calls</li><li>Log clearing</li></ul><h4>Evaluating:</h4><ul><li>Was anomaly detected?</li><li>Was execution blocked?</li><li>Was ATM locked automatically?</li></ul><p>If response requires human triage → <strong>failure</strong>.</p><h3>Case Study: AppGuard Deployment in ATM Infrastructure (NuSource Financial, LLC)</h3><p>To understand how prevention-first security performs in real-world ATM environments, we examine an <strong>official case study provided by AppGuard</strong> documenting its deployment at <strong>NuSource Financial, LLC</strong> — a banking technology provider supporting over 700 financial institutions in the United States.</p><p>This case provides a rare operational view into how ATM malware defenses perform at scale.</p><h4>Operational Context</h4><p>NuSource Financial operates as a managed service provider for ATM infrastructure, delivering:</p><ul><li>ATM deployment and lifecycle management</li><li>Branch transformation solutions</li><li>Security services for financial institutions</li></ul><p>Their customers rely on them to ensure:</p><ul><li>Continuous ATM availability</li><li>Minimal operational complexity</li><li>Strong security without requiring internal expertise</li></ul><p>As noted in the case study, financial institutions do not want their ATMs to become IT or cybersecurity burdens .</p><h4>The Core Problem</h4><p>NuSource faced increasing pressure from:</p><ul><li>ATM jackpotting attacks</li><li>Evolving malware threats</li><li>Ineffective traditional anti-malware tools</li></ul><p>The key limitations identified were:</p><h4>Detection-Based Security Was Reactive</h4><ul><li>Detected threats after execution</li><li>Required investigation and remediation</li><li>Created operational overhead</li></ul><h4>Internet Dependency Conflicted with ATM Design</h4><p>Many tools required:</p><ul><li>Continuous Internet access</li><li>Real-time threat intelligence updates</li></ul><p>But ATM environments are:</p><ul><li>Network-isolated</li><li>Managed through controlled access</li><li>Restricted by PCI compliance</li></ul><h4>Hardware Constraints</h4><p>ATMs typically have:</p><ul><li>Low CPU and memory</li><li>Limited storage capacity</li></ul><p>This makes heavy EDR or ML-based tools impractical.</p><h4>Operational Simplicity Requirements</h4><p>NuSource emphasized that:</p><ul><li>End customers “abhor complexity”</li><li>Security must not interfere with operations</li></ul><h4>Evaluation and Decision</h4><p>NuSource evaluated multiple security models:</p><ul><li>Signature-based antivirus</li><li>Machine learning AV</li><li>Endpoint Detection &amp; Response (EDR)</li><li>Application control solutions</li></ul><p>Findings included:</p><ul><li>ML-based AV provided only marginal improvements</li><li>EDR introduced excessive alerts and investigation overhead</li><li>Most solutions required Internet connectivity</li></ul><p>This led to a strategic conclusion: <strong>Detection-heavy models were not aligned with ATM operational realities</strong></p><h3>AppGuard Approach: Prevention Over Detection</h3><p>NuSource selected AppGuard based on a <strong>prevention-first, zero-trust execution model</strong>.</p><h4>Key Design Principles</h4><ul><li>Block malicious activity before execution</li><li>Eliminate reliance on signatures</li><li>Operate without Internet connectivity</li><li>Remove need for alert triage</li></ul><p>From the case study:</p><blockquote><strong>AppGuard “blocks attacks in real-time” and does not require analysts for investigation or remediation</strong></blockquote><h3>Deployment Characteristics</h3><h4>Resource Efficiency</h4><p>AppGuard demonstrated:</p><ul><li>~10 MB disk usage</li><li>~10 MB memory usage</li><li>~0% CPU overhead (average)</li></ul><p>This is critical in ATM environments where resources are constrained.</p><h4>Operational Compatibility</h4><p>NuSource reported:</p><ul><li>No disruption to patching or configuration</li><li>No interference with system migrations</li><li>Minimal deployment complexity</li></ul><h3>Measured Outcomes</h3><p>Across deployment:</p><ul><li>Protection applied to ATMs from NCR, Hyosung, and Nautilus</li><li>No malware compromises reported</li><li>No alert triage or incident response required</li><li>No PCI compliance issues introduced</li></ul><p>From the case study:</p><blockquote><em>“Four years malware-free… no bloat, no burden, no disruptions.”</em></blockquote><h3>Technical Interpretation</h3><p>This case demonstrates a shift in security philosophy:</p><h4>Execution Control Instead of Detection</h4><p>Rather than identifying malware: The system enforces what is allowed to execute</p><h4>Offline-First Security Model</h4><ul><li>No dependency on cloud intelligence</li><li>Suitable for isolated ATM environments</li></ul><h4>Operational Simplicity</h4><ul><li>No alert fatigue</li><li>No SOC dependency for routine operations</li></ul><h4>Real-Time Prevention</h4><ul><li>Stops threats before impact</li><li>Eliminates delay between detection and response</li></ul><h3>What Actually Stops Ploutus</h3><p>Layered defense:</p><ol><li>Physical hardening</li><li>Full-disk encryption</li><li>USB lockdown</li><li>Application whitelisting</li><li>XFS monitoring</li><li>Dispense anomaly auto-stop</li><li>SOC visibility</li></ol><h3>Future Threat Evolution</h3><p>Expect:</p><ul><li>Kernel-level malware</li><li>Firmware attacks</li><li>Supply chain compromise</li><li>Lateral movement via ATM networks</li></ul><blockquote>Detection must evolve into: <strong>Autonomous interruption systems</strong></blockquote><h3>Final Assessment</h3><p>Ploutus is not unstoppable. It is successful because:</p><ul><li>Fundamentals are ignored</li><li>Detection replaces prevention</li><li>Physical security is underestimated</li></ul><p>Security that alerts after cash is dispensed is not security. Real defense requires:</p><ul><li>Execution control</li><li>Behavioral detection</li><li>Immediate response</li></ul><blockquote>Because once malware reaches XFS, <strong>the ATM is no longer in control.</strong></blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=554a944847b6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ploutus-malware-uptick-in-atm-jackpotting-incidents-prompts-fbi-warning-554a944847b6">Ploutus Malware: Uptick in ATM jackpotting incidents prompts FBI warning</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unnütze Windows-11-Funktionen loswerden: So geht es gratis und schnell]]></title>
<description><![CDATA[Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></description>
<link>https://tsecurity.de/de/3369319/downloads/unnuetze-windows-11-funktionen-loswerden-so-geht-es-gratis-und-schnell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3369319/downloads/unnuetze-windows-11-funktionen-loswerden-so-geht-es-gratis-und-schnell/</guid>
<pubDate>Sat, 21 Mar 2026 17:15:59 +0100</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/ac117d69-dcc2-4f63-9301-2f3dceb6584b.f19a67d7-36bd-44a4-94c6-eaab6f157c90.jpeg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=e230a50cecd67771f427e3f12b5177499565d135a03e2b30210588f96bb8c9a6"> Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Free and opensource software for capillary electrophoresis fragment analysis.]]></title>
<description><![CDATA[submitted by    /u/BeneficialAd7575   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3368279/linux-tipps/free-and-opensource-software-for-capillary-electrophoresis-fragment-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368279/linux-tipps/free-and-opensource-software-for-capillary-electrophoresis-fragment-analysis/</guid>
<pubDate>Sat, 21 Mar 2026 02:50:46 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/BeneficialAd7575"> /u/BeneficialAd7575 </a> <br> <span><a href="https://i.redd.it/tdod39rpy6qg1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ryvhzb/free_and_opensource_software_for_capillary/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perseus Android Malware Targets Mobile Banking Users via Fake IPTV Apps]]></title>
<description><![CDATA[A newly identified strain of Perseus Android malware is quietly infiltrating smartphones by disguising itself as television streaming apps, an approach that says a lot about where mobile threats are headed. According to researchers at ThreatFabric, this Android malware is not just another credent...]]></description>
<link>https://tsecurity.de/de/3365775/it-security-nachrichten/perseus-android-malware-targets-mobile-banking-users-via-fake-iptv-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365775/it-security-nachrichten/perseus-android-malware-targets-mobile-banking-users-via-fake-iptv-apps/</guid>
<pubDate>Fri, 20 Mar 2026 06:51:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1408" height="768" src="https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Perseus Android malware" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware.webp 1408w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-1140x622.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware.webp 1408w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/Perseus-Android-malware-1140x622.webp 1140w" sizes="(max-width: 1408px) 100vw, 1408px" title="Perseus Android Malware Targets Mobile Banking Users via Fake IPTV Apps 1"></p>A newly identified strain of Perseus Android malware is quietly infiltrating smartphones by disguising itself as television streaming apps, an approach that says a lot about where mobile threats are headed. According to <a href="https://www.threatfabric.com/blogs/perseus-dto-malware-that-takes-notes" target="_blank" rel="nofollow noopener">researchers at ThreatFabric</a>, this Android malware is not just another credential stealer. It is more invasive, more persistent, and far more aware of how people actually use their devices today.

At a time when smartphones double as banking hubs, personal diaries, and authentication tools, the emergence of Perseus Android malware highlights a worrying shift: attackers are no longer just stealing <a href="https://thecyberexpress.com/steps-to-create-unbreakable-passwords/" target="_blank" rel="noopener">passwords</a>, they are studying users.
<h3><strong>Perseus Android Malware Shows Evolution of Mobile Threats</strong></h3>
The Perseus Android malware builds on older malware families like Cerberus and <a href="https://thecyberexpress.com/phoenix-hackers-ministry-of-health-india/" target="_blank" rel="noopener">Phoenix</a>, but it doesn’t simply replicate them, it refines them. This is part of a broader trend in Android <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27106">malware</a>, where attackers reuse proven codebases and add targeted enhancements rather than reinventing the wheel.

This evolution matters. Instead of noisy, easily detectable attacks, modern mobile <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27107">security</a> threats are becoming quieter and more efficient. Perseus, for instance, leverages legitimate Android features like Accessibility Services to maintain control over infected devices. This allows it to operate in ways that mimic normal user behavior, making detection significantly harder.

The result? A <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27111">malware</a> strain that blends in rather than stands out.
<h3><strong>IPTV Apps Malware: A Familiar Trap with Higher Stakes</strong></h3>
One of the most notable aspects of the Perseus Android malware is its distribution method. It hides inside IPTV apps, streaming applications that users often download outside official app stores.

This is not accidental. IPTV apps are widely used and frequently sideloaded, especially in regions like <a href="https://thecyberexpress.com/ai-revolution-in-meta-banks/" target="_blank" rel="noopener">Turkey</a> and Italy, which are the primary targets of this campaign. Users are already conditioned to install these apps manually, lowering their guard in the process.

This tactic reflects a growing pattern in IPTV apps malware campaigns. Instead of exploiting technical <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="27109">vulnerabilities</a>, attackers exploit user behavior. It’s a subtle but effective shift—from <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/" title="hacking" data-wpil-keyword-link="linked" data-wpil-monitor-id="27104">hacking</a> systems to manipulating habits.
<h3><strong>Targeting Notes and Personal Data</strong></h3>
What sets the <strong>Perseus Android malware</strong> apart from typical Android malware is its focus on personal notes. While most malware targets login credentials or banking <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="27110">data</a>, Perseus goes a step further by scanning note-taking applications.

This is a significant escalation. Notes often contain highly sensitive information, passwords, recovery phrases, financial details, and even private thoughts. By accessing this data, attackers gain context, not just credentials.

The malware uses a command called “scan_notes” to systematically open note-taking apps and extract their contents without user interaction. This isn’t just data theft—it’s surveillance.
<h3><strong>Full Device Takeover Through Advanced Remote Control</strong></h3>
The Perseus Android malware also enables full device takeover using remote control capabilities. Through Accessibility-based sessions, attackers can monitor screens in near real time, capture user inputs, and even overlay fake interfaces to steal sensitive information.

This combination of <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-keylogging/" target="_blank" rel="noopener" title="keylogging" data-wpil-keyword-link="linked" data-wpil-monitor-id="27108">keylogging</a> and overlay attacks makes it particularly dangerous for mobile banking data theft. Users may believe they are interacting with legitimate banking apps, while in reality, their inputs are being intercepted.

In practical terms, this means attackers can not only access accounts but also initiate and authorize fraudulent transactions.
<h3><strong>Strong Evasion Tactics Make Detection Harder</strong></h3>
Another reason the Perseus Android malware is concerning is its ability to evade detection. It performs extensive environment checks to determine whether it is running on a real device or within an analysis environment.

It looks for signs like:
<ul>
 	<li>Presence of debugging tools</li>
 	<li>Emulator characteristics</li>
 	<li>Root access indicators</li>
 	<li>Unrealistic hardware or battery data</li>
</ul>
If anything seems suspicious, the malware adjusts its behavior or remains dormant. This level of anti-analysis capability shows how far mobile security threats have evolved.
<h3><strong>Perseus Android Malware Is a Sign of What’s Coming Next</strong></h3>
The Perseus Android malware isn’t just another Android malware campaign—it’s a clear signal of how mobile threats are changing. This isn’t about mass infections anymore; it’s about smarter attacks that quietly blend into everyday app usage.

What stands out is intent. From hiding inside IPTV apps to scanning personal notes and enabling full device control, Perseus Android malware shows that attackers are no longer satisfied with just stealing passwords. They want deeper access—context, behavior, and control.

That shift should not be underestimated. When malware starts targeting how people actually use their phones, not just what they store, the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="27105">risk</a> becomes harder to spot and even harder to stop.

For users, this reinforces a simple but often ignored reality: sideloading apps comes with real consequences. And for security teams, it’s another reminder that mobile threat detection needs to go beyond traditional indicators.

Perseus Android malware may be built on older code, but its execution feels current—and that’s exactly why it matters.]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS Apocalypse Could Be OpenSource's Greatest Opportunity]]></title>
<description><![CDATA[Longtime Slashdot reader internet-redstar writes: Nearly a trillion dollars has been wiped from software stocks in 2026, with hedge funds making billions shorting Salesforce, HubSpot, and Atlassian. At FOSDEM 2026, cURL maintainer Daniel Stenberg shut down his bug bounty program after AI-generate...]]></description>
<link>https://tsecurity.de/de/3360132/it-security-nachrichten/saas-apocalypse-could-be-opensources-greatest-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360132/it-security-nachrichten/saas-apocalypse-could-be-opensources-greatest-opportunity/</guid>
<pubDate>Wed, 18 Mar 2026 19:06:35 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader internet-redstar writes: Nearly a trillion dollars has been wiped from software stocks in 2026, with hedge funds making billions shorting Salesforce, HubSpot, and Atlassian. At FOSDEM 2026, cURL maintainer Daniel Stenberg shut down his bug bounty program after AI-generated slop overwhelmed his team. A new article on HackerNoon argues that most commercial SaaS could inevitably become OpenSource, not out of ideology but economics. The author points to Proxmox replacing VMware at enterprise scale and startups like Holosign replicating DocuSign at $19/month flat as evidence. The catch, the article claims, is that maintainers who refuse to embrace AI tools risk being forked, or simply replicated from scratch, by those who do.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=SaaS+Apocalypse+Could+Be+OpenSource's+Greatest+Opportunity%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F03%2F18%2F1629217%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F03%2F18%2F1629217%2Fsaas-apocalypse-could-be-opensources-greatest-opportunity%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/03/18/1629217/saas-apocalypse-could-be-opensources-greatest-opportunity?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MoveIT, Entrust, Fed Reserve, ISPs, Volt Typhoon & More - Chris Wolski - SWN #395]]></title>
<description><![CDATA[Healthcare and malware, MoveIT, Chrome won't trust Entrust, the discovery of Volt Typhoon, & more on this episode of the Security Weekly News! Segment Resources:  https://therecord.media/volt-typhoon-targets-underestimated-cisa-says Visit https://www.securityweekly.com/swn for all the latest epis...]]></description>
<link>https://tsecurity.de/de/3356551/it-security-nachrichten/moveit-entrust-fed-reserve-isps-volt-typhoon-more-chris-wolski-swn-395/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356551/it-security-nachrichten/moveit-entrust-fed-reserve-isps-volt-typhoon-more-chris-wolski-swn-395/</guid>
<pubDate>Tue, 17 Mar 2026 18:04:10 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Healthcare and malware, MoveIT, Chrome won't trust Entrust, the discovery of Volt Typhoon, &amp; more on this episode of the Security Weekly News!</p> <p>Segment Resources: <a rel="noopener" target="_blank" href="https://therecord.media/volt-typhoon-targets-underestimated-cisa-says"> https://therecord.media/volt-typhoon-targets-underestimated-cisa-says</a></p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-395">https://securityweekly.com/swn-395</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI investment paradox: Genuine transformation or FOMO at scale?]]></title>
<description><![CDATA[As Microsoft, Alphabet, Amazon and Meta plan to invest a combined $320 billion in AI technologies in 2025 based on the findings of Ropes & Gray LLP, the technology industry faces a critical question: Are we witnessing a transformative productivity revolution, or inflating the most anticipated bub...]]></description>
<link>https://tsecurity.de/de/3355382/it-security-nachrichten/the-ai-investment-paradox-genuine-transformation-or-fomo-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3355382/it-security-nachrichten/the-ai-investment-paradox-genuine-transformation-or-fomo-at-scale/</guid>
<pubDate>Tue, 17 Mar 2026 14:04:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As Microsoft, Alphabet, Amazon and Meta plan to invest a combined $320 billion in AI technologies in 2025 based on the findings of <a href="https://www.ropesgray.com/en/insights/alerts/2025/08/artificial-intelligence-h1-2025-global-report" rel="nofollow">Ropes &amp; Gray LLP</a>, the technology industry faces a critical question: Are we witnessing a transformative productivity revolution, or inflating the most anticipated bubble in market history?</p>



<p>The question isn’t academic. For CTOs and CIOs making budget decisions in 2026, the stakes couldn’t be higher. Bet too conservatively and risk competitive obsolescence as AI-powered competitors surge ahead. Bet too aggressively on unproven technology and risk joining the growing list of organizations that have poured millions into AI initiatives without measurable returns.</p>



<p>The answer reveals a market simultaneously delivering measurable productivity gains while exhibiting concerning characteristics of speculative excess. Understanding the dynamics driving investment in your organization and industry may determine whether AI becomes a transformative catalyst or an expensive cautionary tale.</p>



<h2 class="wp-block-heading">The scale of the bet</h2>



<p>AI investment has reached unprecedented levels, dwarfing previous technology cycles. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-09-17-gartner-says-worldwide-ai-spending-will-total-1-point-5-trillion-in-2025" rel="nofollow">Gartner, Inc.</a> estimates that global spending is projected to hit $1.5 trillion in 2025, climbing to over $2 trillion by 2026. Organizations increased AI infrastructure spending by 166% year over year in Q2 2025, reaching $82 billion, according to the <a href="https://my.idc.com/getdoc.jsp?containerId=prUS53894425" rel="nofollow">International Data Corporation</a>. AI-related capital expenditures accounted for 1.1% of GDP growth in H1 2025, surpassing the U.S. consumer as the primary driver of economic growth documented by <a href="https://am.jpmorgan.com/us/en/asset-management/adv/insights/market-insights/market-updates/on-the-minds-of-investors/is-ai-already-driving-us-growth/" rel="nofollow">J.P. Morgan Asset Management</a>.</p>



<p><a href="https://www.goldmansachs.com/insights/articles/why-ai-companies-may-invest-more-than-500-billion-in-2026" rel="nofollow">Goldman Sachs</a> Research notes consensus estimates have underestimated AI capex growth by more than 50% for two consecutive years. Wall Street analysts, known for aggressive growth projections, have consistently been too conservative. <a href="https://rsmus.com/insights/industries/technology-companies/tech-continues-to-bet-on-ai-future.html" rel="nofollow">RSM US LLP</a> estimates that these financial commitments extend far into the future, with Big Tech expected to dedicate $300-400 billion annually over the next eight years.</p>



<p>The velocity and magnitude of this investment cycle set it apart. During the dot-com bubble, investment ramped up over several years. With AI, we’ve seen near-vertical acceleration within months of ChatGPT’s November 2022 launch.</p>



<h2 class="wp-block-heading">The case for genuine value</h2>



<p>Enterprise adoption has accelerated dramatically, with 78% of organizations now using AI, up from 55% in 2023, according to Stanford HAI. This isn’t superficial experimentation but core workflow integration. Research done by Fullview estimates that early adopters report a $3.70 value per dollar invested, with top performers achieving returns of $10.30. <a href="https://knowledge.wharton.upenn.edu/special-report/2025-ai-adoption-report/" rel="nofollow">Wharton</a> research found 72% of enterprises formally measure AI ROI, with three-quarters seeing positive returns.</p>



<p>The productivity gains are substantial and measurable. Workers save 40-60 minutes daily, resulting in a 10% productivity improvement based on research by <a href="https://almcorp.com/blog/openai-state-of-enterprise-ai-report-2025/" rel="nofollow">ALM Corporation</a>. For a 1,000-person organization with average labor costs of $100,000, this represents $10 million in annual value. <a href="https://www.ibm.com/think/insights/enterprise-transformation-extreme-productivity-ai" rel="nofollow">IBM</a> has documented $4.5 billion in productivity savings through internal AI initiatives.</p>



<p>Specific use cases demonstrate concrete impact. Software development AI spending reached $4 billion, with 50% of developers using AI coding tools daily, based on <a href="https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/" rel="nofollow">Menlo Ventures</a> findings. Menlo also discovered healthcare AI solutions captured $1.5 billion in 2025, up from $500 million the previous year. Administrative burden has become unsustainable for many healthcare organizations, and AI-powered clinical documentation tools are delivering immediate relief.</p>



<p>Fullview noted that financial services firms report average productivity gains of 20%, with 57% of AI leaders in finance reporting ROI exceeding expectations. Loan processing accuracy has increased by 90%, while processing times have fallen by 70%. <a href="https://www.ibm.com/think/insights/enterprise-transformation-extreme-productivity-ai" rel="nofollow">IBM</a> noted that across industries, 66% of surveyed enterprises reported significant productivity gains.</p>



<p>The pattern is clear: organizations with disciplined implementation, rigorous measurement and fundamental workflow redesign are capturing substantial value.</p>



<h2 class="wp-block-heading">The warning signs mount</h2>



<p>These genuine achievements coexist with alarming indicators of speculative excess. Jamie Dimon, head of <a href="https://en.wikipedia.org/wiki/AI_bubble" rel="nofollow">JPMorgan</a>, warns that while “AI is real,” much money being invested will be wasted. Coming from one of the most influential voices in global finance, this isn’t casual skepticism but a considered assessment of systemic risk.</p>



<p>The structural concerns fall into three categories. First, circular financing has become endemic. NVIDIA’s $100 billion investment in OpenAI, in which NVIDIA funds a customer to purchase its own products, exemplifies this pattern. Michael Burry, who famously predicted the 2008 housing crisis, observes: “True end demand is ridiculously small. Almost all customers are funded by their dealers” based on an investigation by <a href="https://www.npr.org/2025/11/23/nx-s1-5615410/ai-bubble-nvidia-openai-revenue-bust-data-centers" rel="nofollow">NPR</a>. These circular arrangements make it nearly impossible to assess genuine market demand.</p>



<p>Second, companies employ increasingly complex financial engineering to keep AI debt off balance sheets. Special-purpose vehicles now represent at least $100 billion in off-balance-sheet debt. Meta’s Louisiana data center deal involves a $27 billion loan that never appears on Meta’s balance sheet, according to NPR. The structure is reminiscent of special-purpose entities that obscured risk in previous financial crises.</p>



<p>Third, valuations badly mismatch realistic revenue trajectories. OpenAI, valued at $500 billion, loses over $11.5 billion quarterly while projecting only $13 billion in annual revenue in 2025 according to <a href="https://prospect.org/2025/11/19/ai-bubble-bigger-than-you-think/" rel="nofollow">The American Prospect</a>. The company simultaneously commits to $300 billion in computing spending with Oracle over five years.</p>



<p>An <a href="https://www.technologyreview.com/2025/12/15/1129183/what-even-is-the-ai-bubble/" rel="nofollow">MIT</a> study finding 95% of generative AI initiatives are getting zero return reflects genuine monetization challenges. NPR noted that only 3% of customers currently pay for AI services. If users won’t pay directly, the business model depends entirely on indirect value capture, neither of which has been demonstrated at the scale required to justify current valuations.</p>



<h2 class="wp-block-heading">The concentration risk</h2>



<p>Market concentration has reached concerning levels. In late 2025, 30% of the S&amp;P 500 was held by just five companies, the greatest concentration in half a century. AI-related stocks accounted for 75% of S&amp;P 500 returns since ChatGPT’s launch, based on <a href="https://insights.som.yale.edu/insights/this-is-how-the-ai-bubble-bursts" rel="nofollow">Yale Insights</a> research.</p>



<p>Harvard’s Andy Wu notes that Big Tech’s hedging strategies, Microsoft outsourcing to OpenAI, Amazon supporting any model and Meta building open-source suggest these companies “don’t really think that core AI technology is a meaningful business in and of itself” in an open article in the <a href="https://news.harvard.edu/gazette/story/2025/12/should-u-s-be-worried-about-ai-bubble/" rel="nofollow">Harvard Gazette</a>.</p>



<p>The downstream customers of AI infrastructure face acute risk. Wu observes, “there’s no short-term scenario in which they are economically viable given how costly it is today”. These companies lack immediate paths to profitability.</p>



<h2 class="wp-block-heading">Distinguishing signal from noise</h2>



<p>FOMO and genuine value coexist and interact in complex ways. Fullview noted the challenge for technology leaders is separating sustainable transformation from speculative mania. Success correlates strongly with execution discipline rather than investment magnitude. Organizations achieving impact commit 20%+ of digital budgets to AI, invest 70% of AI resources in people and processes rather than technology alone, and implement rigorous oversight.</p>



<p>The size advantage is real but not deterministic. IBM determined that large enterprises report productivity gains (72%) more frequently than small businesses (55%). This gap reflects not only resource availability but also organizational maturity, change management capability and the presence of standardized processes that can benefit from automation. Small organizations can succeed, but must be even more disciplined in their use-case selection and implementation rigor.</p>



<p>The measurement gap remains the most concerning indicator separating winners from losers. Research performed by <a href="file:///G:/Articles/Foundary/.%20https:/www.larridin.com/blog/state-of-enterprise-ai-in-2025">Larridin</a> noted that while 89% of enterprises use AI, only 23% measure ROI. Without rigorous metrics, organizations cannot distinguish between genuine transformation and expensive experimentation. They’re flying blind, making continued investment decisions based on enthusiasm rather than evidence.</p>



<p>Organizations with rigorous metrics report impressive returns: 27% productivity improvement, 11.4 hours saved per knowledge worker per week and $8,700 per employee annually reported by Larridin. These organizations didn’t achieve better results by accident. They established clear baselines, systematically tracked usage and outcomes, and made data-driven decisions about scaling or pivoting. The measurement discipline itself drives better outcomes by forcing clarity about objectives and accountability for results.</p>



<h2 class="wp-block-heading">The path forward for technology leaders</h2>



<p>For technology leaders navigating 2026’s investment decisions, several principles emerge:</p>



<ul class="wp-block-list">
<li><strong>Measure relentlessly.</strong> The divide between success and disappointment correlates directly with measurement rigor. Connect AI usage to revenue per employee, cost per transaction or other metrics that matter to the business. Create dashboards that make AI’s impact visible.</li>



<li><strong>Redesign workflows fundamentally.</strong> Organizations achieving enterprise-wide impact are three times more likely to fundamentally redesign workflows rather than automate existing processes, based on research performed by <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">McKinsey &amp; Company</a>. AI’s value emerges from transformation, not incremental efficiency. The organizations seeing 10x improvements have stopped asking “how can AI help with this task” and started asking “if we could do this perfectly, what would it look like.”</li>



<li><strong>Build organizational capabilities systematically.</strong> Formal AI training programs achieve 2.7x higher proficiency and 4.1x higher satisfaction than self-guided learning, according to Larridin. The most successful organizations treat AI capability building like any other critical skill, with a structured curriculum and regular assessment.</li>



<li><strong>Maintain healthy skepticism.</strong> Federal Reserve Chair Powell notes AI differs from previous bubbles because corporations generate substantial revenue. However, risk remains significant. For corporate technology leaders, this means being selective about vendor dependencies.</li>



<li><strong>Expect longer payback periods.</strong> Fullview noted that most organizations achieve ROI within 2-4 years, substantially longer than typical technology payback periods. Early wins matter for maintaining momentum, but sustainable transformation requires patience and persistent iteration.</li>
</ul>



<h2 class="wp-block-heading">Both…and neither</h2>



<p>Current AI investment is driven by both FOMO and genuine value operating simultaneously at a massive scale. This dual reality makes navigation particularly treacherous. The technology delivers measurable productivity gains when implemented with discipline. Organizations with the right approach are capturing real value that compounds over time. Simultaneously, speculative excess, circular financing and questionable valuations suggest significant correction risk that could affect even well-managed initiatives.</p>



<p>Organizations that will thrive through this period can maintain a clear-eyed assessment of both opportunities and risks. They must invest aggressively enough to capture productivity gains and avoid competitive disadvantage while remaining disciplined enough to avoid the financial engineering and speculative commitments that characterize bubble-era excess. This requires what might seem like contradictory stances: ambitious about possibility, skeptical about hype, patient with timelines and rigorous about measurement.</p>



<p><a href="https://www.npr.org/2025/11/23/nx-s1-5615410/ai-bubble-nvidia-openai-revenue-bust-data-centers" rel="nofollow">NPR</a> noted in a recent story that 2024 Nobel Prize winner Daron Acemoglu observes: “I have no doubt that there will be AI technologies that will come out in the next ten years that will add real value and add to productivity, but much of what we hear from the industry now is exaggeration”. This balanced view captures the essential truth. AI is neither the solution to all problems nor a complete mirage. It’s a powerful set of tools that will transform many aspects of work, but transformation takes time, requires hard work and delivers unevenly across use cases and organizations.</p>



<p>Technology leaders must bet boldly on AI’s transformative potential while maintaining rigorous measurement and risk management that distinguishes sustainable transformation from speculative mania. The stakes are high, the uncertainties substantial and the need for balanced, evidence-based decision-making has never been greater. The winners won’t be those who invested most or least, but those who invested most wisely, with clear objectives, rigorous measurement and the organizational discipline to learn and adapt as this technology continues to evolve.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows aufräumen: Gratis-Tool entfernt unnötige Funktionen mit wenigen Klicks]]></title>
<description><![CDATA[Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></description>
<link>https://tsecurity.de/de/3347994/downloads/windows-aufraeumen-gratis-tool-entfernt-unnoetige-funktionen-mit-wenigen-klicks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3347994/downloads/windows-aufraeumen-gratis-tool-entfernt-unnoetige-funktionen-mit-wenigen-klicks/</guid>
<pubDate>Fri, 13 Mar 2026 19:01:12 +0100</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/ac117d69-dcc2-4f63-9301-2f3dceb6584b.f19a67d7-36bd-44a4-94c6-eaab6f157c90.jpeg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=e230a50cecd67771f427e3f12b5177499565d135a03e2b30210588f96bb8c9a6"> Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why M&A technology integrations are harder than expected. Here’s what you should look for early]]></title>
<description><![CDATA[Mergers and acquisitions are often driven by strategic growth, market expansion or operational efficiency. But one area that is frequently underestimated during the deal process is technology and that oversight can significantly change the complexity of the integration once the deal closes.



Ha...]]></description>
<link>https://tsecurity.de/de/3347754/it-security-nachrichten/why-ma-technology-integrations-are-harder-than-expected-heres-what-you-should-look-for-early/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3347754/it-security-nachrichten/why-ma-technology-integrations-are-harder-than-expected-heres-what-you-should-look-for-early/</guid>
<pubDate>Fri, 13 Mar 2026 17:04:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mergers and acquisitions are often driven by strategic growth, market expansion or operational efficiency. But one area that is frequently underestimated during the deal process is technology and that oversight can significantly change the complexity of the integration once the deal closes.</p>



<p>Having gone through several acquisitions, I have seen a consistent pattern emerge. While every integration brings a different level of complexity, many of the underlying technology challenges tend to repeat themselves.</p>



<p>In my experience, real work begins when you start to look under the hood. That is when technical debt, undocumented integrations, inconsistent data models, aging infrastructure and security gaps start to surface. The real surprises are often the things you do not initially see: Dependencies and risks that only appear once teams dig deeper.</p>



<p>Technology rarely determines whether a deal gets signed. But it often determines how difficult the integration becomes afterward, and, in some cases, the underlying technology complexity can make what initially looked like a valuable deal far less attractive than expected.</p>



<p>That is why CIOs and technology leaders must be involved early in the due diligence process. When technology diligence is treated as an afterthought, organizations risk inheriting operational complexity, cybersecurity exposure and integration timelines that are far longer than anticipated.</p>



<h2 class="wp-block-heading">Bring IT into due diligence earlier</h2>



<p>In many acquisitions, technology due diligence happens late in the process. By that point, leadership may already have expectations about the deal’s value, the integration timeline and the synergies the acquisition will deliver.</p>



<p>That is when surprises can emerge.</p>



<p>Over time, I have learned that technology diligence must go far beyond a simple inventory of systems. Understanding how those systems support the business is just as important. How data moves between applications, how reporting is generated and how security controls are implemented often matter more than the systems themselves.</p>



<p>In one integration effort, I experienced the process from the other side when the company I was working for was being acquired. As the acquiring organization began its technology diligence, it became clear that several systems were running versions that were no longer supported or were out of compliance with current standards. While those systems continued to function for daily operations, they introduced real risks for the acquiring company including security exposure, limited ability to apply patches and potential compliance concerns once integrated into a larger enterprise environment.</p>



<p>That experience reinforced how important it is for acquiring organizations to evaluate lifecycle status, supportability and compliance readiness during diligence rather than simply confirming that systems are operational.</p>



<p>Through several acquisitions, I have also found it useful to maintain a technology due diligence checklist that evolves after each integration. Every deal reveals new questions that should be asked earlier the next time. Over time, that checklist becomes one of the most valuable tools a CIO can bring to the deal process.</p>



<p>Industry research reinforces this point. In my experienc,e integrations go more smoothly when leaders treat diligence and integration planning as a discipline rather than a scramble. McKinsey’s research on merger integration highlights the importance of structured planning and governance early in the process <a href="https://www.mckinsey.org/~/media/mckinsey/business%20functions/strategy%20and%20corporate%20finance/our%20insights/how%20the%20best%20acquirers%20excel%20at%20integration/perspectives%20on%20merger%20integration.pdf" rel="nofollow">(McKinsey’s “Perspectives on merger integration”).</a></p>



<h2 class="wp-block-heading">Expect hidden complexity beneath the surface</h2>



<p>Even when a target company appears technologically mature, teams often uncover hidden complexity once integration work begins.</p>



<p>One of the most common challenges is undocumented system integrations. Many organizations operate with scripts, scheduled exports or small applications built years earlier that quietly connect systems together. These dependencies may not appear in architecture diagrams, but often support critical business processes. In some environments, the knowledge behind these integrations lives with one or two individuals, creating key man risk if that knowledge is not documented before integration begins.</p>



<p>Data is another frequent challenge.</p>



<p>Two companies may run similar applications, yet their underlying data structures can be completely different. Product hierarchies, customer definitions, vendor records and financial reporting structures often evolve independently within each organization, which makes data integration far more complex than system integration. KPMG’s research on complex deal integration highlights how misaligned data models frequently become one of the largest integration challenges organizations face (<a href="https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2024/mastering-complex-deal-and-integration.pdf" rel="nofollow">KPMG, Mastering Complex Deals and Integration, 2024</a>).</p>



<p>Technical debt is another reality that often surfaces during integration. Systems that appear functional during diligence may be built on legacy platforms that are difficult to scale or integrate with modern architecture. In other cases, organizations discover overlapping applications that perform similar functions or vendor contracts that no longer align with the combined technology strategy. These situations add unnecessary complexity and increase operational overhead across the enterprise.</p>



<p>Security is another area that requires careful attention and this is rarely about assigning blame. Smaller or growing organizations often operate with limited security resources, and their environments may evolve quickly over time. As a result, integration teams may discover outdated security controls, unknown access points or configurations that would not meet the acquiring company’s standards.</p>



<p>Given the constant news around cyber breaches and backdoor attacks, overlooking these risks can create real liability for the acquiring organization. Once an acquisition becomes public, the newly acquired company can quickly become a more attractive target for attackers, particularly if systems have not yet been integrated into the acquiring company’s security environment. Deloitte’s research on cyber risk in M&amp;A transactions highlights the importance of evaluating these risks during diligence (<a href="https://www.deloitte.com/an/en/services/risk-advisory/blogs/due-diligence-for-mergers-and-acquisitions-through-a-cybersecurity-lens.html" rel="nofollow">Deloitte on cyber risk in M&amp;A transactions</a>).</p>



<p>Cybersecurity insurance can also become a factor. Policies often require organizations to meet certain security standards and inherited vulnerabilities or aging infrastructure can complicate compliance if they are not addressed early in the integration. In some environments where governance has been limited, technology adoption can resemble the wild west with individuals deploying tools or systems outside of formal oversight, which can unintentionally introduce security gaps or backdoor access points.</p>



<p>For that reason, it is important during diligence to review security policies, understand the organizational structure responsible for technology oversight and examine licensing and system ownership. These steps help identify potential exposure and ensure the acquired environment can align with the acquiring organization’s security standards and cybersecurity insurance requirements.</p>



<p>Another pattern I have seen across acquisitions is that the type of complexity often depends on the size of the organization being acquired.</p>



<p>With smaller companies, the challenge is often that their technology environments are heavily reliant on managed service providers. Core systems may be hosted within an MSP’s infrastructure, and the acquiring organization quickly finds itself navigating contract terms, service agreements and transition timelines. In some cases, systems are tightly integrated into the MSP’s environment, which can make extracting or migrating them more complicated than expected.</p>



<p>Larger organizations present a different kind of complexity. Their environments tend to be more mature but also far more layered. Multiple systems, specialized platforms and deeper technical teams create questions about where capabilities overlap and whether the right skills exist within the combined organization.</p>



<h2 class="wp-block-heading">Integration success depends on people, process and realistic timelines</h2>



<p>Technology often receives the most attention during acquisitions, but successful integrations depend just as much on people and process.</p>



<p>Business leaders understandably want to capture the benefits of an acquisition quickly. But technology integrations rarely follow identical timelines. Each environment introduces its own architecture, technical debt and operational dependencies.</p>



<p>One lesson I have learned is that organizations improve their integration speed over time by building integration muscle. With each acquisition, teams refine their playbooks, improve governance and develop a clearer understanding of how long certain types of work actually take.</p>



<p>Realistic expectations make a difference here. When integration timelines are grounded in experience, both technology teams and business leaders can plan more effectively.</p>



<p>Just as important is ensuring technology teams are partnered with the right business leaders during integration. In several acquisitions I have been involved in, having a representative from the business, often from a business process organization, proved critical in helping bridge the gap between technology and operations.</p>



<p>These leaders help ensure that systems are not simply connected but that the underlying business processes are aligned.</p>



<p>Employees in newly acquired organizations often face uncertainty about their roles, their systems and their future within the combined company. Without clear communication and leadership, that uncertainty can slow adoption and complicate knowledge transfer.</p>



<p>Mergers and acquisitions will always introduce complexity. But when CIOs are involved early in the diligence process, prepared to uncover hidden technology dependencies, integrations become far more manageable.</p>



<p>Technology may not drive the acquisition decision itself. But in many cases, it determines whether the value of the deal is ultimately realized.</p>



<p>As AI becomes more embedded in enterprise operations, it introduces a new layer of diligence and integration considerations. CIOs will increasingly need to evaluate not only systems and infrastructure during diligence but also how AI is being used, governed and secured within the target environment.</p>



<p>Looking under the hood will only become more important as technology environments continue to evolve. The deal may be negotiated in the boardroom, but its success is ultimately decided in the integration.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 metrics to drive successful AI outcomes]]></title>
<description><![CDATA[Despite massive investments in AI last year, most businesses have struggled to achieve measurable results. In PwC’s January 2026 Global CEO Survey, 56% of CEOs reported neither increased revenue nor decreased costs from AI in the last 12 months — a statistic backed by Gartner figures that show on...]]></description>
<link>https://tsecurity.de/de/3340804/it-security-nachrichten/5-metrics-to-drive-successful-ai-outcomes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3340804/it-security-nachrichten/5-metrics-to-drive-successful-ai-outcomes/</guid>
<pubDate>Wed, 11 Mar 2026 11:07:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite massive investments in AI last year, most businesses have struggled to achieve measurable results. In <a href="https://www.pwc.com/gx/en/news-room/press-releases/2026/pwc-2026-global-ceo-survey.html" rel="nofollow">PwC’s January 2026 Global CEO Survey</a>, 56% of CEOs reported neither increased revenue nor decreased costs from AI in the last 12 months — a statistic backed by Gartner figures that show only 5% of CFOs have reported cost reductions due to AI, and only 6% have reported revenue increases. So what’s behind those dismal numbers?</p>



<p>“They’re really laser-focused on measuring the wrong things,” says Shamim Mohammad, executive VP and CITO at CarMax. “There’s a fundamental misunderstanding of how to measure AI.”</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Shamim Mohammad, Shamim Mohammad, executive VP and CITO, CarMax</p></figcaption></figure><p class="imageCredit">CarMax</p></div>



<p>Companies also tend to focus on the wrong business goals, such as boosting employee productivity without fully capturing business outcomes. An AI that saves two hours of time per software developer means nothing unless you can tell the CFO what they did with that time, and that can be hard to do. Also, some corporations have underestimated the level of organizational <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html?utm=hybrid_search">change management</a> required to achieve efficiency gains. And the metrics to assess performance, such as what percentage of any gains are directly attributable to AI and predicting the ongoing costs of running AI projects at scale, can be difficult to nail down.</p>



<p>Some CEOs who thought AI productivity gains might demonstrate value by reducing headcount or new hires have also come away disappointed. Organizations need at least a 50 to 70% productivity gain before headcount can be reduced, according to Gartner. “We’re not seeing many use cases this high,” says Nate Suda, the research firm’s senior director analyst, with most falling between no gain at all to about 30%.</p>



<p>But some organizations are achieving results by aligning with strategic business outcomes, taking a long view on ROI, and focusing on critical business goals that may or may not fall inside the purview of traditional financial metrics. So here are five key benchmarks to apply to, or check against, your AI pursuits.</p>



<h2 class="wp-block-heading">Choose the right projects and align with strategic business goals</h2>



<p>Before considering success metrics and milestones, make sure you have use cases aligned with business goals, and you’ve prioritized the most strategically important business outcomes. The business cases for AI should come from the top down, says Keith Sarbaugh, EVP and chief digital and technology officer at animal health firm Zoetis. “Working with the board, we prioritized use cases in R&amp;D and commercial business areas,” he says.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=1536%2C1024&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=1046%2C697&amp;quality=50&amp;strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=720%2C480&amp;quality=50&amp;strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Keith-Sarbaugh-EVP-and-chief-digital-and-technology-Zoetis.png?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Keith Sarbaugh, EVP and chief digital and technology, Zoetis</p>
</figcaption></figure><p class="imageCredit">Zoetis</p></div>



<p>Also, benchmark against strategic business outcomes, and benchmark spend against best-in-class organizations in your industry, adds Zar Toolan, former chief data and AI officer at Edward Jones, and current executive-in-residence at Practitioners for Practitioners, a network of expert AI and data advisors. Based on his research of category-leading organizations in the financial services sector, for example, data and AI consumes 15 to 20% of overall IT budgets, which itself constitutes 10 to12% of topline revenue for the business. “While these numbers will vary by organization, it’s important to know where and how much your key competitors are investing and divesting,” he says.</p>



<p>Non-tech leaders are often the ones deciding on AI spend, while tech leaders are responsible for implementation, Suda says, which necessitates a shared understanding of value expectations and timescales.</p>



<p>That’s what’s happening at CarMax. “The business owners sign up for the benefits, and the CFO and I review the use cases,” Mohammad says. “The cost comes out of the budget for that business unit, and accountability lies in the hands of the business unit head.”</p>



<p>When Zoetis decided to pilot an AI project to make the customer service team more productive, it measured time spent on each call, and the time required to generate a follow up. The former stayed constant while the latter improved dramatically due to AI-generated follow up recommendations. The quality of the experience improved, and the team was able to reach more customers, which was the primary success metric. Zoetis also deployed Microsoft Copilot and additional AI capabilities to democratize AI, but is now focused on bigger transformative things in the areas of supply chain and contract lifecycle management.</p>



<p>So having an overall AI strategy aligned with your organization’s business strategy is crucial. At Edward Jones, the process of setting up its data and AI strategy stretched over two years, says Toolan. The company armed advisors with gen AI tools trained against the firm’s own data, and developed advice agents to help its financial advisors quickly create plans for client portfolios using inputs from meeting notes and data in the CRM system.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=1536%2C1024&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=1046%2C697&amp;quality=50&amp;strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=720%2C480&amp;quality=50&amp;strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Zar-Toolan-executive-in-residence-Practitioners-for-Practitioners.jpg?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Zar Toolan, executive-in-residence, Practitioners for Practitioners</p>
</figcaption></figure><p class="imageCredit">Technology Partners</p></div>



<p>“It takes internal research, matches that with the client’s plan, and gives recommendations about how to implement the plan for the client,” he says. Advisor teams saved about one person day per week and could get back to clients faster. “They could go deeper with clients, had better client satisfaction scores, and client outcomes were better aligned with what was most important to their goals,” he adds.</p>



<p>AI that improves customer service can also have a direct impact on the P&amp;L sheet. For example, a reduction in customer churn avoids revenue losses, while an increase in conversions leads to higher sales. The trick lies in measuring the change in revenues and determining what percentage of any impacts are directly related to AI.</p>



<p>Still, other projects may have strong financial benefits that are less visible. For example, using AI to improve capital use through better sales and AP forecasting can substantially improve the working capital cycle and average revolving debt utilization, effectively increasing liquidity. “As you increase accuracy, the amount of working capital or revolving debt interest payments decreases.</p>



<p>“Both can increase free cash flow and therefore are often considered functionally the same as cost savings, even though they show up in different places,” Suda says, “like working capital reduction in cash flow, and revolving debt interest expense reduction on the income statement/P&amp;L.”</p>



<p>For some AI projects the goal may be simply keeping ahead of users already familiar with tools like ChatGPT. There’s the risk that if you don’t provide basic gen AI tools in the enterprise, employees will push company data into publicly available tools for analysis. <a href="https://www.cio.com/article/4095393/6-strategies-for-cios-to-effectively-manage-shadow-ai.html?utm=hybrid_search">That risk</a> may be a larger one than having your own Copilot or GPT solutions.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2025/07/afshean-talasaz-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1240" height="698" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Afshean Talasaz, former SVP and CTO, Colonial Pipeline</p></figcaption></figure><p class="imageCredit">Colonial Pipeline</p></div>



<p>But gen AI is becoming a must-have part of every office worker’s toolset. “How do you measure the value of Excel in an organization,” asks Afshean Talasaz, former SVP and CTO at Colonial Pipeline. “Everyone uses it, but no one asks if you need it anymore. We’re not there yet with gen AI, but it’s certainly a possible outcome as ways of working, costs, and expectations around AI change in the enterprise.” </p>



<h2 class="wp-block-heading">Know your true costs</h2>



<p>When <a href="https://www.cio.com/article/4114010/2026-the-year-ai-roi-gets-real.html?utm=hybrid_search">projecting ROI</a>, the investment or cost denominator can be tricky to nail down. Unlike traditional IT projects, the costs to build an AI are smaller than the ongoing run costs, especially at scale. “AI flips the script, and you need to plan for that,” says Suda. “For CIOs, this isn’t a cost dynamic they’re used to.”</p>



<p>That’s especially problematic because the stakes can be so high as the cost of both individual AI projects and the underlying data, infrastructure, and governance work that must be completed to support those efforts heighten risks of failure. “I’ve been in technology for 25 years and this is the most expensive and complex thing I’ve ever worked on,” says Sarbaugh.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=1536%2C1025&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=1045%2C697&amp;quality=50&amp;strip=all 1045w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=719%2C480&amp;quality=50&amp;strip=all 719w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Nate-Suda-senior-director-analyst-Gartner.jpg?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Nate Suda, senior director analyst, Gartner</p>
</figcaption></figure><p class="imageCredit">Gartner</p></div>



<p>But not all projects are expensive, says Talasaz. “I’ve seen projects that don’t cost a lot and I’ve seen others in the millions.” The cost of a given AI project depends in part on if an organization has internal staff that can build and develop AI projects or rely on external partners; if it’s already addressed data and infrastructure requirements or if it’s fully digital and in the cloud.  </p>



<p>How you measure success matters when it comes to ROI, says Talasaz. Most projects sit on top of common platforms that can be costly to set up, and how those costs are allocated affects the economics of AI projects. That’s why, he says, project economics matter, but it can be challenging to get the full picture depending on the project. There’s a degree of innovation and uncertainty in those that can take on characteristics of risk capital projects, similar to drug discovery in pharma, or oil and gas exploration. “Articulating financial metrics for AI projects is more effective at a portfolio level, where data and AI infrastructure investments, platforming, scalability, expectations, time to adoption uncertainties, and interconnectedness to other use cases can be more effectively measured,” he says.</p>



<p>The FinOps Foundation’s FinOps for AI working group is hashing out how to measure the value of AI projects at a more granular level since 98% of enterprises are managing AI spends, up from 31% two year ago, according to the Foundation’s recent <a href="https://data.finops.org/" rel="nofollow">State of FinOps Survey</a>.</p>



<p>While the financial reporting indicators are the same, the data needed to compile those metrics differ, which can be difficult to obtain. “With AI, success is measured in tokens instead of minutes, or <a href="https://www.cio.com/article/4018578/why-cios-see-apis-as-vital-for-agentic-ai-success.html?utm=hybrid_search">API</a> calls instead of usage hours and minutes,” says Rob Martin, FinOps fellow at the Foundation. “And, unfortunately, a lot of the cost and usage data doesn’t come with the billing data.” So this leaves organizations with no choice but to collect it through API proxies or by using third-party products.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=1536%2C1025&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=1045%2C697&amp;quality=50&amp;strip=all 1045w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=719%2C480&amp;quality=50&amp;strip=all 719w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2026/02/Rob-Martin-FinOps-fellow-The-FinOps-Foundation.png?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Rob Martin, FinOps fellow, The FinOps Foundation</p>
</figcaption></figure><p class="imageCredit">The FinOps Foundation</p></div>



<p>But models can’t always tell you how many tokens were used. “AI costs and service availability are more volatile, so you may not be able to predict the costs of operating your model at scale,” Martin adds. That’s forced many IT executives to forecast costs in ranges rather than using fixed numbers. So he recommends forming an AI investment council or tiger team chaired by the CIO that includes all stakeholders involved in AI spending, and an experienced executive who can help create a FinOps scope for spending, incrementally fund competing projects, develop a plan to gather and analyze data, and translate performance metrics to the board.</p>



<h2 class="wp-block-heading">Prioritize for success </h2>



<p>Of the 10 AI value metrics Gartner has identified, productivity is on the lowest end of the spectrum. Projects that improve capital use, reduce losses, <a href="https://www.cio.com/article/3966301/customer-centric-it-strategies-for-delivering-winning-customer-experiences.html?utm=hybrid_search">improve customer experience</a>, or help with new products have a much greater potential for revenue growth.</p>



<p>Then operational metrics like net promote score, output per hour, and backlog reduction are all about return on employees, while financial measures such as average labor cost per worker, sales and conversion rates, and losses avoided focus on ROI. Leading indicators like traffic and clicks, and market share growth are all about what Gartner calls return on future.</p>



<p>For Toolan, there are certain AI scorecard benchmarks that every business should follow, tailored to each set of circumstances. Evaluate the AI strategy, technology stack, or platform, assess AI readiness relating to mindsets and skillsets of employees adopting the technology, and measure the results against desired business outcomes. “These need to be very industry- and sector-specific, and tailored to where your organization is on its AI journey,” he says.</p>



<p>But traditional financial metrics aren’t always the most important measures for desired business outcomes. For example, the business goal may be to improve customer satisfaction through measures such as NPS surveys. But they have limits. “You have to rely on survey answers, and it’s tempting to overstate the value of the improvement,” says Sarbaugh.</p>



<p>At CarMax, the most important metrics for its two major AI projects include customer satisfaction, conversions, and sales. The online auto retailer built its Skye AI assistant to help customers navigate the buying process; and Rhodes, a virtual agent, guides call center associates by providing questions to ask customers, quickly surfacing needed documents, and helping them navigate state rules, regulations, and policies.</p>



<p>“Time savings is a good metric to have, but what we look at are the business outcomes it’s driving,” says Mohammad. “What are we doing with the time that’s freed up to create more value for the company.”</p>



<p><a href="https://www.cio.com/article/4090235/measuring-and-scaling-ai-agent-value-beyond-productivity-gains.html?utm=hybrid_search">NPS scores</a> show a better customer experience, while the combination of Skye and Rhodes has generated higher conversion rates and elevated sales. “It’s about the elevation of the associates’ role from an information retriever to a trusted advisor,” he adds. “Roles are converging, what people do is getting redefined and processes are getting reengineered.”</p>



<h2 class="wp-block-heading">Prepare your users and track acceptance rates</h2>



<p>Even the best laid plans for AI will fail if users won’t adopt it, so user acceptance is yet another critical metric that requires advanced planning. It’s not enough to just train the AI models — you have to train people how to use AI and personalize it to their role in the organization. “It has to be a great experience in their flow of work,” Toolan says. “If it’s not, you’ll see a lower sentiment score and poor AI adoption.”</p>



<p>At first, says Sarbaugh, Zoetis underestimated the investment needed to make in change management since early on it was about how to move quickly. “We assumed if we built it they would come, but you won’t see value if users don’t understand how to incorporate it into their day-to-day work,” he says.</p>



<h2 class="wp-block-heading">Think long-term value — and trust your judgement</h2>



<p>At CarMax, the AI project metrics conveyed to top management fall into four areas: ROI, revenue impact, cost efficiency, and strategic value or the capability to gain a competitive advantage.</p>



<p>When presenting the business value of AI projects, include a value exposure measure, Talasaz says. Each AI use case may require changes to data, processes, and platforms or create new capabilities that may enable other projects to leverage those investments. “It opens the door for other things,” he says. “It’s usually a qualitative element as you may not know the costs and benefits for those other projects in detail yet, but there’s value in knowing that the current project is strategically opening up other capabilities.” And if a project will be a competitive differentiator, you need success measures for that as well.</p>



<p>When pitching a project, Talasaz adds he sets expectations transparently. “It’s important to provide scenarios, not just one financial metric, so provide a range of outcomes and the underlying assumptions and factors that impact those outcomes,” he says. For example, he’ll paint a picture that includes expected outcomes based on different adoption or implementation rates. “Leaders want to understand how all of the dots connect and what the bigger picture is,” he continues.</p>



<p>Ultimately the success metrics that matter are those that show the impact on P&amp;L, and how the AI use case affects the employee experience. “Any chance you get to put a quantitative metric at any step in the process, do it,” says Sarbaugh. “But with the newness of AI, and being in the early stage of adoption, there’s an element to things that can’t be measured at the moment. So there’ll be times when you have to trust the judgments of the people who understand the business. Just use common sense and make sure you don’t overstate the results.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Age Assurance Laws and Open Source]]></title>
<description><![CDATA[This report, "Age Assurance Laws and the End of General Purpose Computing California AB 1043, Colorado SB 26-051, KOSA, and the EU's Parallel Path Open Source Elimination, Trillion-Dollar Market Transfer, and the Hardware Attestation Endgame", authored in March 2026, looks at a coordinated wave o...]]></description>
<link>https://tsecurity.de/de/3334879/linux-tipps/age-assurance-laws-and-open-source/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3334879/linux-tipps/age-assurance-laws-and-open-source/</guid>
<pubDate>Mon, 09 Mar 2026 07:05:06 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This report, "Age Assurance Laws and the End of General Purpose Computing California AB 1043, Colorado SB 26-051, KOSA, and the EU's Parallel Path Open Source Elimination, Trillion-Dollar Market Transfer, and the Hardware Attestation Endgame", authored in March 2026, looks at a coordinated wave of US state and federal legislation mandating age assurance at the operating system level. It examines laws like California's AB 1043, Colorado's SB 26-051, the federal Kids Online Safety Act (KOSA), and recent COPPA amendments, arguing they collectively pose an existential threat to open source software by creating insurmountable compliance burdens that force privatization, enable surveillance, and ultimately pave the way for hardware-level controls that would end general-purpose computing.</p> <p>The Core Problem: These laws require operating systems to collect user age data and provide it to applications via APIs. While framed as child protection, the report contends this creates an impossible compliance burden for community-driven open source projects. Unlike corporations, volunteer-run projects lack the legal entities, revenue streams, and paid staff to implement mandated features, conduct security audits, or afford liability insurance. This creates an unfunded obligation—regulatory expectations imposed without resources to meet them—that makes open source legally non-viable.</p> <p>Key Issues Facing Open Source:</p> <ol> <li>Unfunded Compliance Obligations: Open source projects cannot absorb costs that corporations treat as routine business expenses. The report details required elements—written security programs, designated compliance coordinators, annual risk assessments, third-party audits, and liability insurance—that are structurally impossible for volunteer projects. Compliance cost estimates range from thousands to hundreds of thousands of dollars, with insurance unattainable for projects lacking formal legal entities.</li> <li>Loss of User Base Through Geoblocking: Faced with impossible compliance requirements, projects like MidnightBSD and the DB48x calculator have announced they will exclude California and Colorado users entirely. Each such announcement transfers users in the nation's most populous states to corporate alternatives like Windows, macOS, or corporate-backed Linux distributions. This loss of user base represents the first stage of market exclusion.</li> <li>Market Transfer Mechanism: The report argues this is not merely about open source dying, but about its market share being systematically transferred to corporate entities. When open source projects geoblock or shut down, users migrate to corporate-controlled operating systems. This eliminates the competitive constraint that free open source alternatives placed on corporate pricing. A Harvard-backed study cited in the report estimates the demand-side value of open source at approximately $8.8 trillion, with businesses needing to spend 3.5 times more on software if open source disappeared.</li> <li>Forced Privatization: The compliance burden creates multiple pathways that push open source toward corporate control: acquisition by companies that can afford compliance, dual-licensing models where only paid versions are compliant, or service-layer mandates that shift users from local software to cloud services. The effect is the transformation of community-developed software into corporate-controlled products, eliminating the public good aspect of open source.</li> <li>Surveillance Infrastructure: The data collection required for "compliance" creates infrastructure equally usable for mass surveillance. Age verification APIs, parental control tools, and reporting mechanisms built for child safety can be repurposed for government monitoring. Open source software, which by design resists this through transparency and user control, is eliminated as the last privacy-preserving option. The FTC has endorsed "portable" age verification that would follow users everywhere, creating the technical foundation for universal digital ID.</li> <li>Hardware Attestation Endgame: The report warns that current laws are merely stepping stones to hardware-level attestation. KOSA Section 107 already mandates a study of "device or operating system level age verification systems," including "potential hardware and software changes." Future federal legislation could require Trusted Platform Modules to cryptographically validate that only certified, compliant operating systems can boot on new devices. This would make open source operating systems impossible to run on any new hardware sold in the United States, regardless of user sophistication, and criminalize circumvention. The EU is simultaneously funding hardware root-of-trust research, indicating global convergence.</li> </ol> <p>The Unified Theory: The report argues these effects are not accidental. The regulatory framework serves convergent government and corporate interests: governments gain universal surveillance infrastructure and control over computing environments, while corporations gain market monopoly, pricing power, and the elimination of free competitors. Because government action creates these barriers, they are exempt from antitrust scrutiny under the state action doctrine, despite achieving results that would be illegal if corporations accomplished them alone.</p> <p>Conclusion: The trajectory of these laws leads to an inescapable outcome: open source software becomes legally non-viable in regulated markets, control shifts to corporations with compliance resources, surveillance becomes structurally inevitable, consumer costs rise as free alternatives disappear, and hardware attestation permanently locks this system in place. For those who value privacy, user autonomy, and the right to control their own devices, the report argues this represents not a warning but a present reality.</p> <p>The report is available at <a href="http://samtrevino.substack.com/">samtrevino.substack.com</a> and can be freely downloaded in PDF or Word format.</p> <h1>opensource #linux #tech</h1> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/urbancatwalk"> /u/urbancatwalk </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ros74x/age_assurance_laws_and_open_source/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ros74x/age_assurance_laws_and_open_source/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Age Assurance laws]]></title>
<description><![CDATA[This report, "Age Assurance Laws and the End of General Purpose Computing California AB 1043, Colorado SB 26-051, KOSA, and the EU's Parallel Path Open Source Elimination, Trillion-Dollar Market Transfer, and the Hardware Attestation Endgame", authored in March 2026, looks at a coordinated wave o...]]></description>
<link>https://tsecurity.de/de/3334861/linux-tipps/age-assurance-laws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3334861/linux-tipps/age-assurance-laws/</guid>
<pubDate>Mon, 09 Mar 2026 06:51:39 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This report, "Age Assurance Laws and the End of General Purpose Computing California AB 1043, Colorado SB 26-051, KOSA, and the EU's Parallel Path Open Source Elimination, Trillion-Dollar Market Transfer, and the Hardware Attestation Endgame", authored in March 2026, looks at a coordinated wave of US state and federal legislation mandating age assurance at the operating system level. It examines laws like California's AB 1043, Colorado's SB 26-051, the federal Kids Online Safety Act (KOSA), and recent COPPA amendments, arguing they collectively pose an existential threat to open source software by creating insurmountable compliance burdens that force privatization, enable surveillance, and ultimately pave the way for hardware-level controls that would end general-purpose computing.</p> <p>The Core Problem: These laws require operating systems to collect user age data and provide it to applications via APIs. While framed as child protection, the report contends this creates an impossible compliance burden for community-driven open source projects. Unlike corporations, volunteer-run projects lack the legal entities, revenue streams, and paid staff to implement mandated features, conduct security audits, or afford liability insurance. This creates an unfunded obligation—regulatory expectations imposed without resources to meet them—that makes open source legally non-viable.</p> <p>Key Issues Facing Open Source:</p> <ol> <li>Unfunded Compliance Obligations: Open source projects cannot absorb costs that corporations treat as routine business expenses. The report details required elements—written security programs, designated compliance coordinators, annual risk assessments, third-party audits, and liability insurance—that are structurally impossible for volunteer projects. Compliance cost estimates range from thousands to hundreds of thousands of dollars, with insurance unattainable for projects lacking formal legal entities.</li> <li>Loss of User Base Through Geoblocking: Faced with impossible compliance requirements, projects like MidnightBSD and the DB48x calculator have announced they will exclude California and Colorado users entirely. Each such announcement transfers users in the nation's most populous states to corporate alternatives like Windows, macOS, or corporate-backed Linux distributions. This loss of user base represents the first stage of market exclusion.</li> <li>Market Transfer Mechanism: The report argues this is not merely about open source dying, but about its market share being systematically transferred to corporate entities. When open source projects geoblock or shut down, users migrate to corporate-controlled operating systems. This eliminates the competitive constraint that free open source alternatives placed on corporate pricing. A Harvard-backed study cited in the report estimates the demand-side value of open source at approximately $8.8 trillion, with businesses needing to spend 3.5 times more on software if open source disappeared.</li> <li>Forced Privatization: The compliance burden creates multiple pathways that push open source toward corporate control: acquisition by companies that can afford compliance, dual-licensing models where only paid versions are compliant, or service-layer mandates that shift users from local software to cloud services. The effect is the transformation of community-developed software into corporate-controlled products, eliminating the public good aspect of open source.</li> <li>Surveillance Infrastructure: The data collection required for "compliance" creates infrastructure equally usable for mass surveillance. Age verification APIs, parental control tools, and reporting mechanisms built for child safety can be repurposed for government monitoring. Open source software, which by design resists this through transparency and user control, is eliminated as the last privacy-preserving option. The FTC has endorsed "portable" age verification that would follow users everywhere, creating the technical foundation for universal digital ID.</li> <li>Hardware Attestation Endgame: The report warns that current laws are merely stepping stones to hardware-level attestation. KOSA Section 107 already mandates a study of "device or operating system level age verification systems," including "potential hardware and software changes." Future federal legislation could require Trusted Platform Modules to cryptographically validate that only certified, compliant operating systems can boot on new devices. This would make open source operating systems impossible to run on any new hardware sold in the United States, regardless of user sophistication, and criminalize circumvention. The EU is simultaneously funding hardware root-of-trust research, indicating global convergence.</li> </ol> <p>The Unified Theory: The report argues these effects are not accidental. The regulatory framework serves convergent government and corporate interests: governments gain universal surveillance infrastructure and control over computing environments, while corporations gain market monopoly, pricing power, and the elimination of free competitors. Because government action creates these barriers, they are exempt from antitrust scrutiny under the state action doctrine, despite achieving results that would be illegal if corporations accomplished them alone.</p> <p>Conclusion: The trajectory of these laws leads to an inescapable outcome: open source software becomes legally non-viable in regulated markets, control shifts to corporations with compliance resources, surveillance becomes structurally inevitable, consumer costs rise as free alternatives disappear, and hardware attestation permanently locks this system in place. For those who value privacy, user autonomy, and the right to control their own devices, the report argues this represents not a warning but a present reality.</p> <p>The report is available at <a href="http://samtrevino.substack.com/">samtrevino.substack.com</a> and can be freely downloaded in PDF or Word format.</p> <h1>opensource #linux #tech</h1> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/urbancatwalk"> /u/urbancatwalk </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rorz1r/age_assurance_laws/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rorz1r/age_assurance_laws/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das stört mich an Linux Mint - immer noch die beste Linux Distribution?]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 26x - Views:195 In diesem Video zeigt Jean, wo er aktuell noch Verbesserungsbedarf in Linux Mint sieht und warum es trotzdem noch die aus seiner Sicht beste Linux Distribution ist.
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schre...]]></description>
<link>https://tsecurity.de/de/3330493/linux-tipps/das-stoert-mich-an-linux-mint-immer-noch-die-beste-linux-distribution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3330493/linux-tipps/das-stoert-mich-an-linux-mint-immer-noch-die-beste-linux-distribution/</guid>
<pubDate>Fri, 06 Mar 2026 15:23:53 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 26x - Views:195 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/pRkT9qB8DR8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean, wo er aktuell noch Verbesserungsbedarf in Linux Mint sieht und warum es trotzdem noch die aus seiner Sicht beste Linux Distribution ist.<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Über Timeshift: https://youtu.be/3cTeIIyNk_s<br />
- Unterstütze mein Issue auf Github, um die Verschlüsselung des Home-Ordners im Linux Mint-Installer auszublenden.: https://github.com/linuxmint/ubiquity/issues/104<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Intro<br />
01:10 persönliche Ordnerverschlüsselung<br />
04:45 das neue Startmenü<br />
06:35 langsame Anwendungsverwaltung<br />
09:00 Timeshift<br />
11:50 AppImages und Snap<br />
16:32 Update-Politik<br />
20:14 Vorschaubild im Dateimanager<br />
24:32 Druckerfehler<br />
26:54 Zeichenprogramm<br />
29:55 Spiegelserver<br />
32:34 /boot läuft voll<br />
37:09 Weitere Punkte<br />
42:04 Fazit<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linuxmint #opensource #freesoftware #foss #linux<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium), Fedora (freerdp, libsixel, opensips, and yt-dlp), Mageia (python-django, rsync, and vim), Red Hat (go-rpm-macros and osbuild-composer), SUSE (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-imp...]]></description>
<link>https://tsecurity.de/de/3330492/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3330492/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 06 Mar 2026 15:23:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium), <b>Fedora</b> (freerdp, libsixel, opensips, and yt-dlp), <b>Mageia</b> (python-django, rsync, and vim), <b>Red Hat</b> (go-rpm-macros and osbuild-composer), <b>SUSE</b> (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-importer, cpp-httplib, docker, docker-stable, expat, firefox, gnutls, go1.25-openssl, golang-github-prometheus-prometheus, haproxy, ImageMagick, incus, kernel, kubevirt, libsoup, libsoup2, mchange-commons, ocaml, openCryptoki, openvpn, php-composer2, postgresql14, postgresql15, python-Authlib, python-azure-core, python-nltk, python-urllib3_1, python311-Django4, python311-pillow-heif, python311-PyPDF2, python313, python313-Django6, qemu, rhino, roundcubemail, ruby4.0-rubygem-rack, sdbootutil, and wicked2nm), and <b>Ubuntu</b> (less, nss, python-bleach, qtbase-opensource-src, and zutty).]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows nach Wunsch anpassen: Gratis-Tool entfernt unnötige Funktionen]]></title>
<description><![CDATA[Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></description>
<link>https://tsecurity.de/de/3328786/downloads/windows-nach-wunsch-anpassen-gratis-tool-entfernt-unnoetige-funktionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328786/downloads/windows-nach-wunsch-anpassen-gratis-tool-entfernt-unnoetige-funktionen/</guid>
<pubDate>Thu, 05 Mar 2026 20:15:48 +0100</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/ac117d69-dcc2-4f63-9301-2f3dceb6584b.f19a67d7-36bd-44a4-94c6-eaab6f157c90.jpeg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=e230a50cecd67771f427e3f12b5177499565d135a03e2b30210588f96bb8c9a6"> Microsoft liefert für Windows 11 immer wieder neue Funktionen, doch die finden längst nicht alle nützlich. Ein Opensource-Tool hilft dabei, das System so zu formen, wie Sie es wollen.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,19ms -->